Mohammad El-Hajj 0001

dblp:68/3563-1 · also Mohammed El-Hajj 0001, Mohammed El-hajj 0001, Mohammed Elhajj 0001, Mohammed Ibrahim El-Hajj · DBLP profile ↗
← Back
9ranked-venue papers
4as first author
8since 2021 · last 2026
0000-0002-4022-9999ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 4 · 1 first-author · 4 since 2021Computer networks · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2026 Threat-Reactive Encryption: Real-Time ML-Driven Key Rotation for Adaptive Cryptographic Defense
Mohammad El-Hajj 0001
SECRYPT (1)1
2025 Hybrid Malware Classification using Static and Dynamic Features with Machine Learning
abstract
The increasing sophistication of malware demands hybrid detection strategies combining static and dynamic analysis. We present a machine learning framework integrating PE header analysis, byte n-grams, API calls, and sandbox behavioral traces through attention-based hierarchical fusion. Evaluated on Microsoft Malware Classification Challenge, VirusShare, and Malimg datasets, the framework achieves 92 % accuracy and 0.96 AUC-ROC, outperforming static-only (87 %) and dynamic-only (83 %) approaches, with 32 ms inference latency. Feature importance analysis highlights byte-level patterns (35%) and system call sequences (28%) as critical discriminators. Despite 8 % undetected adversarial samples and a 7.5 GB memory foot-print, the approach offers a modular foundation for robust malware detection, balancing efficacy and operational feasibility in enterprise environments.
Mohammad El-Hajj 0001
WINCOM1
2024 NAISS: A reverse proxy approach to mitigate MageCart's e-skimmers in e-commerce
abstract
The rise of payment details theft has led to increasing concerns regarding the security of e-commerce platforms. For the MageCart threat family, the attacks employ e-skimmers, which are pieces of software code that instruct clients to forward payment details to an attacker-controlled server. They can be injected into hosting providers' servers as HTML tags such as script, iframe, and img. By leveraging image steganography - the technique of hiding structured information inside images without visual perturbances - MageCart groups can deliver e-skimmers without raising suspicion. In this work, we systematically review applicable solutions in the literature and evaluate their drawbacks in the setting of a compromised hosting provider. While promising, existing solutions in the literature present shortcomings such as a lack of compatibility, adaptability, or functionality in the presence of an attacker. Based on this review, we compile a set of features for a better solution, which we use as a foundation for designing our proposed solution - NAISS: Network Authentication of Images to Stop e-Skimmers. Through our solution, digital signatures of individual images are checked inside a server-side middlebox residing in the hosting provider's network to prevent the transmission of unauthorized images to clients. Elliptic curve signatures are provided by the e-commerce platform developer prior to uploading a website to the hosting provider. Our proof-of-concept implementation shows that NAISS is capable of filtering 100% of present stegoimages, regardless of their novelty, while imposing a minimal performance detriment and no client-side modifications.
Adrian-Catalin Rus, Mohammad El-Hajj 0001, Dipti Kapoor Sarmah
Comput. Secur.2
2023 Security Aspects of Digital Twins in IoT
abstract
The number of Internet-connected devices are expected to reach almost 30 billion by 2030, and already today the Internet of Things (IoT) technologies is a part of everyday life in sectors like public health, smart cars, smart grids, smart cities, smart manufacturing and smart homes. An even tighter integration between IoT technology and physical objects within these sectors has been made possible by the Digital Twin (DT) technology providing better abilities for real-time monitoring, data-driven modeling and process optimization. One integral aspect of this approach is the connection between IoT end-devices and their corresponding digital twins for real-time data communication. Depending on the envisioned scenario, the involved data and derived processes affect the safety of human lives, hence an authentic connection is of major importance. At the same time, IoT devices have restrictions on the available power sources and provided computing resources. In this work we report on our ex periments with the Azure IoT Hub, the commercial platform that supports digital twins offered by Microsoft. First, we set up a real-time connection between the cloud platform and two different IoT devices and explore how an authentic connection is established between IoT devices and their corresponding DTs. Based on a test bed consisting of widely used IoT devices we analyse the power consumption and execution time of the offered authentication mechanisms that are based on general symmetric or asymmetric encryption. While the authentication time for a Raspberry Pi is below 0.5 seconds, the same task took above 4.5 seconds for an Arduino, highlighting the importance of lightweight authentication mechanisms for real-time communication between IoT devices and DT platforms.
Vitomir Pavlov, Florian Hahn 0001, Mohammad El-Hajj 0001
ICISSP3
2023 A Comparison of Authentication Protocols for Unified Client Applications
abstract
OAuth, LDAP, forward authentication, and proxy authentication are protocols that allow a service to use a third party for user authentication. We compare these protocols on a variety of aspects, concluding that OAuth offers the greatest end-user convenience, forward and proxy authentication are the easiest to implement for the client application, and LDAP puts restrictions on how to identify the end-users. We then demonstrate a single data structure that can be used to store a client application in all four protocols, overcoming their disparate ways of functioning.
Floris Breggeman, Mohammad El-Hajj 0001, Florian Hahn 0001
ISNCC2
2023 Enhancing IoT Security: Design and Evaluation of a Raspberry Pi-Based Intrusion Detection System
abstract
With the increasing number of IoT devices, safe-guarding them against cyber attacks has become a complex task. Traditional intrusion detection system (IDS) solutions are often impractical for resource-constrained IoT devices. To address this challenge, this research proposes and evaluates a Raspberry Pi-based IDS specifically designed to secure IoT devices. The study aims to analyze the effectiveness of the Pi-based IDS in detecting various network attacks, identify configuration changes to enhance its performance, and assess any potential vulnerabilities. The methodology involves conducting attacks on an IoT environment consisting of a Raspberry Pi with IDS, a temperature sensor transmitting data to a web server, and a background traffic generator. The study analyzes and presents metrics data extracted from log files. The expected outcome is to demonstrate the efficacy of the Raspberry Pi-based IDS and provide insights into its potential advantages for securing IoT devices by detecting network attacks. The findings of this research will contribute to the existing IoT security literature and offer recommendations for optimizing the Snort IDS on the Raspberry Pi platform.
Toghrul Garalov, Mohammad El-Hajj 0001
ISNCC2
2023 Defeating MageCart Attacks in a NAISS Way
abstract
MageCart attacks pose a security threat to E-commerce platforms by using e-skimmers to steal payment details. Image steganography is used by attackers to conceal e-skimmers, making detection challenging. Existing solutions have limitations, such as incompatibility or insufficient functionality. This research proposes NAISS, a server-side middlebox solution that leverages digital signatures to filter unauthorized images without requiring client-side modifications. The proof-of-concept implementation demonstrates the efficacy of NAISS, filtering 100% of state of the art stegoimages, while indicating areas for further improvement.
Catalin Rus, Dipti Kapoor Sarmah, Mohammad El-Hajj 0001
SECRYPT3
2021 A taxonomy of PUF Schemes with a novel Arbiter-based PUF resisting machine learning attacks
Mohammad El-Hajj 0001, Ahmad Fadlallah, Maroun Chamoun, Ahmed Serhrouchni
Comput. Networks1
2019 Ethereum for Secure Authentication of IoT using Pre-Shared Keys (PSKs)
abstract
Enterprises are no doubt interested in reaching data collected from billions of Internet of Things (IoT) devices which opens a huge potential business. The main concern remains the security challenges from the distribution of key while using public key cryptography. To ensure that IOT connected devices can be trusted to be what they are supposed to be, robust IoT device authentication is mandated. Each IoT device therefore requires a unique identity which can be verified when the device tries to link to an intermediate device. One of the early solutions used to secure data transmission among parties in public networks is the Public Key Infrastructure (PKI) which is used to distribute and manage public keys (digital certificates) among different parties and these certificates are generated upon request by Certificate Authorities (CA). Nevertheless, for billions of devices connected to IoT and mobile phones, the distribution management of certificates for each client proved to be inefficient. In this research, we propose a decentralized authentication platform based on PKI and Ethereum Blockchain. The public key certificates are stored in a decentralized fashion and the private keys are stored inside the devices themselves. It also includes a protocol for Pre-Shared Keys (PSK) distribution. PSK keys are then used by PSK-based security protocols for securing the communication channel between two devices. This platform includes a client-side module, a server-side Wallet Management Function, and a smart contract deployed on the Ethereum Blockchain network. This platform can be used by applications for end devices and/or intermediate devices authentication and a secure Machine-to-Machine (M2M) communication. The proposed platform is validated by the implementation of a Secure Session Establishment between IoT devices. Results show that the solution implementation has minimal impact on the existing networks, and the secure session setup time between two devices is negligible compared to the existing security methods. Eventually, this scheme can help removing the trust requirement placed on clients by the current PKI/CAs infrastructure.
Mohammad El-Hajj 0001, Ahmad Fadlallah, Maroun Chamoun, Ahmed Serhrouchni
WINCOM1