VLDB 2026 Research / reviewers in the wild / expert
Zouheir Trabelsi
dblp:40/6418
· DBLP profile ↗
56ranked-venue papers
28as first author
16since 2021 · last 2026
0000-0001-8686-8975ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Applied, interdisciplinary, general and emerging computing · 20 · 11 first-author · 9 since 2021Human-computer interaction and ubiquitous computing · 14 · 10 first-author · 6 since 2021Security and privacy · 13 · 8 first-author · 1 since 2021Computer networks · 10 · 5 first-author · 3 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | A Quantum-Resilient Sharded Blockchain Framework for Secure V2X and Federated Learning in Intelligent Transportation SystemsabstractThe emergence of large-scale quantum computers threatens the security of classical public-key cryptosystems, making it essential to adopt post-quantum (PQ) security in Intelligent Transportation Systems (ITS). We introduce a framework that blends quantum-resilient cryptographic primitives with a sharded blockchain architecture. Each shard maintains a local ledger for its vehicle group, enabling real-time transactions and efficient certificate management without overloading any single chain. A lightweight global chain periodically anchors all shards, preserving system-wide consistency and blocking malicious revocations. Vehicles register or revoke PQ credentials via a lightweight Proof-of-Stake consensus, while roadside units (RSUs) handle signature verification to offload on-board computation. We further demonstrate practicality through a federated-learning case study in which vehicles exchange signed model updates over the same secure channel. SUMO/TraCI simulations with 2 000 vehicles and 10 shards show that despite PQ overhead the system sustains near real-time delays and high throughput. The framework thus offers a decentralized, quantum-resilient solution for secure Vehicle-to-Everything communications in next-generation ITS. Tariq Qayyum, Zouheir Trabelsi, Asadullah Tariq, Mohamed Adel Serhani, Shabir Ahmad |
IEEE Trans. Intell. Transp. Syst. | 2 |
| 2025 | Integrating Generative AI in Cybersecurity CurriculaabstractArtificial intelligence technologies with generative capabilities have accelerated fundamental transformations in security architectures, necessitating reconceptualization of security frameworks and threat assessment protocols. This study presents a pedagogical framework for integrating generative AI (GenAI) into university-level cybersecurity curricula. The methodology establishes foundational knowledge in generative models and language processing architectures, followed by applications across defensive security measures. The framework includes automated cyber threat intelligence, malicious code and malware detection, log anomaly detection, digital image forensics, and AI-assisted penetration testing. The framework acknowledges the dual-use nature of GenAI in security domains, incorporating prompt injection attacks that manipulate model behaviors and compromise system integrity. Laboratory modules presented will provide students with hands-on experience on advanced tools including large language models, diffusion models, and cognitive architectures for automated security assessment. This study seeks to prepare cybersecurity professionals with critical competencies necessary for effective operation within an environment increasingly shaped by artificial intelligence systems. Ban Al-Omar, Zouheir Trabelsi |
EDUCON | 2 |
| 2025 | Incorporating Dark Web Education into Cybersecurity CurriculaabstractThe Dark web is considered the concealed part of the internet and harbors a huge assortment of cyber threats that compromise global security. One must understand what goes into the technical infrastructure of the Dark Web to develop an effective strategy for monitoring threats, conducting investigations, and implementing the appropriate security measures necessary to protect against illegal activities and data breaches originating from the Dark Web. In such a rapidly changing cyber threat landscape, especially threats originating from the Dark Web, it calls for a re-evaluation of the traditional information security curricula at academic institutions. This educational research work investigates the compelling need to integrate Dark Web Education into Cybersecurity programs for arming the future workforce with a comprehensive knowledge base and skillset necessary to fight modern-day cyber threats. A review of the current state of cybersecurity education reveals wide gaps in knowledge and readiness about Dark Web issues. This paper presents a structured approach for integrating Dark Web topics into the existing curricula on cybersecurity, focusing on legal, ethical, and technical dimensions. We believe in balance: on one side, theoretical knowledge; on the other, hands-on experiences that ensure the learner takes away just how complex the Dark Web is-without taking part in or condoning any illegal activities. Equally, a set of recommendations are commented on for educators and developers of curricula to integrate education about Dark Web safely and effectively into their cybersecurity programs, which will enhance the overall quality and relevance of cybersecurity education in preparing the students for the challenges of the digital age. Zouheir Trabelsi, Firas Saidi, Ban Al-Omar, Tariq Qayyum |
EDUCON | 1 |
| 2025 | Intelligent Task Offloading in VANETs: A Hybrid AI-Driven Approach for Low-Latency and Energy EfficiencyabstractVehicular Ad-hoc Networks (VANETs) are integral to intelligent transportation systems, enabling vehicles to offload computational tasks to nearby roadside units (RSUs) and mobile edge computing (MEC) servers for real-time processing. However, the highly dynamic nature of VANETs introduces challenges, such as unpredictable network conditions, high latency, energy inefficiency, and task failure. This research addresses these issues by proposing a hybrid AI framework that integrates supervised learning, reinforcement learning, and Particle Swarm Optimization (PSO) for intelligent task offloading and resource allocation. The framework leverages supervised models for predicting optimal offloading strategies, reinforcement learning for adaptive decision-making, and PSO for optimizing latency and energy consumption. Extensive simulations demonstrate that the proposed framework achieves significant reductions in latency and energy usage while improving task success rates and network throughput. By offering an efficient, and scalable solution, this framework sets the foundation for enhancing real-time applications in dynamic vehicular environments. Tariq Qayyum, Asadullah Tariq, Mohamed Adel Serhani, Zouheir Trabelsi, Maite López-Sánchez |
IWCMC | 5 |
| 2025 | Optimizing Post-Quantum Secure Communication via DL-Based KEM Selection in VANETsabstractPost-quantum cryptography (PQC) is essential to secure vehicular ad-hoc networks (VANETs) against emerging quantum computing threats. However, selecting an appropriate Post-Quantum Key Encapsulation Mechanism (PQ-KEM) is challenging due to varying performance metrics such as key generation time, encapsulation/decapsulation latency, and ciphertext overhead. This issue becomes particularly critical in VANETs, where vehicles and roadside units (RSUs) must rapidly and securely exchange data under dynamic network conditions. Current methods typically overlook the initial key distribution phase, leaving communications vulnerable at the earliest interaction. To address these challenges, we created an extensive, open-source benchmark dataset that rigorously evaluates several candidate PQ-KEM algorithms based on performance factors relevant to vehicular environments. Leveraging this benchmark, we developed a lightweight deep learning model that dynamically selects the most suitable PQ-KEM algorithm by predicting optimal performance considering security requirements and real-time conditions such as message size and network congestion. Each recommended PQ-KEM algorithm is authenticated using Dilithium-2 post-quantum signatures, ensuring secure and quantum-resilient initial key distribution between vehicles and RSUs. Our comprehensive simulations demonstrate that our adaptive PQ-KEM selector significantly reduces end-to-end latency and ciphertext overhead without compromising security, thus enhancing secure, efficient communication in VANET scenarios. Tariq Qayyum, Asad Waqar Malik, Asadullah Tariq, Mohamed Adel Serhani, Zouheir Trabelsi |
VTC2025-Fall | 5 |
| 2025 | Detection of Tor network obfuscated traffic using Bidirectional Generative Adversarial NetworkabstractCensorship systems face significant challenges in detecting anonymity-preserving traffic due to advanced obfuscation techniques employed by Tor pluggable transports like Obfs4 and Snowflake. Conventional detection approaches exhibit diminished effectiveness in operational environments where obfuscated traffic constitutes a minute fraction of overall network communications. We present a Cost-Sensitive Bidirectional Generative Adversarial Network (CS-BiGAN) that addresses these challenges through enhanced feature representation learning and classification resilience under extreme class imbalance. Our methodology incorporates a custom dataset collection framework capturing representative traffic patterns from multiple obfuscation protocols, coupled with a cost-sensitive learning mechanism to mitigate class disparity effects. Comprehensive evaluation demonstrates that CS-BiGAN achieves 98.25% accuracy under balanced conditions, with protocol-specific F1-scores of 99.29% for Obfs4 and 97.16% for Snowflake. The model’s distinguishing characteristic is the sustained performance under severe base rate imbalances (1000:1:1:1) that reflect real-world network conditions, maintaining F1-scores exceeding 90.80% for minority classes on average. This performance substantially surpasses existing approaches, establishing practical applicability in operational environments. Our findings offer insights relevant to both censorship system deployment and the advancement of robust obfuscation methodologies designed to circumvent detection mechanisms. Ban Al-Omar, Zouheir Trabelsi, Saed Alrabaee |
Comput. Networks | 2 |
| 2025 | Meta-XPFL: An Explainable and Personalized Federated Meta-Learning Framework for Privacy-Aware IoMTabstractIn the Internet of Medical Things (IoMT), specifically in the field of medical image classification—particularly for skin cancer detection—traditional methods face challenges related to data privacy, heterogeneity, and the need for personalization across institutions. This research proposes a personalized federated learning (PFL) framework Meta-XPFL that addresses these challenges through a decentralized approach, allowing institutions to collaboratively train models without sharing raw data. The framework integrates meta-learning for adaptability, and self-supervised learning to leverage unlabeled data and secure multiparty computation (SMPC). Adversarial training improves model robustness, while attention mechanisms enhance the focus on relevant image features. The use of explainable AI techniques ensures interpretability, which is crucial in clinical settings. To validate the proposed framework, experiments were conducted on the HAM10000 dataset for skin cancer classification, demonstrating significant improvements in model accuracy, privacy preservation, and robustness against adversarial attacks compared to traditional methods. The results indicate that the framework not only enhances scalability and diagnostic accuracy but also offers a privacy-preserving solution that can be extended to various types of medical images, making it adaptable for broader applications in IoMT. Mohamed Adel Serhani, Asadullah Tariq, Tariq Qayyum, Ikbal Taleb, Zouheir Trabelsi |
IEEE Internet Things J. | 6 |
| 2024 | AI and Network Security Curricula: Minding the GapabstractThe ongoing expansion of the digital landscape has led to a growing convergence between the fields of artificial intelligence (AI) and network security. This has necessitated the need for universities to incorporate AI into their network security curriculum. Although traditional network security courses are considered crucial, they lack the agility to address constantly evolving threats. AI offers a transformative solution to such difficulties with its predictive analytics, real-time intrusion detection, and adaptive learning capabilities. This study highlights the importance of incorporating AI into network security curricula at the undergraduate level. A modification to the curriculum is proposed, wherein AI themes are integrated into network security courses and labs. The proposed curricula include understanding theoretical AI concepts and designing AI -augmented hands-on laboratories. The pedagogy emphasizes the tools, and frame-works that facilitate the construction of AI models for intrusion detection, mal ware analysis, and network analytics. This plays a significant importance in providing a simulated environment for students to engage with AI tools and methods to address authentic cyber threats. Ban Al-Omar, Zouheir Trabelsi, Tariq Qayyum, Medha Mohan Ambali Parambil |
EDUCON | 2 |
| 2024 | Enhancing Fog/Edge Computing Education Using Extended Network Simulator Omnet++ (xFogSim)abstractFog computing is a technology that brings computing, storage, and networking services closer to devices and systems, aiming to improve speed, efficiency, and data processing capabilities for various applications. The growing importance of fog and edge computing technologies means we need new and better ways to teach students about these areas. This paper offers a detailed guide on how to use xFogSim, an extended version of the Omnet++ network simulator, for teaching fog and edge computing. We give students a clear path to follow, starting with simple network designs and moving to more complex ones, helping them understand how federated learning works. We tested xFogSim with a group of students and found that it really helps them grasp fog and edge computing ideas better than traditional teaching methods. xFogSim also gives practical information about important performance metrics, helping bridge the gap between what students learn in class and what they need to know in the real world. This paper shows that using xFogSim in classrooms gives students a strong base in distributed computing systems, getting them ready for future tech challenges. Tariq Qayyum, Zouheir Trabelsi, Ban Al-Omar, Medha Mohan Ambali Parambil |
EDUCON | 2 |
| 2024 | Teaching DNS Spoofing Attack Using a Hands-on Cybersecurity Approach Based on Virtual Kali Linux PlatformabstractThe realm of academic security education is primarily focused on defensive strategies. However, there's a growing acceptance of offensive techniques, initially crafted by hackers. Several educators in the field of information security believe that incorporating offensive strategies into the curriculum creates more adept security professionals than focusing solely on defensive methods. Students in information security courses must engage in offensive and defensive tactics to effectively handle malicious activities and devise suitable security measures. This paper presents a case study on executing an in-depth, practical cybersecurity laboratory exercise centered on a prevalent network attack, the DNS spoofing attack, which is vital for network security training. The primary educational goal of this hands-on lab exercise is to equip students with the skills to conduct a DNS spoofing attack within a controlled, virtual network environment using Kali Linux. The introduction of this offensive cybersecurity lab exercise resulted in enhanced student performance; however, it also raised significant ethical issues. Consequently, the paper outlines several measures that academic institutions should consider to mitigate the risks associated with teaching offensive strategies in information security education programs. Zouheir Trabelsi, Medha Mohan Ambali Parambil, Tariq Qayyum, Ban Al-Omar |
EDUCON | 1 |
| 2024 | Harnessing the Power of Quantum Computing for URL Classification: A Comprehensive Study
Tariq Qayyum, Asadullah Tariq, M. Waqas Haseeb Khan, Saed Alrabaee, Zouheir Trabelsi, Farag M. Sallabi, Mohamed Adel Serhani |
SecureComm (1) | 5 |
| 2023 | Diagnosis of Schizophrenia from EEG signals Using ML AlgorithmsabstractEarly treatment is required to control the symptoms and serious complications caused by schizophrenia (SZ). People suffering from SZ require lifelong treatment. The use of machine learning (ML) models to detect various health problems such as SZ has received considerable attention from researchers in recent years. This study investigated the effectiveness of various ML models to detect and predict SZ using electroencephalogram data. A dataset of 14 healthy schizophrenic patients was used, and 12 features were extracted after applying independent component analysis. Three traditional ML models (logistic regression, support vector machine, and K-nearest neighbors) and a convolutional neural network (CNN) were trained, and their performance was compared. Results demonstrated that the CNN model outperformed the other three models with the highest accuracy score of 95% on validation data. Our results highlight the potential of using ML in the early detection and prediction of SZ, which can help in timely and effective treatment. Tariq Qayyum, Zouheir Trabelsi, Assadullah Tariq, Abdelkader Nasreddine Belkacem, Mohamed Adel Serhani |
BIBM | 2 |
| 2023 | Airborne Computing: A Toolkit for UAV-Assisted Federated Computing for Sustainable Smart CitiesabstractSmart vehicles are equipped with onboard computing units designed to run in-vehicle applications. However, due to limited computing power, the onboard units are unable to execute compute-intensive tasks and those that require near real-time processing. Therefore tasks are offloaded to nearby fog/edge devices that have more powerful processors. However, the fog devices are static, placed at fixed locations such as intersections, and have a limited communication range. Therefore, they can only facilitate vehicles in their immediate vicinity and only limited areas of the city can be covered to provide services on demand. In this article, we propose an unmanned aerial vehicle (UAV)-based computing framework design termed Skywalker to provide computing in regions where there are no static fog units thereby extending coverage. Skywalker’s contributions are threefold: 1) it allows for load-aware UAV placement and provisions a swarm of UAVs to fly to areas experiencing a gap in service where the size of the swarm is proportional to the demand; 2) it implements multiple scheduling algorithms that the UAVs swarm employs to divide up the task processing responsibility for individual UAVs within the swarm; and 3) a zone-based delivery mechanism is being proposed to facilitate the return of completed tasks, either through direct delivery or relay-based methods. The choice between these options depends on the distance covered by the requesting vehicle from the UAV swarm. The efficiency of the framework is compared with existing techniques and it is found that it can greatly extend coverage during peak traffic hours while providing low communication delay and consuming minimum energy. Kadhim Hayawi, Zahid Anwar, Asad Waqar Malik, Zouheir Trabelsi |
IEEE Internet Things J. | 4 |
| 2022 | A novel framework for semantic classification of cyber terrorist communities on Twitter
Firas Saidi, Zouheir Trabelsi, Eswari Thangaraj |
Eng. Appl. Artif. Intell. | 2 |
| 2022 | A Novel Multifaceted Trust Management Framework for Vehicular NetworksabstractMaintaining interconnectivity between dynamic vehicular nodes and ensuring trust in vehicular networking is still a challenging issue. It is crucial for the vehicular environments to maintain a stable interconnectivity between the vehicular nodes and further to prevent the vehicular nodes from broadcasting fake messages and simultaneously protect the vehicles against tracking attacks. An efficient Trust Management System (TMS) is proposed in this paper that will ensure trustworthiness and stable interconnectivity between vehicular entities to assure road safety and reliable communication. The proposed approach incorporates a novel timestamp mechanism and block chain concepts to ensure the steady inter-connectivity between the dynamic vehicular nodes. Further, the framework leverages block chain concepts to verify the correctness of the events stored in the Road Side Units (RSUs). It also proposes a versatile hybrid trust model that uses innovative direct and recommended trust evaluation techniques to compute trust between the vehicular entities. Moreover, the framework integrates a threading mechanism to schedule message execution in direct trust evaluation, and clustering techniques to group similar messages in indirect trust evaluation. Various experimental and comparative analyses with other related studies are carried out in a simulated environment to evaluate the performance of the proposed hybrid trust model. The findings show that the proposed trust model produces an accuracy of 92% in identifying malicious nodes. Hesham El-Sayed, Henry Alexander Ignatious, Parag Kulkarni, Manzoor Ahmed Khan, Rafidah Md Noor, Zouheir Trabelsi |
IEEE Trans. Intell. Transp. Syst. | 6 |
| 2021 | IoT based Smart Home Security Education using a Hands-on ApproachabstractIoT (Internet of Things) devices are expected to be installed in most smart homes. However, these devices can pose huge risks to consumers' privacy and security. As a consequence, there is a raising interest from the security research and professional communities into the field of IoT based smart home security. For academia, the inclusion of IoT security in information security curricula is therefore considered a valuable extension. However, there are no available educational publications discussing approaches for teaching IoT based smart home security. To contribute to fill the aforementioned void in security education, a set of comprehensive hands-on lab exercises that are essential to smart home security education are proposed in this paper. The exercises allow students to better anatomize smart home security using a hands-on approach. The lab exercises are designed to accompany and compliment any existing trade or academic press text. Anonymous questionnaires were administrated to students to evaluate their self-assessment of acquired skills and identify their overall satisfaction level about the offered hands-on lab activities. Zouheir Trabelsi |
EDUCON | 1 |
| 2020 | Teaching Network Covert Channels using a Hands-on ApproachabstractNowadays, cybercriminals are using a diversity of techniques to keep their communication channels and exchanged messages secret and hidden. Information hiding techniques, such as network covert channels, are examples of techniques used to preserve secrecy and guarantee hidden communication channels that cannot be captured or discovered by security and surveillance state agencies. The inclusion of network covert channels in information security curricula is therefore considered a valuable extension. However, information hiding techniques are not covered sufficiently in most information security curricula. In addition, there are few educational publications that discuss teaching approaches of such techniques. This paper contributes to fill this gap by providing a method for teaching network covert channels using a hands-on lab based educational approach. The proposed hands-on lab activities can be used in didactic environments to build and detect network covert channels. The impact of offering the hands-on lab exercises on the students’ performance is discussed. Moreover, anonymous questionnaires were administered to students, who participated in the hands-on lab exercises, to evaluate student’s self-assessment of acquired skills and identify their overall satisfaction level about the offered hands-on lab exercises. Zouheir Trabelsi |
EDUCON | 1 |
| 2019 | Fuzzy Logic Based Intrusion Detection System as a Service for Malicious Port Scanning Traffic DetectionabstractPort scanning is a cyber-network attack allows cyber terrorists to gather valuable information about target hosts namely defense, governmental and banks servers by trying to identify instantly open ports, which correspond to specific services on the cloud, such as HTTP, DNS, and email. The basic role of Intrusion Detection Systems (IDSs) is to monitor networks and systems for malicious activities, policy violations attacks and unauthorized information gathering activities. In this paper, we proposed a TCP port scanning detection framework, based on fuzzy logic controller, which uses fuzzy rules base and the Mamdani inference method. The proposed platform is a Fuzzy IDS as a Service, which enables network administrators and cyber security specialists to follow in real time the network traffic behavior, i.e., the Port Scanning Criticity Level (PSCL). A SaaS dynamic dashboard is implemented to quickly and efficiently identify malicious port scanning activities. Experimentations and evaluations showed the efficiency of the proposed system in multilevel port scanning detection compared to Snort and the related IDS systems. Firas Saidi, Zouheir Trabelsi, Henda Ben Ghézala |
AICCSA | 2 |
| 2019 | Resilence of Network Stateful Firewalls against Emerging DoS Attacks: A Case Study of the BlackNurse AttackabstractTraditional Distributed Denial of Service (DDoS) attacks usually flood target network servers with malicious traffic. This would generally require a set of attack hosts and large network traffic volume to be able to crash or degrade the performance of target servers causing service disruptions. Recently, new types of DDoS attacks have emerged and target specifically network security devices, mainly firewalls and intrusion prevention systems (IPS). In contrast to traditional DDoS attacks, these emerging attacks use low volume of malicious traffic. This paper is concerned solely with an emerging denial of firewalling attack, called the BlackNurse attack. This new attack uses special formatted ICMP packets to overwhelm the CPUs on targeted firewalls. This paper offers detailed insights into the understanding of the BlackNurse attack principles, practical attack generation, and its general effect on impacted firewalls and the network behind them. Performance evaluations are conducted on commercial grade Juniper NetScreen SSG 20 and Cisco ASA 5540 firewalls to measure the harmfulness of the BlackNurse attack when subjected to each of them. In addition, available attack mitigations pros and cons are discussed. OS screening features on Juniper NetScreen SSG 20 are used, as example, to test their effectiveness in thwarting the attack. Zouheir Trabelsi, Safaa Zeidan |
AICCSA | 1 |
| 2019 | An Approach for Thwarting Malicious Secret Channel: The Case of IP Record Route Option Header-Based Covert Channels
Firas Saidi, Zouheir Trabelsi, Henda Ben Ghézala |
CRiSIS | 2 |
| 2019 | A Basic Course Model on Information Security for High School IT CurriculumabstractAs more of the activities of daily living take place online, computer security education for high school students is of increasing importance. To address this need, we design a course model as prototype curriculum to teach high school students about the basics of information security. Prototype examples of hands-on lab activities are also introduced for enhancing students' practical skills on information security. IT educators can consider the proposed work in this paper as a guideline for designing and developing information security courses to high school students. We identify challenges encountered in this process, and contend that these challenges stem from the nature of the information security field. Zouheir Trabelsi, Ezedin Barka |
EDUCON | 1 |
| 2019 | Exploring the Opportunities of Cisco Packet Tracer For Hands-on Security Courses on FirewallsabstractAlong with teaching the fundamental and theoretical information security concepts, nowadays, hands-on lab activities are key to any information security education program. Moreover, the use of a hands-on approach that is based on a virtual or simulated lab environment is important. Such an environment offers a safer, more secure, and affordable solution to build security laboratories where students can experiment with offensive and defensive techniques. This is especially beneficial for academic institutions with limited lab budgets. Cisco Packet Tracer is an educational simulation tool that is designed to simulate the creation and testing of network architectures based on Cisco networking devices. This paper explores the opportunities of using this tool for hands-on information security education, along with teaching networking concepts. Practically, the capabilities of Cisco Packet Tracer for the development of hands-on lab activities on firewall concepts (Network traffic filtering) will be demonstrated. The goal is to use Cisco Packet Tracer to allow students to better understand the basic concepts of firewalls through experiments on in a virtual laboratory. This paper also discusses the impact of offering Cisco Packet Tracer to the students and the instructors' opinions on the tool. Using the tool was found to help students understand course material easier at a lower cost but affected the amount of material that could be covered by the instructor. Zouheir Trabelsi, Heba Saleous |
EDUCON | 1 |
| 2019 | Teaching Emerging DDoS Attacks on Firewalls: A Case Study of the BlackNurse AttackabstractInformation security is an ever-evolving field that is important in order to keep the confidentiality, integrity and availability of assets. Although defensive measures are constantly being updated, so are attack methods. Computer security specialists need to stay updated with current defense and attack techniques. The objective of this paper is to discuss how teaching methods for computer security can be improved to ensure students and trainees learn the required skills relevant to modern defense and attack measures. This is done through a case study of an emerging Distributed Denial of Service (DDoS) attack known as BlackNurse. The paper introduces the fundamental concepts of the BlackNurse attack and provides hands-on lab activities on attack generation and mitigation in an isolated laboratory environment. The detailed conducted experiments can be considered as a model example of hands-on lab activities for improving student's security skills. This paper aims to offer instructors an easy way to update their courses' contents accordingly and insures updated information security knowledge is delivered to students. Additionally, this paper offers more insights into the understanding of several emerging security vulnerabilities, which would open new research perspectives and topics for both graduate students and researchers. Finally, surveys are conducted to collect instructors and students' feedbacks on using such a paper model to enhance network security education and students learning outcomes achievements. Zouheir Trabelsi, Safaa Zeidan, Heba Saleous |
EDUCON | 1 |
| 2019 | A Dendritic Cell Algorithm Based Approach for Malicious TCP Port Scanning DetectionabstractThe proliferation of cyber-attacks brings up an urgent need to develop sophisticated detection tools. Some of these tools are based on algorithms inspired from the Human Immune System (HIS). The Dendritic Cell Algorithm (DCA) is one of such HIS inspired methods, which is based on the Danger model. In the current study, two kinds of DCA algorithms (deterministic and classical DCA) are analyzed in order to detect DoS attacks. Moreover, this paper discusses the enhancement of the DCA algorithm to cover the detection of malicious TCP port scanning. By using different use-cases, the evaluation and results are accumulated to show the efficiency of the DCA algorithm used in the Port scanning detection. Nuha Almasalmeh, Firas Saidi, Zouheir Trabelsi |
IWCMC | 3 |
| 2019 | Enhancing Firewall Filter Performance Using Neural NetworksabstractThe Internet has grown to a point where people all over the world have grown dependent of the convenient communication medium that is being provided. However, with this dependency, malicious traffic has become a major concern. Because of this, firewalls are a mandatory part of any network, due to their ability to filter the traffic based on rules that state which packets should be accepted or denied. However, filter rules must be manually configured by a network administrator, and packets that do not fit any rule may be subject to wrong judgment by the firewall. This can become tedious in larger networks. Neural networks can learn the filter rules that have been set by administrators in order to decide if packets that do not fit any specific rules should be accepted or denied. The neural network will be trained with existing packet data and their firewall actions, and then tested to determine its filtering accuracy compared to the firewall. Heba Saleous, Zouheir Trabelsi |
IWCMC | 2 |
| 2018 | Teaching keylogging and network eavesdropping attacks: Student threat and school liability concernsabstractNowadays, keylogging and network eavesdropping are very common network attacks and important topics in information security education. This paper discusses what academics need to know about keylogging and network eavesdropping attacks. The paper does so in the hope that it will encourage the teaching of these security topics when offering modules on information security. Then, the paper discusses the threat of teaching keylogging and network eavesdropping attacks and proposes steps to minimize the risk of inappropriate student behavior and reduce institutional liability. Zouheir Trabelsi, Heba Saleous |
EDUCON | 1 |
| 2018 | Enhanced Session Table Architecture for Stateful FirewallsabstractStateful firewall keeps track of the state of network connections. The performance of stateful firewall determines by both the performance of its session table and the mechanism used for packet filtering. This paper presents a stateful session table architecture then integrates it with Splay tree firewall. Splay tree firewall organizes policy rules in a designated prefix length splay tree data structure, and a collection of hash tables grouped by prefix length. Packet filtering time using Splay tree firewall is essentially reduced through multilevel filtering paths, where unwanted packets are rejected as early as possible. The proposed session table architecture reduces memory space consumption and session operations time, as it uses one hash slot per connection. Keeping all connection related information in one session entry produces additional processing time, particularly for session timeout attribute processing. Our proposed session architecture separates session state and timeout attributes information into different data structures to enhance the overall system performance. Zouheir Trabelsi, Safaa Zeidan |
ICC | 1 |
| 2018 | A novel approach for terrorist sub-communities detection based on constrained evidential clusteringabstractThe emergence of web 2.0 virtual spaces, namely social networks and social media, enables terrorist organizations to flourish and advance their cyber malicious activities by posting criminal contents, exchanging information and polarizing new members. Thus, there is an immense need for the development of effective approaches to understand cyber terrorist organizations structures, working strategies, and operation tactics. A terrorist community is a set of subgroups, which share many properties but differ on others, such as degree of activity and roles. The identification of these sub-communities is a key task not only to understand the topology of these organizations but also to discover their operation methods. In this paper, we propose a cyber community detection approach based on Constrained Evidential C-Means (CECM) algorithm which is an adequate evidential clustering method that can be applied to detect cyber terrorist subgroups. Based on Must-link and Cannot-link constraints, objects (network members) can be classified into various sub-classes Cn, such as military, finance and local leaders committees. The membership of nodes to clusters (sub-communities) is described by Belief functions. Clustering results show the efficiency of our evidential constrained approach not only in classifying cyber terrorist actors into the aforementioned communities, but also in allocating a degree of membership for each member to each class. Firas Saidi, Zouheir Trabelsi, Henda Ben Ghézala |
RCIS | 2 |
| 2017 | Approaches to analyze cyber terrorist communities: Survey and challenges
Firas Saidi, Zouheir Trabelsi, Khaled Salah 0001, Henda Ben Ghézala |
Comput. Secur. | 2 |
| 2017 | Hybrid mechanism towards network packet early acceptance and rejection for unified threat managementabstractRecent network architectures utilise many types of security appliances to combat blended attacks. However, managing multiple separate security appliances can be overwhelming, inefficient and expensive. Thus, multiple security features are needed to be integrated into unified security architecture resulting in an unified threat management system (UTM). In most current UTM systems, whenever a security feature is needed, the corresponding module is just ‘attached or added on’. This approach of adding on may reduce the UTM performance dramatically, especially when security features such as IDS/IPS are enabled. In this study, a hybrid mechanism is proposed to solve UTM redundant packet classification problem. The mechanism is based on the use of splay tree filters and pattern‐matching algorithms to enhance packet filtering and deep packet inspection (DPI) performance. The proposed mechanism uses network traffic statistics to dynamically optimise the order of the splay tree filters, allowing early acceptance and rejection of network packets. In addition, DPI signature rules are reordered according to their matching frequencies, allowing early packets acceptance. The authors demonstrate the merit of their mechanism through simulations performed on firewall and snort as independent packet manipulation systems compared with the proposed hybrid mechanism that uses unified communication between them. Zouheir Trabelsi, Safaa Zeidan, Mohammad M. Masud 0001 |
IET Inf. Secur. | 1 |
| 2016 | Network Packet Filtering and Deep Packet Inspection Hybrid Mechanism for IDS Early Packet MatchingabstractModern network packet processing applications such as Intrusion Detection System (IDS) perform packet filtering and deep packet inspection (DPI), also known as packet content inspection. Fundamentally, for packet filtering, these applications attempt to use the contents of some header fields of the network, transport and application layers of the packets. While for DPI, these applications use attack signature rules to search for predefined patterns in the packet application header fields or payload data. This paper discusses a hybrid mechanism based on the use of splay tree filters and pattern-matching algorithms to enhance IDS packet filtering and DPI performance, respectively. The proposed mechanism uses network traffic statistics to dynamically optimize the order of the splay tree filters, allowing early acceptance and rejection of network packets. In addition, DPI signature rules are reordered according to their matching frequencies, allowing early packets acceptance. We demonstrate the merit of our mechanism through simulations performed on Snort's string set. Zouheir Trabelsi, Safaa Zeidan, Mohammad M. Masud 0001 |
AINA | 1 |
| 2016 | The robustness of Microsoft Windows and Apple Mac OS X against ARP cache poisoning based network attacksabstractRobust security measures are integrated into new release versions of operating systems (OSs) to ensure that users have a more secure and reliable environment to run their daily tasks. In this paper, through extensive practical experiments, we evaluate and compare the effectiveness of popular versions of Microsoft Windows OSs and Apple Mac OS X in thwarting Address Resolution Protocol (ARP) cache poisoning attack in Local Area Network (LAN). The experimental results demonstrate clearly that all tested versions of Windows OSs and Apple Mac OS X are still very vulnerable to the ARP cache poisoning attack, and do not deploy built-in efficient security features to prevent the success of this attack. In addition, the experimental results directly allow to contradict the common belief that Windows OSs are always less security aspects compared to Apple OSs. Zouheir Trabelsi |
CCNC | 1 |
| 2016 | Edu-firewall device: An advanced firewall hardware device for information security educationabstractFirewalls are security devices used to apply an organization's security policy. However, commercial firewalls, such as Juniper Networks and Cisco ASA firewall devices, are mainly designed to be used by networking and security professionals, are not very appropriate for the academia environment, and lack simplicity. In addition, commercial firewalls are usually considered high-cost hardware devices. However, academic institutions usually have tight budget and few financial resources for purchasing networking and security devices for their laboratories. To overcome the aforementioned limitation of commercial firewalls, an educational firewall hardware device, called Edu-Firewall, is discussed and demonstrated. Edu-Firewall main objectives are to offer advanced educational security functions that are not commonly available in current commercial firewalls, and an easy-to-use friendly graphical interface to configure the firewall and manipulate the filtering rules. In addition, Edu-Firewall's objective is to offer an affordable educational device, compared to the available commercial firewall devices. Edu-Firewall allows students to implement hands-on lab exercises on firewalls and better anatomize network traffic filtering concepts and firewall configuration, and contributes to enhance students' hands-on security skills. Zouheir Trabelsi, Vasiqullah Molvizadah |
CCNC | 1 |
| 2016 | Virtualization based ethical educational platform for hands-on lab activities on DoS attacksabstractRecently, teaching ethical hacking techniques has become a vital component of information security programs that aim to produce competent information security professionals. Students need exposure to offensive techniques developed usually by hackers, along with the defensive techniques. This is problematic since students need to work with tools that may pose threat to the stability and security of the laboratories' computers and live networks within academic institutions. In an attempt to overcome the aforementioned issue, this paper discusses an ethical educational platform, called DoS_VLab, that aims at allowing students experience common denial of service (DoS) attacks, in secure academic environment. DoS_VLab platform is based on virtualization technologies and GNS3 network simulator for building virtual networks. Compared to traditional physical laboratories, practices show that the DoS_VLab platform helped produce more lab practices within the students, reduced training hours required for implementing hands-on lab exercises, and resulted in higher completion rate of the hands-on lab exercises. Shamma Al Kaabi, Nouf Al Kindi, Shaikha Al Fazari, Zouheir Trabelsi |
EDUCON | 4 |
| 2016 | Recurring and Novel Class Detection Using Class-Based Ensemble for Evolving Data StreamabstractStreaming data is one of the attention receiving sources for concept-evolution studies. When a new class occurs in the data stream it can be considered as a new concept and so the concept-evolution. One attractive problem occurring in the concept-evolution studies is the recurring classes from our previous study. In data streams, a class can disappear and reappear after a while. Existing studies on data stream classification techniques either misclassify the recurring class or falsely identify the recurring classes as novel classes. Because of the misclassification or false novel classification, the error rates increases on those studies. In this paper we address the problem by defining a novel ensemble technique “class-based” ensemble which replaces the traditional “chunk-based” approach in order to detect the recurring classes. We discuss the details of two different approaches in class-based ensemble and explain and compare them in detail. Different than the previous studies in the field, we also prove the superiority of both “class-based” ensemble method over state-of-art techniques via empirical approach on a number of benchmark data sets including Web comments as text mining challenge. Tahseen Al-Khateeb, Mohammad M. Masud 0001, Khaled Al-Naami, Sadi Evren Seker, Ahmad Mustafa 0001, Latifur Khan, Zouheir Trabelsi, Charu C. Aggarwal, Jiawei Han 0001 |
IEEE Trans. Knowl. Data Eng. | 7 |
| 2015 | Statistical dynamic splay tree filters towards multilevel firewall packet filtering enhancement
Zouheir Trabelsi, Safaa Zeidan, Mohammad M. Masud 0001, Kilani Ghoudi |
Comput. Secur. | 1 |
| 2014 | IDS performance enhancement technique based on dynamic traffic awareness histogramsabstractThis paper discusses an approach to improve the performance of Intrusion Detection Systems (IDSs) through optimizing the order of the attack signature rules as well as the order of the rule fields. The proposed approach is based on calculating the histograms of the attack packets that match the signature rules and of those that do not match the rule-fields. The histograms are used to effectively monitor the IDS performance in real-time and to predict the optimal orders of the signature rules and the rule-fields, based on the attack packets patterns. The paper discusses the evaluation of the proposed approach with other conventional approaches using Snort tool as an example of IDS system. The numerical results obtained by simulations demonstrate that the proposed approach is able to significantly improve Snort performance in terms of cumulative packet processing time. Zouheir Trabelsi, Safaa Zeidan |
ICC | 1 |
| 2014 | Dynamic rule and rule-field optimisation for improving firewall performance and securityabstractA novel approach is presented to improve firewall packet filtering through optimising the order of firewall rules for early packet acceptance as well as the order of rule‐fields for early packet rejection. The proposed approach is based on the calculation of the histograms of packet matching rules and of packet not matching rule‐fields. These histograms are able to effectively monitor firewall performance in real‐time and to predict the patterns of packet filtering in terms of rules order and rule‐fields order. Furthermore, the proposed approach becomes even more significant when firewall is heavily loaded with burst traffic. A comparison of the proposed approach and the other conventional approaches, including static rule order approach and dynamic rule order approach is presented. The numerical results obtained by simulations demonstrate that the proposed approach is able to significantly improve the firewall efficiency in terms of cumulative processing time compared to other conventional approaches. Furthermore, the proposed scheme also has the capability to significantly reduce the effect of many common network attacks on firewall performance. Zouheir Trabelsi, Liren Zhang, Safaa Zeidan |
IET Inf. Secur. | 1 |
| 2013 | Teaching ethical hacking in information security curriculum: A case studyabstractDenial of Service (DoS) attacks are important topics for security courses that teach ethical hacking techniques and intrusion detection. This paper presents a case study of the implementation of comprehensive offensive hands-on lab exercises about three common DoS attacks. The exercises teach students how to perform practically the DoS attacks in an isolated network laboratory environment. The paper discuses also some ethical and legal issues related to teaching ethical hacking, and then lists steps that schools and educators should take to improve the chances of having a successful and problem free information security programs. Zouheir Trabelsi, Walid Ibrahim |
EDUCON | 1 |
| 2013 | Using network packet generators and snort rules for teaching denial of service attacksabstractTeaching ethical hacking techniques is fundamental to security education and allows students to better understand the ways in which computer and network systems fail. This paper discusses the implementation of comprehensive offensive hands-on lab exercises about four common Denial of Service (DoS) attacks. Moreover, the paper discusses the implementation of a defense technique against the DoS attacks using Snort tool, as an intrusion detection system. The impact of offering the exercises on the student performance in terms of achieving the course outcomes is also discussed. Although a significant improvement in the student performance has been observed, a major ethical concern has been identified when teaching ethical hacking techniques. As a consequence, the paper lists a number of steps that should be taken by schools and educators to reduce the liability of teaching ethical hacking techniques in information security curriculum. Zouheir Trabelsi, Latifa Alketbi |
ITiCSE | 1 |
| 2013 | Firewall performance optimization using data mining techniquesabstractThis paper presents a novel approach to improve firewall performance using data mining techniques. A traditional packet filtering firewall compares a packet against each filtering rule until a match is found. The filtering rules are stored as a rule list. Therefore, the time required to process a packet depends linearly on the number of filtering rules. This time can be prohibitively large for a firewall containing hundreds of rules and the firewall can be a bottleneck for the network if high bandwidth is required. To enhance the firewall performance, we propose a data mining solution. In this approach, instead of comparing the packet with each of the filtering rules, the firewall predicts which rule is most likely going to match the packet. This significantly reduces the processing time taken by the firewall to filter each packet and thus improves its performance. Comparisons were made between the cumulative processing time taken by a standard firewall and the enhanced firewall with data mining to process millions of packets. Compared to the standard firewall, the enhanced firewall took 40% less time in processing the packets. Umniya Mustafa, Mohammad M. Masud 0001, Zouheir Trabelsi, Timothy Wood 0001, Zainab Al Harthi |
IWCMC | 3 |
| 2013 | Dynamic traffic awareness statistical model for firewall performance enhancement
Zouheir Trabelsi, Liren Zhang, Safaa Zeidan, Kilani Ghoudi |
Comput. Secur. | 1 |
| 2012 | Multilevel early packet filtering technique based on traffic statistics and splay trees for firewall performance improvementabstractThis paper presents a mechanism to improve firewall packet filtering time through optimizing the order of security policy filtering fields for early packet rejection. The proposed mechanism is based on the optimization of the filtering fields order according to traffic statistics. Furthermore, the mechanism uses multilevel packet filtering, and in each level unwanted packets are rejected as early as possible. So, the proposed mechanism can be considered also as a device protection mechanism against denial of service (DoS) attacks targeting the default policy rule. In addition, early packet acceptance is done through using the splay tree data structure which changes dynamically according to traffic flows. So, repeated packets will have less memory accesses and therefore reducing the overall packets matching time. The proposed technique aims to overcome some of the performance limitations of the previous technique, named Self Adjusting Binary Search on Prefix Length (SA-BSPL). The numerical results obtained by simulations demonstrate that the proposed mechanism is able to significantly improve the firewall performance in terms of cumulative packet processing time compared to SA-BSPL technique. Zouheir Trabelsi, Safaa Zeidan |
ICC | 1 |
| 2012 | Firewall Packet Filtering Optimization Using Statistical Traffic Awareness Test
Zouheir Trabelsi, Liren Zhang, Safaa Zeidan |
ICICS | 1 |
| 2011 | Updating snort with a customized controller to thwart port scanningabstractAbstract Wired and wireless networks are being attacked and hacked on continuous basis. One of the critical pieces of information the attacker needs to know is the open ports on the victim's machine, thus the attacker does what is called port scanning. Port scanning is considered one of the dangerous attacks that intrusion detection tries to detect. Snort, a famous network intrusion detection system (NIDS), detects a port scanning attack by combining and analyzing various traffic parameters. Because these parameters cannot be easily combined using a mathematical formula, fuzzy logic can be used to combine them; fuzzy logic can also reduce the number of false alarms. This paper presents a novel approach, based on fuzzy logic, to detect port scanning attacks. A fuzzy logic controller is designed and integrated with Snort in order to enhance the functionality of port scanning detection. Experiments are carried out in both wired and wireless networks. The results show that applying fuzzy logic adds to the accuracy of determining bad traffic. Moreover, it gives a level of degree for each type of port scanning attack. Copyright © 2010 John Wiley & Sons, Ltd. Wassim El-Hajj, Hazem M. Hajj, Zouheir Trabelsi, Fadi A. Aloul |
Secur. Commun. Networks | 3 |
| 2010 | Implementation of a DNA-based anomaly identification system utilizing associative string processor (ASP)abstractThe genetic material that encodes the unique characteristics of each individual, such as gender, eye color, and other human features is the well-known DNA. In this work, we introduce an anomaly intrusion detection system, built on the notion of a DNA sequence or gene, which is responsible for the normal network traffic patterns. Subsequently, the system detects suspicious activities by searching the “normal behavior DNA sequence” through string matching. Conversely, string matching is a computationally intensive task and can be converted into a potential bottleneck without high-speed processing. Furthermore, conventional software implemented string matching algorithms have not kept pace with the ever increasing network speeds. As a result, we adopt a monitoring phase that is hardware implemented with the intention that DNA pattern matching is performed at wire-speed. Finally, we provide the details of our FPGA implementation of the bioinformatics-based string matching technique. The associative string processor (ASP) is an associative memory-based micro-architecture with long fixed-length words that can be partially searched. We show that the proposed micro-architecture can handle fixed-length patterns at a rate of more than one character per cycle. Zouheir Trabelsi, Riham Hamdy |
AICCSA | 1 |
| 2010 | Towards More Secure Biometric Readers for Effective Digital Forensic Investigation
Zouheir Trabelsi, Mohamed Al-Hemairy, Ibrahim M. Baggili, Saad Ali Amin |
ICDF2C | 1 |
| 2009 | On fault tolerant ad hoc network designabstractMinimal configuration and quick deployment of ad hoc networks make it suitable for numerous applications such as emergency situations, border monitoring, and military missions, etc. For such ad hoc networks to fulfill their mission in a timely manner, they should be able to establish a connection between nodes and to maintain this connection until the communication halts. Establishing a connection is achieved by using a routing protocol, and maintaining it is achieved by having a resilient fault tolerant network. In this paper, we propose a network design scheme that incorporates these features. We first propose a special network topology that is unique in terms of how nodes are interconnected. After constructing the initial topology, we propose a distributed routing protocol that allows any two sites to communicate by traversing at most 2 nodes regardless of the network size. We conducted both simulation study and theoretical analysis; the results show that the proposed scheme is resilient to network dynamics and has high quality as well as efficient routing. Wassim El-Hajj, Hazem M. Hajj, Zouheir Trabelsi |
IWCMC | 3 |
| 2009 | An enhanced secure ARP protocol and LAN switch for preveting ARP based attacksabstractAfter the ARP protocol was drafted, a subtle weakness in the protocol was discovered. In fact, ARP provides no means to establish the authenticity of the source of incoming ARP packets. That's why any host of a LAN network can forge an ARP message containing malicious information to poison the ARP caches of target hosts. This lack of authentication mechanisms has made ARP vulnerable to a raft of IP-based impersonation, Man-in-the-Middle (MiM) and DoS attacks. In this paper we discuss a security solution to solve the ARP vulnerabilities and authenticity issues. For that purpose, a novel secure extended ARP protocol is proposed. In addition, the LAN switch has been enhanced to assume the role of "Trusted Authority" and assure the hosts authentication while exchanging ARP messages. Senda Hammouda, Zouheir Trabelsi |
IWCMC | 2 |
| 2008 | A new covert channel in WIFI networksabstractCovert channels are not a new topic. However they remain an interesting research area. The most proposed techniques are located in the upper layers of the OSI model. In this paper, we present a new covert channel in the data link layer dedicated to wireless local area networks. It uses either sequence control or initial vector fields or both of them depending on the configuration of the network. We present also some measurements to protect the proposed channel against steganalysis and sniffing. Lilia Frikha, Zouheir Trabelsi |
CRiSIS | 2 |
| 2007 | Preventing ARP Attacks Using a Fuzzy-Based Stateful ARP CacheabstractARP cache poisoning is considered to be one of the easiest and dangerous attacks in local area networks. This paper proposes a solution to the ARP poisoning problem by extending the current ARP protocol implementation. Instead of the traditional stateless ARP cache, we use a stateful ARP cache in order to manage and secure the ARP cache. We also use a novel Fuzzy Logic approach to differentiate between normal and malicious ARP replies. The Fuzzy Logic controller uses a dynamically populated data base that adapts to network changes. The limits of the current approaches are discussed and analyzed. Zouheir Trabelsi, Wassim El-Hajj |
ICC | 1 |
| 2007 | Using a Fuzzy Logic Controller to Thwart Data Link Layer Attacks in Ethernet NetworksabstractNowadays data networks represent the most common communication environment for transfer of data, voice or image. Such popularity led network users to becoming more vulnerable to network attacks and intrusions. Data link layer attacks, ex. ARP poisoning, is considered to be one of these dangerous attacks. ARP poisoning attack is a technique used to attack an Ethernet network. It may allow an attacker to sniff network traffic or stop the traffic altogether. In this paper, we use a fuzzy logic controller to thwart data link layer attacks in Ethernet networks (ARP poisoning). Each host in the network is assigned certain dynamic characteristics. Then a fuzzy logic controller is used to combine these characteristics keeping in mind the synergy between them. The output of the controller decides if the host is trusted or not. Moreover, we use a stateful ARP cache, instead of the traditional stateless ARP cache. Wassim El-Hajj, Zouheir Trabelsi |
WCNC | 2 |
| 2007 | Fast distributed dominating set based routing in large scale MANETs
Wassim El-Hajj, Zouheir Trabelsi, Dionysios Kountanis |
Comput. Commun. | 2 |
| 2006 | Man in the Middle Intrusion DetectionabstractLocal area network (LAN) security is a critical and mandatory element that network administrators must master. It is often thought of network security as protecting the network from external attacks and intrusions. However, internal attacks can also be as damaging and malicious as external ones. One of the well known attacks in networking is packet spoofing at the different network layers. This paper discusses how spoofed ARP packets can be used by malicious users to redirect and use network's traffic to launch an attack against users' hosts. Limitations of current intrusion detection systems (IDSs) in detecting traffic redirection attacks are also discussed. The paper then proposes practical and efficient mechanisms for detecting such malicious attacks in a switched LAN environment. In addition, the effect of the proposed techniques on network performance is shown to be minimal given the gained benefits. Zouheir Trabelsi, Khaled Shuaib |
GLOBECOM | 1 |
| 2006 | Spoofed ARP Packets Detection in Switched LAN Networks
Zouheir Trabelsi, Khaled Shuaib |
SECRYPT | 1 |
| 2004 | Detection of Sniffers in an Ethernet Network
Zouheir Trabelsi, Hamza Rahmani |
ISC | 1 |