VLDB 2026 Research / reviewers in the wild / expert
Noura Limam
dblp:82/281
· DBLP profile ↗
26ranked-venue papers
4as first author
14since 2021 · last 2026
0000-0002-7759-3751ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 17 · 2 first-author · 9 since 2021Software engineering, systems software and programming languages · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | 5Guard: Isolation-Aware End-to-End Slicing of 5G NetworksabstractNetwork slicing logically partitions the 5G infrastructure to cater to diverse verticals with varying requirements. However, resource sharing exposes the slices to threats and performance degradation, making slice isolation essential. Fully isolating slices is resource-prohibitive, prompting the need for isolation-aware network slicing, where each slice is assigned a tailored isolation level to balance security, usability, and overhead. This paper investigates end-to-end 5G network slicing with resource isolation from the perspective of the infrastructure provider, ensuring compliance with the customers' service-level agreements. We formulate the online 5G isolation-aware network slicing (5G-INS) as a mixed-integer programming problem, modeling realistic slice isolation levels and integrating slice prior itization. To solve 5G-INS, we propose 5Guard, a novel adaptive framework that leverages an ensemble of custom optimization algorithms to achieve the best solution within resource budget and time constraints. Our results show that 5Guard increases profit by up to 15.1% and admission by up to 33.5% in a real-world large-scale network compared to the best-performing individual. Furthermore, we analyze the trade-offs between isolation levels, their impact on resource utilization, and the effects of slice placement, demonstrating significant advantages over baseline approaches that enforce uniform isolation policies. Mehdi Bolourian, Noura Limam, Mohammad Ali Salahuddin 0001, Raouf Boutaba |
IEEE Trans. Mob. Comput. | 2 |
| 2025 | Multi-Connectivity for Enhanced Throughput: a Critical StudyabstractMulti-connectivity is anticipated to provide more reliable, higher data rate connections for cellular network users by leveraging all available radio resources across base stations within one or multiple radio access technology(ies) (RAT). It aims to improve user mobility through multi-RAT connections or mitigate quality of service (QoS) degradation when users connect to congested cells through load-balancing traffic among base stations and distributing the user's flow across multiple links. Although many studies have investigated the benefits of multi-connectivity across various network deployments using analytical models or simulated environments, we critically assess these reported gains, particularly regarding system throughput. We argue that multi-connectivity's advantages are primarily restricted to scenarios with a low user-to-base station ratio and that dense networks are less likely to benefit. We formulate the user-to-base station association and resource allocation within a proportional fair (PF) setting across varying user densities to examine this. Our findings demonstrate that multi-connectivity offers no superiority over the PF single-connectivity baseline in dense networks. Furthermore, in sparse networks, we show that while multi-connectivity can potentially enhance system throughput, it does not significantly improve individual users' QoS, as the PF single-connectivity scheme can offer sufficient resources to every user. Amirmohammad Ghasemi, Noura Limam, Raouf Boutaba, Aladdin Saleh |
NOMS | 2 |
| 2025 | Monarch: Monitoring Architecture for 5G and Beyond Network SlicesabstractData-driven algorithms play a pivotal role in the automated orchestration and management of network slices in 5G and beyond networks, however, their efficacy hinges on the timely and accurate monitoring of the network and its components. To support 5G slicing, monitoring must be comprehensive and encompass network slices end-to-end (E2E). Yet, several challenges arise with E2E network slice monitoring. Firstly, existing solutions are piecemeal and cannot correlate network-wide data from multiple sources (e.g., different network segments). Secondly, different slices can have different requirements regarding Key Performance Indicators (KPIs) and monitoring granularity, which necessitates dynamic adjustments in both KPI monitoring and data collection rates in real-time to minimize network resource overhead. To address these challenges, in this paper, we present Monarch, a scalable monitoring architecture for 5G. Monarch is designed for cloud-native 5G deployments and focuses on network slice monitoring and per-slice KPI computation. We validate the proposed architecture by implementing Monarch on a 5G network slice testbed, with up to 50 network slices. We exemplify Monarch’s role in 5G network monitoring by showcasing two scenarios: monitoring KPIs at both slice and network function levels. Our evaluations demonstrate Monarch’s scalability, with the architecture adeptly handling varying numbers of slices while maintaining consistent ingestion times between 2.25 to 2.75 ms. Furthermore, we showcase the effectiveness of Monarch’s adaptive monitoring mechanism, exemplified by a simple heuristic, on a real-world 5G dataset. The adaptive monitoring mechanism significantly reduces the overhead of network slice monitoring by up to 76% while ensuring acceptable accuracy. Niloy Saha, Nashid Shahriar, Noura Limam, Raouf Boutaba, Aladdin Saleh |
IEEE Trans. Netw. Serv. Manag. | 4 |
| 2024 | 5GProvGen: 5G Provenance Dataset Generation FrameworkabstractThe softwarization and virtualization of the fifth-generation (5G) cellular networks bring about increased flexibility and faster deployment of new services. However, these advancements also introduce new vulnerabilities and unprecedented attack surfaces. The cloud-native nature of 5G networks mandates detecting and protecting against threats and intrusions in the cloud systems. Additionally, the evolving cyber-threat landscape and the growing reliance on cellular networks for mission-critical tasks reinforce the need for robust security systems, which should be capable of detecting stealthy and zero-day attacksRecent developments in Provenance-based Intrusion Detection Systems (PIDS) address these requirements. These host-based systems aim to analyze provenance graphs derived from system calls to uncover any deviation from the expected benign behaviour of the host. Provenance graphs are structured as holistic representations of the dependencies and causal relationships between digital objects, and hence they fit well in the Service-based Architecture (SBA) of 5G networks. However, deploying PIDS requires substantial datasets of provenance graphs collected from the relevant hosts. In this work, we propose a framework to generate provenance graphs datasets for a 5G core network. We provide an example dataset and evaluate the state-of-the-art PIDS in protecting a 5G network core from various threats. Amr Abouelkhair, Kiarash Majdi, Noura Limam, Mohammad A. Salahuddin 0002, Raouf Boutaba |
CNSM | 3 |
| 2024 | Signalling Load-aware Conditional Handover in 5G Non-Terrestrial NetworksabstractLow Earth orbit (LEO) satellites-based non-terrestrial networks (NTN) are envisioned to complement the fifth-generation (5G) terrestrial networks (TN), enabling global cellular services. However, the high mobility and large coverage of these satellites result in frequent and numerous inter-satellite handovers, leading to signalling storms that degrade the satellite gNodeB services. To address this, we mathematically formulate the handover problem and propose a novel signalling load-aware handover protocol based on conditional handover. We evaluate the effectiveness of the protocol using a customized discrete-event simulator and compare it against a set of baseline conditional handover schemes. Our findings show that the proposed protocol significantly reduces signalling peaks and balances the load more effectively, enhancing the robustness and efficiency of handover in 5G NTN. The simulator is made publicly available. Mohammad Ali Salahuddin 0001, Yunli Wang, Noura Limam, Bo Sun 0004, Diogo Barradas, Raouf Boutaba |
CNSM | 5 |
| 2024 | Secure and Efficient Group Handover Protocol in 5G Non-Terrestrial NetworksabstractThe growing low-Earth orbit (LEO) satellite con-stellations have become an essential part of the fifth-generation (5G) non-terrestrial network (NTN) market. These satellites can enable direct-to-cell connectivity for mobile devices and support various applications with ubiquitous coverage for 5G and beyond networks. However, satellite-based NTNs bring several challenges to the 5G handover protocol design. The high mobility of satellites can lead to signaling storms and security compromises during handovers. This paper addresses these challenges by proposing a secure and efficient group hand over protocol. The protocol's effectiveness is evaluated on a custom discrete-event simulator and compared against the baseline 5G hand over scheme. The simulator is made publicly available. A. Akbariazirani, Mohammad Ali Salahuddin 0001, Diogo Barradas, Noura Limam, Raouf Boutaba |
ICC | 6 |
| 2024 | AutoML4ETC: Automated Neural Architecture Search for Real-World Encrypted Traffic ClassificationabstractDeep learning (DL) has been successfully applied to encrypted network traffic classification in experimental settings. However, in production use, it has been shown that a DL classifier’s performance inevitably decays over time. Re-training the model on newer datasets has been shown to only partially improve its performance. Manually re-tuning the model architecture to meet the performance expectations on newer datasets is time-consuming and requires domain expertise. We propose AutoML4ETC, a novel tool to automatically design efficient and high-performing neural architectures for encrypted traffic classification. We define a novel, powerful search space tailored specifically for the early classification of encrypted traffic using packet header bytes. We show that with different search strategies over our search space, AutoML4ETC generates neural architectures that outperform the state-of-the-art encrypted traffic classifiers on several datasets, including public benchmark datasets and real-world TLS and QUIC traffic collected from the Orange mobile network. In addition to being more accurate, AutoML4ETC’s architectures are significantly more efficient and lighter in terms of the number of parameters. Finally, we make AutoML4ETC publicly available for future research. Navid Malekghaini, Elham Akbari, Mohammad Ali Salahuddin 0001, Noura Limam, Raouf Boutaba, Bertrand Mathieu, Stephanie Moteau, Stéphane Tuffin |
IEEE Trans. Netw. Serv. Manag. | 4 |
| 2023 | A Critical Study of Few-Shot Learning for Encrypted Traffic ClassificationabstractOver the past twenty years, a plethora of methods have been proposed for encrypted traffic classification (ETC), while the Server name indication (SNI) is deemed to solve the problem of classification for TLS traffic. However, SNI-based classification has its pitfalls and the SNI will likely be pushed into the encrypted tunnel in the future. In this work, we envision a futuristic scenario in which encrypted SNI is the norm and labeled traffic flows are scarce. In such settings, we tackle the problem of traffic classification at ISP level using few-shot learning. By means of six real-world ISP-level datasets collected between 2019 and 2021 and two publicly available client-side datasets, we study the performance of a few-shot learner on TLS data, including its cross-dataset generalizability. We further investigate the effect of the number of required labeled samples on the learner's performance. Our experiments show that the dataset-specificity of deep learners carries over to few-shot meta-learning, and calls for addressing the problem of generalizability for deep learning architectures. Elham Akbari, Sheikh A. Tahmid, Navid Malekghaini, Mohammad Ali Salahuddin 0001, Noura Limam, Raouf Boutaba, Bertrand Mathieu, Stephanie Moteau, Stéphane Tuffin |
CNSM | 5 |
| 2023 | Mitigating Signaling Storms in 5G with Blockchain-assisted 5GAKAabstractThis paper examines the registration signaling storm attack in 5G networks. This attack is initiated by massive registration requests and targets the 5G core network functions, leading to large-scale user service disruption. To mitigate this problem, we review the 5G Authentication and Key Agreement (5GAKA) protocol and highlight the impact of the exposure of the 5G core network (CN) to massive registration requests. We propose a blockchain-based authentication protocol to effectively block adversarial registration requests and secure the 5G network at a small cost. Our experiments reveal that our protocol is resistant to attacks and prove its superiority compared to a baseline mitigation approach. Paul Zeinaty, Noura Limam, Raouf Boutaba |
CNSM | 3 |
| 2023 | Meta-ATMoS+: A Meta-Reinforcement Learning Framework for Threat Mitigation in Software-Defined NetworksabstractAs cyber threats become increasingly common, automated threat mitigation solutions are more necessary than ever. Conventional threat mitigation frameworks are difficult to tune for different network environments, but frameworks utilizing deep reinforcement learning (RL) have been proven to be an effective approach that can adapt to different networks automatically. Existing RL-based frameworks have shown to be generalizable to different network sizes and threats, and robust to false positives. However, training RL agents for these frameworks can be challenging in a production environment as the training process is time-consuming and disruptive to the production network. Hence, a staging environment is required to effectively train them. In this paper, we propose Meta-ATMoS+, a meta-RL framework for threat mitigation in software-defined networks. We leverage Model-Agnostic Meta-Learning (MAML) to find an initialization for the RL agent that generalizes to a variety of different network configurations. We show that the RL agent with MAML-learned initialization can accomplish few-shot learning on a target network with comparable performance to training on a staging environment. Few-shot learning not only allows the model to be trainable directly in the production environment but also enables human-in-the-loop RL for the mitigation of threats that do not have an easily-definable reward function. Hauton Tsang, Mohammad Ali Salahuddin 0001, Noura Limam, Raouf Boutaba |
LCN | 3 |
| 2023 | Deep learning for encrypted traffic classification in the face of data drift: An empirical study
Navid Malekghaini, Elham Akbari, Mohammad Ali Salahuddin 0001, Noura Limam, Raouf Boutaba, Bertrand Mathieu, Stephanie Moteau, Stéphane Tuffin |
Comput. Networks | 4 |
| 2022 | Editorial for Special Issue on Machine Learning approaches in IoT scenarios
Gaia Maselli, Laura Galluccio, Imen Grida Ben Yahia, Noura Limam |
Comput. Commun. | 4 |
| 2021 | RDP-based Lateral Movement detection using Machine Learning
Tim Bai, Haibo Bian, Mohammad Ali Salahuddin 0001, Abbas Abou Daya, Noura Limam, Raouf Boutaba |
Comput. Commun. | 5 |
| 2021 | Uncovering Lateral Movement Using Authentication LogsabstractNetwork infiltrations due to advanced persistent threats (APTs) have significantly grown in recent years. Their primary objective is to gain unauthorized access to network assets, compromise system and data. APTs are stealthy and remain dormant for an extended period of time, which makes their detection challenging. In this article, we leverage machine learning (ML) to detect hosts in a network that are a target of an APT attack. We evaluate a number of ML classifiers to detect susceptible hosts in the Los Alamos National Lab dataset. We (i) scrutinize graph-based features extracted from host authentication logs, (ii) use feature engineering to reduce dimensionality, (iii) explore balancing the training dataset using over- and under-sampling techniques, (iv) evaluate numerous supervised ML techniques and their ensemble, (v) compare our classification model to the state-of-the-art approaches that leverage the same dataset, and show that our model outperforms them with respect to prediction performance and overhead, and (vi) perturb the attack patterns to study the influence of change in attack frequency and scale on classification performance, and propose a solution for such adversarial behavior. Haibo Bian, Tim Bai, Mohammad Ali Salahuddin 0001, Noura Limam, Abbas Abou Daya, Raouf Boutaba |
IEEE Trans. Netw. Serv. Manag. | 4 |
| 2020 | ATMoS: Autonomous Threat Mitigation in SDN using Reinforcement LearningabstractMachine Learning has revolutionized many fields of computer science. Reinforcement Learning (RL), in particular, stands out as a solution to sequential decision making problems. With the growing complexity of computer networks in the face of new emerging technologies, such as the Internet of Things and the growing complexity of threat vectors, there is a dire need for autonomous network systems. RL is a viable solution for achieving this autonomy. Software-defined Networking (SDN) provides a global network view and programmability of network behaviour, which can be employed for security management. Previous works in RL-based threat mitigation have mostly focused on very specific problems, mostly non-sequential, with ad-hoc solutions. In this paper, we propose ATMoS, a general framework designed to facilitate the rapid design of RL applications for network security management using SDN. We evaluate our framework for implementing RL applications for threat mitigation, by showcasing the use of ATMoS with a Neural Fitted Q-learning agent to mitigate an Advanced Persistent Threat. We present the RL model’s convergence results showing the feasibility of our solution for active threat mitigation. Iman Akbari, Ezzeldin Tahoun, Mohammad Ali Salahuddin 0001, Noura Limam, Raouf Boutaba |
NOMS | 4 |
| 2020 | Guest Editorial Special Issue on Advances in Artificial Intelligence and Machine Learning for Networkingabstracthttps://www.youtube.com/watch?v=SQmgSOi5oos Prosper Chemouil, Pan Hui 0001, Wolfgang Kellerer, Noura Limam, Rolf Stadler, Yonggang Wen 0001 |
IEEE J. Sel. Areas Commun. | 4 |
| 2020 | BotChase: Graph-Based Bot Detection Using Machine LearningabstractBot detection using machine learning (ML), with network flow-level features, has been extensively studied in the literature. However, existing flow-based approaches typically incur a high computational overhead and do not completely capture the network communication patterns, which can expose additional aspects of malicious hosts. Recently, bot detection systems that leverage communication graph analysis using ML have gained attention to overcome these limitations. A graph-based approach is rather intuitive, as graphs are true representation of network communications. In this paper, we propose BotChase, a two-phased graph-based bot detection system that leverages both unsupervised and supervised ML. The first phase prunes presumable benign hosts, while the second phase achieves bot detection with high precision. Our prototype implementation of BotChase detects multiple types of bots and exhibits robustness to zero-day attacks. It also accommodates different network topologies and is suitable for large-scale data. Compared to the state-of-the-art, BotChase outperforms an end-to-end system that employs flow-based features and performs particularly well in an online setting. Abbas Abou Daya, Mohammad Ali Salahuddin 0001, Noura Limam, Raouf Boutaba |
IEEE Trans. Netw. Serv. Manag. | 3 |
| 2019 | Host in Danger? Detecting Network Intrusions from Authentication LogsabstractRecently, network infiltrations due to advanced persistent threats (APTs) have grown significantly, resulting in considerable losses to businesses and organizations. APTs are stealthy attacks with the primary objective of gaining unauthorized access to network assets. They often remain dormant for an extended period of time, which makes their detection challenging. In this paper, we leverage machine learning (ML) to detect hosts in a network that are targeted by an APT attack. We evaluate a number of ML classifiers to detect susceptible hosts in the Los Alamos National Lab dataset. We explore (i) graph-based features extracted from multiple data sources i.e., network flows and host authentication logs, (ii) feature engineering to reduce dimensionality, and (iii) balancing the training dataset using numerous over- and under-sampling techniques. Finally, we compare our model to the state-of-the-art approaches that leverage the same dataset, and show that our model outperforms them with respect to prediction performance and overhead. Haibo Bian, Tim Bai, Mohammad Ali Salahuddin 0001, Noura Limam, Abbas Abou Daya, Raouf Boutaba |
CNSM | 4 |
| 2019 | A Graph-Based Machine Learning Approach for Bot Detection
Abbas Abou Daya, Mohammad Ali Salahuddin 0001, Noura Limam, Raouf Boutaba |
IM | 3 |
| 2019 | A Machine Learning Approach for RDP-based Lateral Movement DetectionabstractDetecting cyber threats has been an on-going research endeavor. In this era, advanced persistent threats (APTs) can incur significant cost for organizations and businesses. The ultimate goal of cyber security is to thwart attackers from achieving their malicious intent, whether it is credential stealing, infrastructure takeover, or program sabotage. Every cyber attack goes through several stages before its termination. Lateral movement (LM) is one of those stages which is of particular importance. Remote Desktop Protocol (RDP) is a method used in LM to successfully authenticate to an unauthorized host that leaves footprints on both host and network logs. In this paper, we propose to detect evidence of LM with an anomaly detection approach that leverages Windows RDP event logs. We evaluate various supervised machine learning (ML) techniques for classifying RDP sessions with high precision and recall. We also compare the performance of our proposed approach to a state-of-the-art approach and demonstrate that our ML model outperforms in classifying RDP sessions in Windows event logs. Tim Bai, Haibo Bian, Abbas Abou Daya, Mohammad Ali Salahuddin 0001, Noura Limam, Raouf Boutaba |
LCN | 5 |
| 2015 | Cloud networking and communications IIabstractMade available in DSpace on 2016-06-07T13:36:10Z (GMT). No. of bitstreams: 1 wos_000367123300001.pdf: 410004 bytes, checksum: 6de6b0e120e3cfc1bb14dcf5e725aa36 (MD5) Previous issue date: 2015 Raouf Boutaba, Nelson L. S. da Fonseca, Dzmitry Kliazovich, Noura Limam |
Comput. Networks | 4 |
| 2014 | Cloud networking and communications
Raouf Boutaba, Noura Limam, Stefano Secci, Tarik Taleb |
Comput. Networks | 2 |
| 2010 | Assessing Software Service Quality and Trustworthiness at Selection TimeabstractThe integration of external software in project development is challenging and risky, notably because the execution quality of the software and the trustworthiness of the software provider may be unknown at integration time. This is a timely problem and of increasing importance with the advent of the SaaS model of service delivery. Therefore, in choosing the SaaS service to utilize, project managers must identify and evaluate the level of risk associated with each candidate. Trust is commonly assessed through reputation systems; however, existing systems rely on ratings provided by consumers. This raises numerous issues involving the subjectivity and unfairness of the service ratings. This paper describes a framework for reputation-aware software service selection and rating. A selection algorithm is devised for service recommendation, providing SaaS consumers with the best possible choices based on quality, cost, and trust. An automated rating model, based on the expectancy-disconfirmation theory from market science, is also defined to overcome feedback subjectivity issues. The proposed rating and selection models are validated through simulations, demonstrating that the system can effectively capture service behavior and recommend the best possible choices. Noura Limam, Raouf Boutaba |
IEEE Trans. Software Eng. | 1 |
| 2008 | QoS and reputation-aware service selectionabstractThe advent of service-oriented architectures has created a unique opportunity for business providers and consumers to establish more versatile and flexible interactions across the Internet by means of a new generation of services that are discoverable, composable, configurable, and reusable. In order to support such services all along their life cycle, underlying service-oriented infrastructures have to provide various functionalities, including service discovery. In large scale environments, like the Internet, a discovery process may result in a very large number of matching services. Service quality, cost and reputation are substantial aspects for differentiating between similar services. In order to help users select the most appropriate service, an automated service selection algorithm is proposed. The devised algorithm helps to accurately predict service suitability to quality requirements while taking into account the reputation parameter. Noura Limam, Raouf Boutaba |
NOMS | 1 |
| 2007 | OSDA: Open service discovery architecture for efficient cross-domain service provisioning
Noura Limam, Joanna Ziembicki, Reaz Ahmed, Youssef Iraqi, Tianshu Li, Raouf Boutaba, Fernando Cuervo |
Comput. Commun. | 1 |
| 2005 | Service management in secure and QoS-aware wireless enterprise networksabstractWireless local-area networks (WLANs) based on the IEEE 802.11 technology have been widely adopted for private use over the past few years. However, several issues remain concerns for large-scale deployment in corporate environments. Enforcing security and quality-of-service (QoS) has become a fundamental challenge to managing IEEE 802.11-based enterprise networks. In order to provide corporate networks with a global management solution, we have designed a service-oriented management system that enables user-centric service provisioning, while enforcing security and QoS requirements. As enterprises may be comprised of a number of distinct networks, we have extended our system to support the roaming of users between different enterprise sites. In this paper, we describe the design, implementation, and performance evaluation of our solution. Noura Limam, Julien Rotrou, Marc Loutrel, Laurent Ouakil, Hayder Saleh, Guy Pujolle |
IEEE J. Sel. Areas Commun. | 1 |