Mustafa Kaiiali

dblp:49/7851 · DBLP profile ↗
← Back
6ranked-venue papers
2as first author
2since 2021 · last 2022
0000-0003-0783-2777ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 4 · 2 since 2021Artificial intelligence and machine learning · 1 · 1 first-authorSystems, architecture and hardware · 1 · 1 first-authorApplied, interdisciplinary, general and emerging computing · 1 · 1 first-author
YearPublicationVenuePosition
2022 MFMCNS: a multi-feature and multi-classifier network-based system for ransomworm detection
abstract
Ransomware is a type of advanced malware that can encrypt a user’s files or lock a computer system until a ransom has been paid. Ransomworm is a type of malware that combines the payload of ransomware with the propagation feature of a computer worm. Most host-based detection methods require the host to be infected and the payload to be executed first to be able to identify anomalies and detect the malware. By the time of infection, it might too late as some of the system’s assets would have been already encrypted or exfiltrated by the malware. On the contrary, the network-based methods can be one of the crucial means in detecting ransomworm activities when it attempts to spread to infect other networks before executing the payload. Therefore, a thorough analysis of ransomworm network traffic can be one of the essential means for early detection. This paper presents a comprehensive behavioral analysis of ransomworm network traffic, taking WannaCry, which launched a worldwide cyberattack, and NotPetya as a case study. Two sets of related features were extracted based on two independent flow levels: session-based and time-based. On top of each set, an independent classifier was built. Moreover, to improve the reliability, a multi-feature and multi-classifier network-based system, MFMCNS, has been proposed. MFMCNS employs these classifiers working in parallel on different flow levels, then it adopts a fusion rule to combine the classifiers’ decisions. The experimental results prove that MFMCNS is reliable and has high detection accuracy.
Ahmad O. Almashhadani, Domhnall Carlin, Mustafa Kaiiali, Sakir Sezer
Comput. Secur.3
2021 Improved Access Control Mechanisms Using Action Weighted Grid Authorization Graph for Faster Decision Making
abstract
Access control mechanisms are the way to guarantee secure access to grid resources. Recent research works were focused on how to improve the representation of the resources' security policies for faster decisions making. PCM, HCM, GAG, and WGAG are all different ways to represent these security policies. This paper presents an enhancement to WGAG, the action-weighted grid authorization graph (Action-WGAG). A security policy-parser (SP-Parser) has been developed to implement the Action-WGAG. The evaluation results of the proposed model showed that it assures a smaller number of security rule checking in some cases and a reduction of the answer time to an access control request.
Sarra Namane, Nassira Ghoualmi-Zine, Mustafa Kaiiali
Int. J. Inf. Secur. Priv.3
2020 MaldomDetector: A system for detecting algorithmically generated domain names with machine learning
abstract
One of the leading problems in cyber security at present is the unceasing emergence of sophisticated attacks, such as botnets and ransomware, that rely heavily on Command and Control (C&C) channels to conduct their malicious activities remotely. To avoid channel detection, attackers constantly try to create different covert communication techniques. One such technique is Domain Generation Algorithm (DGA), which allows malware to generate numerous domain names until it finds its corresponding C&C server. It is highly resilient to detection systems and reverse engineering, while allowing the C&C server to have several redundant domain names. This paper presents a malicious domain name detection system, MaldomDetector, which is based on machine learning. It is capable of detecting DGA-based communications and circumventing the attack before it makes any successful connection with the C&C server, using only domain name's characters. MaldomDetector uses a set of easy-to-compute and language-independent features in addition to a deterministic algorithm to detect malicious domains. The experimental results demonstrate that MaldomDetector can operate efficiently as a first alarm to detect DGA-based domains of malware families while maintaining high detection accuracy.
Ahmad O. Almashhadani, Mustafa Kaiiali, Domhnall Carlin, Sakir Sezer
Comput. Secur.2
2017 Trust Management for Public Key Infrastructures: Implementing the X.509 Trust Broker
abstract
A Public Key Infrastructure (PKI) is considered one of the most important techniques used to propagate trust in authentication over the Internet. This technology is based on a trust model defined by the original X.509 (1988) standard and is composed of three entities: the certification authority (CA), the certificate holder (or subject), and the Relying Party (RP). The CA plays the role of a trusted third party between the certificate holder and the RP. In many use cases, this trust model has worked successfully. However, we argue that the application of this model on the Internet implies that web users need to depend on almost anyone in the world in order to use PKI technology. Thus, we believe that the current TLS system is not fit for purpose and must be revisited as a whole. In response, the latest draft edition of X.509 has proposed a new trust model by adding new entity called the Trust Broker (TB). In this paper, we present an implementation approach that a Trust Broker could follow in order to give RPs trust information about a CA by assessing the quality of its issued certificates. This is related to the quality of the CA’s policies and procedures and its commitment to them. Finally, we present our Trust Broker implementation that demonstrates how RPs can make informed decisions about certificate holders in the context of the global web, without requiring large processing resources themselves.
Ahmad Samer Wazan, Romain Laborde, David W. Chadwick, François Barrère, Benzekri Abdelmalek, Mustafa Kaiiali, Adib Habbal
Secur. Commun. Networks6
2013 Grid Authorization Graph
Mustafa Kaiiali, Rajeev Wankar, C. Raghavendra Rao 0001, Arun Agarwal, Rajkumar Buyya
Future Gener. Comput. Syst.1
2010 A Rough Set based PCM for authorizing grid resources
abstract
Many existing grid authorization systems adopt an inefficient structure of storing security policies for the available resources. That leads to huge repetitions in checking security rules. One of the efficient mechanisms that handle these repetitions is the Hierarchical Clustering Mechanism (HCM) [1]. HCM reduces the redundancy in checking security rules compared to the Brute Force Approach as well as the Primitive Clustering Mechanism (PCM). Further enhancement of HCM is done to make it suitable for dynamic environments [2]. However, HCM is not totally free from repetitions. Moreover, HCM is an expensive process in terms of decision tree size and memory consuming. In this paper, a new Rough Set based PCM is proposed which increases the efficiency of the authorization process and further reduces the redundancy.
Mustafa Kaiiali, Rajeev Wankar, C. Raghavendra Rao 0001, Arun Agarwal
ISDA1