Ali El Kamel

dblp:71/7380 · DBLP profile ↗
← Back
20ranked-venue papers
11as first author
13since 2021 · last 2026
0000-0002-7377-1469ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Applied, interdisciplinary, general and emerging computing · 7 · 3 first-author · 4 since 2021Artificial intelligence and machine learning · 6 · 2 first-author · 4 since 2021Computer networks · 5 · 5 first-author · 4 since 2021Security and privacy · 1
YearPublicationVenuePosition
2026 ICAP: Intelligent Context-Aware Platooning with Friction-Adaptive Control for Adverse Weather Conditions
Mohamed Amine Marzouk, Ali El Kamel, Habib Youssef
IWCMC2
2025 Smart Routing in IoV Environments: An Evolutionary-based Approach for Emergency Response Optimization
abstract
In emergency healthcare situations, both time and connectivity represent critical factors in the efficiency of the emergency process. The quick transportation of the patient and the synchronization with the target hospital help save lives and avoid complications during the route. While traditional emergency routing systems typically prioritize shortest path algorithms, they often overlook an important dimension in today’s connected world: the stability of mobile communication throughout the transit process. In this paper, we propose a smart, urgency-sensitive emergency routing approach in Internet of Vehicles (IoV) environments, which selects emergency routes depending on both the travel time and the communication quality constraints. Our solution integrates real-time network metrics such as signal strength and latency measurements into the route decision-making process, ensuring uninterrupted data transmission between moving emergency vehicles and hospital systems. Optimization is based on the Reference-Point-Based NSGA-II genetic algorithm and compared to the classical routing process. Results demonstrate that our approach favors slightly longer but better-connected routes, significantly improving the reliability of patient data streaming during emergency situations, and is computationally feasible for real-time EMS deployment.
Mohamed Amine Marzouk, Ali El Kamel, Habib Youssef
AICCSA2
2025 Dual Connectivity for Seamless Mobility in Software Defined Content Delivery Networks (SD-CDN)
Ali El Kamel, Habib Youssef
AINA (1)1
2025 CHC-DDoS: A DDoS Attacks Detection Scheme Using Host-Connection Graph Representation and GCN
Ahmed Saidane, Ali El Kamel, Habib Youssef
AINA (8)2
2024 Using FlowVisor and evolutionary algorithms to improve the switch migration in SDN
Ali El Kamel
J. Netw. Comput. Appl.1
2023 Towards DDoS-aware Routing in SDN using Cross-layer Knowledge Transfer
abstract
Routing packets efficiently is the main purpose of today’s networking. Mainly, efficiency deals with how securely are packets delivered taking in consideration the exponential growth of network threats, particularly the Distributed Denial of Service (DDoS) Attacks. However, security and routing are separately addressed in literature and little work was devoted to security-aware routing.In this paper, we point out the need to merge security and routing in SDN instead of addressing them separately. We propose a new DDoS-aware routing scheme using a cross-layer knowledge transfer between flows and switches. This scheme consists of learning features from flow-based DDoS attack datasets then transferring knowledge to switches. Transferred knowledge is used to establish reliable paths between end-points that avoid suspicious switches. Mainly, evaluation of a switch risk is based on a computation of a Suspicion Risk Factor (SRF) using a set of features learned from an ML-based classification of flows. Finally, SRFs of switches are used to seek for DDoS-aware paths. Evaluation results and analysis show that the proposed scheme outperforms the baseline protocol OSPF in terms of finding the most secure path and offered throughput.
Ahmed Saidane, Ali El Kamel, Habib Youssef
INISTA2
2023 A GNN-Based Rate Limiting Framework for DDoS Attack Mitigation in Multi-Controller SDN
abstract
This paper proposes a proactive protection against DDoS attacks in SDN that is based on dynamically monitoring rates of hosts and penalizing misbehaving ones through a weight-based rate limiting mechanism. Basically, this approach relies on the power of Graph Neural Networks (GNN) to leverage online deep learning. First, an encoder-decoder function converts a time-series vector of a host features to an embedding representation. Then, GraphSAGE uses hosts' embedding vectors to learn latent features of switches which are used to forecast next time-step values. Predicted values are inputted to a multi-loss DNN model to compute two discounts that are applied to weights associated to source edges using mutli-hop SDG-based backpropagation. Realistic experiments show that the proposed solution succeeds in minimizing the impact of DDoS attacks on both the controllers and the switches regarding the PacketIn arrival rate at the controller and the rate of accepted requests.
Ali El Kamel
ISCC1
2023 A Fast Failure Recovery Mechanism using On-Premise/Cloud-based NAS in SDN
abstract
This paper proposes a Fast Failure recovery mechanism which uses a set of Backup Assistants (BA) deployed in an SDN network to backup packets during the establishment of the recovery path. BAs can be either On-Premise or Cloud-based Network-Attached Storages (NAS). The recovery path is setup using a Fast Parallel Path Computation algorithm (FPPC) which is based on the Breadth-first Search (BFS) approach. Packets which are already stored are sent back once the recovery path is established. Simulations show that the proposed approach efficiently reduces the packet loss ratio compared to existing solutions while maintaining acceptable delay bounds for losssensitive applications.
Ali El Kamel
ISCC1
2022 Securing East-West Communication in a Distributed SDN
Hamdi Eltaief, Kawther Thabet, Ali El Kamel
HIS3
2022 Secure East-West Communication to Authenticate Mobile Devices in a Distributed and Hierarchical SDN
Maroua Moatemri, Hamdi Eltaief, Ali El Kamel, Habib Youssef
HIS3
2022 Secure East-West Communication to Approve Service Access Continuity for Mobile Devices in a Distributed SDN
Maroua Moatemri, Hamdi Eltaief, Ali El Kamel, Habib Youssef
ICCSA (1)3
2022 Improving the Routing Process in SDN Using a Combination of the Evidence Theory and ML
Ali El Kamel, Hamdi Eltaief, Habib Youssef
ISDA (4)1
2022 On-the-fly (D)DoS attack mitigation in SDN using Deep Neural Network-based rate limiting
Ali El Kamel, Hamdi Eltaief, Habib Youssef
Comput. Commun.1
2019 An Efficient MPLS-Based Approach for QoS Providing in SDN
Manel Majdoub, Ali El Kamel, Habib Youssef
ISDA2
2017 An Efficient MPLS-Based Source Routing Scheme in Software-Defined Wide Area Networks (SD-WAN)
abstract
Software Defined Networks (SDN) is a promising network paradigm that offers flexibility, efficiency and finegrained control over forwarding Elements (FE) by decoupling control and data planes. The forwarding decision is often made by the controller by managing flow table entries in the switches. Certainly, flow table management raises a lot of concerns and various schemes have been proposed such as the traditional Hopby-Hop Forwarding scheme. Studies have proved that this scheme may lead to performance degradation due to a huge control traffic and a massive flow table consumption. To reduce performance degradation, source routing was proposed. Unfortunately, this may also lead to significant bandwidth overhead, particularly in large-scale networks.This paper deals with the concept of source routing using MPLS labels. Basically, our scheme ensures flexibility and is suitable for application both in SD-LAN and SD-WAN by supporting various n-port switches (n ≥ 4). Using a MaxHop clustering algorithm, the network is divided into several sections. In each section, a trade-off between control traffic overhead, bandwidth overhead and flow table usage is achieved using a linear weighted scalarization of the Multi-Objective optimization problem. Finally, we present the θ-MOBO algorithm to be run by the controller. Simulation results show that the proposed scheme outperforms parallel solutions such as MPLS label-based forwarding [1] [2] and Hop-by-Hop forwarding [3] schemes in terms of the bandwidth overhead and flow rejection rate.
Ali El Kamel, Manel Majdoub, Habib Youssef
AICCSA1
2013 ARMLCC: Adaptive and recovery-based Multi-Layer Connected Chain Mechanism for Multicast Source Authentication
abstract
Source authentication in multicast communication is essential and challenging requirement. In this paper we address the multicast stream authentication problem when the communication channel is under the control of an opponent who can drop, reorder or inject data. In such a network model, robustness against packet loss, packet overhead and computing efficiency are important parameters to be taken into account when designing a multicast source authentication mechanism. The proposed scheme is based on adaptive and multi-layer connected chain structure in addition to an efficient recovery information model. It adapts the redundancy chaining degree depending on the actual packet loss rate in the network. Our mechanism provides non-repudiation of the origin and tolerates packet loss with low communication overhead, low delay and buffer capacity on the receiver side. NS-2 simulations show significant improvements over mechanisms in the same category.
Hamdi Eltaief, Ali El Kamel, Habib Youssef
IAS2
2013 A Bayesian k-NN based scheme for QoS provisioning in IP/MPLS networks
abstract
The Quality of Service (QoS) provisioning paradigm has become highly complicated due to the rising of networks complexity, heterogeneity and unpredictability. This complexity resulted in the need to satisfy stringent user's QoS requirements which depends generally on network capabilities. To deal with this complexity, an autonomic management of the global network seems to be mandatory. Indeed, autonomic network management can offer a new way to master end-to-end performances by providing self-* properties to networks. Self-* properties include self-optimization, self-organization, self-protection and many others. This paper proposes an autonomic and flexible end-to-end QoS provisioning scheme which is based on the per-hop classes of service discovery and its mapping to user's QoS requirements basing on the k-nearest neighbor algorithm (k-NN). Simulation results show that the proposed scheme significantly outperforms performances of parallel solutions such as the IntServ-over-Diffserv model and the EEAC-SV approach proposed in [14] with respect to the request delay bounds and the packet dropping ratio capability, respectively.
Ali El Kamel, Habib Youssef
AICCSA1
2013 A new Bayesian Model of QoS provisioning in DiffServ over MPLS networks
abstract
Natively, Multi Protocol Label Switching (MPLS) allows LSP/Tunnel setup using a round trip model. This Model consists of sending a request message, like the PATH message in the Resource Reservation Protocol(RSVP), and standing for a response message, like the RESV message in RSVP, upon which required resources are reserved. Moreover, crossed routers do not participate in flows classification according to DiffServ Model, since this classification is stringent and is driven by the ingress node at network entry. This paper proposes a new flexible one-way model of the LSP/Tunnel setup in MPLS networks which are based on the mapping of incoming requests on flows admission using a Naive Bayes model and the weighted K-nearest neighbor algorithm. The proposed model is compared to parallel solutions such as the IntServ-over-Diffserv model, the classical model using RSVP-TE and the EEAC-SV approach proposed in [12]. Simulation results show that the new model outperforms other solutions with respect to the request delay bounds and the packet dropping ratio capability, respectively.
Ali El Kamel, Hamdi Eltaief, Habib Youssef
HIS1
2012 A Distributed E2E Recovery Mechanism for MPLS Networks
abstract
This paper presents a new solution for inter-domain recovery within MPLS networks. The proposed mechanism is based on efficient collaboration between several entities called PCEs (Path Computation Elements). One PCE is designated at each domain. All PCEs should communicate in order to ensure suitable End-to-End(E2E) failure handling, recovery and restoration. Based on normative instructions described in the RFC 5298 and the Backward Recursive PCE-based Computation approach (BRPC) presented in RFC 5441, the new mechanism offers an opportunity to achieve E2E recovery using up-to-date information and giving a way to maintain correct network states with respect to intra-domain as well as inter-domain contexts, without care of heterogeneity and autonomy of crossed areas. Simulation results prove that, compared to existing E2E protection and on-demand backup path recovery mechanisms, the proposed solution is able to support, more efficiently, inter-domain recovery regardless of per-domains policies and rules, by ensuring lower recovery time, improved resources management and low packet loss/disorder bounds.
Ali El Kamel, Habib Youssef
PDP1
2009 An efficient hybrid recovery mechanism for MPLS-based networks
abstract
This paper proposes an improvement to the IETF (Internet Engineering Task Force) standard intra-domain recovery mechanisms based on a combination of the existing IETF standards. The proposed mechanism defines a new fast recovery process that ensures efficient resource utilization. Since the IETF protection switching mechanism follows a pre-planned approach, i.e., it selects a backup path only once at the LSP (Label Switched Path) setup time, it may not reflect the exact status of network resources at the time of a fault. Moreover, backup path computation may infer unsolicited delay before an available backup path can be selected. The proposed solution combines the pre-planned protection switching mechanism with an on-line computation of an available backup path that may be closer to the failing point. The backup path computation is ensured by an efficient and fast engine based on up-to-date network state and capability to support the required Forwarding Equivalence Class (FEC). Once found, a safe transition from protection model to the new backup path is performed. Simulations results prove that the proposed mechanism is able to ensure and maintain an optimized network state regardless of the fault occurrence.
Ali El Kamel, Habib Youssef
ISCC1