Sherif M. Khattab

dblp:60/6179 · DBLP profile ↗
← Back
19ranked-venue papers
7as first author
4since 2021 · last 2022
0000-0002-0141-8543ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 6 · 1 first-authorSystems, architecture and hardware · 5 · 4 first-authorHuman-computer interaction and ubiquitous computing · 4 · 1 first-author · 3 since 2021Software engineering, systems software and programming languages · 2 · 1 since 2021Security and privacy · 1 · 1 first-authorApplied, interdisciplinary, general and emerging computing · 1
YearPublicationVenuePosition
2022 Rethinking the Bottleneck in Diversifying the Cybersecurity Talent Pool: What Actions can We Take and How can We Measure Success?
abstract
Although the number of cybersecurity programs is increasing, the field remains challenged in sourcing talent, particularly among underrepresented groups (URGs). The need for inclusion and diversity is critical to a better workforce and to better problem solving which is critical in cybersecurity. Many people want to contribute to diversifying cybersecurity but don't know where/how to start. In this BoF session, participants will explore the following questions: (1) what are the most significant barriers preventing wider diversity in cybersecurity, (2) what are the most significant enablers to increase URGs participation in cybersecurity, (3) what are some actionable items to improve the diversity landscape in cybersecurity, and (4) how to measure the success of these actions. Participants should exit this session with a better understanding on what change they can make to have a positive impact on diversifying the cybersecurity workforce at their institution. This BoF will plant a seed for a community of educators who want to contribute to the cybersecurity diversification effort through evidence-based interventions. A summary of the BoF discussion will be disseminated publicly and shared with the BoF participants for possible future collaboration. The BoF facilitators will create a working group for the participants to follow up on diversification efforts and will hold periodic virtual meetings to discuss contributions, observations, outcomes and recommendations.
Ahmed Ibrahim 0004, Chelsea Gunn, Leona Mitchell, Sherif M. Khattab
SIGCSE (2)4
2022 The Effect of Animations Using Real-world Analogies on Diverse Computer Systems Students
abstract
It is a challenge to engage students when teaching them abstract and complex computer systems concepts, such as buffer overflow, memory management, concurrent execution, and process synchronization. Past research has shown that interactive animation and real-life analogies make STEM concepts more approachable and help students achieve better learning outcomes. Based on these findings, we introduce interactive analogies into learning the concept of buffer overflow. More specifically, we created a dry-cleaning shop animation tool (https://scratch.mit.edu/projects/571317697/) targeting K-12 and undergraduate students. To assess the effectiveness of our tool, we are in the process of conducting a user study, in which students use our animation tool to learn about buffer overflow and take pre- and post-assessment on the concept. Our goal is to make CS learning more accessible to diverse students, regardless of their background and age.
Rachel Puckett, Wonsun Ahn, Sherif M. Khattab, Luis Oliveira 0002, Vinicius Petrucci
SIGCSE (2)4
2022 Laundry Overflow: Engaging Diverse Students in CyberSecurity using Interactive Analogies
abstract
Past research has shown interactive animations, and those that use real-life analogies in particular, can play an important role in providing the intuition required to understand Computer Science concepts. Nonetheless, the use of analogies continues to be under-explored in CS education compared to other STEM fields. To break the impasse, we aim to create and evaluate a set of interactive animations based on analogies to understand their efficacy. As our first addition, we have created an animation explaining the Buffer Overflow computer systems concept. Explaining the concept abstractly has had a track record of ineffectiveness in our department, since the concept of computer memory as a series of contiguous storage locations is so foreign to students. Instead, the animation uses the analogy of a dry-cleaning shop with a series of hangers to provide a concrete mental picture of computer memory. Students explore various dry-cleaning scenarios, in which customers drop off and pick up their laundry, to understand at their own pace when buffer overflows cause harm and when they are silently ignored. This animation: https://scratch.mit.edu/projects/571317697/ (and others) will be provided as an open educational resource to instructors to encourage the use of interactive analogies in their teaching, and to undergraduate and K-12 students.
Rachel Puckett, Wonsun Ahn, Sherif M. Khattab, Luis Oliveira 0002, Vinicius Petrucci
SIGCSE (2)4
2021 STAGER: Semantic-Based Framework for Generating Adapters of Service-Based Generic-API for Portable Cloud Applications
abstract
In PaaS model, providers have different proprietary APIs, which make developers locked inside a specific platform and not able to easily port their applications among different platforms. So, vendor lock-in problem appeared. One solution to this problem is to use generic APIs with specific adapters. However, any update in a PaaS specific-API makes its corresponding adapter is unusable which causes, what we call, API synchronization problem. Therefore, STAGER (SemanTic-based GenERation of Generic-API Adapters) framework is proposed. STAGER framework provides a semi-automatic adapter generation process, which generates specific adapters of generic APIs for PaaS services (e.g., blob storage and datastore services) for target PaaS platforms. The adapter generation process is based on semantic annotations of the generic APIs and their corresponding PaaS specific-APIs. In order to evaluate STAGER framework, two generic APIs for blob storage and NoSQL datastore services have been proposed. STAGER framework is used to generate the adapters of these generic APIs for two PaaS platforms: Google App Engine (GAE) and Windows Azure. Although there is some overhead for semantically annotating the PaaS APIs, the evaluation results prove the feasibility of STAGER framework and promote the usage of the generated adapters for implementing portable cloud applications.
Eman Hossny, Sherif M. Khattab, Fatma A. Omara, Hesham A. Hassan
IEEE Trans. Serv. Comput.2
2016 Prediction mechanisms for monitoring state of cloud resources using Markov chain model
Mustafa M. Al-Sayed, Sherif M. Khattab, Fatma A. Omara
J. Parallel Distributed Comput.2
2013 GPSO: An improved search algorithm for resource allocation in cloud databases
abstract
The Virtual Design Advisor (VDA) has addressed the problem of optimizing the performance of Database Management System (DBMS) instances running on virtual machines that share a common physical machine pool. In this work, the search algorithm in the optimization module of the VDA is improved. The particle swarm optimization (PSO) heuristic is used as a controller of the greedy heuristic algorithm to reduce trapping into local optima. Our proposed algorithm, called Greedy Particle Swarm Optimization (GPSO), was evaluated using prototype experiments on TPC-H benchmark queries against PostgreSQL instances in Xen virtualization environment. Our results show that the GPSO algorithm required more computation but in many test cases have succeeded to escape local optima and reduced the cost as compared to the greedy algorithm alone.
Radhya Sahal, Sherif M. Khattab, Fatma A. Omara
AICCSA2
2010 A key-agreement protocol based on the stack-overflow software vulnerability
abstract
Exploiting software vulnerabilities, such as stack overflow, heap overflow, and format string exploits, enables attackers to break into victim machines. Moreover, attackers tend to use obfuscation techniques, such as encryption, to evade intrusion detection systems. In this paper, we show that a common stack-overflow attack, namely the return-to-libc attack, coupled with a common defense, namely the Address Space Layout Randomization (ASLR), together allow for constructing a key-agreement protocol that allows two entities (e.g., a Trojan and a controller) to agree on a shared key, whereas the shared key can then be used to encrypt further communication. We have developed a prototype of our key-agreement protocol to evaluate its feasibility and performance. Our results show that both time and message overhead of our protocol are linear in key length. Although our key-agreement protocol can be used by attackers for malicious purposes, it has low computation overhead, making it a candidate for adoption in CPU-constrained platforms.
Tamer S. Fatayer, Sherif M. Khattab, Fatma A. Omara
ISCC2
2009 Considering Link Qualities in Fault-Tolerant Aggregation in Wireless Sensor Networks
abstract
The goal of Wireless Sensor Networks is to extract useful global information from individual sensor readings, which are typically collected and aggregated over a spanning tree. However, the spanning tree structure is not robust against communication errors; a low-quality (i.e., high-error-rate) wireless link close to the tree root may result in a high rate of global information loss. Therefore, many schemes have been proposed to achieve fault-tolerant aggregation. Intuitively, using timely link-quality information, which is gathered by continuous monitoring and error-rate measurement of network links, improves the performance of fault-tolerant aggregation schemes. In this paper, we show that this intuition is not always true. In particular, we show that using link-quality information in an intuitive but wrong way results in degraded performance in some schemes, and therefore, care should be taken in using link-quality information. We also show that some schemes make better usage of link-quality information than others, and some schemes are more robust to errors in link-quality estimation than others. We support our findings by an extensive simulation study, and we focus on the (more general) class of fault-tolerant duplicate-sensitive aggregation schemes.
Sameh Gobriel, Sherif M. Khattab, Daniel Mossé, Rami G. Melhem
GLOBECOM2
2008 Live Baiting for Service-Level DoS Attackers
abstract
Denial-of-service (DoS) attacks remain a challenging problem in the Internet. By making resources unavailable to intended legitimate clients, DoS attacks have resulted in significant loss of time and money for many organizations, thus, many DoS defense mechanisms have been proposed. In this paper we propose live baiting, a novel approach for detecting the identities of DoS attackers. Live baiting leverages group-testing theory, which aims at discovering defective members in a population using the minimum number of dasiadasiatestspsilapsila. This leverage allows live baiting to detect attackers using low state overhead without requiring models of legitimate requests nor anomalous behavior. The amount of state needed by live baiting is in the order of number of attackers not number of clients. This saving allows live baiting to scale to large services with millions of clients. We analyzed the coverage, effectiveness (detection time, false positive and false negative probabilities), and efficiency (memory, message overhead, and computational complexity) of our approach. We validated our analysis using NS-2 simulations modeled after real Web traces.
Sherif M. Khattab, Sameh Gobriel, Rami G. Melhem, Daniel Mossé
INFOCOM1
2008 GroupBeat: Wireless sensor networks made reliable
abstract
In wireless sensor networks (WSN) node failures are typically detected using a heartbeat application, where a neighbor detects a failed node when it misses successive short messages (ldquoheartbeatsrdquo) that should have been sent by the failed node. However, wireless links are usually lossy, hence, to distinguish node failures from intermittent link failures, the threshold on the number of missed heartbeats is usually set to a large number, incurring in a long delay for declaring a node dead. In this paper we present ldquoGroupBeatrdquo an accurate node failure detection system for WSN and propose the ldquoCommunication By Signalingrdquo scheme as an energy-efficient low-overhead implementation of GroupBeat.
Sameh Gobriel, Sherif M. Khattab, Daniel Mossé, Rami G. Melhem
MASS2
2008 Modeling of the channel-hopping anti-jamming defense in multi-radio wireless networks
abstract
Multi-radio (multi-interface, multi-channel) 802.11 and sensor networks have been proposed to increase network capacity and to reduce energy consumption, to name only a few of their applications. They are vulnerable, however, to jamming attacks, in which attackers block communication by radio int
Sherif M. Khattab, Daniel Mossé, Rami G. Melhem
MobiQuitous1
2008 Jamming Mitigation in Multi-Radio Wireless Networks: Reactive or Proactive?
abstract
Jamming is a serious security problem in wireless networks. Recently, software-based channel hopping has received attention as a jamming countermeasure. In particular, proactive, or periodic, channel hopping has been studied more extensively than reactive hopping. In this paper, we address the question of which of the two defense strategies, namely proactive and reactive channel-hopping, provides better jamming resiliency than the other? in the context of single-and multi-radio wireless devices. In the single-radio context, we develop theoretical models to analyze the blocking probability for combinations of defense and attack strategies. In the multi-radio setting, we formulate the jamming problem as a max-min game and show through simulation that the game outcome depends on the payoff function. Our results show that reactive defense provides better jamming tolerance than proactive when considering communication availability. However, both reactive and proactive defenses have almost the same performance when energy efficiency is considered as a performance metric.
Sherif M. Khattab, Daniel Mossé, Rami G. Melhem
SecureComm1
2006 Integrated Scheduling of Application- and Network-Layer Tasks in Delay-Tolerant MANETs
abstract
Natural or man-made disasters can partition networks while threatening human lives. Because conventional mobile ad-hoc networks (MANETs) cannot route messages across partitions, they may not adequately support relief efforts. To forward messages across partitions, delay-tolerant networks (DTNs) exploit in-network storage and mobility. Many previous DTN routing protocols either opportunistically use, but do not modify, nodes' mobility, or require dedicated mobile gateways. This paper contributes a cross-layer DTN routing approach based on the observation that application-layer orders from a MANET's leader also control workers' mobility and ability to forward messages. Our approach attempts to minimize deadline misses and energy consumption by scheduling worker tasks considering both application- and network-layer needs. Simulations demonstrate performance benefits of our approach in a variety of scenarios.
José Carlos Brustoloni, Sherif M. Khattab, Christopher Santamaria, Brian Smyth, Daniel Mossé
GLOBECOM2
2006 Honeybees: combining replication and evasion for mitigating base-station jamming in sensor networks
abstract
By violating MAC-layer protocols, the jamming attack aims at blocking successful communication among wireless nodes. Wireless sensor networks (WSNs) are highly vulnerable to jamming because of reliance on shared wireless medium, constrained per-sensor resources, and high risk of sensor compromise. Moreover, base stations of WSNs are single points of failure and, thus, attractive jamming targets. To tackle base-station jamming, replication of base stations as well as jamming evasion, by relocation to unjammed locations, have been proposed. In this paper, we propose Honeybees, an energy-aware defense framework against base-station jamming attack in WSNs. Honeybees efficiently combines replication and evasion to allow WSNs to continue delivering data for a long time during a jamming attack. We present three defense strategies: reactive, proactive, and hybrid, in the context of multi-hop WSN deployment. Through simulation, we show the interaction of these strategies with different attack tactics as well as the effect of system and attack parameters. We found that our honeybees framework struck an energy-efficient balance between replication and evasion that outperformed both separate mechanisms. Specifically, hybrid honeybees outperformed replication and evasion at low and intermediate number of attackers and gracefully degraded to high attack intensity
Sherif M. Khattab, Daniel Mossé, Rami G. Melhem
IPDPS1
2006 Honeypot back-propagation for mitigating spoofing distributed Denial-of-Service attacks
abstract
The Denial-of-Service (DoS) attack remains a challenging problem in the current Internet. In a DoS defense mechanism, a honeypot acts as a decoy within a pool of servers, whereby any packet received by the honeypot is most likely an attack packet. We have previously proposed the roaming honeypots scheme to enhance this mechanism by camouflaging the honey-pots within the server pool, thereby making their locations highly unpredictable. In roaming honeypots, each server acts as a honeypot for some periods of time, or honeypot epochs, the duration of which is determined by a pseudo-random schedule shared among servers and legitimate clients. In this paper, we propose a honeypot back-propagation scheme to trace back attack sources when attacks occur. Based on this scheme, the reception of a packet by a roaming honeypot triggers the activation of a DAG of honeypot sessions rooted at the honeypot under attack towards attack sources. The formation of this tree is achieved in a hierarchical fashion: first at the autonomous system (AS) level and then at the router level within an AS if needed. The proposed scheme supports incremental deployment and provides deployment incentives for ISPs. Through ns-2 simulations, we show how the proposed scheme enhances the performance of a vanilla Pushback defense by obtaining accurate attack signatures and acting promptly once an attack is detected
Sherif M. Khattab, Rami G. Melhem, Daniel Mossé, Taieb Znati
IPDPS1
2006 RideSharing: Fault Tolerant Aggregation in Sensor Networks Using Corrective Actions
abstract
In wireless sensor networks (WSNs), the users' objective is to extract useful global information by collecting individual sensor readings. Conventionally, this is done using in-network aggregation on a spanning tree from sensors to data sink. However, the spanning tree structure is not robust against communication errors; when a packet is lost, so is a complete subtree of values. Multipath routing can mask some of these errors, but on the other hand, may aggregate individual sensor values multiple times. This may produce erroneous results when dealing with duplicate-sensitive aggregates, such as SUM, COUNT, and AVERAGE. In this paper, we present and analyze two new fault tolerant schemes for duplicate-sensitive aggregation in WSNs: (1) cascaded ridesharing and (2) diffused ridesharing. These schemes use the available path redundancy in the WSN to deliver a correct aggregate result to the data sink. Compared to state-of-the-art, our schemes deliver results with lower root mean square (RMS) error and consume much less energy and bandwidth. RideSharing can consume as much as 50% less resources than hash-based schemes, such as SKETCHES and synopsis diffusion, while achieving lower RMS for reasonable link error rates
Sameh Gobriel, Sherif M. Khattab, Daniel Mossé, José Carlos Brustoloni, Rami G. Melhem
SECON2
2006 Honeypot back-propagation for mitigating spoofing distributed Denial-of-Service attacks
Sherif M. Khattab, Rami G. Melhem, Daniel Mossé, Taieb Znati
J. Parallel Distributed Comput.1
2004 Roaming Honeypots for Mitigating Service-Level Denial-of-Service Attacks
abstract
Honeypots have been proposed to act as traps for malicious attackers. However, because of their deployment at fixed (thus detectable) locations and on machines other than the ones they are supposed to protect, honeypots can be avoided by sophisticated attacks. We propose roaming honeypots, a mechanism that allows the locations of honeypots to be unpredictable, continuously changing, and disguised within a server pool. A (continuously changing) subset of the servers is active and providing service, while the rest of the server pool is idle and acting as honeypots. We utilize our roaming honeypots scheme to mitigate the effects of service-level DoS attacks, in which many attack machines acquire service from a victim server at a high rate, against back-end servers of private services. The roaming honeypots scheme detects and filters attack traffic from outside a firewall (external attacks), and also mitigates attacks from behind a firewall (internal attacks) by dropping all connections when a server switches from acting as a honeypot into being active. Through ns-2 simulations, we show the effectiveness of our roaming honeypots scheme. In particular, against external attacks, our roaming honeypots scheme provides service response time that is independent of attack load for a fixed number of attack machines.
Sherif M. Khattab, Chatree Sangpachatanaruk, Daniel Mossé, Rami G. Melhem, Taieb Znati
ICDCS1
2004 Design and analysis of a replicated elusive server scheme for mitigating denial of service attacks
Chatree Sangpachatanaruk, Sherif M. Khattab, Taieb Znati, Rami G. Melhem, Daniel Mossé
J. Syst. Softw.2