VLDB 2026 Research / reviewers in the wild / expert
Mohamed Shehab
dblp:89/6785
· DBLP profile ↗
56ranked-venue papers
15as first author
6since 2021 · last 2024
0000-0002-4189-9118ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 26 · 7 first-author · 3 since 2021Human-computer interaction and ubiquitous computing · 15 · 2 first-author · 3 since 2021Databases, data management, data science and information retrieval · 10 · 4 first-authorApplied, interdisciplinary, general and emerging computing · 6 · 1 first-authorArtificial intelligence and machine learning · 5 · 2 first-authorComputer networks · 5 · 3 first-authorSoftware engineering, systems software and programming languages · 4Systems, architecture and hardware · 3 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | The Impact of Risk Appeal Approaches on Users' Sharing Confidential InformationabstractEnd-to-end encrypted email can help users prevent unauthorized access of their sensitive information. However, many users struggle to utilize encryption tools due to usability issues and low understanding. Thus, we designed video messaging interventions to persuade users to use email encryption software (Virtru). Our first intervention combined Protection Motivation Theory with Anticipated Regret (PMT+AR), and was designed to help participants understand the benefits of using encrypted email. Our second intervention also included Action Planning (PMT+AR+AP), and was designed to help participants recognize opportunities to use encrypted email. We conducted online interviews with 121 participants and used a follow-up survey to evaluate our interventions. Pre-intervention, participants believed that Gmail encrypted standard email content by default. Post-intervention, both messages made participants more likely to utilize encrypted email in a simulated information sharing scenario compared to Control. Our results suggest that our interventions can help people adopt protective technologies and address their misconceptions about them. Elham Al Qahtani, Peter Story, Mohamed Shehab |
CHI | 3 |
| 2023 | Exploring the Usability, Security, and Privacy of Smart Locks from the Perspective of the End User
Hussein Hazazi, Mohamed Shehab |
SOUPS | 2 |
| 2022 | "Why would Someone Hack Me out of Thousands of Students": Video Presenter's Impact on Motivating Users to Adopt 2FAabstractThe voluntary adoption rate of two-factor authentication (2FA) remains low. This paper investigates whether video-based risk communication messages about Duo 2FA impacts voluntary 2FA adoption rate when delivered by a human speaker versus a cartoon speaker. We conducted an online two-phased survey-based study with 435 university students comprised of those who have not enabled Duo 2FA (non-adopters) on their university account as well as those who had previously enabled Duo 2FA (adopters). Participants in the non-adopters group (139) were assigned to one of the three groups: Threat-R (human speaker video), Threat-A (cartoon speaker video), and Control (no video). We found that 31% of participants enabled Duo 2FA through the human speaker video message compared to 7% with the cartoon speaker video message. However, there was no significant difference between the treatment and control groups (17% of participants enabled Duo 2FA in the Control group). Nevertheless, the treatment group participants showed their intention to activate Duo 2FA on their university account in the future. Those who enabled Duo 2FA rated Duo's usability as good. Moreover, enabling Duo 2FA on university accounts led some participants to enable 2FA on other online accounts. Our findings suggest that risk communication through videos that have a human speaker could increase users' willingness to adopt security features. Elham Al Qahtani, Lipsarani Sahoo, Yousra Javed, Mohamed Shehab |
SACMAT | 4 |
| 2022 | User Perceptions of Gmail's Confidential Mode
Elham Al Qahtani, Yousra Javed, Mohamed Shehab |
Proc. Priv. Enhancing Technol. | 3 |
| 2021 | Exploring Perceptions of a Localized Content-Sharing System Using Users-as-Beacons
Md. Nazmus Sakib Miazi, Heather Lipford, Mohamed Shehab |
INTERACT (2) | 3 |
| 2021 | Formal approach to thwart against insider attacks: A bio-inspired auto-resilient policy regulation framework
Usman Rauf, Mohamed Shehab, Nafees Qamar, Sheema Sameen |
Future Gener. Comput. Syst. | 2 |
| 2019 | Privacy Is The Best Policy: A Framework for BLE Beacon Privacy ManagementabstractBluetooth Low Energy (BLE) beacons are an emerging type of technology in the Internet-of-Things (IoT) realm, which use BLE signals to broadcast a unique identifier that is detected by a compatible device to determine the location of nearby users. Beacons can be used to provide a tailored user experience with each encounter, yet can also constitute an invasion of privacy, due to their covertness and ability to track user behavior. Therefore, we hypothesize that user-driven privacy policy configuration is key to enabling effective and trustworthy privacy management during beacon encounters. We developed a framework for beacon privacy management that provides a policy configuration platform. Through an empirical analysis with 90 users, we evaluated this framework through a proof-of-concept app called Beacon Privacy Manager (BPM), which focused on the user experience of such a tool. Using BPM, we provided users with the ability to create privacy policies for beacons, testing different configuration schemes to refine the framework and then offer recommendations for future research. Emmanuel Bello-Ogunu, Mohamed Shehab, Md. Nazmus Sakib Miazi |
COMPSAC (1) | 2 |
| 2018 | CordovaConfig: A Tool for Mobile Hybrid Apps' ConfigurationabstractDespite their recentness, hybrid mobile apps have established an increasing share in the mobile apps market. This can be attributed to the fact that these apps offer the balance between providing full functionality at an affordable development cost. Hybrid mobile apps are web apps hosted in a thin native container. Several libraries facilitate building hybrid apps by providing interfaces through which native phone resources can be accessed using Javascript code. Configuring mobile hybrid apps properly is an important but often neglected activity. Coarse-grained configurations and risky default settings result in several privacy and security breaches. Moreover, middleware libraries provide a basic interface to the developers which may drive them off from changing the default settings. We are seeking to provide an automated, interactive, and contextual support for configuring hybrid apps. In this paper, we present a tool prototype, CordovaConfig, which provides fine-grained configurations that are aligned with the app's behavior. We evaluate the potential use and effectiveness of CordovaConfig on 22 students. Our results demonstrate that interactive configuration support can (1) help address this important non-functional requirement early in the development cycle (2) increase programmers awareness in potential risks associated with insecure settings (3) increase developers understanding of configuration items. This is supported by a quantitative and qualitative evaluation. We also uncover common programmers practices and perceptions of hybrid apps security & configurations Abeer Al Jarrah, Mohamed Shehab |
MUM | 2 |
| 2018 | Mobile Users as Advertisers: User Perceptions of Product Sensitivity, Exposure, and Public InfluenceabstractToday mobile marketing is booming at an exponential rate with the increased use of smartphones and other mobile devices. Smartphones provide ubiquitous access to digital information anywhere, anytime, thus enabling the marketers to reach customers more directly, and engagingly. A scalable amalgamation of cellular networks, WiFi, and BLE Beacons enable us to formulate a new mode of advertising, where we can employ mobile users as live and localized advertisers. That means a user can potentially be an advertiser for a company using smartphones by creating an ad and broadcasting it to people around them. Implementation of this idea integrates Consumer Generated Advertising (CGA), as the users actively customize the ads. In this paper, we explore the user's perception toward sharing personal information along with the ads they advertise. We tested our hypothesis by conducting a user study that investigates two key factors: the sensitivity level of the product, and the exposure level to the public. Also, we analyzed the effect of the public influence on the consumers' minds. Our result shows that people share more information with not-sensitive products than they share with sensitive products. We found several factors that can be utilized to conduct our future studies. Md. Nazmus Sakib Miazi, Carlos Alberto Campos Castro, Mohamed Shehab |
MUM | 3 |
| 2018 | Trust-Aware Goal Modeling from Use Case for Cooperative Self-Adaptive SystemsabstractThe self-adaptive systems are the systems that can adjust its behavior based on the dynamically changing environments to provide the appropriate services to the user. However, as the user demands the complicated service from the self-adaptive systems, they should cooperate with other systems because they have the dedicated services for the specific demand. The system should select the appropriate cooperation partner among many candidates. In this situation, the trust becomes one of the important criteria to achieve the minimum level of security in the open and distributed environment. However, many existing works on the self-adaptive system focus on the internal adaptation process or the adaptation in the closed environment. As the first attempt to tackle the trust attribute, in this paper, we propose the trust-aware goal modeling from the use case for cooperative self-adaptive system. By analyzing the characteristics of the trust in the requirements engineering process, we can understand when the trust should be considered and how it can be represented in the system design. In addition, we illustrate the unmanned vehicle scenario to show how the proposed approach can be applied to the real case. Min-Ju Kim, Mohamed Shehab, Hyo-Cheol Lee, Seok-Won Lee |
SMC | 2 |
| 2017 | The Demon is in the Configuration: Revisiting Hybrid Mobile Apps Configuration ModelabstractHTML-5 hybrid apps have the potential to dominate the mobile and IoTs market as hybrid platforms are providing a promising development choice. This approach "wraps" standard web code (HTML, Javascript, and CSS) into a thin native layer, enabling the same code base to run on several platforms. This approach also provides a mechanism to access device native sensors, such as camera and geolocation, through Javascript code. Apache Cordova is an open source library that is a common component in many hybrid platforms, such as PhoneGap and IBM Worklight. Yet, its configuration model suffers several security limitations including a coarse-grained access control model, risky defaults, and for many developers, a non-trivial configuration process. Hybrid app development is an intricate task as is, not to mention configuring these apps securely. Given the increased popularity of the approach itself and the proven tendency of developers to use platform-provided default settings, this paper presents a novel approach to automatically generate configurations that are more aligned to the app requirements, more granular, and more conformant with Least Privilege principle. We argue that having aligned configurations forms the first line of defense against attacks similar to injection attacks. Such attacks could have been voided if the app configurations were more granular and tailored. Our approach generates initial configuration settings based on modeling app behavior. The model generates twofold policies, one centered around APIs access and another around controlling app states transition. We have successfully instrumented Cordova library to implement our approach. We have tested the instrumented version, and our experiments demonstrate that the instrumented version is a practical and performant alternative. Abeer Al Jarrah, Mohamed Shehab |
ARES | 2 |
| 2017 | Investigating User Comprehension and Risk Perception of Apple's Touch ID TechnologyabstractApple's Touch ID serves as an alternative to PIN/password for unlocking Apple devices, signing into third party iOS applications, and authorizing purchases on the iTunes Store by simply tapping a registered finger on the home button. Yousra Javed, Mohamed Shehab, Emmanuel Bello-Ogunu |
ARES | 2 |
| 2017 | The Design of Cyber Threat Hunting Games: A Case StudyabstractCyber Threat Hunting is an emerging cyber security activity. Recent studies show that, although similar actions like threat hunting are being actively practiced in some organization, security administrator and policy makers are far from being satisfied with their effectiveness. Most security professionals lack expertise in data analytics while most people with data analytics skills lack security knowledge. To understand the necessity of threat hunting education at university level, we organized a \textit{Threat Hunting Competition} on campus with generated logs. In this paper, we identify skills needed for cyber threat hunting, describe the data generation process as well as the usage of logs to teach threat hunting at universities. Md. Nazmus Sakib Miazi, Mir Mehedi Ahsan Pritom, Mohamed Shehab, Bill Chu, Jinpeng Wei |
ICCCN | 3 |
| 2017 | Look before you Authorize: Using Eye-Tracking to Enforce User Attention towards Application PermissionsabstractAbstract Habituation is a key factor behind the lack of attention towards permission authorization dialogs during third party application installation. Various solutions have been proposed to combat the problem of achieving attention switch towards permissions. However, users continue to ignore these dialogs, and authorize dangerous permissions, which leads to security and privacy breaches. We leverage eye-tracking to approach this problem, and propose a mechanism for enforcing user attention towards application permissions before users are able to authorize them. We deactivate the dialog’s decision buttons initially, and use feedback from the eye-tracker to ensure that the user has looked at the permissions. After determining user attention, the buttons are activated. We implemented a prototype of our approach as a Chrome browser extension, and conducted a user study on Facebook’s application authorization dialogs. Using participants’ permission identification, eye-gaze fixations, and authorization decisions, we evaluate participants’ attention towards permissions. The participants who used our approach on authorization dialogs were able to identify the permissions better, compared to the rest of the participants, even after the habituation period. Their average number of eye-gaze fixations on the permission text was significantly higher than the other group participants. However, examining the rate in which participants denied a dangerous and unnecessary permission, the hypothesized increase from the control group to the treatment group was not statistically significant. Yousra Javed, Mohamed Shehab |
Proc. Priv. Enhancing Technol. | 2 |
| 2017 | Secure and Private Data Aggregation for Energy Consumption Scheduling in Smart GridsabstractThe recent proposed solutions for demand side energy management leverage the two-way communication infrastructure provided by modern smart-meters and sharing the usage information with the other users. In this paper, we first highlight the privacy and security issues involved in the distributed demand management protocols. We propose a novel protocol to share required information among users providing privacy, confidentiality, and integrity. We also propose a new clustering-based, distributed multi-party computation (MPC) protocol. Through simulation experiments we demonstrate the efficiency of our proposed solution. The existing solutions typically usually thwart selfish and malicious behavior of consumers by deploying billing mechanisms based on total consumption during a few time slots. However, the billing is typically based on the total usage in each time slot in smart grids. In the second part of this paper, we formally prove that under the per-slot based charging policy, users have incentive to deviate from the proposed protocols. We also propose a protocol to identify untruthful users in these networks. Finally, considering a repeated interaction among honest and dishonest users, we derive the conditions under which the smart grid can enforce cooperation among users and prevents dishonest declaration of consumption. Mohammad Ashiqur Rahman, Mohammad Hossein Manshaei, Ehab Al-Shaer, Mohamed Shehab |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2016 | Maintaining User Interface Integrity on AndroidabstractThe demand of having a multi-window and multitasking option in Android devices has been an emerging topic among Android users, especially with the trends toward larger hand-held screen sizes. One option to meet this demand, is to use floating windows. This feature enables users to perform more than one task at the same time while sharing the same screen. Device screens can be divided into multiple windows that can have different visual features in terms of size, location and transparency. While this feature addresses user complaints about Android on large screen devices, attention must be given to the security implications of such an option. In this work, we demonstrate how the current implementation of floating windows on Android can be abused to compromise user interface integrity through several attacks such as tapjacking, event eavesdropping and event hijacking. Although previous versions of Android have evolved to handle the issue of eventhijacking enabled by Toasts, recent versions fail to address security concerns related to floating windows. We propose and describe two approaches, an application level and a system level, to enable secure apps against possible malicious floating windows. The application level approach aims to detect existence and location of floating windows on top of an app. System level approach not only detects their existence, but also extends the system to include an event handler that notifies apps when floating windows are rendered over the apps' secure regions. We implemented our proposed approaches and performed experiments to evaluate their efficiency. Abeer Al Jarrah, Mohamed Shehab |
COMPSAC | 2 |
| 2016 | Crowdsourcing for Context: Regarding Privacy in Beacon Encounters via Contextual IntegrityabstractAbstract Research shows that context is important to the privacy perceptions associated with technology. With Bluetooth Low Energy beacons, one of the latest technologies for providing proximity and indoor tracking, the current identifiers that characterize a beacon are not sufficient for ordinary users to make informed privacy decisions about the location information that could be shared. One solution would be to have standardized category and privacy labels, produced by beacon providers or an independent third-party. An alternative solution is to find an approach driven by users, for users. In this paper, we propose a novel crowdsourcing based approach to introduce elements of context in beacon encounters.We demonstrate the effectiveness of this approach through a user study, where participants use a crowd-based mobile app designed to collect beacon category and privacy information as a scavenger hunt game. Results show that our approach was effective in helping users label beacons according to the specific context of a given beacon encounter, as well as the privacy perceptions associated with it. This labeling was done with an accuracy of 92%, and with an acceptance rate of 82% of all recommended crowd labels. Lastly, we conclusively show how crowdsourcing for context can be used towards a user-centric framework for privacy management during beacon encounters. Emmanuel Bello-Ogunu, Mohamed Shehab |
Proc. Priv. Enhancing Technol. | 2 |
| 2015 | Towards a General Framework for Optimal Role Mining: A Constraint Satisfaction ApproachabstractRole Based Access Control (RBAC) is the most widely used advanced access control model deployed in a variety of organizations. To deploy an RBAC system, one needs to first identify a complete set of roles, including permission role assignments and role user assignments. This process, known as role engineering, has been identified as one of the costliest tasks in migrating to RBAC. Since many organizations already have some form of user permission assignments defined, it makes sense to identify roles from this existing information. This process, known as role mining, has gained significant interest in recent years and numerous role mining techniques have been developed that take into account the characteristics of the core RBAC model, as well as its various extended features and each is based on a specific optimization metric. In this paper, we propose a generic approach which transforms the role mining problem into a constraint satisfaction problem. The transformation allows us to discover the optimal RBAC state based on customized optimization metrics. We also extend the RBAC model to include more context-aware and application specific constraints. These extensions broaden the applicability of the model beyond the classic role mining to include features such as permission usage, hierarchical role mining, hybrid role engineering approaches, and temporal RBAC models. We also perform experiments to show applicability and effectiveness of the proposed approach. Jafar Haadi Jafarian, Hassan Takabi, Hakim Touati, Ehsan Hesamifard, Mohamed Shehab |
SACMAT | 5 |
| 2015 | A Lightweight Secure Scheme for Detecting Provenance Forgery and Packet DropAttacks in Wireless Sensor NetworksabstractLarge-scale sensor networks are deployed in numerous application domains, and the data they collect are used in decision-making for critical infrastructures. Data are streamed from multiple sources through intermediate processing nodes that aggregate information. A malicious adversary may introduce additional nodes in the network or compromise existing ones. Therefore, assuring high data trustworthiness is crucial for correct decision-making. Data provenance represents a key factor in evaluating the trustworthiness of sensor data. Provenance management for sensor networks introduces several challenging requirements, such as low energy and bandwidth consumption, efficient storage and secure transmission. In this paper, we propose a novel lightweight scheme to securely transmit provenance for sensor data. The proposed technique relies on in-packet Bloom filters to encode provenance. We introduce efficient mechanisms for provenance verification and reconstruction at the base station. In addition, we extend the secure provenance scheme with functionality to detect packet drop attacks staged by malicious data forwarding nodes. We evaluate the proposed technique both analytically and empirically, and the results prove the effectiveness and efficiency of the lightweight secure provenance scheme in detecting packet forgery and loss attacks. Salmin Sultana, Gabriel Ghinita, Elisa Bertino, Mohamed Shehab |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2014 | POSTER: Android System Broadcast Actions Broadcasts Your PrivacyabstractAndroid provides finer-grained security features through a "permission" mechanism that puts limitations on the resources that each application can access. Upon installing a new Android application, a user is prompted to grant it a set of permissions. There are two typical assumptions made regarding permissions and mobile application security and privacy. The first one is that malicious applications need to retain many permissions. Secondly, mobile devices users assume that installed applications do not access data if they are not in the foreground. In this project, we show that malicious Android applications can still fulfill their objectives with minimum permissions and that they can access user data while in the background. This could happen with the help of another Android component, called broadcast receiver. We study the evaluation of Android broadcast actions. We demonstrate an attack scenario made possible by the broadcast receivers. Moreover, we propose solutions to protect from such attacks. Fadi Mohsen, Mohamed Shehab, Emmanuel Bello-Ogunu, Abeer Al Jarrah |
CCS | 2 |
| 2014 | Securing OAuth implementations in smart phonesabstractWith the roaring growth and wide adoption of smart mobile devices, users are continuously integrating with culture of the mobile applications (apps). These apps are not only gaining access to information on the smartphone but they are also able gain users' authorization to access remote servers on their behalf. The Open standard for Authorization (OAuth) is widely used in mobile apps for gaining access to user's resources on remote service providers. In this work, we analyze the different OAuth implementations adopted by some SDKs of the popular resource providers on smartphones and identify possible attacks on most OAuth implementations. We give some statistics on the trends followed by the service providers and by mobile applications developers. In addition, we propose an application-based OAuth Manager framework, that provides a secure OAuth flow in smartphones that is based on the concept of privilege separation and does not require high overhead. Mohamed Shehab, Fadi Mohsen |
CODASPY | 1 |
| 2014 | Human Effects of Enhanced Privacy Management ModelsabstractWe enhance existing and introduce new social network privacy management models and we measure their human effects. First, we introduce a mechanism using proven clustering techniques that assists users in grouping their friends for traditional group-based policy management approaches. We found measurable agreement between clusters and user-defined relationship groups. Second, we introduce a new privacy management model that leverages users' memory and opinion of their friends (called example friends) to set policies for other similar friends. Finally, we explore different techniques that aid users in selecting example friends. We found that by associating policy temples with example friends (versus group labels), users author policies more efficiently and have improved perceptions over traditional group-based policy management approaches. In addition, our results show that privacy management models can be further enhanced by utilizing user privacy sentiment for mass customization. By detecting user privacy sentiment (i.e., an unconcerned user, a pragmatist or a fundamentalist), privacy management models can be automatically tailored specific to the privacy sentiment and needs of the user. Gorrell P. Cheek, Mohamed Shehab |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2013 | Usable object management approaches for online social networksabstractOnline social networks have seen tremendous adoption and growth in recent years. Most attention, in access control literature, has been placed on abstracting and managing the large numbers of subjects or friends within these online social networks. Usable approaches for managing large amounts of objects, in the form of privacy information and content, have lagged. We introduce two approaches for object management. We extend our previous work to accommodate for object grouping and we introduce Same-As Object Management, which provides for a more usable object management approach that is effective, efficient and satisfying to the user. Same-As Object Management leverages a user's memory and perception of their objects for setting permissions for other similar objects. We implemented our model in an online social network and conducted a user study whose results are encouraging. Gorrell P. Cheek, Mohamed Shehab |
ASONAM | 2 |
| 2013 | Game-theoretic approach for user migration in DiasporaabstractDiaspora is a decentralized online social networking platform where user profiles are hosted in multiple Diaspora nodes (pods) and the social connections can exist across different pods. User profile migration is a promising feature that would enable users to seamlessly migrate their profile data between different pods. However, to the best of our knowledge, there has been no research done on how this data portability may affect the user distribution and the performance of the pods. In this paper, our goal is to design an approach that facilitates the users to choose appropriate pods that would ensure better service quality. We propose a decentralized game-theoretic approach that is based on user's local neighborhood information and the quality of the pods. We have analytically determined, and experimentally substantiated, that through the proposed profile migration approach the users of Diaspora reach a stable and balanced distribution that improves their overall experience in respective pods. Mohammad Rashedul Hasan, Mohamed Shehab, Ali Noorollahiravari |
ASONAM | 2 |
| 2013 | Android keylogging threatabstractThe openness of Android platform has attracted users, developers and attackers. Android offers bunch of capabilities and flexibilities, for instance, developers can write their own keyboard service-similar to Android soft keyboards-using the KeyboardView class. This class is available since api leve Fadi Mohsen, Mohamed Shehab |
CollaborateCom | 2 |
| 2013 | Secure Provenance Transmission for Streaming DataabstractMany application domains, such as real-time financial analysis, e-healthcare systems, sensor networks, are characterized by continuous data streaming from multiple sources and through intermediate processing by multiple aggregators. Keeping track of data provenance in such highly dynamic context is an important requirement, since data provenance is a key factor in assessing data trustworthiness which is crucial for many applications. Provenance management for streaming data requires addressing several challenges, including the assurance of high processing throughput, low bandwidth consumption, storage efficiency and secure transmission. In this paper, we propose a novel approach to securely transmit provenance for streaming data (focusing on sensor network) by embedding provenance into the interpacket timing domain while addressing the above mentioned issues. As provenance is hidden in another host-medium, our solution can be conceptualized as watermarking technique. However, unlike traditional watermarking approaches, we embed provenance over the interpacket delays (IPDs) rather than in the sensor data themselves, hence avoiding the problem of data degradation due to watermarking. Provenance is extracted by the data receiver utilizing an optimal threshold-based mechanism which minimizes the probability of provenance decoding errors. The resiliency of the scheme against outside and inside attackers is established through an extensive security analysis. Experiments show that our technique can recover provenance up to a certain level against perturbations to inter-packet timing characteristics. Salmin Sultana, Mohamed Shehab, Elisa Bertino |
IEEE Trans. Knowl. Data Eng. | 2 |
| 2012 | How do Facebookers Use FriendlistsabstractFacebook friend lists are used to classify friends into groups and assist users in controlling access to their information. In this paper, we study the effectiveness of Facebook friend lists from two aspects: Friend Management and Policy Patterns by examining how users build friend lists and to what extent they use them in their policy templates. We have collected real Facebook profile information and photo privacy policies of 222 participants, through their consent in our Facebook survey application posted on Mechanical Turk. Our data analysis shows that users' customized friend lists are less frequently created and have fewer overlaps as compared to Facebook created friend lists. Also, users do not place all of their friends into lists. Moreover, friends in more than one friend lists have higher values of node betweenness and outgoing to incoming edge ratio values among all the friends of a particular user. Last but not the least, friend list and user based exceptions are less frequently used in policies as compared to allowing all friends, friends of friends and everyone to view photos. Yousra Javed, Mohamed Shehab |
ASONAM | 2 |
| 2012 | Semi-Supervised Policy Recommendation for Online Social NetworksabstractFine grain policy settings in social network sites is becoming a very important requirement for managing user's privacy. Incorrect privacy policy settings can easily lead to leaks in private and personal information. At the same time, being too restrictive would reduce the benefits of online social networks. This is further complicated with the growing adoption of social networks and with the rapid growth in information uploading and sharing. The problem of facilitating policy settings has attracted numerous access control, and human computer interaction researchers. The solutions proposed range from usable interfaces for policy settings to automated policy settings. We propose a fine grained policy recommendation system that is based on an iterative semi-supervised learning approach that uses the social graph propagation properties. Active learning and social graph properties were used to detect the most informative instances to be labeled as training sets. We implemented and tested our approach using real Facebook dataset. We compared our proposed approach to supervised learning and random walk approaches. Our proposed approaches provided high accuracy and precision when compared to the other approaches. Mohamed Shehab, Hakim Touati |
ASONAM | 1 |
| 2012 | Towards improving browser extension permission management and user awarenessabstractBrowsers have become the de-facto platform for users and their online presence. They have also become a rich environment for 3rd party extensions that enrich the user browsing experience by extending upon the browser’s function- alities. Protecting user privacy against malicious or vulnerable extens Said Marouf, Mohamed Shehab |
CollaborateCom | 2 |
| 2012 | Anomaly Discovery and Resolution in MySQL Access Control Policies
Mohamed Shehab, Saeed Al-Haj, Salil Bhagurkar, Ehab Al-Shaer |
DEXA (2) | 1 |
| 2012 | A Lightweight Secure Provenance Scheme for Wireless Sensor NetworksabstractLarge-scale sensor networks are being deployed in numerous application domains, and often the data they collect are used in decision-making for critical infrastructures. Data are streamed from multiple sources through intermediate processing nodes that aggregate information. A malicious adversary may tamper with the data by introducing additional nodes in the network, or by compromising existing ones. Therefore, assuring high data trustworthiness in such a context is crucial for correct decision-making. Data provenance represents a key factor in evaluating the trustworthiness of sensor data. Provenance management for sensor networks introduces several challenging requirements, such as low energy and bandwidth consumption, efficient storage and secure transmission. In this paper, we propose a novel light-weight scheme to securely transmit provenance for sensor data. The proposed technique relies on in-packet Bloom filters to encode provenance. In addition, we introduce efficient mechanisms for provenance verification and reconstruction at the base station. We evaluate the proposed technique both analytically and empirically, and the results prove its effectiveness and efficiency for secure provenance encoding and decoding. Salmin Sultana, Gabriel Ghinita, Elisa Bertino, Mohamed Shehab |
ICPADS | 4 |
| 2012 | REM: A runtime browser extension manager with fine-grained access controlabstractIn this paper we implement a runtime framework that monitors the accesses made by third party Chrome extensions, informs users of the accesses, & allows them to customize extension permissions. The custom permission settings are enforced by the framework at runtime. We evaluated our framework on popular Chrome extensions and were successful in monitoring and controlling their accesses with little overhead. Said Marouf, Mohamed Shehab, Adharsh Desikan |
PST | 2 |
| 2012 | Policy-by-example for online social networksabstractWe introduce two approaches for improving privacy policy management in online social networks. First, we introduce a mechanism using proven clustering techniques that assists users in grouping their friends for group based policy management approaches. Second, we introduce a policy management approach that leverages a user's memory and opinion of their friends to set policies for other similar friends. We refer to this new approach as Same-As Policy Management. To demonstrate the effectiveness of our policy management improvements, we implemented a prototype Facebook application and conducted an extensive user study. Leveraging proven clustering techniques, we demonstrated a 23% reduction in friend grouping time. In addition, we demonstrated considerable reductions in policy authoring time using Same-As Policy Management over traditional group based policy management approaches. Finally, we presented user perceptions of both improvements, which are very encouraging. Gorrell P. Cheek, Mohamed Shehab |
SACMAT | 2 |
| 2012 | Secure Distributed Solution for Optimal Energy Consumption Scheduling in Smart GridabstractThe demand-side energy management is crucial to optimize the energy usage with its production cost, so that the price paid by the users is minimized, while it also satisfies the demand. The recent proposed solutions leverage the two- way communication infrastructure provided by modern smart- meters. The demand management problem assumes that users can shift their energy usage from peak hours to off-peak hours with the goal of balancing the energy usage. The scheduling of the energy consumption is often formulated as a game- theoretic problem, where the players are the users and their strategies are the load schedules of their household appliances. The Nash equilibrium of the formulated game provides the global optimal performance (i.e., the minimum energy costs). To provide a distributed solution the users require to share their usage information with the other users to converge to the Nash equilibrium. Hence, this open sharing among users introduces potential privacy and security issues. In addition, the existing solutions assume that all the users are rational and truthful. In this paper, we first highlight the privacy and security issues involved in the distributed demand management protocols. Secondly, we propose an efficient clustering based multi-party computation (MPC) distributed protocol that enables users to share their usage schedules and at the same time preserve their privacy and confidentiality. To identify untruthful users, we propose a mechanism based on a third party verifier. Through simulation experiments we have demonstrated the scalability and efficiency of our proposed solution. Mohammad Ashiqur Rahman, Libin Bai, Mohamed Shehab, Ehab Al-Shaer |
TrustCom | 3 |
| 2012 | Access control for online social networks third party applications
Mohamed Shehab, Anna Cinzia Squicciarini, Gail-Joon Ahn, Irini Kokkinou |
Comput. Secur. | 1 |
| 2012 | Policy-driven role-based access management for ad-hoc collaborationabstractAd-hoc collaboration is a newly emerged environment enabling distributed collaborators to share resources. The dynamic nature and unique sharing pattern in ad-hoc collaboration poses great challenges for security services to accommodate both access control and trust management requirements in providing controlled resource sharing. In this paper, we propose a comprehensive, integrated and implemented access management framework, called RAMARS, for secure digital information sharing in ad-hoc collaboration. Our framework incorporates a role-based approach to leverage the originator control, delegation and dissemination control. A trust awareness feature is integrated for dynamic user-role assignment based on user attributes. The access control polices are formally specified, and a peer-to-peer scientific information sharing system – ShareEnabler – is presented to demonstrate the feasibility of our approach. The performance evaluation of our prototype system with potential system improvements is also discussed. Gail-Joon Ahn, Mohamed Shehab |
J. Comput. Secur. | 3 |
| 2012 | Recommendation Models for Open AuthorizationabstractMajor online platforms such as Facebook, Google, and Twitter allow third-party applications such as games, and productivity applications access to user online private data. Such accesses must be authorized by users at installation time. The Open Authorization protocol (OAuth) was introduced as a secure and efficient method for authorizing third-party applications without releasing a user's access credentials. However, OAuth implementations don't provide the necessary fine-grained access control, nor any recommendations, i.e., which access control decisions are most appropriate. We propose an extension to the OAuth 2.0 authorization that enables the provisioning of fine-grained authorization recommendations to users when granting permissions to third-party applications. We propose a multicriteria recommendation model that utilizes application-based, user-based, and category-based collaborative filtering mechanisms. Our collaborative filtering mechanisms are based on previous user decisions, and application permission requests to enhance the privacy of the overall site's user population. We implemented our proposed OAuth extension as a browser extension that allows users to easily configure their privacy settings at application installation time, provides recommendations on requested privacy permissions, and collects data regarding user decisions. Our experiments on the collected data indicate that the proposed framework efficiently enhanced the user awareness and privacy related to third-party application authorizations. Mohamed Shehab, Said Marouf |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2011 | MasterBlaster: Identifying Influential Players in Botnet TransactionsabstractBotnets continue to be a critical tool for hackers in exploiting vulnerabilities of systems and destructing computer networks. Botnet monitoring is a method used to study and identify malicious capabilities of a botnet, but current botnet monitoring projects mainly identify the magnitude of the botnet problem and tend to overt some fundamental problems, such as the diversified sources of the attacks. Most malicious botnets have the ability to be rented out to a broad range of potential customers, allowing each customer to launch different attacks from the other. Consequently, under the control of multiple botmasters, various attacks and transactions at different times attempt to damage networked infrastructures. In this paper we propose a multi-layered analysis system called Master Blaster which identifies the communication characteristics of a botmaster in botnet transactions and correlates those characteristics with evolutionary changes within botnet communication channels. Our results show the level of involvement of the monitored botmasters within a botnet as well as their general motives. Our system clearly indicates that the investigation of each botmaster and analysis of botmaster interactions are essential to cope with net-centric attacks caused by botnets. Napoleon Paxton, Gail-Joon Ahn, Mohamed Shehab |
COMPSAC | 3 |
| 2011 | ROAuth: recommendation based open authorizationabstractMany major online platforms such as Facebook, Google, and Twitter, provide an open Application Programming Interface which allows third party applications to access user resources. The Open Authorization protocol (OAuth) was introduced as a secure and efficient method for authorizing third party applications without releasing a user's access credentials. However, OAuth implementations don't provide the necessary fine-grained access control, nor any recommendations vis-a-vis which access control decisions are most appropriate. We propose an extension to the OAuth 2.0 authorization that enables the provisioning of fine-grained authorization recommendations to users when granting permissions to third party applications. We propose a mechanism that computes permission ratings based on a multi-criteria recommendation model which utilizes previous user decisions, and application requests to enhance the privacy of the overall site's user population. We implemented our proposed OAuth extension as a browser extension that allows users to easily configure their privacy settings at application installation time, provides recommendations on requested privacy attributes, and collects data regarding user decisions. Experiments on the collected data indicate that the proposed framework efficiently enhanced the user awareness and privacy related to third party application authorizations. Mohamed Shehab, Said Marouf, Christopher Hudel |
SOUPS | 1 |
| 2011 | Adaptive Reordering and Clustering-Based Framework for Efficient XACML Policy EvaluationabstractThe adoption of XACML as the standard for specifying access control policies for various applications, especially web services is vastly increasing. This calls for high performance XACML policy evaluation engines. A policy evaluation engine can easily become a bottleneck when enforcing XACML policies with a large number of rules. In this paper we propose an adaptive approach for XACML policy optimization. We apply a clustering technique to policy sets based on the K-means algorithm. In addition to clustering we find that, since a policy set has a variable number of policies and a policy has a variable number of rules, their ordering is important for efficient execution. By clustering policy sets and reordering policies and rules in a policy set and policies respectively, we formulated and solved the optimal policy execution problem. The proposed clustering technique categorizes policies and rules within a policy set and policy respectively in respect to target subjects. When a request is received, it is redirected to applicable policies and rules that correspond to its subjects; hence, avoiding unnecessary evaluations from occurring. We also propose a usage based framework that computes access request statistics to dynamically optimize the ordering access control to policies within a policy set and rules within a policy. Reordering is applied to categorized policies and rules from our proposed clustering technique. To evaluate the performance of our framework, we conducted extensive experiments on XACML policies. We evaluated separately the improvement due to categorization and to reordering techniques, in order to assess the policy sets targeted by our techniques. The experimental results show that our approach is orders of magnitude more efficient than standard Sun PDP. Said Marouf, Mohamed Shehab, Anna Cinzia Squicciarini, Smitha Sundareswaran |
IEEE Trans. Serv. Comput. | 2 |
| 2010 | Learning based access control in online social networksabstractOnline social networking sites are experiencing tremendous user growth with hundreds of millions of active users. As a result, there is a tremendous amount of user profile data online, e.g., name, birthdate, etc. Protecting this data is a challenge. The task of access policy composition is a tedious and confusing effort for the average user having hundreds of friends. We propose an approach that assists users in composing and managing their access control policies. Our approach is based on a supervised learning mechanism that leverages user provided example policy settings as training sets to build classifiers that are the basis for auto-generated policies. Furthermore, we provide mechanisms to enable users to fuse policy decisions that are provided by their friends or others in the social network. These policies then regulate access to user profile objects. We implemented our approach and, through extensive experimentation, prove the accuracy of our proposed mechanisms. Mohamed Shehab, Gorrell P. Cheek, Hakim Touati, Anna Cinzia Squicciarini, Pau-Chen Cheng |
WWW | 1 |
| 2010 | Privacy policies for shared content in social network sites
Anna Cinzia Squicciarini, Mohamed Shehab, Joshua Wede |
VLDB J. | 2 |
| 2009 | Privacy-Enhanced User-Centric Identity ManagementabstractUser-centric identity management approaches have received significant attention for managing private and critical identity attributes from the user's perspective. User-centric identity management allows users to control their own digital identities. Users are allowed to select their credentials when responding to an authentication or attribute requester and it gives users more rights and responsibility over their identity information. However, current user-centric approaches mainly focus on interoperable architectures between existing identity management systems and privacy issues have not been considered in depth. In this paper, we propose a category-based privacy preference approach to enhance the privacy of user-centric identity management systems. In addition, we present our proof- of-concept prototype of our approach in the Identity Metasystem. Gail-Joon Ahn, Moonam Ko, Mohamed Shehab |
ICC | 3 |
| 2009 | Social applications: exploring a more secure frameworkabstractOnline social network sites, such as MySpace, Facebook and others have grown rapidly, with hundreds of millions of active users. A new feature on many sites is social applications -- applications and services written by third party developers that provide additional functionality linked to a user's profile. However, current application platforms put users at risk by permitting the disclosure of large amounts of personal information to these applications and their developers. This paper formally abstracts and defines the current access control model applied to these applications, and builds on it to create a more secure framework. We do so in the interest of preserving as much of the current architecture as possible, while seeking to provide a practical balance between security and privacy needs of the users, and the needs of the applications to access users' information. We present a user study of our interface design for setting a user-to-application policy. Our results indicate that the model and interface work for users who are more concerned with their privacy, but we still need to explore alternate means of creating policies for those who are less concerned. Andrew Besmer, Heather Lipford, Mohamed Shehab, Gorrell P. Cheek |
SOUPS | 3 |
| 2009 | Collective privacy management in social networksabstractSocial Networking is one of the major technological phenomena of the Web 2.0, with hundreds of millions of people participating. Social networks enable a form of self expression for users, and help them to socialize and share content with other users. In spite of the fact that content sharing represents one of the prominent features of existing Social Network sites, Social Networks yet do not support any mechanism for collaborative management of privacy settings for shared content. In this paper, we model the problem of collaborative enforcement of privacy policies on shared data by using game theory. In particular, we propose a solution that offers automated ways to share images based on an extended notion of content ownership. Building upon the Clarke-Tax mechanism, we describe a simple mechanism that promotes truthfulness, and that rewards users who promote co-ownership. We integrate our design with inference techniques that free the users from the burden of manually selecting privacy preferences for each picture. To the best of our knowledge this is the first time such a protection mechanism for Social Networking has been proposed. In the paper, we also show a proof-of-concept application, which we implemented in the context of Facebook, one of today’s most popular social networks. We show that supporting these type of solutions is not also feasible, but can be implemented through a minimal increase in overhead to end-users. Anna Cinzia Squicciarini, Mohamed Shehab, Federica Paci |
WWW | 2 |
| 2008 | Beyond User-to-User Access Control for Online Social Networks
Mohamed Shehab, Anna Cinzia Squicciarini, Gail-Joon Ahn |
ICICS | 1 |
| 2008 | Proactive Role Discovery in Mediator-Free EnvironmentsabstractThe rapid proliferation of Internet and related technologies has created tremendous possibilities for the interoperability between domains in distributed environments. Interoperability does not come easy at it opens the way for several security and privacy breaches. In this paper, we focus on the distributed authorization discovery problem that is crucial to enable secure interoperability. We present a distributed access path discovery framework that does not require a centralized mediator. We propose and verify a role routing protocol that propagates secure, minimal-length paths to reachable roles in other domains. Finally, we present experimental results of our role routing protocol based on a simulation implementation. Mohamed Shehab, Elisa Bertino, Arif Ghafoor |
Peer-to-Peer Computing | 1 |
| 2008 | Visualization based policy analysis: case study in SELinuxabstractDetermining whether a given policy meets a site's high-level security goals can be difficult, due to the low-level nature and complexity of the policy language, and the multiple policy violation patterns. In this paper, we propose a visualization-based policy analysis framework that enables system administrators to visually query and visualize SELinux security policies and to easily identify the policy violations. We propose and formalize both a semantic substrate and adjacency matrix visualization techniques for policy visualization. Furthermore, we propose a visual query language for expressing policy queries in a visual form. Our framework is targeted towards enabling the average administrator by providing an intuitive cognitive sense about the policy, policy queries and policy violations. We also describe our implementation of a visualization-based policy analysis tool that provides the functionalities discussed in our framework. Wenjuan Xu, Mohamed Shehab, Gail-Joon Ahn |
SACMAT | 2 |
| 2008 | Portable User-Centric Identity Management
Gail-Joon Ahn, Moonam Ko, Mohamed Shehab |
SEC | 3 |
| 2008 | Watermarking Relational Databases Using Optimization-Based TechniquesabstractProving ownership rights on outsourced relational databases is a crucial issue in today's internet-based application environments and in many content distribution applications. In this paper, we present a mechanism for proof of ownership based on the secure embedding of a robust imperceptible watermark in relational data. We formulate the watermarking of relational databases as a constrained optimization problem and discuss efficient techniques to solve the optimization problem and to handle the constraints. Our watermarking technique is resilient to watermark synchronization errors because it uses a partitioning approach that does not require marker tuples. Our approach overcomes a major weakness in previously proposed watermarking techniques. Watermark decoding is based on a threshold-based technique characterized by an optimal threshold that minimizes the probability of decoding errors. We implemented a proof of concept implementation of our watermarking technique and showed by experimental results that our technique is resilient to tuple deletion, alteration, and insertion attacks. Mohamed Shehab, Elisa Bertino, Arif Ghafoor |
IEEE Trans. Knowl. Data Eng. | 1 |
| 2008 | Secure Collaboration in a Mediator-Free Distributed EnvironmentabstractThe Internet and related technologies have made multidomain collaborations a reality. Collaboration enables domains to effectively share resources; however it introduces several security and privacy challenges. Managing security in the absence of a central mediator is even more challenging. In this paper, we propose a distributed secure interoperability framework for mediator-free collaboration environments. We introduce the idea of secure access paths which enables domains to make localized access control decisions without having global view of the collaboration. We also present a path authentication technique for proving path authenticity. Furthermore, we present an on-demand path discovery algorithms that enable domains to securely discover paths in the collaboration environment. We implemented a simulation of our proposed framework and ran experiments to investigate the effect of several design parameters on our proposed access path discovery algorithm. Mohamed Shehab, Arif Ghafoor, Elisa Bertino |
IEEE Trans. Parallel Distributed Syst. | 1 |
| 2007 | Towards trust-aware access management for ad-hoc collaborationsabstractIn an ad-hoc collaborative sharing environment, attribute-based access control provides a promising approach in defining authorization over shared resources based on userspsila properties/attributes rather than their identities. While the userpsilas attributes are always asserted by different authorities in the form of credentials, these authorities may not be accepted by the resource owner with the same degree of trust. In this paper, we present a trust-aware role-based authorization framework, called RAMARS_TM, to address both the access control and the trust management issues in such environment. Central to our approach is the dynamic role assignment based on a userpsilas attributes, and trust management, as a special constraint, is in place to make trust decisions on a userpsilas attributes. Required components and functions are identified and specified in our trust and access management policies. An architecture of prototype system implementation is also discussed. Gail-Joon Ahn, Mohamed Shehab, Hongxin Hu |
CollaborateCom | 3 |
| 2007 | Web services discovery in secure collaboration environmentsabstractMultidomain application environments where distributed domains interoperate with each other is a reality in Web-services-based infrastructures. Collaboration enables domains to effectively share resources; however, it introduces several security and privacy challenges. In this article, we use the current web service standards such as SOAP and UDDI to enable secure interoperability in a service-oriented mediator-free environment. We propose a multihop SOAP messaging protocol that enables domains to discover secure access paths to access roles in different domains. Then we propose a path authentication mechanism based on the encapsulation of SOAP messages and the SOAP-DISG standard. Furthermore, we provide a service discovery protocol that enables domains to discover service descriptions stored in private UDDI registries. Mohamed Shehab, Kamal Bhattacharya, Arif Ghafoor |
ACM Trans. Internet Techn. | 1 |
| 2005 | Secure collaboration in mediator-free environmentsabstractThe internet and related technologies have made multidomain collaborations a reality. Collaboration enables domains to effectively share resources; however it introduces several security and privacy challenges. Managing security in the absence of a central mediator is even more challenging. In this paper, we propose a distributed secure interoperability framework for mediator-free collaboration environments. We introduce the idea of secure access paths which enables domains to make localized access control decisions without having global view of the collaboration. We also present a path authentication technique for proving path authenticity. Furthermore, we present both a proactive and on-demand path discovery algorithms that enable domains to securely discover paths in the collaboration environment. Mohamed Shehab, Elisa Bertino, Arif Ghafoor |
CCS | 1 |
| 2005 | SERAT: SEcure role mApping technique for decentralized secure interoperabilityabstractMulti-domain application environments where distributed domains interoperate with each other are becoming a reality in internet-based and web-services based enterprise applications. The secure interoperation in a multidomain environment is a challenging problem. In this paper, we propose a distributed secure interoperability protocol that ensures secure interoperation of the multiple collaborating domains without compromising the security of collaborating domains. We introduce the idea of access paths and access paths constraints. Furthermore, we device a path discovery algorithm that is capable of querying interoperating domains for the set of secure access paths between different domains. Mohamed Shehab, Elisa Bertino, Arif Ghafoor |
SACMAT | 1 |
| 2005 | Efficient hierarchical key generation and key diffusion for sensor networksabstractAbstract — Sensor networks are designed with the assumption that nodes are willing to collaborate. However, the open collaboration of nodes introduces privacy and security issues. Therefore, ensuring privacy in wireless sensor networks is a challenging task. Based on a multilevel security paradigm, in this paper we present a hierarchical key generation and distribution protocol for wireless sensor networks. We show by simulation results that our key generation scheme outperforms the existing hierarchical key generation schemes thus it is suitable for sensor networks with limited computation and energy capabilities. Furthermore, we present an energy efficient key diffusion protocol. We also discuss the possible security threats involved with the proposed protocol and provide suitable solutions to such threats. I. Mohamed Shehab, Elisa Bertino, Arif Ghafoor |
SECON | 1 |