Ahmed Serhrouchni

dblp:77/6060 · DBLP profile ↗
← Back
53ranked-venue papers
0as first author
10since 2021 · last 2026
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 25 · 6 since 2021Security and privacy · 7 · 1 since 2021Human-computer interaction and ubiquitous computing · 4Software engineering, systems software and programming languages · 3 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 2 since 2021Artificial intelligence and machine learning · 1
YearPublicationVenuePosition
2026 Unlocking the potential of data: Toward a secure and privacy-preserving blockchain-based health data governance framework
abstract
Data have always been at the heart of organizations, fueling decision-making, service delivery, and influencing people's way of life. Organizations work to improve the visibility, reliability, security, and scalability of data. Yet, these attempts are not without challenges. One of the biggest challenges faced by organizations is data confidentiality since a data breach can affect a person's dignity with severe consequences for the organization itself. Data governance is necessary to mitigate these risks, especially when dealing with sensitive information such as health data. This research paper presents a novel approach to data governance through the development of a blockchain-based framework that aims to unlock the potential of data while minimizing the risk of data breaches and unauthorized access. It involves three critical components - data classification, data segregation, and data access control – to ensure proper management, protection, and utilization of data within an organization. While this paper discusses the implementation of our framework within the healthcare ecosystem, it also offers a clear roadmap to facilitate its adoption across any data-driven domain. Our approach demonstrates how data accessibility can be enhanced while safeguarding data privacy and upholding its availability, integrity, and confidentiality.
Rita Azzi, Rima Kilany, Ahmed Serhrouchni, Maria Sokhn
Blockchain Res. Appl.3
2024 DNS flooding attack detection scheme through Machine Learning
abstract
Domain Name System (DNS) servers are considered registers that enable internet devices to quickly look up specific web servers and access web pages. DNS flooding is a type of distributed denial of service (DDoS) attack in which an attacker overwhelms DNS servers with a huge number of resolution requests. Such an attack can prevent DNS servers from responding to legitimate traffic. In this paper, we propose a new approach that relies on monitoring and analyzing incoming DNS requests to identify flooding attacks against DNS servers. The detection is carried out using a Machine Learning-based Intrusion Detection System at the entry point of networks. We analyze the performance of different machine learning methods (decision tree, random forest, XGBoost, SVM, K-nearest neighbors, logistic regression, and Multi-Layer Perceptron) for detecting DNS flooding attacks. The evaluation was conducted in the context of emulated attacks. The obtained results reveal that all six methods exhibit the capability to effectively detect DNS attacks, even when dealing with low attack rates. This highlights the robustness of these methods and their potential to maintain high accuracy levels in identifying DNS attack patterns.
Ali El Attar, Rida Khatoun, Fadlallah Chbib, Ahmad Fadlallah, Ahmed Serhrouchni
IWCMC5
2023 DS-IRSA: A Deep Reinforcement Learning and Sensing Based IRSA
abstract
One of the main difficulties to enable the future scaling of IoT networks is the issue of massive connectivity. Recently, Modern Random Access protocols have emerged as a promising solution to provide massive connections for IoT. One main protocol of this family is Irregular Repetition Slotted Aloha (IRSA), which can asymptotically reach the optimal throughput of 1 packet/slot. Despite this, the problem is not yet solved due to lower throughput in non-asymptotic cases with smaller frame sizes. In this paper, we propose a new variant of IRSA protocol named Deep-Learning and Sensing-based IRSA (DS-IRSA) to optimise the performance of IRSA in short frame IoTs, where a sensing phase is added before the transmission phase and users' actions in both phases are managed by a deep reinforcement learning (DRL) method. Our goal is to learn to interact and ultimately to learn a sensing protocol entirely through Deep Learning. In this way, active users can coordinate well with each other and the throughput of the whole system can be well improved. Simulation results show that our proposed scheme convergence quickly towards the optimal performance of almost 1 packet/slot for small frame sizes and with enough minislots and can achieve higher throughput in almost all cases.
Iman Hmedoush, Pengwenlong Gu, Cédric Adjih, Paul Mühlethaler, Ahmed Serhrouchni
GLOBECOM5
2023 Lightweight TLS 1.3 Handshake for C-ITS Systems
abstract
Cooperative Intelligent Transport Systems (C-ITS) Deployment Platform is considered the newest version of vehicular communication systems, which enables the cooperation between two or more ITS sub-systems to provide enhanced services. With the expanded communication range and system complexity, ensuring the credibility of access nodes and protecting users from being monitored has become a difficult problem in network security, especially the services provided by remote servers like navigation. Transport Layer Security (TLS) is widely used for user authentication and encrypted data transmission in all networks. However, although the TLS handshake complexity is significantly reduced in TLS 1.3 the transmission of a full certificate chain during the handshake is still costly, especially for high-mobility vehicles. In this paper, we propose an optional extension named Certificate Get to reduce the TLS handshake overhead in C-ITS. Specifically, with our proposed extension, the revisiting client transmits a hash value of the certificate chain corresponding to a certain server in the ClientHello message, which can reduce the transmission payload of the certificate chain from an average of 4874 bytes to 68 bytes. Simulation results show that our proposed scheme achieves a significant performance gain by greatly reducing the certificate transmission delay by 50% for both TLS 1.3 and TLS 1.2.
Danylo Goncharskyi, Sung Yong Kim, Pengwenlong Gu, Ahmed Serhrouchni, Rida Khatoun, Farid Naït-Abdesselam
ICC4
2022 Delay Measurement of 0-RTT Transport Layer Security (TLS) Handshake Protocol
abstract
Transport Layer Security (TLS) 1.3 was normalised in 2018, in which an efficient 0-rtt handshake protocol was proposed. For future 5G networks, the 0-RTT handshake will be a more suitable choice for both secrecy and efficiency. However, 4 years after it was proposed, the 0-rtt handshake protocol is still not widely accepted by network service providers due to concerns about its ability to resist replay attacks. In order to address this issue, many solutions have be proposed in the past few year but all of them will increase the complexity and overhead of the 0-RTT protocol. In this paper, we focus on testing whether the 0-RTT handshake protocol is supported by service providers, and testing its performance in a real network environment to verify whether it can withstand continuous optimization in terms of security. Test results show that with 0-RTT, the server received the first application data up to 37 time faster than the 1-RTT and up to 83 time faster than 2-RTT. However, at the client side, the performance of 0-RTT protocol is virtually the same as 1-RTT, as predicted.
Danylo Goncharskyi, Sung Yong Kim, Ahmed Serhrouchni, Pengwenlong Gu, Rida Khatoun, Joel Hachem
CoDIT3
2022 TLS Early Data Resistance to Replay Attacks in Wireless Internet of Things
abstract
Transport Layer Security (TLS) is widely used for user authentication and encrypted data transmission in all kinds of networks. In its newly published version, TLS 1.3, a 0- RTT handshake protocol is proposed for session resumptions in low delay networks, which makes it possible to secure the data transmission and protect users from being monitored in wireless Internet of Things (IoTs). However, the 0-RTT TLS handshake protocol is vulnerable to the replay attack. In this paper, we propose a Time-Based One-Time Password (TOTP) empowered TLS encryption algorithm to resist replay attacks during the handshake process, in which we propose to integrate the TOTP into the encryption process of the EarlyData. It can significantly improve the forward secrecy of the 0-RTT handshake protocol and its capacity to resist the replay attack. On the other hand, we make no changes to the interaction process of the standardized 0- RTT handshake protocol to guarantee the compatibility of our proposed scheme, which makes our proposed scheme suitable for large area wireless IoTs. Simulation results show that under the premise of choosing an appropriate TOTP update rate, our proposed scheme can effectively resist replay attacks while ensuring the processing efficiency of the system.
Sung Yong Kim, Danylo Goncharskyi, Pengwenlong Gu, Ahmed Serhrouchni, Rida Khatoun, Farid Naït-Abdesselam, Jean-Jacques Grund
GLOBECOM4
2021 Scaling A Blockchain System For 5G-based Vehicular Networks Using Heuristic Sharding
abstract
5G communications are expected to expand both capacity and flexibility in future vehicular networks. However, due to the wide coverage range of 5G-based networks, massive device access in the 5G era will pose great challenges in access control and terminal management. In order to address the scalability issue in large-scale 5G-based vehicular networks, we propose in this paper the use of two heuristic sharding schemes which are based on the Determinantal Point Process (DPP) with different complexities. Specifically, in the proposed algorithms, both location and wireless channel condition of a base station (BS) are jointly considered respectively as diversity and quality parameters in the DPP. Both of them can effectively control the size of each shard, ensure the shards are evenly distributed and allow in-shard cooperation among the BSs. The communication robustness is then greatly improved due to the efficient in-shard cooperation and the system guarantees stable throughput even in scenarios where transactions volume changes dynamically. While compared to benchmark schemes, the simulation results of the proposed protocol and algorithms show significant performance gains in terms of coverage and load balancing.
Pengwenlong Gu, Dingjie Zhong, Cunqing Hua, Farid Naït-Abdesselam, Ahmed Serhrouchni, Rida Khatoun
GLOBECOM5
2021 Improved CRL Distribution point for Cooperative Intelligent Transportation Systems
Adja Elloh Yves-Christian, Ahmed Serhrouchni
IM2
2021 A taxonomy of PUF Schemes with a novel Arbiter-based PUF resisting machine learning attacks
Mohammad El-Hajj 0001, Ahmad Fadlallah, Maroun Chamoun, Ahmed Serhrouchni
Comput. Networks4
2021 A blockchain-based certificate revocation management and status verification system
Adja Elloh Yves-Christian, Badis Hammi, Ahmed Serhrouchni, Sherali Zeadally
Comput. Secur.3
2020 An Intelligent Mechanism for Sybil Attacks Detection in VANETs
abstract
Vehicular Ad Hoc Networks (VANETs) have a strategic goal to achieve service delivery in roads and smart cities, considering the integration and communication between vehicles, sensors and fixed road-side components (routers, gateways and services). VANETs have singular characteristics such as fast mobile nodes, self-organization, distributed network and frequently changing topology. Despite the recent evolution of VANETs, security, data integrity and users privacy information are major concerns, since attacks prevention is still open issue. One of the most dangerous attacks in VANETs is the Sybil, which forges false identities in the network to disrupt compromise the communication between the network nodes. Sybil attacks affect the service delivery related to road safety, traffic congestion, multimedia entertainment and others. Thus, VANETs claim for security mechanism to prevent Sybil attacks. Within this context, this paper proposes a mechanism, called SyDVELM, to detect Sybil attacks in VANETs based on artificial intelligence techniques. The SyDVELM mechanism uses Extreme Learning Machine (ELM) with occasional features of vehicular nodes, minimizing the identification time, maximizing the detection accuracy and improving the scalability. The results suggest that the suitability of SyDVELM mechanism to mitigate Sybil attacks and to maintain the service delivery in VANETs.
Carlos H. O. O. Quevedo, Ana M. B. C. Quevedo, Gustavo A. Campos, Rafael L. Gomes, Joaquim Celestino Jr., Ahmed Serhrouchni
ICC6
2020 Control Channel Anti-Jamming in Vehicular Networks via Cooperative Relay Beamforming
abstract
In vehicular networks, radio-frequency (RF) jamming attacks are considered a major threat to the availability of control channel (CCH). In particular, vehicles may not be able to receive control messages from roadside units (RSUs) due to persistent interference in the CCH, which may claim human lives and result in significant economic losses. In this article, a cooperative anti-jamming beamforming scheme is proposed to address the CCH jamming problems in vehicular networks. This scheme utilizes spatial diversity provided by the multiantenna RSU and relay vehicles to improve the transmission reliability of downlink control messages. In addition, to address the additive effects of the jamming signals and the intergroup interference, the relay selection problem and the beamformer design problem are jointly considered, which is modeled as a mixed-integer nonlinear programming (MINLP) problem. Then, we address this challenging problem by relaxing it into a series of convex subproblems via the semi-definite relaxation (SDR) and convex-concave process (CCP) methods, and then propose to solve these convex subproblems iteratively. The simulation results show that our proposed method convergences rapidly, and compared to the benchmark schemes, significant performance gains can be observed.
Pengwenlong Gu, Cunqing Hua, Wenchao Xu 0001, Rida Khatoun, Yue Wu 0010, Ahmed Serhrouchni
IEEE Internet Things J.6
2019 Ethereum for Secure Authentication of IoT using Pre-Shared Keys (PSKs)
abstract
Enterprises are no doubt interested in reaching data collected from billions of Internet of Things (IoT) devices which opens a huge potential business. The main concern remains the security challenges from the distribution of key while using public key cryptography. To ensure that IOT connected devices can be trusted to be what they are supposed to be, robust IoT device authentication is mandated. Each IoT device therefore requires a unique identity which can be verified when the device tries to link to an intermediate device. One of the early solutions used to secure data transmission among parties in public networks is the Public Key Infrastructure (PKI) which is used to distribute and manage public keys (digital certificates) among different parties and these certificates are generated upon request by Certificate Authorities (CA). Nevertheless, for billions of devices connected to IoT and mobile phones, the distribution management of certificates for each client proved to be inefficient. In this research, we propose a decentralized authentication platform based on PKI and Ethereum Blockchain. The public key certificates are stored in a decentralized fashion and the private keys are stored inside the devices themselves. It also includes a protocol for Pre-Shared Keys (PSK) distribution. PSK keys are then used by PSK-based security protocols for securing the communication channel between two devices. This platform includes a client-side module, a server-side Wallet Management Function, and a smart contract deployed on the Ethereum Blockchain network. This platform can be used by applications for end devices and/or intermediate devices authentication and a secure Machine-to-Machine (M2M) communication. The proposed platform is validated by the implementation of a Secure Session Establishment between IoT devices. Results show that the solution implementation has minimal impact on the existing networks, and the secure session setup time between two devices is negligible compared to the existing security methods. Eventually, this scheme can help removing the trust requirement placed on clients by the current PKI/CAs infrastructure.
Mohammad El-Hajj 0001, Ahmad Fadlallah, Maroun Chamoun, Ahmed Serhrouchni
WINCOM4
2018 BCTrust: A decentralized authentication blockchain-based mechanism
abstract
Internet of Things becomes a major part of our lives, billions of autonomous devices are connected and communicate with each other. This revolutionary paradigm creates a new dimension that removes the boundaries between the real and the virtual worlds. The Wireless Sensor Networks are a masterpiece of the success of this technology, using limited capacity sensors and actuators, industrial, medical, agricultural and many other environments can be covered and managed automatically. This autonomous interacting things should authenticate each other, and communicate securely. Otherwise malicious users can cause serious damages on such systems. In this paper we propose a robust, transparent, flexible and energy efficient blockchain-based authentication mechanism called BCTrust, which is designed especially for devices with computational, storage and energy consumption constraints. In order to evaluate our approach, we realized a real implementation with C programming language, and Ethereum Blockchain.
Mohamed Tahar Hammi, Patrick Bellot, Ahmed Serhrouchni
WCNC3
2018 CDBE: A cooperative way to improve end-to-end congestion control in mobile network
abstract
The advancing MAC/PHY technique and architecture in the mobile network allows the DownLink (DL) capacity in radio access network (RAN) to vary from Kilo-Byte per-second level up to Giga-byte per-second level in a glimpse. The existing TCP congestion control algorithms (CCA) were not designed for such dramatic variability. In this paper, we proposed an improvement for end-to-end congestion control, called Client Driven Bandwidth Estimation (CDBE), which allows TCP clients to cooperate with its CDBE. The cooperation can enhance the down-stream (DS) performance of the connections, even in the mobile network. The CDBE client can measure the available bandwidth (BW) on the bottleneck and inform the server of the BW estimation (BWE) result. Unlike existing mobile cross-layer congestion control proposals, the proposed algorithm on TCP client does not directly invoke information from UE MAC/PHY layer module but implicitly reflect the varying cellular BW when the mobile last hop is the bottleneck of the network. The CDBE TCP server uses the received BWE value to calculate its pacing rate and congestion window, and it further calibrates the result according to the variation of down-stream delay (DSDL). The state transition in the server can react rapidly to eNB BW and queue variation. Sets of NS3 system simulation in a LTE network is conducted with BBR and CQIC as the baseline. The result shows that the proposed algorithm can improve the end-to-end throughput and good-put while keeping the DS delay at a low level.
Zhenzhe Zhong, Isabelle Hamchaoui, Alexandre Ferrieux, Rida Khatoun, Ahmed Serhrouchni
WiMob5
2018 Cooperative relay beamforming for control channel jamming in vehicular networks
abstract
Radio Frequency (RF) jamming attacks constitute a major threat to the availability of control channel communications in the vehicular networks. In particular, the victim vehicles may fail to receive the safety related messages from the Road Side Unit (RSU) due to persistent jamming attacks, which can possibly cause tremendous economic loss and claim human lives. In this paper, we propose a cooperative anti-jamming beamforming scheme for the control channel jamming problem in vehicular networks, which takes advantage of the multi-antenna and spatial diversity provided by the RSU and relay vehicles to improve the transmission reliability of the victim vehicles. The anti-jamming beamformer design problem is formulated as a Mixed-integer Nonlinear Programming (MINLP) problem, which is intractable in general. We address this challenging problem by reformulating it as a sequence of convex sub-problems using the semi-definite relaxation (SDR) and convex-concave procedure (CCP) methods. Simulation results are provided to investigate the convergence of the proposed scheme, and significant performance gain can be observed comparing with other benchmark schemes.
Pengwenlong Gu, Cunqing Hua, Rida Khatoun, Yue Wu 0010, Ahmed Serhrouchni
WiOpt5
2018 Bubbles of Trust: A decentralized blockchain-based authentication system for IoT
Mohamed Tahar Hammi, Badis Hammi, Patrick Bellot, Ahmed Serhrouchni
Comput. Secur.4
2018 Event Detection in Wireless Body Area Networks Using Kalman Filter and Power Divergence
abstract
The collected data by biomedical sensors must be analyzed for automatic detection of physiological changes. The early identification of an event in collected data is required to trigger an alarm upon detection of patient health degradation. Such alarms inform healthcare professionals and allow them to quickly react by taking appropriate actions. However, events result from physiological change or faulty measurements, and lead to false alarms and unnecessary medical intervention. In this paper, we propose a framework for automatic detection of events from collected data by biomedical sensors. The proposed approach is based on the Kalman filter to forecast the current measurement and to derive the baseline of the time series. The power divergence is used to measure the distance between the forecasted and measured values. When a change occurs, this metric significantly deviates from past values. To distinguish emergency events from faulty measurements, we exploit the spatial correlation between the monitored attributes. We conduct experiments on real physiological data set and our results show that our proposed framework achieves a good detection accuracy with a low false alarm rate. Its simplicity and processing speed make our proposed framework efficient and effective for real-world deployment.
Osman Salem, Ahmed Serhrouchni, Ahmed Mehaoua, Raouf Boutaba
IEEE Trans. Netw. Serv. Manag.2
2017 Towards an Efficient File Synchronization between Digital Safes
abstract
One of the main concerns of Cloud storage solutions is to offer the availability to the end user. Thus, addressing the mobility needs and device's variety has emerged as a major challenge. At first, data should be synchronized automatically and continuously when the user moves from one equipment to another. Secondly, the Cloud service should offer to the owner the possibility to share data with specific users. The paper's goal is to develop a secure framework that ensures file synchronization with high quality and minimal resource consumption. As a first step towards this goal, we propose the SyncDS protocol with its associated architecture. The synchronization protocol efficiency raises through the choice of the used networking protocol as well as the strategy of changes detection between two versions of file systems located in different devices. Our experiment results show that adopting the Hierarchical Hash Tree to detect the changes between two file systems and adopting the WebSocket protocol for the data exchanges improve the efficiency of the synchronization protocol.
Mayssa Jemel, Mounira Msahli, Ahmed Serhrouchni
AINA3
2017 Cooperative Anti-Jamming Relaying for Control Channel Jamming in Vehicular Networks
abstract
Radio Frequency (RF) jamming attacks represent a major threat to the availability of services in vehicular networks. In particular, if the control channel is under persistent jamming attacks, the vehicles within the jamming area cannot receive the safety related messages from the road side unit (RSU), which can possibly cause tremendous economic loss and claim human lives. In this paper, we propose to adopt the cooperative relaying technique to address this problem, whereby the neighbouring vehicles outside of the jamming area serve as the relay nodes to forward the received control channel signal to the victim vehicles through the jamming- free service channel. To investigate the performance of this cooperative relaying scheme, we analyse the outage probability at the victims under different jamming scenarios based on Poisson point process (PPP) model. Simulation results are provided to validate the theoretical results and show the effectiveness of the cooperative anti-jamming relay scheme under different conditions.
Pengwenlong Gu, Cunqing Hua, Rida Khatoun, Yue Wu 0010, Ahmed Serhrouchni
GLOBECOM5
2017 Support Vector Machine (SVM) Based Sybil Attack Detection in Vehicular Networks
abstract
Vehicular networks have been drawing special atten- tion in recent years, due to its importance in enhancing driving experience and improving road safety in future smart city. In past few years, several security services, based on cryptography, PKI and pseudonymous, have been standardized by IEEE and ETSI. However, vehicular networks are still vulnerable to various attacks, especially Sybil attack. In this paper, a Support Vector Machine (SVM) based Sybil attack detection method is proposed. We present three SVM kernel functions based classifiers to distinguish the malicious nodes from benign ones via evaluating the variance in their Driving Pattern Matrices (DPMs). The effectiveness of our proposed solution is evaluated through extensive simulations based on SUMO simulator and MATLAB. The results show that the proposed detection method can achieve a high detection rate with low error rate even under a dynamic traffic environment.
Pengwenlong Gu, Rida Khatoun, Youcef Begriche, Ahmed Serhrouchni
WCNC4
2016 SyncDS: A digital safe based file synchronization approach
abstract
Within the diversity of existing Cloud storage solutions, meeting the requirements of user mobility and devices' variety is crucial. First, data should be synchronized automatically and continuously when the user moves from one equipment to another. Second, the service should offer to the owner the possibility to share some of his data with specific users. Working on the probative value archiving of sensitive documents, we propose an architecture and a protocol that ensure the data synchronization with high security and minimal resource consumption. We focus mainly on the security requirements when data are stored locally, synchronized and shared. In fact, the concepts of Digital Safe and timely-based file sharing are adopted. As a proof of conception, a formal security validation is provided to prove the safety of the proposed protocol, and an implementation of file sharing is performed on the Ciphertext Policy Attribute Based Encryption (CP-ABE) toolkit.
Mayssa Jemel, Mounira Msahli, Ahmed Serhrouchni
CCNC3
2016 Security Incident Response: Towards a Novel Decision-Making System
Samih Souissi, Ahmed Serhrouchni, Layth Sliman, Benoit Charroux
ISDA2
2015 Digital safe: Secure synchronization of shared files
abstract
Cloud Storage services are increasingly adopted by users to outsource their data. These services tend essentially to synchronize data across user's devices and to share them between different users. Two issues raise when dealing with synchronizing shared data. First, synchronizing data that are already encrypted by users to multiple destinations may clearly introduce key and access control management challenges. Second, it is essential to deal with the states constrains of the owner and the consumer. In fact, neither the owner who shared the data nor the consumer are usually connected at the same time. In the context of probative value storage of sensitive data, we focus mainly on the security requirements while considering a timely-file sharing. The shared data are synchronized for the legitimate user only for a specified period of time. A Synchronization Protocol for Digital Safe (SyncDS) is proposed and the Attribute Based Encryption (CP-ABE) is adapted to meet the data sharing requirements. In fact, a formal security validation is provided to demonstrate the safety of the proposed protocol. In addition, an implementation of the timely-file sharing is performed on the CP-ABE toolkit and integrated into the digital safe synchronization framework.
Mayssa Jemel, Mounira Msahli, Ahmed Serhrouchni
IAS3
2014 Security assurance of local data stored by HTML5 web application
abstract
Local data storage is one of the features that came with the HTML5 standard. Its purpose is to ensure the storage of web application's data in the device of the user rather than in the server side. With HTM5, the storage is no more achieved by proprietary solution as it is ensured by standardized APIs. However, with this new functionality that improves the user's quality of experience, it is crucial to reassure the end user about his data protection when they are stored locally and when they are externalized. In this work, our contribution deals with the assurance and security of data stored by HTML5 APIs. These measures are integrated into the browser to be performed automatically. In fact, data will be stored safely in a secure local space devoted to each user. As a proof of concept, we implemented our approach on the chromium browser, and we studied its performances.
Mayssa Jemel, Ahmed Serhrouchni
IAS2
2014 Improving Web Application Firewalls to detect advanced SQL injection attacks
abstract
Injections flaws which include SQL injection are the most prevalent security threats affecting Web applications[1]. To mitigate these attacks, Web Application Firewalls (WAFs) apply security rules in order to both inspect HTTP data streams and detect malicious HTTP transactions. Nevertheless, attackers can bypass WAF's rules by using sophisticated SQL injection techniques. In this paper, we introduce a novel approach to dissect the HTTP traffic and inspect complex SQL injection attacks. Our model is a hybrid Injection Prevention System (HIPS) which uses both a machine learning classifier and a pattern matching inspection engine based on reduced sets of security rules. Our Web Application Firewall architecture aims to optimize detection performances by using a prediction module that excludes legitimate requests from the inspection process.
Abdelhamid Makiou, Youcef Begriche, Ahmed Serhrouchni
IAS3
2014 Content protection and secure synchronization of HTML5 local storage data
abstract
Storage is one of the main services that came with Cloud Computing. It offers to the client the possibility to externalize his data. In this work, we concentrate on the use of HTML5 standard in SaaS cloud Services. In particular, we focus on the local storage APIs that offer to Web application the possibility to store user's data and information in browsers. These APIs allow the user to work in offline mode. The problem with HTML5 local storage, besides the lack of security in storage, is the loss of data while moving from one machine to another. Based on the adoption of Digital Safe, the main contributions of our proposal are as follows. First, we add new secure mechanisms to enhance the security in HTML5 local storage APIs. Second, we propose an architecture that ensures a secure synchronization of local data stored with HTML5.
Mayssa Jemel, Ahmed Serhrouchni
CCNC2
2014 Hybrid approach to detect SQLi attacks and evasion techniques
abstract
Injections flaws which include SQL injection are the most prevalent security threats affecting Web applications[1]. To mitigate these attacks, Web Application Firewalls (WAFs) apply security rules in order to both inspect HTTP data streams and detect malicious HTTP transactions. Nevertheless, at
Abdelhamid Makiou, Youcef Begriche, Ahmed Serhrouchni
CollaborateCom3
2014 A novel name-based security mechanism for information-centric networking
abstract
The Information-Centric Networking (ICN) approach represents a prominent future Internet research activity. It aims to ensure a large-scale content distribution while supporting mobility and security natively. In this approach, named content represents the central element and it is independent from its delivering host. Security can no longer be tied to a particular location. It is built-in the content and it strongly depends on names. There are mainly two naming approaches: (1) hierarchical and human readable, (2) flat and self-certifying. Each one provides certain security services. The other services are ensured using additional mechanisms. In this paper, we propose the adaptation of the naming system in order to provide a robust security model built-in the name. The proposed solution combines the benefits of the two existing naming system and it is built on top of Identity-Based Cryptography (IBC). A formal security analysis is provided to confirm the safety of the new proposal.
Balkis Hamdane, Sihem Guemara El Fatmi, Ahmed Serhrouchni
WCNC3
2013 Collaborative approach for inter-domain botnet detection in large-scale networks
abstract
The members of almost all botnets are distributed between several networks. Such distribution hardens their detection as the centralized approaches require to centralize network data for their analysis, which is indeed not possible in regard to the legacy and business constraints applied to network
Hachem Guerid, Karel Mittig, Ahmed Serhrouchni
CollaborateCom3
2013 Data-based access control in named data networking
abstract
Named Data Networking (NDN) presents one of the first and most emergent Information Centric Networking (ICN) project. It offers an excellent substrate to solve today's Internet problems. To ensure security challenge, it adopts a data-centric model. The access control represents a fundamental securit
Balkis Hamdane, Mounira Msahli, Ahmed Serhrouchni, Sihem Guemara El Fatmi
CollaborateCom3
2013 SBaaS: Safe Box as a service
abstract
While paperless is a source of tremendous opportunities for companies, it is also a bearing of many new risks. Indeed, externalization of electronic filing system can expose the company to several vulnerabilities and threats. We propose, in our gSafe (Government Safe) project a new Cloud service, na
Mounira Msahli, Ahmed Serhrouchni
CollaborateCom2
2010 Bayesian statistical analysis for spams
abstract
This paper presents a Bayesian statistical analysis applied to the spam problem. In most anti-spam related research, generally it is assumed that the probability of a spam occurrence is equal to 0.5, which is in our opinion unrealistic. It is also assumed that in the spam message, words are considered as an independent family of words. This makes us look at how the posterior probability behaves when the a priori probability is different from 0.5 and derive the consequences of the assumption of independent words on the posterior probability. The first assumption pushes us to define a prior and find a posterior probability laws to enhance the spam detection and increase the reliability decision. This analysis differs from previous results, that used the Bayesian approach to the anti-spam issue, especially through refinement and enhancement of various probability laws.
Youcef Begriche, Ahmed Serhrouchni
LCN2
2009 Conference knowledge modeling for conference-video-recordings querying & visualization
abstract
The evolution of the web in the last decades has created the need for new requirements towards intelligent information retrieval capabilities and advanced user interfaces. Nowadays, effective retrieval and usage of multimedia resources have to deal with the issues of creating efficient indexes, developing retrieval tools and improving user oriented visualization interfaces. To that end we put forward an integrated framework named CALIMERA. The framework is based on a High-level modEL for cOnference (HELO) and aims at enhancing the information management, retrieval and visualization of recorded talks of scientific conferences. This paper presents the conference model HELO developed to perform high level annotation of scientific talk recordings, to allow granular search facilities and complex queries, and to enhance knowledge retrieval and visualization of the recordings. As a proof-of-concept a prototype has been implemented and is presented in this paper.
Maria Sokhn, Francesco Carrino, Elena Mugellini, Omar Abou Khaled, Ahmed Serhrouchni
MEDES5
2009 Random Values, Nonce and Challenges: Semantic Meaning versus Opaque and Strings of Data
abstract
Current authentication and security protocols provide authentication services using either shared secret keys or certificates and public key infrastructures. They usually involve using random values and nonce to prohibit replay attacks and to generate fresh keys per each session. The Challenge-Response authentication mechanisms are the predominant access method for authentication and access control of today Internet applications. These mechanisms provide a proof of knowledge of the secret and then authenticate the communicating entity, which applies a cryptographic algorithm on the shared secret and the challenge sent by the other entity. Unfortunately, basic challenge-response mechanisms, such as HTTP Digest, do not provide mutual authentication and therefore suffer from several attacks, especially the man-in-the-middle and replay attacks. In this paper, we propose a semantic meaning for the challenge becoming used by these mechanisms. The proposed enhancement is completely backward-compatible; an entity aware of our extension connecting to another that does not wish to use or does not support it, will continue the basic authentication process. Moreover, our extension helps in reducing the identity usurpation attacks. A computation of the cryptographic loads and the data transfer demonstrates a negligible overall performance impact on the network and the entities.
Mohamad Badra, Ahmed Serhrouchni, Thomas Guillet
VTC Fall2
2008 A collaborative peer-to-peer architecture to defend against DDoS attacks
abstract
Nowadays, we are witnessing an important increase in attacks among which distributed denial-of-service (DDoS) that easily flood the victims using multiple paths. Intrusion detection and filtering are necessary mechanisms to combat against these attacks and secure networks. However, the existing detection techniques for DDoS attacks have their entities work in isolation. In this paper, we propose an efficient and distributed collaborative architecture that allows the placement and the cooperation of the defense entities to better address the main security challenges. The use of content based DHT (distributed hash table) algorithm permits also to improve the scalability and the load balancing of the whole system. This modular architecture has been implemented on IDS (intrusion detection system) entities with the DHT Pastry protocol and has shown a promising performance.
Radwane Saad, Farid Naït-Abdesselam, Ahmed Serhrouchni
LCN3
2006 Simple voice security protocol
abstract
The public telephone network has been evolving from manually switching wires carrying analog encoded voice to an automatically switched grid of copper-wired, fiber optical and wireless mobile connectivity carrying digitally encoded voice, image and data. The evolution of the information technology yields to a converged data and voice network based on IP technology. VoIP emerged and it is taking a large part of the telephony market nowadays. However, the IP network presents security threats to both data and voice packets. To ensure a secure voice network, the security services and mechanisms are defined and the security protocols are created. But, the existing security solutions are related to each network infrastructure. Also, the existing public telephone network does not provide such a service. This paper describes the Simple Voice Security Protocol that provides a secure end-to-end voice communication with an abstraction of the underlying infrastructure.
Carole Bassil, Ahmed Serhrouchni, Nicolas Rouhana
IWCMC2
2006 Internet Routing Security: An Approach to Detect and to React to Incorrect Advertisements
Ines Feki, Xiaoli Zheng, Mohammed Achemlal, Ahmed Serhrouchni
SECRYPT4
2005 Reliable Multicast over Satellite Networks
abstract
In this paper we address the issue of reliable multicast transport over satellite networks. The considered satellite system is a LEO constellation which has been simulated using the network simulator ns in order to analyze the delay characteristics of the system. To enable reliable multicast over satellite networks we propose to use Sat-RMTP. We propose as well to integrate forward error correction (FEC) into Sat-RMTP in order to increase its performance and to reduce the need of retransmission requests. Unfortunately the simulation results show that FEC is unable to fulfil its role in error recovery due to the fact that errors over satellite networks are temporally very bursty. To overcome this problem we propose a new mechanism that we call "error distribution mechanism". This mechanism intends to make loss appear more distributed at the receiver side. To achieve this objective, the sender has to send data out of order so that the probability that many consecutive packets in the same FEC block will be lost simultaneously decreases.
Taghrid Asfour-Block, Ahmed Serhrouchni
ISCC2
2004 DHCP Authentication Using Certificates
abstract
In this paper, we describe several methods of DHCP authentication. We propose an extension to DHCP protocol in order to allow a strict control on equipments by using a strong authentication. This extension, called E-DHCP (Extended-Dynamic Host Configuration Protocol) is based on two principles. The first one is the defimition of a new DHCP option that provides simultaneously the authentication of entities (client/server) and DHCP messages. The technique used by this option is based mainly on the use of asymmetric keys encryption RSA, X.509 identity certificates and attribute certificates. The second principle is the attribution of PMI (Privilege Management Infrastructure) attribute authority server functionalities to DHCP server. This server creates an attribute certificate to the client, which ensures the relation between the identity certifiicate of the client and the allocated IP address. This attribute certificate will be then used in the access control.
Jacques Demerjian, Ahmed Serhrouchni
SEC2
2004 A lightweight identity authentication protocol for wireless networks
Mohamad Badra, Ahmed Serhrouchni, Pascal Urien
Comput. Commun.2
2003 ISAKMP handshake for SSL/TLS
abstract
SSL/TLS protocol is without any doubt the most used security protocol. It presents nevertheless some limitations regarding the weakness of the handshake protocol and the absence of an authorization mechanism. In this paper, we give a new dimension to SSL/TLS by integrating the Internet security association and key management protocol (ISAKMP) in its session establishment phase. ISAKMP defines a framework for security association management and cryptographic key establishment for the Internet. This protocol opens a new perspective for secure sessions for all network layers. We then define an SSL/TLS security domain of interpretation (TLS DOI) which instantiates ISAKMP for use with SSL/TLS. This makes it possible to extend the work of SSL/TLS to support new services.
Ibrahim Hajjeh, Ahmed Serhrouchni, Frédérique Tastet
GLOBECOM2
2003 A new secure session exchange key protocol for wireless communications
abstract
WAP architectures consist of several protocols, especially WTLS (wireless transport layer security) and SSL (secure sockets layer). Although both protocols secure data over an open network, they differ in their mode of operation. SSL secures end-to-end communications whereas WTLS defines connection-oriented and datagram transport protocols. As these two protocols are incompatible with each other, WTLS does not provide secure connections with SSL. Thus, WAP gateways break secure links. This paper proposes a new security protocol in order to ensure an end-to-end secure session key exchange between the client and the web server and thus would have an impact on new services independent of WAP gateways.
Mohamad Badra, Ahmed Serhrouchni
PIMRC2
2002 Using distributed component model for active service deployment
abstract
This paper presents a novel active architecture for building and deploying network services: HABA, hyper active components architecture. At the architectural level, HABA defines an active node whose functionalities are divided into the node operating system, the execution environment, and the active applications. At the implementation level, HABA is a component-based platform where new components could be added and deployed, in order to modify network node behavior dynamically. Applications can communicate across multi-tiered heterogeneous environments, and across Internet and intranet structures. Interoperability with ANTS is achieved by "composition". At the deployment level, HABA uses an active node approach, and offers a parallel controlled deployment mode and a sequential by request mode. In terms of security, HABA offers different security levels according to service profiles. Authentication of deployed code, and protection of nodes, is achieved by the deployment of certificates on the nodes.
Rima Kilany, Ahmed Serhrouchni
ISCC2
2001 RMTP Performance in Heterogeneous Environments & a New QoS-Based Mechanism for Building RMTP Trees
abstract
We present a simplified model of RMTP (reliable multicast transport protocol) that we have integrated in the network simulator NS. The integration of this model results in five agents that can be used with any RMTP-based multicast simulation using NS. Based on these agents we analyze the performance of RMTP in heterogeneous environments. For this purpose nine RMTP-based multicast scenarios with different network conditions like loss rate, delay and bandwidth are simulated. We then present a new QoS-based mechanism for multicast group management that we call CGM (contractual group membership). This mechanism is mainly based on the contract notion. A "contract" is a set of rules established between a sender and a group of receivers, which determines worst case bounds on the physical conditions that the receivers must fulfil during the whole period of a multicast session. Based on a formal definition of the contract and on the use of the "minimum spanning tree-clustering method" a set of N receivers will be split into homogeneous subgroups. We finally propose a hybrid CGM/geographical subgrouping method to be used by RMTP in order to increase the performance of this protocol in heterogeneous environments.
Taghrid Asfour, Ahmed Serhrouchni
ISCC2
2000 Contractual Group Membership CGM: A New Mechanism for Multicast Group Management
abstract
We present a new concept for multicast group management called contractual group membership or CGM. The main idea behind this concept is the division of the receiver group into homogeneous subgroups. This division is based on physical conditions or/and QoS criteria like available bandwidth, delay, loss probability, ... . The sender will carry a separate conversation with each subgroup using the scalable reliable multicast protocol (SRMTP). We define a multidimensional distance factor to evaluate the logical distance between the members of a group in order to split this group into homogeneous subgroups. The dimensions of this distance factor are end-to-end bandwidth, delay, and loss rate. ESRMTP is an extended version of SRMTP that we have developed in order to support our new distance factor. The simulation results that we have obtained using the three dimensional distance factor with ESRMTP show that the bandwidth splitting is very important for increasing the average throughput of the multicast session and to minimize the average end-to-end delay. It shows as well that the delay and loss probability splitting decrease the jitter for each receiver which is very important for real-time applications. In addition to jitter minimization, loss rate splitting plays a key role in minimizing the network load caused by the FEC integrated in ESRMTP, due to the possibility of controlling the amount of FEC overhead as a function of the loss rate.
Taghrid Asfour, Stephan Block, Ahmed Serhrouchni, Samir Tohmé
ISCC3
2000 SPIN Model Checking: An Introduction
Gerard J. Holzmann, Ahmed Serhrouchni
Int. J. Softw. Tools Technol. Transf.3
1999 SNMPv3 Can Still be Simple?
abstract
The simple network management protocol (SNMP) was introduced in 1988. The initial version (SNMPv1) is still widely implemented, deployed, and used. SNMPv3 is now in its final stages of standardization. SNMPv3 allows new capabilities for open, interoperable, and secure management on the Internet environment. SNMPv3 builds on SNMPv1 and v2 to include methods for security (authentication, encryption, and privacy), and a new administrative framework. From a practical perspective, the SNMPv3 architecture must allow the evolution of the system to consider different versions of SNMP, different applications, and different security models. We present an implementation model for SNMPv3 that keeps the simplicity of SNMPv1, while at the same time making it possible to evolve the framework to address different security needs and different configurations. The implementation model is an abstract view of the implementation that represents the building blocks required for any realization of agents, platform, proxies, etc. We explain how the model with a modular approach can allow interoperability with other SNMP applications. The model uses the interfaces as defined by the RFC to achieve the architectural goals (extensibility, reusability, etc.) and to simplify the module construction. An implementation was done at UQAM and it uses Java to create the modular reusable components.
Omar Cherkaoui, Nathalie Rico, Ahmed Serhrouchni
Integrated Network Management3
1998 The modularity of SNMPv3
abstract
The Simple Network Management Protocol (SNMP) was introduced in 1988 and is still widely implemented, deployed, and used. SNMPv3 is now in its final stages of standardization. From a practical perspective, we need to consider how telecommunication systems can be extended to consider different versions of SNMP, different applications and different security models. We present an object-oriented implementation of SNMPv3 to create a flexible product architecture. This architecture allows one to easily interface with other modules as required. We also describe network object models and relationships required for the architecture. The implementation uses Java to create modular reusable components. We explain how the architecture using a modular approach can allow interoperability with other SNMP applications. Also, the systems can possibly connect via an API bus to CORBA, JMAPI or WBEM.
Omar Cherkaoui, Ylian Saint Hillaire, Hafedh Mili, Abdellatif Obaid, Ahmed Serhrouchni
ISCC5
1998 SET and SSL: electronic payments on the Internet
abstract
This paper presents a service architecture that combines SET and SSL to provide a lightweight secure electronic commerce system. Although both protocols secure data over an open network like the Internet, they differ in their mode of operation. SET defines secure transaction-oriented exchanges for payment systems whereas SSL secures point-to-point communications. SET and SSL are complementary and the combined architecture permits a gradual introduction of SET services by reducing the need for cardholder certification.
Mostafa Hashem Sherif, Ahmed Serhrouchni, A. Yassin Gaid, Farshid Farazmandnia
ISCC2
1998 QOS metrics tool using management by delegation
abstract
The Internet has become a widespread technology for providing public data, voice, video and multimedia services internationally. This paper presents a measurement methodology for evaluating quality of Internet service given by an ISP (Internet Service Provider), including a framework for defining the context and parameters for such measurement. The originality of this methodology lies principally in its reliance on sampling techniques and on its use of distributed applications to carry out measurement. The nature of the Internet places particular constraints on the amount and nature of data that can be collected, making statistical sampling necessary to answer certain types of questions. This paper addresses a number of methodological issues that arise when applying sampling techniques to the problem of measuring Internet service quality. This methodology is currently being implemented and tested by a major Canadian ISP.
Omar Cherkaoui, Abdellatif Obaid, Ahmed Serhrouchni, Noëmie Simoni
NOMS3
1998 Towards a modular and interoperable SNMPv3
abstract
The Simple Network Management Protocol (SNMP) was introduced in 1988 and is still widely implemented, deployed, and used. SNMPv3 is now in its final stages of standardization. From a practical perspective, we need to consider how telecommunication systems can be extended to consider different versions of SNMP, different applications and different security models. We will present an object-oriented implementation of SNMPv3 to create a flexible product architecture. This architecture allows to easily interface with other modules as required. We also describe network object models and relationships required for the architecture. The implementation uses Java to create modular reusable components. We explain how the architecture using a modular approach can allow interoperability with other SNMP applications. Also, the systems can possibly connect via an API bus to CORBA, JMAPI or WBEM.
Omar Cherkaoui, Ylian Saint-Hilaire, Hafedh Mili, Ahmed Serhrouchni
NOMS4
1990 PIL: A Tool for Pre-implementation of LOTOS
J. Queiroz, Ahmed Serhrouchni, P. Cunha
FORTE2