Maha Shamseddine

dblp:98/1104 · DBLP profile ↗
← Back
6ranked-venue papers
3as first author
3since 2021 · last 2025
0000-0002-6965-653XORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Systems, architecture and hardware · 2 · 1 first-author · 1 since 2021Computer networks · 2 · 1 first-author · 1 since 2021Security and privacy · 2 · 1 first-author · 1 since 2021

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Network and information security
1 paper
Network security · 100%
Computer architecture, parallel and distributed computing, and storage systems
1 paper
Cloud and datacenter computing · 50% Distributed systems · 50%

Topics — the 4 heaviest of 4, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Network security › intrusion detection and prevention › intrusion detection › intrusion detection system
distributed intrusion detection
0.912025
dcGuard: A Holistic Approach for Detecting and Isolating Malicious Nodes in Cloud Data Centers · IEEE Trans. Dependable Secur. Comput. 2025
Network security › intrusion detection and prevention
intrusion detection
0.912025
dcGuard: A Holistic Approach for Detecting and Isolating Malicious Nodes in Cloud Data Centers · IEEE Trans. Dependable Secur. Comput. 2025
Cloud and datacenter computing
cloud security
0.912025
dcGuard: A Holistic Approach for Detecting and Isolating Malicious Nodes in Cloud Data Centers · IEEE Trans. Dependable Secur. Comput. 2025
Distributed systems › distributed system security
malicious node detection
0.912025
dcGuard: A Holistic Approach for Detecting and Isolating Malicious Nodes in Cloud Data Centers · IEEE Trans. Dependable Secur. Comput. 2025

Methods — techniques the papers use, named apart from their topics

virtual machine introspection · 1.7software-defined networking · 1.7probabilistic sketching · 1.7
YearPublicationVenuePosition
2025 dcGuard: A Holistic Approach for Detecting and Isolating Malicious Nodes in Cloud Data Centers
abstract
This paper presentsdcGuard, a unified security approach for detecting and isolating misbehaving computing and forwarding nodes in multi-tenant virtualized cloud data centers.dcGuardemploys technological advancements in Virtual Machine Introspection (VMI), Software-Defined Networking (SDN), and secure probabilistic sketching to detect and isolate parts of the Virtual Machines (VMs) and network switches experiencing malicious behavior dynamically. The main contribution lies in designing a divide-and-conquer strategy that utilizes VMI and network programmability to apply focused distributed task and packet probing mechanisms on portions of the data center network rather than focusing the security functions on the entire physical network. The processing VMs and network switches are recursively partitioned into independent logical groups inspected individually to localize abnormal/malicious computing and switching nodes incrementally. This remarkably enhances the efficiency of the detection mechanisms, which opportunistically approaches a logarithmic time complexity in the number of protocol steps towards convergence (compared to a linear time complexity in traditional intrusion detection systems) when a relatively low number of hostile VMs and switches are present. Real experiments are evaluated, and a test-bed blueprint of the proposed design is emulated in a virtualized cloud environment using the Mininet emulator. The performance, convergence, and accuracy benchmarks corroborate the analytical advantage of the proposed security approach.
Wassim Itani, Maha Shamseddine, Auday Aldulaimy, Thomas Nolte, Alessandro Vittorio Papadopoulos
IEEE Trans. Dependable Secur. Comput.2
2022 Nodeguard: A Virtualized Introspection Security Approach for the Modern Cloud Data Center
abstract
This paper presents Nodeguard, a security approach for detecting and isolating misbehaving Virtual Machines (VMs) in multi-tenant virtualized cloud data centers, based on the Virtual Machine Introspection (VMI) monitoring primitives. Nodeguard employs a divide-and-conquer strategy that checks logical groups of VMs to ensure the efficiency of the detection mechanisms which opportunistically approaches a complexity of$\mathcal{O}(\log_{2}(n))$when there is a relatively low number of hostile VMs. This greatly enhances the algorithmic time complexity of the pro-posed security system compared to the$\mathcal{O}(n)$complexity achieved by the traditional VMI inspection strategy that checks each VM separately. The approach has been evaluated in a virtualized cloud environment using the Mininet network emulator.
Maha Shamseddine, Auday Aldulaimy, Wassim Itani, Thomas Nolte, Alessandro Vittorio Papadopoulos
CCGRID1
2022 Security-Aware Node Replacements and Incremental Updates in Industrial IoT Platforms
abstract
IIoT is the industrial tier of the Internet of Things initiative characterized by stringent security requirements, high sensor fault rates, and frequent mission-critical software updates. In this work, we propose the design and implementation of two security-aware protocols for node replacements and incremental software updates in IIoT. The node replacement protocol ensures the legitimacy of newly added replacement sensors by coordinating an efficient key management procedure to refresh their cryptographic keying material without the need of resource-intensive public-key cryptographic techniques. This is done by leveraging private secret sharing protocols and relying on the already established security associations between the IoT gateway and neighboring sensor nodes. The node update protocol supports multi-component software updates on the IIoT sensors and ensures their authenticity using probabilistic set membership data structures. This results in major reductions in network traffic overhead and protocol convergence times compared to traditional integrity enforcement approaches at the expense of minimal false positives probability. Moreover, the node update protocol realizes an incremental component loading and integrity verification mechanism on the IIoT sensors that lessens their storage requirements and avoids any superfluous operation intermission. A prototype implementation of the two proposed protocols demonstrates their feasibility in a real IoT network and exhibits high savings in convergence time and network traffic overhead.
Wassim Itani, Maha Shamseddine, Elisha J. Hosey-Stewart
GLOBECOM2
2020 bwSlicer: A bandwidth slicing framework for cloud data centers
Auday Aldulaimy, Wassim Itani, Javid Taheri, Maha Shamseddine
Future Gener. Comput. Syst.4
2018 Network Programming and Probabilistic Sketching for Securing the Data Plane
abstract
This paper presents VISKA, a cloud security service for dynamically detecting malicious switching elements in software defined networking (SDN) infrastructures. The main contributions of VISKA lie in (1) utilizing network programming and secure probabilistic sketching in SDN environments to dynamically detect and isolate parts of the data plane that experience malicious behavior, (2) applying a set of focused packet probing and sketching mechanisms on isolated network partitions/views rather than focusing the security mechanisms on the whole physical network, (3) efficiently analyzing the network behavior of the resulting views by recursively partitioning them in a divide-and-conquer fashion to logarithmically reduce the problem size in order to localize abnormal/malicious switching units, and (4) providing an attack categorization module that analyzes live ingress/egress traffic of the maliciously detected switch(es) solely to identify the specific type of attack, rather than inspecting the whole network traffic as is done in traditional intrusion detection systems. This significantly enhances the performance of attack detection and reduces the load on the controller. A testbed prototype implementation is realized on the Mininet network emulator. The experimental analysis corroborated the algorithms’ convergence property using the linear and FatTree topologies with network sizes of up to 250 switches. Moreover, an implementation of the attack categorization module is realized and achieved an accuracy rate of over 90% for the different attack types supported.
Maha Shamseddine, Wassim Itani, Ali Chehab, Ayman I. Kayssi
Secur. Commun. Networks1
2017 Virtualized network views for localizing misbehaving sources in SDN data planes
abstract
In this paper, we present VISKA, a Cloud security service for detecting malicious switching elements in software defined networking (SDN) environments. VISKA leverages network virtualization and secure probabilistic sketching to isolate misbehaving switches in the underlying SDN network data plane. The main contribution lies in utilizing network virtualization in SDN environments to dynamically isolate parts of the data plane and check their forwarding behavior. This is achieved by applying a set of focused packet probing and sketching mechanisms on virtualized network views mapped to these data plane partitions instead of focusing the security mechanisms on the whole physical network. VISKA flexibly analyzes the network behavior of the granular virtual views and recursively partitions these views to reduce the problem size in order to localize abnormal/malicious network switching units. A test bed prototype implementation is realized on the OpenVirtex SDN network virtualization platform. The experimental analysis corroborated the algorithm's convergence property using the linear and FatTree topologies with SDN network sizes of up to 250 switching units.
Maha Shamseddine, Wassim Itani, Ayman I. Kayssi, Ali Chehab
ICC1