VLDB 2026 Research / reviewers in the wild / expert
Amine Boukhtouta
dblp:94/5043
· DBLP profile ↗
13ranked-venue papers
2as first author
7since 2021 · last 2025
0000-0002-0261-815XORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 9 · 2 first-author · 3 since 2021Computer networks · 3 · 3 since 2021Systems, architecture and hardware · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | CSyncProxy: Differentially Private Third-party Cookie SynchronizationabstractCookie synchronization enables multiple advertising networks to share user browsing data, thus refining ad targeting without explicit user consent. Although existing mitigation strategies, such as cookie blockers, reduce privacy risks, they can also decrease website revenue or restrict certain online services. To address this limitation, we introduce a differentially private cookie synchronization proxy, CSyncProxy, that leverages the exponential mechanism to grant users granular control over the amount of data shared during cookie synchronization. By obfuscating user identities across websites, the proxy maintains sufficient personalization for advertisements while safeguarding user privacy. Experimental web crawls of the top 100 websites per visit and analysis of the likelihood of successful anonymization indicate that our approach reduces the number of instances of cookie synchronization by over 40% compared to standard browsing and 11% compared to Chrome’s cookie-blocking feature, without blocking or barring the user from any website. Sarah Bellemare, Daniel Migault, Benjamin C. M. Fung, Stere Preda, Amine Boukhtouta |
GLOBECOM | 5 |
| 2024 | tBPF: Testing Berkeley Packet Filter Programs Using User Mode LinuxabstractThe Berkeley Packet Filter (BPF) is increasingly used for a variety of use cases including auditing, security, monitoring, networking, etc. However, BPF lacks improved and effective tools, which makes the integration of programs written for BPF quite hard in current automated testing solutions and continue integration pipelines. We present tBPF, a library for integration testing of BPF programs that allows automated testing of arbitrary programs in a kernel agnostic manner without superuser privileges. We show that our solution can be integrated in existing development workflows and pipelines to enable reproducible testing and auditing of BPF programs. In this article, we describe our approach and compare it against other approaches in relevant work and literature. Alexis Brodeur, Guillaume Tassotti, Amine Boukhtouta, Abdeljouad Necir Medakene, Abdelouahed Gherbi |
CloudCom | 3 |
| 2023 | Evaluating the Security Posture of 5G Networks by Combining State Auditing and Event Monitoring
Md. Nazmul Hoq, Jia Wei Yao, Suryadipta Majumdar, Lingyu Wang 0001, Amine Boukhtouta, Makan Pourzandi, Mourad Debbabi |
ESORICS (2) | 6 |
| 2022 | Inferring and Investigating IoT-Generated Scanning Campaigns Targeting a Large Network TelescopeabstractThe analysis of recent large-scale cyber attacks, which leveraged insecure Internet of Things (IoT) devices to perform malicious activities on the Internet, highlighted the rise of IoT-tailored malware/botnets. These malware propagate by scanning the Internet for vulnerable, exploitable IoT devices that could be utilized for further malicious activities. In this article, we devise a multi-level methodology to investigate Internet-scale reconnaissance activities generated by infected IoT devices. We leverage theShodanIoT search engine and over 6TB of passive network traffic from a large network telescope (darknet) to infer compromised IoT devices and characterize the generated scanning campaigns. The results highlight a distinctive characteristic of IoT malware/botnets, represented by the targeted ports/services over the analysis interval. Furthermore, while these ports/services are mainly associated with well-known IoT malware/botnets (e.g.,MiraiandSatori), we uncovered newly targeted ports, which indicate emerging IoT malware/botnet. Finally, by comparing two instances of analyzed IoT-generated scanning campaigns, we highlight the persistence and evolution of IoT malware/botnets (e.g.,ADB.MinerandFbot), which exploit existing, and in some cases, possibly new vulnerabilities. Sadegh Torabi, Elias Bou-Harb, Chadi Assi, ElMouatez Billah Karbab, Amine Boukhtouta, Mourad Debbabi |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2022 | Multi-Perspective Content Delivery Networks Security Framework Using Optimized Unsupervised Anomaly DetectionabstractContent delivery networks (CDNs) provide efficient content distribution over the Internet. CDNs improve the connectivity and efficiency of global communications, but their caching mechanisms may be breached by cyber-attackers. Among the security mechanisms, effective anomaly detection forms an important part of CDN security enhancement. In this work, we propose a multi-perspective unsupervised learning framework for anomaly detection in CDNs. In the proposed framework, a multi-perspective feature engineering approach, an optimized unsupervised anomaly detection model that utilizes an isolation forest and a Gaussian mixture model, and a multi-perspective validation method, are developed to detect abnormal behaviors in CDNs mainly from the client Internet Protocol (IP) and node perspectives, therefore to identify the denial of service (DoS) and cache pollution attack (CPA) patterns. Experimental results are presented based on the analytics of eight days of real-world CDN log data provided by a major CDN operator. Through experiments, the abnormal contents, compromised nodes, malicious IPs, as well as their corresponding attack types, are identified effectively by the proposed framework and validated by multiple cybersecurity experts. This shows the effectiveness of the proposed method when applied to real-world CDN data. Li Yang 0010, Abdallah Moubayed, Abdallah Shami, Parisa Heidari, Amine Boukhtouta, Adel Larabi, Richard Brunner, Stere Preda, Daniel Migault |
IEEE Trans. Netw. Serv. Manag. | 5 |
| 2021 | AutoGuard: A Dual Intelligence Proactive Anomaly Detection at Application-Layer in 5G Networks
Taous Madi, Hyame Assem Alameddine, Makan Pourzandi, Amine Boukhtouta, Moataz Samir 0001, Chadi Assi |
ESORICS (1) | 4 |
| 2021 | NFV security survey in 5G networks: A three-dimensional threat taxonomy
Taous Madi, Hyame Assem Alameddine, Makan Pourzandi, Amine Boukhtouta |
Comput. Networks | 4 |
| 2018 | Fingerprinting Crowd Events in Content Delivery Networks: A Semi-supervised Methodology
Amine Boukhtouta, Makan Pourzandi, Richard Brunner, Stéphane Dault |
DBSec | 1 |
| 2018 | Inferring, Characterizing, and Investigating Internet-Scale Malicious IoT Device Activities: A Network Telescope PerspectiveabstractRecent attacks have highlighted the insecurity of the Internet of Things (IoT) paradigm by demonstrating the impacts of leveraging Internet-scale compromised IoT devices. In this paper, we address the lack of IoT-specific empirical data by drawing upon more than 5TB of passive measurements. We devise data-driven methodologies to infer compromised IoT devices and those targeted by denial of service attacks. We perform large-scale characterization analysis of their traffic, as well as explore a public threat repository and an in-house malware database, to underlie their malicious activities. The results expose a significant 26 thousand compromised IoT devices "in the wild," with 40% being active in critical infrastructure. More importantly, we uncover new, previously unreported malware variants that specifically target IoT devices. Our empirical results render a first attempt to highlight the large-scale insecurity of the IoT paradigm, while alarming about the rise of new generations of IoT-centric malware-orchestrated botnets. Sadegh Torabi, Elias Bou-Harb, Chadi Assi, Mario Galluscio, Amine Boukhtouta, Mourad Debbabi |
DSN | 5 |
| 2012 | Investigating the dark cyberspace: Profiling, threat-based analysis and correlationabstractAn effective approach to gather cyber threat intelligence is to collect and analyze traffic destined to unused Internet addresses known as darknets. In this paper, we elaborate on such capability by profiling darknet data. Such information could generate indicators of cyber threat activity as well as providing in-depth understanding of the nature of its traffic. Particularly, we analyze darknet packets distribution, its used transport, network and application layer protocols and pinpoint its resolved domain names. Furthermore, we identify its IP classes and destination ports as well as geo-locate its source countries. We further investigate darknet-triggered threats. The aim is to explore darknet embedded threats and categorize their severities. Finally, we contribute by exploring the inter-correlation of such threats, by applying association rule mining techniques, to build threat association rules. Specifically, we generate clusters of threats that co-occur targeting a specific victim. Such work proves that specific darknet threats are correlated. Moreover, it provides insights about threat patterns and allows the interpretation of threat scenarios. Claude Fachkha, Elias Bou-Harb, Amine Boukhtouta, Son Dinh, Farkhund Iqbal, Mourad Debbabi |
CRiSIS | 3 |
| 2010 | Insights from the analysis of the Mariposa botnetabstractNowadays, botnets are among the topmost network threats by combining innovative hacking capabilities. This is due to the fact that they are constantly improved by hackers to become more resilient against detection and debugging techniques. In this respect, we analyze one of the most prominent botnets, namely Mariposa, which infected more than 13 million computers that are located in more than 190 countries. In this regard, we analyze the botnet architecture, components, commands and communication. In this setting, we detail the obfuscation and anti-debugging techniques it uses. Moreover, we detail the infection and code-injection techniques into legitimate processes. In addition, we explain the spreading mechanisms that are employed in Mariposa as well as the underlying communication protocols. More importantly, we analyze the injected bot code. This is accomplished by a reverse engineering exercise that uses both a network analysis together with reverse-engineering analysis. The insights from this work are meant to illustrate the know-how used in current botnet technologies and enable the elaboration of analysis, detection and prevention techniques. Prosenjit Sinha, Amine Boukhtouta, Victor Heber Belarde, Mourad Debbabi |
CRiSIS | 2 |
| 2010 | On the analysis of the Zeus botnet crimeware toolkitabstractIn this paper, we present our reverse engineering results for the Zeus crimeware toolkit which is one of the recent and powerful crimeware tools that emerged in the Internet underground community to control botnets. Zeus has reportedly infected over 3.6 million computers in the United States. Our analysis aims at uncovering the various obfuscation levels and shedding the light on the resulting code. Accordingly, we explain the bot building and installation/infection processes. In addition, we detail a method to extract the encryption key from the malware binary and use that to decrypt the network communications and the botnet configuration information. The reverse engineering insights, together with network traffic analysis, allow for a better understanding of the technologies and behaviors of such modern HTTP botnet crimeware toolkits and opens an opportunity to inject falsified information into the botnet communications which can be used to defame this crimeware toolkit. Hamad Binsalleeh, Thomas C. Ormerod, Amine Boukhtouta, Prosenjit Sinha, Amr M. Youssef, Mourad Debbabi, Lingyu Wang 0001 |
PST | 3 |
| 2009 | A Practical Framework for the Dataflow Pointcut in AspectJabstractIn this paper, we present the design and the implementation of the dataflow pointcut in AspectJ compiler ajc 1.5.0. Some security concerns are sensitive to flow of information in a program execution. The dataflow pointcut has been proposed by Masuhara and Kawauchi in order to easily implement such security concerns in aspect-oriented programming languages. The pointcut identifies join points based on the origins of values. The dataflow pointcut can detect and fix a lot of vulnerabilities that result from not validating input effectively, e.g., Web application vulnerabilities, process injection, log forging, and path injection. AspectJ extends the Java programming language to implement crosscutting concerns modularly in general. The implementation methodology of the dataflow pointcut which depends in define-use analysis is described in detail together with case studies that demonstrate how the implemented dataflow pointcut can detect a considerable number of vulnerabilities. Amine Boukhtouta, Dima Alhadidi, Mourad Debbabi |
ARES | 1 |