VLDB 2026 Research / reviewers in the wild / expert
Khaled Salah 0001
dblp:s/KhaledSalah · also Khaled Hamed Salah
· DBLP profile ↗
90ranked-venue papers
38as first author
21since 2021 · last 2026
0000-0002-2310-2558ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 29 · 21 first-author · 5 since 2021Systems, architecture and hardware · 16 · 6 first-author · 3 since 2021Security and privacy · 14 · 4 first-authorApplied, interdisciplinary, general and emerging computing · 14 · 2 first-author · 5 since 2021Artificial intelligence and machine learning · 5 · 5 since 2021Software engineering, systems software and programming languages · 4 · 1 first-author · 3 since 2021Databases, data management, data science and information retrieval · 2 · 1 first-authorHuman-computer interaction and ubiquitous computing · 2 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Leveraging Hyperledger Fabric for Enhanced Compliance Monitoring in UAV OperationsabstractThe current Unmanned Aerial Vehicle (UAV) systems lack traceable, secure, private, and trustworthy automated assurance that UAV operations comply with regulatory rules and regulations. In this article, we propose a blockchain-based solution to ensure that the operations of UAVs comply with critical regulatory parameters such as geofencing and operational time restrictions. By utilizing smart contracts and blockchain’s inherent features, such as immutability, data integrity, and decentralization, our proposed system facilitates automated UAV compliance verification, ensures accountable UAV operations, and establishes a secure, private, and trustworthy framework for all stakeholders involved in UAV commercial activities. We leverage Hyperledger Fabric (HLF) to configure and implement a permissioned blockchain network capable of handling transactions amongst all stakeholders, including regulators, service providers, and UAV operators. We present our system architecture and detailed sequence diagrams for compliance assurance of UAV operations. We also discuss the configuration details of the Fabric network, the implementation of the algorithms behind the chaincode, and performance results. We conduct functional validation and evaluate the performance of our implementation in terms of both throughput and latency. The assessment shows that the solution processes over 72,000 beacons per second, making it suitable for large-scale deployment. Furthermore, we compare our proposed solution with the existing solutions to show its superiority. We make our chaincode files, which represent the smart contracts defining the set of rules and processes for a blockchain network, publicly available on GitHub. Diana Hawashin, Mohammad Moussa Madine, Mohamed Nemer, Khaled Salah 0001, Raja Jayaraman, Ernesto Damiani, Ibrar Yaqoob |
Distributed Ledger Technol. Res. Pract. | 4 |
| 2026 | LLM-based exploration and analysis of real-time and historical blockchain data
Senay A. Gebreab, Ahmad Musamih, Khaled Salah 0001, Raja Jayaraman |
Expert Syst. Appl. | 3 |
| 2026 | Blockchain for Large Language Models (LLMs): Applications, challenges, and framework implementationabstractLarge Language Models (LLMs) are increasingly embedded in intelligent systems across domains such as healthcare, finance, and smart infrastructure. However, their reliance on centralized data pipelines raises unresolved challenges concerning provenance, accountability, and verifiable trust. As the demand for transparent and regulation-aligned AI grows, these challenges have become central to the responsible deployment of intelligent systems. This review examines how blockchain technology can address them by introducing decentralized integrity, immutable audit trails, and cryptographic verification into the LLM lifecycle. Through a structured synthesis of current research, we identify conceptual and architectural gaps that limit trustworthy data management, inference authentication, and explainability. To bridge these gaps, a methodological framework is proposed that integrates blockchain mechanisms across the LLM pipeline using smart contracts, Merkle-based commitments, and decentralized storage. The framework’s feasibility is demonstrated through an illustrative prototype, confirming its practical applicability for building verifiable and transparent AI infrastructures. We further outline application domains such as healthcare, smart cities, Industry 4.0, and supply-chain management, where blockchain-anchored LLMs can enhance auditability and regulatory compliance. The review concludes by highlighting key insights and challenges for future research, emphasizing the need for decentralized attestation models, scalable verification protocols, and governance mechanisms that advance accountable and privacy-preserving intelligent systems. Ahmad Musamih, Ibrar Yaqoob, Khaled Salah 0001, Raja Jayaraman, Mohammed A. Omar |
Expert Syst. Appl. | 3 |
| 2026 | Agentic LLM for anonymizing healthcare data with contextual awarenessabstractLarge language models (LLMs) are transforming healthcare applications by enhancing data analysis, yet their adoption remains constrained by stringent privacy requirements that limit access to sensitive medical data. Anonymization offers a pathway to address this challenge; however, existing techniques often lack contextual understanding and exhibit low accuracy, compromising either patient privacy or the utility of clinical content. In this paper, we propose an end-to-end, modular agentic LLM system for processing sensitive healthcare data with contextual awareness. The system is orchestrated by a central agent coordinating specialized components for structured data retrieval, clinical narrative generation, anonymization, public LLM querying, and secure deanonymization. Locally hosted LLMs handle all privacy-sensitive steps, including context generation and anonymization, while public LLMs are used exclusively for reasoning on pre-anonymized inputs. We evaluate our system on a synthetic clinical dataset and benchmark it against five state-of-the-art named entity recognition (NER) techniques. Our approach achieves high precision and a recall of 93.6%, significantly outperforming baselines such as spaCy (33% precision, 89% recall) and Presidio (41% precision, 90% recall). Additional evaluation on real-world clinical notes from the MIMIC-III dataset demonstrates strong generalization to unstructured narratives, achieving a clean transformation rate of 98.6%. We further evaluate medical richness, showing that anonymized outputs retain clinically relevant information and semantic structure, preserving downstream utility. Adversarial re-identification experiments confirm that no true identifiers can be reconstructed, highlighting the framework’s effectiveness in balancing privacy, robustness, and clinical usefulness. Rana Azzam, Ahmad Musamih, Senay A. Gebreab, Khaled Salah 0001, Mohammed A. Omar |
Knowl. Based Syst. | 4 |
| 2025 | Leveraging Blockchain and Machine Learning to Promote Child Labor-Free Sustainable DevelopmentabstractChild labor has been on the rise in recent years, which necessitates improved identification and reporting mechanisms. Current labor management systems, which are often manual or article-based, lack traceability, audit, privacy, security, and trust features. This leads to challenges in detecting and reporting violations, particularly in large or remote areas. The persistence of this issue undermines the achievement of Sustainable Development Goals (SDGs) and highlights the important role of Corporate Social Responsibility (CSR) in addressing this challenge. Our article proposes a solution combining machine learning and blockchain to automate child labor detection and ensure traceable, auditable, private, and secure reporting. Utilizing Decentralized Proxy Re-Encryption (DPRE), Zero-Knowledge Proofs (ZKPs), and oracles on the Ethereum blockchain, with decentralized storage, our approach maintains privacy and transparency. We present a child labor detection model using Mask2Former and ResNet-18 Convolutional Neural Network (CNN) to achieve high accuracy and reliability. The model’s performance is evaluated using various metrics, achieving an accuracy rate of 89.45%, a precision score of 0.906, and a recall score of 0.9332. Additionally, we assess smart contracts for cost-efficiency and security, and discuss the solution’s generalizability, challenges, and practical implications. We make the source code of our solution publicly available on GitHub. Ahmad Musamih, Abduraouf Hassan, Khaled Salah 0001, Raja Jayaraman, Mohammed A. Omar, Ibrar Yaqoob |
Distributed Ledger Technol. Res. Pract. | 3 |
| 2025 | BackFillMe: An Energy and Performance Efficient Virtual Machine Scheduler for IaaS DatacentersabstractBackfilling refers to the practice of allowing small jobs to be completed ahead of schedule as long as they do not cause the first job in the line to wait. Users are expected to offer estimates of how long jobs will take to complete in order to make these decisions possible, and these projections are often based on historical data. However, predictions are very hard and may not be accurate, particularly in cloud computing scenarios where jobs or applications run on Virtual Machines (VMs). In addition, scheduling and consolidation techniques can improve the energy efficiency and performance of applications. Consolidation involves VM migrations that can have a negative impact on workload performance and users’ costs. Backfilling can be used as an alternative technique for consolidation (short-term) and/or can be used along with consolidation (long-term). Backfilling methods are well-utilised in single computing systems, but are relatively unexplored in cloud resource allocation. A backfilling-based resource allocation and consolidation technique is proposed. Using real workloads from the Google cluster traces, we investigate the impact of backfilling on infrastructure energy efficiency and performance. For 12583 heterogeneous servers and approximately three million jobs that belong to three different applications, we observed that approximately 19% energy savings and 6% workload performance improvements are achievable using the backfilling approach. Furthermore, our evaluation suggests that using VM runtime as a criterion for the backfilling approach is approximately 3.56%–7.78% more energy and 1.91%–3.38% more performance efficient than using priority as a backfilling criterion. Muhammad Zakarya, Lee Gillam, Mohammad Reza Chalak Qazani, Ayaz Ali Khan, Khaled Salah 0001, Omer F. Rana |
IEEE Trans. Serv. Comput. | 5 |
| 2024 | NFTs for accessing, monetizing, and teleporting digital twins and digital artifacts in the metaverseabstractDigital twins and digital artifacts have become integral components of metaverse platforms, providing users with a rich, immersive, and interactive digital experience through the deployment of diverse digital twins and digital artifacts such as 3D avatars, images, and objects. To date, a significant challenge persists in the lack of practical mechanisms to enable seamless teleportation and cross-metaverse interoperability for these digital twins and digital artifacts. There is also a lack of trusted monetization methods that facilitate trading and leasing of digital twins and digital artifacts. To address these important challenges, this paper proposes a blockchain and Non-Fungible Token (NFT)-based solution that facilitates the integration and teleportation of these digital twins and digital artifacts by providing trusted metadata, verifying ownership, and ensuring the authenticity of digital creations in the virtual world. Key to our solution is the introduction of a bridging mechanism that enables cross-metaverse interoperability, allowing for the portable transfer of NFTs across decentralized metaverse platforms. In addition, our solution focuses on empowering original digital creators by enabling the monetization of their creations through the ownership management capabilities offered by NFTs. To reliably and securely store the metadata and content of tokenized digital twins and digital artifacts, we integrate into our solution the Interplanetary File System (IPFS), a decentralized storage system. To demonstrate the feasibility of our solution, we have developed and deployed all necessary smart contracts that govern the main functionalities and interactions of the proposed system on the Ethereum Goerli Testnet. We present our proposed system architecture, accompanied by informative sequence diagrams, algorithms, and testing details. We discuss how our proposed solution attains the main objectives outlined in the paper. We evaluate our proposed solution in terms of cost and security. We have made the complete source code of our smart contracts publicly available on GitHub. Senay A. Gebreab, Ahmad Musamih, Haya R. Hasan, Khaled Salah 0001, Raja Jayaraman, Yousof Al-Hammadi, Mohammed A. Omar |
Comput. Commun. | 4 |
| 2024 | Blockchain-based trusted accountability in the maintenance of medical imaging equipment
Ilhaam Aziz Omar, Haya R. Hasan, Wala' Alkhader, Raja Jayaraman, Khaled Salah 0001, Mohammed A. Omar |
Expert Syst. Appl. | 5 |
| 2024 | Blockchain applications in UAV industry: Review, opportunities, and challenges
Diana Hawashin, Mohamed Nemer, Senay A. Gebreab, Khaled Salah 0001, Raja Jayaraman, Muhammad Khurram Khan, Ernesto Damiani |
J. Netw. Comput. Appl. | 4 |
| 2023 | Using NFTs for ownership management of digital twins and for proof of delivery of their physical assets
Haya R. Hasan, Mohammad Moussa Madine, Ibrar Yaqoob, Khaled Salah 0001, Raja Jayaraman, Dragan Boscovic |
Future Gener. Comput. Syst. | 4 |
| 2023 | Blockchain-based system for tracking and rewarding recyclable plastic waste
Eiman AlNuaimi, Mariam Alsafi, Maitha Alshehhi, Mazin Debe, Khaled Salah 0001, Ibrar Yaqoob, Mohamed Jamal Zemerly, Raja Jayaraman |
Peer Peer Netw. Appl. | 5 |
| 2023 | CoLocateMe: Aggregation-Based, Energy, Performance and Cost Aware VM Placement and Consolidation in Heterogeneous IaaS CloudsabstractIn many production clouds, with the notable exception of Google, aggregation-based VM placement policies are used to provision datacenter resources energy and performance efficiently. However, if VMs with similar workloads are placed onto the same machines, they might suffer from contention, particularly, if they are competing for similar resources. High levels of resource contention may degrade VMs performance, and, therefore, could potentially increase users’ costs and infrastructure's energy consumption. Furthermore, segregation-based methods result in stranded resources and, therefore, less economics. The recent industrial interest in segregating workloads opens new directions for research. In this article, we demonstrate how aggregation and segregation-based VM placement policies lead to variabilities in energy efficiency, workload performance, and users’ costs. We, then, propose various approaches to aggregation-based placement and migration. We investigate through a number of experiments, using Microsoft Azure and Google's workload traces for more than twelve thousand hosts and a million VMs, the impact of placement decisions on energy, performance, and costs. Our extensive simulations and empirical evaluation demonstrate that, for certain workloads, aggregation-based allocation and consolidation is$\sim$9.61% more energy and$\sim$20.0% more performance efficient than segregation-based policies. Moreover, various aggregation metrics, such as runtimes and workload types, offer variations in energy consumption and performance, therefore, users’ costs. Muhammad Zakarya, Lee Gillam, Khaled Salah 0001, Omer F. Rana, Santosh Tirunagari, Rajkumar Buyya |
IEEE Trans. Serv. Comput. | 3 |
| 2022 | Scalable blockchains - A systematic review
Muhammad Hassan Nasir, Junaid Arshad, Muhammad Mubashir Khan, Mahawish Fatima, Khaled Salah 0001, Raja Jayaraman |
Future Gener. Comput. Syst. | 5 |
| 2022 | Blockchain for healthcare data management: opportunities, challenges, and future recommendations
Ibrar Yaqoob, Khaled Salah 0001, Raja Jayaraman, Yousof Al-Hammadi |
Neural Comput. Appl. | 2 |
| 2022 | A Novel Contract Theory-Based Incentive Mechanism for Cooperative Task-Offloading in Electrical Vehicular NetworksabstractThe proliferation of compute-intensive services in next-generation vehicular networks will impose an unprecedented computation demand to meet stringent latency and resource requirements. Vehicular edge or fog computing has been a widely adopted solution to enhance the computational capacity of vehicular networks; however, the computation requirements of these compute hungry applications will surpass the capabilities of such a solution. To address this challenge, the on-board resources of neighboring mobile vehicles can be utilized. However, such resource utilization requires an incentive mechanism to motivate privately owned neighboring vehicles to participate in sharing their resources. In this paper, we propose a contract theory-based incentive mechanism that maximizes the social welfare of the vehicular networks by motivating neighboring vehicles to participate in sharing their resources. The proposed approach enables the Road Side Units (RSUs) to provide appropriate rewards by offering a tailored contract to each resource sharing vehicle based on their contribution and unique characteristics. Moreover, we derive an optimal contract scheme for computational task offloading, taking into account the individual rationality and incentive-compatible constraints. Finally, we perform numerical evaluations to demonstrate the effectiveness of our proposed scheme. The proposed scheme achieves up to 28% higher computing resource utilization, 17.2% lower energy consumption per computing resource utilization, and 17.1% lesser energy consumption per task completed when compared to the linear pricing incentive baseline. S. M. Ahsan Kazmi, Nguyen Dang Tri, Ibrar Yaqoob, Aunas Manzoor, Rasheed Hussain, Adil Khan 0001, Choong Seon Hong, Khaled Salah 0001 |
IEEE Trans. Intell. Transp. Syst. | 8 |
| 2022 | epcAware: A Game-Based, Energy, Performance and Cost-Efficient Resource Management Technique for Multi-Access Edge ComputingabstractInternet of Things (IoT) is producing an extraordinary volume of data daily, and it is possible that the data may become useless while on its way to the cloud, due to long distances. Fog/edge computing is a new model for analysing and acting on time-sensitive data, adjacent to where it is produced. Further, cloud services provided by large companies such as Google, can also be localised to improve response time and service agility. This is accomplished through deploying small-scale datacentres in various locations, where needed in proximity of users; and connected to a centralised cloud that establish a multi-access edge computing (MEC). The MEC setup involves three parties, i.e., service providers (IaaS), application providers (SaaS), network providers (NaaS); which might have different goals, therefore, making resource management difficult. Unlike existing literature, we consider resource management with respect to all parties; and suggest game-theoretic resource management techniques to minimise infrastructure energy consumption and costs while ensuring applications’ performance. Our empirical evaluation, using Google’s workload traces, suggests that our approach could reduce up to 11.95 percent energy consumption, and$\sim$17.86% user costs with negligible loss in performance. Moreover, IaaS can reduce up to 20.27 percent energy bills and NaaS can increase their costs-savings up to 18.52 percent as compared to other methods. Muhammad Zakarya, Lee Gillam, Hashim Ali 0001, Izaz Ur Rahman, Khaled Salah 0001, Rahim Khan, Omer F. Rana, Rajkumar Buyya |
IEEE Trans. Serv. Comput. | 5 |
| 2021 | Device-centric adaptive data stream management and offloading for analytics applications in future internet architectures
Muhammad Habib Ur Rehman, Chee Sun Liew, Ying Wah Teh, Muhammad Imran 0001, Khaled Salah 0001, Nidal Nasser, Davor Svetinovic |
Future Gener. Comput. Syst. | 5 |
| 2021 | Blockchain for IoT-based smart cities: Recent advances, requirements, and future challenges
Umer Majeed, Latif U. Khan, Ibrar Yaqoob, S. M. Ahsan Kazmi, Khaled Salah 0001, Choong Seon Hong |
J. Netw. Comput. Appl. | 5 |
| 2021 | HonestChain: Consortium blockchain for protected data sharing in health information systems
Soumya Purohit, Prasad Calyam, Mauro Lemus, Naga Ramya Bhamidipati, Abu Saleh Mohammad Mosa, Khaled Salah 0001 |
Peer-to-Peer Netw. Appl. | 6 |
| 2021 | TrustFed: A Framework for Fair and Trustworthy Cross-Device Federated Learning in IIoTabstractCross-device federated learning (CDFL) systems enable fully decentralized training networks whereby each participating device can act as a model-owner and a model-producer. CDFL systems need to ensure fairness, trustworthiness, and high-quality model availability across all the participants in the underlying training networks. This article presents a blockchain-based framework, TrustFed, for CDFL systems to detect the model poisoning attacks, enable fair training settings, and maintain the participating devices' reputation. TrustFed provides fairness by detecting and removing the attackers from the training distributions. It uses blockchain smart contracts to maintain participating devices' reputations to compel the participants in bringing active and honest model contributions. We implemented the TrustFed using a Python-simulated federated learning framework, blockchain smart contracts, and statistical outlier detection techniques. We tested it over the large-scale industrial Internet of things dataset and multiple attack models. We found that TrustFed produces better results regarding multiple aspects compared with the conventional baseline approaches. Muhammad Habib Ur Rehman, Ahmed Dirir, Khaled Salah 0001, Ernesto Damiani, Davor Svetinovic |
IEEE Trans. Ind. Informatics | 3 |
| 2021 | Toward Offloading Internet of Vehicles Applications in 5G NetworksabstractThe demand for real-time communication and high performance of the Internet of Vehicles (IoV) system has caused researches to investigate new techniques in edge computing (EC). With the rapid development of the fifth- generation (5G) network, the features of low delay, high reliability and superior communication efficiency can bring historic opportunities for the development of the EC-IoV system. In the 5G-enabled EC-IoV system, extreme densification of 5G base stations (gNBs) provides rapid and reliable network access and information interaction. However, this densification also brings more complex connectivity to the network, which increases the difficulty of resource migration and scheduling for the edge devices. Thus, it is still a challenge to manage the resources of the edge devices under the premise of reducing the energy and time cost in the system while avoiding the situation of overload or underload to maintain the stability of the system. In this article, a 5G-enabled EC-IoV system framework is proposed to enhance the performance of *the existing EC-IoV system. Specific computation offloading in 5G-enabled EC-IoV system is presented under three different cases. Through the above cases, two communication modes are concluded and the corresponding resource allocation strategy is given in this article. The performance of the proposed system is evaluated and compared with the existing system. Finally, future research directions in this area are considered. Shaohua Wan 0001, Renhao Gu, Tariq Umer, Khaled Salah 0001, Xiaolong Xu 0001 |
IEEE Trans. Intell. Transp. Syst. | 4 |
| 2020 | IoT-Enabled Shipping Container with Environmental Monitoring and Location TrackingabstractInternet of Things (IoT) interconnects physical devices and objects that offer services to enrich the user experience. By 2020, it is estimated that up to 50 billion IoT devices will be deployed to offer new services. For instance, empowering traditional transport systems with IoT ensure greater visibility and traceability to remotely monitor the transported objects. In traditional shipping and freight systems, containers carrying donated organs should be sealed carefully, kept below a certain temperature, and placed in a physically safe place to minimize the chances of damage due to jerking and accidental falling. This paper presents a system of a smart shipping container that uses IoT, Cloud computing, Message Queuing Telemetry Transport (MQTT) protocol, and Docker images for effective and remote monitoring of shipping containers. During the shipping process, the IoT-enabled container provides continuous monitoring and readings related to temperature, humidity, location, luminosity, vibration, and open/close conditions. Additionally, automatic push alerts and notifications are sent to stakeholders when certain conditions or violations occur. Examples of these violations may include the opening of a sealed container or exceeding a preset maximum temperature. We have designed, developed, and tested the system under various real conditions. Khaled Salah 0001, A. Alfalasi, M. Alfalasi, M. Alharmoudi, M. Alzaabi, A. Alzyeodi, Raja Wasim Ahmad |
CCNC | 1 |
| 2020 | BehavDT: A Behavioral Decision Tree Learning to Build User-Centric Context-Aware Predictive Model
Iqbal H. Sarker, Alan W. Colman, Jun Han 0004, Asif Irshad Khan, Yoosef B. Abushark, Khaled Salah 0001 |
Mob. Networks Appl. | 6 |
| 2020 | Frequency-Minimal Utility-Maximal Moving Target Defense Against DDoS in SDN-Based SystemsabstractWith the increase of DDoS attacks, resource adaptation schemes need to be effective to protect critical cloud-hosted applications. Specifically, they need to be adaptable to attack behavior, and be dynamic in terms of resource utilization. In this paper, we propose an intelligent strategy for proactive and reactive application migration by leveraging the concept of `moving target defense' (MTD). The novelty of our approach lies in: (a) stochastic proactive migration frequency minimization across heterogeneous cloud resources to optimize migration management overheads, (b) market-driven migration location selection during proactive migration to optimize resource utilization, cloud service providers (CSPs) cost and user quality of experience, and (c) fast converging cost-minimizing reactive migration coupled with a `false reality' pretense to reduce the future attack success probability. We evaluate the effectiveness of our proposed MTD-based defense strategy using a Software-defined Networking (SDN) enabled GENI Cloud testbed for a “Just-in-time news articles and video feeds” application. Our frequency minimization results show more than 40% reduction in DDoS attack success rate in the best cases when compared to the traditional periodic migration schemes on homogeneous cloud resources. The results also show that our market-driven migration location selection strategy decreases CSP cost and increases resource utilization by 30%. Saptarshi Debroy, Prasad Calyam, Roshan Neupane, Bidyut Mukherjee, Ajay Kumar Eeralla, Khaled Salah 0001 |
IEEE Trans. Netw. Serv. Manag. | 7 |
| 2020 | Automating the Configuration of MapReduce: A Reinforcement Learning SchemeabstractWith the exponential growth of data and the high demand for the analysis of large datasets, the MapReduce framework has been widely utilized to process data in a timely, cost-effective manner. It is well-known that the performance of MapReduce is limited by its default configuration parameters, and there are a few research studies that have focused on finding the optimal configurations to improve the performance of the MapReduce framework. Recently, machine learning based approaches have been receiving more attention to be utilized to auto configure the MapReduce parameters to account for the dynamic nature of the applications. In this article, we propose and develop a reinforcement learning (RL)-based scheme, named RL-MRCONF, to automatically configure the MapReduce parameters. Specifically, we explore and experiment with two variations of RL-MRCONF; one variation is based on the traditional RL algorithm and the second is based on the deep RL algorithm. Results obtained from simulations show that the RL-MRCONF has the ability to successfully and effectively auto-configure the MapReduce parameters dynamically according to changes in job types and computing resources. Moreover, simulation results show our proposed RL-MRCONF scheme outperforms the traditional RL-based implementation. Using datasets provided by MR-Perf, simulation results show that our proposed scheme provides around 50% performance improvement in terms of execution time when compared with MapReduce using default settings. Ting-Yu Mu, Ala I. Al-Fuqaha, Khaled Salah 0001 |
IEEE Trans. Syst. Man Cybern. Syst. | 3 |
| 2019 | Towards a Blockchain-Based Decentralized Reputation System for Public Fog NodesabstractThe omnipresence of Internet of Things (IoT) devices nowadays has resulted in a large amount of data transferred regularly to the cloud. This continuous data transfer degrades the application performance in terms of latency, bandwidth consumption, connectivity, security, privacy, user experiences, and energy efficiency. Fog computing brings cloud services closer to the IoT devices. In public settings, variety of handheld and IoT devices need to connect to public fog nodes in order to access localized compute, storage, and networking capabilities. Therefore, the reputations of publicly available fog nodes become critical. Maintaining a reputation score is one of the popular techniques to ensure trust for fog nodes. This paper introduces a blockchain-based solution to establish trust in public fog nodes that provides services for IoT devices in a decentralized manner. Our proposed solution exploits blockchain smart contracts to compute the reputation in a decentralized manner by capturing and analyzing its past interactions with IoT devices. The solution also penalizes IoT devices that may collude to provide dishonest reputation scores. Mazin Debe, Khaled Salah 0001, Muhammad Habib Ur Rehman, Davor Svetinovic |
AICCSA | 2 |
| 2019 | Exploiting Ethereum Smart Contracts for Clinical Trial ManagementabstractBlockchain is a distributed ledger that ensures the authenticity of business transactions without the involvement of intermediaries, brokers or trusted third parties. The main features of blockchain technology include transparency, immutability and data provenance offers an important role in satisfying the requirements of a more secure, visible, efficient, and trusted clinical trial (CT) management. This is because the traditional CTs face significant challenges such as protocol compliance, transparency and patient enrollment. In this paper we discuss how blockchain technology can be leveraged to tackle data management challenges in clinical trials. We propose a blockchain-based framework using Ethereum based smart contract. In the framework, three stages of a CT process were captured: new drug application, CT initiation and patient enrollment stages. The framework captures key interactions among CT stakeholders including the regulatory agency, drug sponsor, principal investigator, physician and patients. The smart contract was written in Remix IDE and was successfully compiled and tested for different scenarios. The proposed approach and results can be highly beneficial to various stakeholders in CT data management. Ilhaam Aziz Omar, Raja Jayaraman, Khaled Salah 0001, Mecit Can Emre Simsekler |
AICCSA | 3 |
| 2019 | Performance analysis of content discovery for ad-hoc tactile networks
Junaid Arshad, Muhammad Ajmal Azad, Khaled Salah 0001, Razi Iqbal, Muhammad Imran Tariq, Tariq Umer |
Future Gener. Comput. Syst. | 3 |
| 2019 | The role of big data analytics in industrial Internet of Things
Muhammad Habib Ur Rehman, Ibrar Yaqoob, Khaled Salah 0001, Muhammad Imran 0001, Prem Prakash Jayaraman, Charith Perera |
Future Gener. Comput. Syst. | 3 |
| 2018 | A User Authentication Scheme of IoT Devices using Blockchain-Enabled Fog NodesabstractThese days, IoT devices are deployed at a massive scale, with Cisco predicting 20 billion devices by the year 2020. As opposed to endpoint devices, IoT devices are resource-constrained devices, incapable of securing and defending themselves, and can be easily hacked and compromised. Fog computing can augment such capacity limitations by providing localized compute, storage, and networking for a group of IoT devices. As fog nodes are deployed in close proximity to IoT devices, fog computing can be more effective than cloud computing. Furthermore, Blockchain has emerged as technology with capabilities to provide secure management, authentication and access to IoT devices and their data, in decentralized manner with high trust, integrity, and resiliency. In this paper, we propose a user authentication scheme using blockhain-enabled fog nodes in which fog nodes interface to Ethereum smart contracts to authenticate users to access IoT devices. The fog nodes are used to provide scalability to the system by relieving the IoT devices from carrying out heavy computation involving tasks related to authentication and communicating with the blockchain. We describe system components, architecture and design, and we discuss key aspects related to security analysis, functionality, testing and implementation of the smart contracts. The full code of the smart contracts for authentication registry, lists, rules and logic is also made publicly available at Github. Randa Almadhoun, Maha Kadadha, Maya Alhemeiri, Maryam R. Al-Shehhi, Khaled Salah 0001 |
AICCSA | 5 |
| 2018 | M2M-REP: Reputation system for machines in the internet of things
Muhammad Ajmal Azad, Samiran Bag, Feng Hao 0001, Khaled Salah 0001 |
Comput. Secur. | 4 |
| 2018 | Systems and methods for SPIT detection in VoIP: Survey and future directions
Muhammad Ajmal Azad, Ricardo Morla, Khaled Salah 0001 |
Comput. Secur. | 3 |
| 2018 | IoT security: Review, blockchain solutions, and open challenges
Minhaj Ahmad Khan, Khaled Salah 0001 |
Future Gener. Comput. Syst. | 2 |
| 2017 | Approaches to analyze cyber terrorist communities: Survey and challenges
Firas Saidi, Zouheir Trabelsi, Khaled Salah 0001, Henda Ben Ghézala |
Comput. Secur. | 3 |
| 2017 | Formal analysis of seamless application execution in mobile cloud computing
Ejaz Ahmed 0003, Anjum Naveed, Siti Hafizah Ab Hamid, Abdullah Gani, Khaled Salah 0001 |
J. Supercomput. | 5 |
| 2017 | Efficient and dynamic scaling of fog nodes for IoT devices
Said El Kafhali, Khaled Salah 0001 |
J. Supercomput. | 2 |
| 2017 | Analytical Model for Elastic Scaling of Cloud-Based FirewallsabstractThis paper shows how to properly achieve elasticity for network firewalls deployed in a cloud environment. Elasticity is the ability to adapt to workload changes by provisioning and de-provisioning resources in an autonomic manner, such that at each point in time the available resources match the current demand as closely as possible. Elasticity for cloud-based firewalls aims to satisfy an agreed-upon performance measure using only the minimal number of cloud firewall instances. Our contribution lies in determining the number of firewall instances that should be dynamically adjusted in accordance with the incoming traffic load and the targeted rules within the firewall rulebase. To do so, we develop an analytical model based on the principles of Markov chains and queueing theory. The model captures the behavior of a cloud-based firewall service comprising a load balancer and a variable number of virtual firewalls. From the analytical model, we then derive closed-form formulas to determine the minimal number of virtual firewalls required to meet the response time specified in the service level agreement. The model takes as input key system parameters including workload, processing capacity of load balancer and virtual machines, as well as the depth of the targeted firewall rules. We validate our model using discrete-event simulation, and real-world experiments conducted on Amazon Web Services cloud. We also provide numerical examples to show how our model can be used in practice by cloud performance/security engineers to achieve proper elasticity under fluctuating traffic load and variable depth of targeted firewall rules. Khaled Salah 0001, Prasad Calyam, Raouf Boutaba |
IEEE Trans. Netw. Serv. Manag. | 1 |
| 2016 | Lightweight Encryption for Smart HomeabstractSmart home is one of the most popular IoT (Internet of Things) applications, which connects a wide variety of objects and home appliances in a single logical network. Smart home applications have benefited from interactions and data transmissions among different devices over the integrated network with or without human interventions. However, like other technologies, smart home likely introduces new security vulnerabilities due to its dynamic and open nature of connectivity with heterogeneous features. Among such vulnerabilities, is the breach of confidentiality which needs to be addressed urgently as data exchanged between smart home devices can contain crucial information related to user's privacy and safety. However, some of the challenges in providing smart home system with confidentiality service are the flexibility of key management and efficiency of computation and communication. These challenges should be addressed carefully as many small and resource-constrained devices are usually involved in smart home systems. In this paper, we address these challenges by proposing a lightweight encryption scheme for smart homes. This scheme will provide users and smart objects with confidentiality service without incurring much overhead cost associated with computation and communication. Our proposed scheme also supports flexible public key management through adopting identity-based encryption, which does not require complex certificate handling. We provide a formal security analysis of our scheme and a performance simulation study. The simulation shows that our scheme provides favorable level of efficiency in terms of overhead cost associated with computation and communication. Sanaah Al Salami, Joonsang Baek, Khaled Salah 0001, Ernesto Damiani |
ARES | 3 |
| 2016 | Adaptive Cloud Resource Allocation scheme to minimize SLO response time violationabstractThis paper presents an Elastic Cloud Resource Allocation scheme that allocates minimal cloud VM resources that are needed to satisfy a given Service Level Objective (SLO) response time for cloud based elastic applications. More importantly, the algorithm attempts to mitigate any response time violation that could arise during the provisioning of cloud VM instances. Our proposed scheme utilizes queueing theory to estimate the number of VM instances that are need to satisfy the response time according to the current workload. The scheme also employs reactive provisioning technique to examine workload conditions and re-compute needed VM instances at a periodic interval (every 1 or two minutes) at CPU utilization of allocated VMs is used as threshold to adjust (to add or remove) the number of allocated VMs. The scheme is implemented and evaluated using real workload traces obtained from World Cup 98. The results show that our scheme is very effective in satisfying SLO response time while minimizing violations during spikes of workload or during provisioning of VMs. Fatima AlQayedi, Khaled Salah 0001, Mohamed Jamal Zemerly |
AICCSA | 2 |
| 2016 | Clustering VoIP caller for SPIT identificationabstractAbstract The number of unsolicited and advertisement telephony calls over traditional and Internet telephony has rapidly increased over recent few years. Every year, the telecommunication regulators, law enforcement agencies and telecommunication operators receive a very large number of complaints against these unsolicited, unwanted calls. These unwanted calls not only bring financial loss to the users of the telephony but also annoy them with unwanted ringing alerts. Therefore, it is important for the operators to block telephony spammers at the edge of the network so to gain trust of their customers. In this paper, we propose a novel spam detection system by incorporating different social network features for combating unwanted callers at the edge of the network. To this extent the reputation of each caller is computed by processing call detailed records of user using three social network features that are the frequency of the calls between caller and the callee, the duration between caller and the callee and the number of outgoing partners associated with the caller. Once the reputation of the caller is computed, the caller is then places in a spam and non‐spam clusters using unsupervised machine learning. The performance of the proposed approach is evaluated using a synthetic dataset generated by simulating the social behaviour of the spammers and the non‐spammers. The evaluation results reveal that the proposed approach is highly effective in blocking spammer with 2% false positive rate under a large number of spammers. Moreover, the proposed approach does not require any change in the underlying VoIP network architecture, and also does not introduce any additional signalling delay in a call set‐up phase. Copyright © 2016 John Wiley & Sons, Ltd. Muhammad Ajmal Azad, Ricardo Morla, Junaid Arshad, Khaled Salah 0001 |
Secur. Commun. Networks | 4 |
| 2016 | A High-Speed FPGA Implementation of an RSD-Based ECC ProcessorabstractIn this paper, an exportable application-specific instruction-set elliptic curve cryptography processor based on redundant signed digit representation is proposed. The processor employs extensive pipelining techniques for Karatsuba-Ofman method to achieve high throughput multiplication. Furthermore, an efficient modular adder without comparison and a high-throughput modular divider, which results in a short datapath for maximized frequency, are implemented. The processor supports the recommended NIST curve P256 and is based on an extended NIST reduction scheme. The proposed processor performs single-point multiplication employing points in affine coordinates in 2.26 ms and runs at a maximum frequency of 160 MHz in Xilinx Virtex 5 (XC5VLX110T) field-programmable gate array. Hamad Marzouqi, Mahmoud Al-Qutayri, Khaled Salah 0001, Dimitrios M. Schinianakis, Thanos Stouraitis |
IEEE Trans. Very Large Scale Integr. Syst. | 3 |
| 2015 | Experimental Proof: Data Remanence in Cloud VMsabstractData security is one of the main concerns organizations have when implementing cloud computing. In particular, data leakage issues in public clouds have been widely studied. Data remanence is considered a major threat, as residual data may include sensitive information like user names, passwords, encryption keys, URLS, etc. However, until now little if any experimental evidence has been put forward supporting the existence and extent of such threat in commercial cloud VMs. In this paper, we provide experimental proof of the remanence of data in VM memory and hard disk. Our experimental design is repeatable and suitable for inclusion in assurance testing and certification suites. Bushra AlBelooshi, Khaled Salah 0001, Thomas Martin 0002, Ernesto Damiani |
CLOUD | 2 |
| 2015 | Cloud-based Arabic reCAPTCHA service: Design and architectureabstractreCAPTCHA is a popular technique used for web security. It distinguishes humans from computer programs to protect websites from automated abuse by presenting a challenge to be solved. reCAPTCHA utilizes human computation power used in solving these challenges to aid in increasing the accuracy of digitizing printed manuscripts. Although reCAPTCHA has been developed in many languages, to date, there is no available reCAPTCHA for the Arabic language. There is an immense need for the development of an Arabic reCAPTCHA service to increase the accuracy that existing OCRs currently lacks in digitizing Arabic manuscripts, and to aid in securing millions of Arabic websites. In this paper, we present a cloud-based design and architecture for an Arabic reCAPTCHA service, and we detail and describe key design and system components which include word classification algorithms, database schema design, and technology selection. We also study the inadequacy of existing popular OCRs in recognizing correctly Arabic printed text. Hanin B. Abubaker, Khaled Salah 0001, Hassan Al-Muhairi, Ahmed Bentiba |
AICCSA | 2 |
| 2015 | Inspection and deconfliction of published virtual machine templates' remnant data for improved assurance in public CloudsabstractA common feature provided by any Cloud Service Provider (CSP) is their library of pre-built and ready to use operating system images that contribute to the overall flexibility, usability and cost savings advantages of Cloud Computing. The pedigree of CSP library images can vary, and some concerns have been raised about confidentiality of user historical data via publicly available images which have not been prepared in a manner consistent with recommended security best practices. In this paper we explore data remanence security concerns associated with virtual machine (VM) instances templates, a popular technique for configuring VMs for new users. We show how forensics tools can be used to check for data remanence and how to appropriately deconflict findings for improved assurance. Bushra AlBelooshi, Khaled Salah 0001, Thomas Martin 0002, Ernesto Damiani |
AICCSA | 2 |
| 2015 | Design of adiabatic TSV, SWCNT TSV, and Air-Gap Coaxial TSVabstractHigh performance three-dimensional (3D) through silicon via (TSV) interconnects are important for reliability, choice of the filler material is also a critical issue as thermal incompatibility, electromigration, and high resistivity are still a bottleneck. In this paper, single wall carbon nanotube (SW-CNT) bundles as a prospective filler material for TSV are investigated compared to conventional filler materials like Cu, W, and poly-silicon. It is found that SW-CNT bundles exhibit unique electrical, thermal, and mechanical characteristics that can be used to fabricate better TSV interconnects. Moreover, performance comparison between Air-Gap Based Coaxial TSV and conventional circular TSV are presented. The comparison shows that the air-gap TSVs reduce the overall parasitic capacitance and the overall energy loss compared to the conventional circular TSV or conventional coaxial TSV. In addition, TSV-based ADIABATIC logic based on the adiabatic switching principle is presented and analyzed. ADIABATIC logic is a design technique for minimizing the energy dissipation. Its major limitation is the requirement for passive components, which cannot be efficiently integrated into current generation ICs. TSV-based 3D heterogeneous integration may enable efficient integration of these passive elements, which were not practically feasible in the past due to technology limitations. Khaled Salah 0001, Yehea I. Ismail |
ISCAS | 1 |
| 2015 | Finite element emulation-based solver for electromagnetic computationsabstractElectromagnetic (EM) computations are the cornerstone in the design process of several real-world applications, such as radar systems, satellites, and cell-phones. Unfortunately, these computations are mainly based on numerical techniques that require solving millions of linear equations simultaneously. Software-based solvers do not scale well as the number of equations-to-solve increases. FPGA solver implementations were used to speed up the process. However, using emulation technology is more appealing as emulators overcome the FPGA memory and area constraints. In this paper, we present a scalable design to accelerate the finite element solver of an EM simulator on a hardware emulation platform. Experimental results show that our optimized solver achieves 101.05x speed-up over the same pure software implementation on MATLAB and 35.29x over the best iterative software solver from ALGLIB C++ package in case of solving 2,002,000 equations. M. Tarek Ibn Ziad, Mohamed Hossam, Mohamad A. Masoud, Mohamed Nagy, Hesham A. Adel, Yousra Al-Kabani, M. Watheq El-Kharashi, Khaled Salah 0001, Mohamed Abdel Salam |
ISCAS | 8 |
| 2015 | An analytical model to achieve elasticity for cloud-based firewallsabstractElasticity for cloud-based services and applications has been studied in the literature to some extent. However, the literature is lacking thorough study on elasticity for cloud-based firewalls. This paper proposes an architectural framework for an elastic virtual firewall service to be deployed at cloud datacenters. The paper presents an analytical model based on Markov chain and queueing theory that can be used to achieve elasticity for cloud-based firewalls. In particular, the model captures the behavior of a cloud-based firewall service comprising a load balancer and a variable number of virtual firewalls. From the analytical model, we then derive closed-form formulas to estimate the minimal number of virtual firewalls required to satisfy a given SLA response time. The model takes as input key system input parameters that include workload, processing capacity of load balancer and virtual machines, as well as firewall rulebase interrogation. Khaled Salah 0001 |
LCN | 1 |
| 2015 | Modelling and analysis of rule-based network security middleboxesabstractThis study presents an analytical model for rule‐based network security middleboxes as those of network firewalls, intrusion detection systems and email spam filters. In these systems, incoming packets carrying requests arrive at the middlebox and obtain queued for processing in multiple stages. The stages consist of first a main stage for packet processing and then subsequent stages of rulebase interrogation in which rules or conditions are checked sequentially until a match is triggered. The service at these stages is characterised to be mutually exclusive; that is, only one stage is active at any time. The authors derive useful formulas that can predict the middlebox performance, taking into account its incoming request rate, the queue size and the processing capacity of the middlebox, and thereby proper engineering capacity of the middlebox can be achieved. Khaled Salah 0001, Aslam Chaudary |
IET Inf. Secur. | 1 |
| 2014 | A novel dimensional analysis method for TSV modeling and analysis in three dimensional integrated circuitsabstractDimensional analysis is one of the most powerful modeling methods, where it is used to reduce the number of physical variables through combining two or more variables into a single dimension neutral one in order to simplify the process of describing a relationship among those variables. That makes curve fitting to obtain final equations simpler. In this paper, dimensional analysis is applied as a new design methodology for TSV modeling. By using the dimensional analysis and the curve-fitting technique, simple formulas of TSV parameters, such as resistance, capacitance, and inductance are obtained. The results are compared with previous work that model TSVs based on measurements, where excellent agreement is obtained. Khaled Salah 0001, Yehea I. Ismail |
ISCAS | 1 |
| 2014 | Accelerating snort NIDS using NetFPGA-based Bloom filterabstractIn recent years, network intrusion detection systems (NIDS) have faced a serious throughput challenge as a result of the rapid increase of network links to 1 and 10 Gbps rates. Consequently, this calls for NIDS to have wire-speed packet processing and real-time detection of malicious traffic. Snort is the most popular NIDS. Snort is an open source software-based NIDS and runs as a single threaded application. Snort processing and detection capabilities can be limited in networks with 1 and 10 Gbps network links. To overcome such a limitation, we present a design and implementation of two layer NIDS for accelerating Snort detection. The design combines hardware and software components whereby Snort operates as the second line of defense after hardware-assisted inspection of packet headers. In our design, Snort's frequently used rules are offloaded from Snort to a NetFPGA-based hardware layer. The NetFPGA implementation is based on Bloom filter to analyze and filter incoming packets with header fields matching those of frequently used rules. The second line of defense will dynamically offload the most frequently triggered rules to the NetFPGA and will only be executed if deep packet analysis is required for the incoming packet. The experimental results show a significant improvement in the CPU usage and an enormous reduction in packet loss when using Snort with NetFPGA filtering. Rami Al-Dalky, Khaled Salah 0001, Hadi Otrok, Mahmoud Al-Qutayri |
IWCMC | 2 |
| 2014 | Harnessing the cloud for teaching cybersecurityabstractCloud computing has become an attractive paradigm for many organizations in government, industry as well as academia. In academia, the cloud can offer instructors and students (whether local or at a distance) on-demand, dedicated, isolated, unlimited, and easily configurable machines. Such an approach has clear advantages over access to machines in a classic lab setting. In this paper, we show how cloud services and infrastructure could be harnessed to facilitate practical experience and training for cybersecurity. We used the popular Amazon Web Services (AWS) cloud; however, the use cases and approaches laid out in this paper are also applicable to other cloud providers. Khaled Salah 0001 |
SIGCSE | 1 |
| 2014 | VDC-Analyst: Design and verification of virtual desktop cloud resource allocations
Prasad Calyam, Sudharsan Rajagopalan, Sripriya Seetharam, Arunprasath Selvadhurai, Khaled Salah 0001, Rajiv Ramnath |
Comput. Networks | 5 |
| 2013 | A Queueing Model to Achieve Proper Elasticity for Cloud Cluster JobsabstractAchieving proper elasticity for cloud jobs is a challenging research problem and far from being solved. In this paper, we focus on how to achieve proper elasticity for highly parallelized jobs which run on cloud clusters. In particular, we present an analytical model based on finite queueing systems that can be used to determine at any given instance of time and under current workload conditions the minimal number of cloud resources needed to satisfy the SLO response time. We give numerical examples to demonstrate the applicability and usefulness of our model. In addition, we verify the correctness of our analytical model using simulation. Khaled Salah 0001 |
IEEE CLOUD | 1 |
| 2013 | Impact of CPU Utilization Thresholds and Scaling Size on Autoscaling Cloud ResourcesabstractCloud computing is currently one of the most hyped information technology fields and it has become one of the fastest growing segments of IT. A cloud introduces a resource-rich computing model with features such as flexibility, pay per use, elasticity, scalability, and others. In the context of cloud computing, auto scaling and elasticity are methods used to assure SLO (Service Level Objectives) for cloud services as well as the efficient usage of resources. There are many factors related to the auto scaling mechanism that might affect the performance of the cloud services. One of such important factors is the setting of CPU thresholds that control the triggering of the auto scaling policies, for the purpose of adding or terminating resources from the auto-scaling group. Another important factor is the scaling size, which is the number of instances that will be added every time such provisioning process takes place to add more resources to cope with workload spikes. In this paper, we simulate and study the impact of setting the upper CPU utilization threshold and the scaling size factors on the performance of the cloud services. Another contribution of this paper is on formulating and solving optimization problems for tuning these parameters based on input loads, considering both the cost and SLO response time. The study helps in deciding about the optimal setting that enables the use of the least number of cloud resources to satisfy QoS or SLO requirements. Fahd Al-Haidari, Mohammed H. Sqalli, Khaled Salah 0001 |
CloudCom (2) | 3 |
| 2013 | TSV-based on-chip inductive coupling communicationsabstractThis paper presents a novel wireless through silicon via (TSV) communication structure based on near-field inductive-coupling. The proposed system uses a spiral inductor built using TSV technology. The electrical performance obtained from EM-based S-parameter simulations for different number of turns and configurations are presented. The proposed wireless TSV shows good coupling coefficient. A closed form expression for the coupling coefficient is presented. This coupling expression is verified against EM simulations and showed good agreement. The proposed wireless TSV system provides small area (30 μm)2for typical design values. This proposed communication system is enabling NoC. Khaled Salah 0001, Alaa B. El-Rouby, Hani F. Ragai, Yehea I. Ismail |
ISCAS | 1 |
| 2013 | Analyzing the security of Windows 7 and Linux for cloud computing
Khaled Salah 0001, José M. Alcaraz Calero, Jorge Bernal Bernabé, Juan Manuel Marín Pérez, Sherali Zeadally |
Comput. Secur. | 1 |
| 2013 | Performance of IP-forwarding of Linux hosts with multiple network interfaces
Khaled Salah 0001, Mohamed Hamawi |
J. Netw. Comput. Appl. | 1 |
| 2013 | Classifying malicious activities in Honeynets using entropy and volume-based thresholdsabstractABSTRACT A Honeynet is a network designed by the Honeynet Project organization to gather information on security threats and attacks. Honeynets are being used by numerous institutions to proactively improve network security by identifying malicious and unauthorized activities in production and private networks. A Honeynet captures a substantial amount of network data and logs. The analysis of these datasets to identify malicious activities is a challenging task. The main aim of the work in this paper is to employ an anomaly detection technique to classify different types of malicious activities present in Honeynet. In particular, we use feature‐based and volume‐based schemes for Honeynet data classification. A detailed analysis of various traffic features is carried out, and the most appropriate ones for Honeynet traffic are selected. The classification of malicious activities is achieved by applying entropy‐based distributions and traffic volume distributions. Entropy‐based distributions are used for feature‐based parameters, whereas traffic volume distributions are used for volume‐based parameters. The behavior of various anomalies or malicious activities is classified using the selected features and their respective threshold values. Finally, we propose a mapping between the various anomalies and their associated behavior, which can be further used to identify similar anomalies in other Honeynet data sets. Copyright © 2012 John Wiley & Sons, Ltd. Mohammed H. Sqalli, Naeem Firdous Syed, Khaled Salah 0001, Marwan H. Abu-Amara |
Secur. Commun. Networks | 3 |
| 2012 | A closed form expression for TSV-based on-chip spiral inductorabstractThis paper presents a new architecture for on-chip spiral inductors, based on through silicon via (TSV) technology. A highly accurate closed form expression for the proposed TSV-based spiral inductor equivalent inductance is presented. This closed form is the first in literature. Moreover, this form is verified against a large number of EM simulations for different setups and shows excellent agreement with less than 5% error. According to the simulation results, the TSV-based spiral inductor exhibits better quality factor than a planar on-chip spiral inductor (120% improvement) and a 3D via-based spiral inductor (76% improvement) for identical inductance. Moreover, the self-resonance frequency of the proposed TSV-based 3D spiral inductor is 38% higher than the conventional 2D spiral inductor and 3% higher than the 3D via-based inductor. The proposed inductor occupies only 15% of the area of the conventional 2D planar spiral inductor and 60% of the area of 3D via-based spiral inductor for the same inductance and higher quality factor. This small area of the proposed inductor leads to significant reducing the cost of the radio frequency system on chip (RF-SoC). Khaled Salah 0001, Alaa B. El-Rouby, Hani F. Ragai, Yehea I. Ismail |
ISCAS | 1 |
| 2012 | Enhanced EDoS-Shield for Mitigating EDoS Attacks Originating from Spoofed IP AddressesabstractCloud computing has become one of the fastest growing segments in IT industry. A cloud introduces resource-rich computing platforms, where adopters are charged based on the usage of the cloud's resources, known as "pay-as-you-use" or utility computing. With this model, a conventional DDoS attack targeting servers and network resources is transformed in a cloud environment to a new attack that targets the cloud adopter's economic resource, namely Economic Denial of Sustainability (EDoS) attack. In this paper, we advocate a novel solution as an enhancement to prior work, namely EDoS-Shield, to mitigate the EDoS attacks originating from spoofed IP addresses. We design a discrete event simulation experiment to evaluate its performance and the results show that it is a promising solution to mitigate the EDoS attacks originating from spoofed IP addresses. The enhanced EDoS-Shield technique also outperforms the original EDoS-Shield in terms of performance and cost metrics. Fahd Al-Haidari, Mohammed H. Sqalli, Khaled Salah 0001 |
TrustCom | 3 |
| 2012 | Assessing Overhead Cost Associated with Encrypting Swap FileabstractPrivacy and security of information are two important concerns for most computer users. Passwords, keys, and encrypted information can be found unencrypted in the swap file which is used by the operating systems to support the implementation of virtual memory. Therefore, encrypting the swap file is essential to provide more security of users' private and confidential information. However, encrypting the swap file comes with an extra overhead cost. In this paper, we measure the overhead cost associated with encrypting the swap file. To effectively measure this cost, we developed our own benchmarks that will enforce heavy swapping with disk write and read operations. We measured the overhead cost for Windows 7 operating system. In our measurements, we considered a number of popular encryption algorithms which include AES, Blowfish, Twofish, and GOST. Our experimental measurements show that Windows 7 incurs considerable overhead penalties when encrypting the swap file. Bushra AlBelooshi, Khaled Salah 0001, T. Marin, Ahmed Bentiba |
TrustCom | 2 |
| 2012 | Mitigating starvation of Linux CPU-bound processes in the presence of network I/O
Khaled Salah 0001, A. Manea, Sherali Zeadally, José M. Alcaraz Calero |
J. Syst. Softw. | 1 |
| 2012 | Performance Modeling and Analysis of Network FirewallsabstractNetwork firewalls act as the first line of defense against unwanted and malicious traffic targeting Internet servers. Predicting the overall firewall performance is crucial to network security engineers and designers in assessing the effectiveness and resiliency of network firewalls against DDoS (Distributed Denial of Service) attacks as those commonly launched by today's Botnets. In this paper, we present an analytical queueing model based on the embedded Markov chain to study and analyze the performance of rule-based firewalls when subjected to normal traffic flows as well as DoS attack flows targeting different rule positions. We derive equations for key features and performance measures of engineering and design significance. These features and measures include throughput, packet loss, packet delay, and firewall's CPU utilization. In addition, we verify and validate our analytical model using simulation and real experimental measurements. Khaled Salah 0001, Khalid Elbadawi, Raouf Boutaba |
IEEE Trans. Netw. Serv. Manag. | 1 |
| 2011 | Equivalent lumped element models for various n-port Through Silicon Vias networksabstractThis paper proposes an equivalent lumped element model for various multi-TSV arrangements and introduces closed form expressions for the capacitive, resistive, and inductive coupling between those arrangements. The closed form expressions are in terms of physical dimensions and material properties and are driven based on the dimensional analysis method. The model's compactness and compatibility with SPICE simulators allows the electrical modeling of various TSV arrangements without the need for computationally expensive field-solvers and the fast investigation of a TSV impact on a 3-D circuit performance. The proposed model accuracy is tested versus a detailed electromagnetic simulation and showed less than 6% difference. Finally, the proposed model can be a possible solution to the industrial need for broadband electrical modeling of TSVs interconnections arising in 3-D integration. Also, our presented work provides valuable insight into creating guidelines for TSV macro-modeling. Khaled Salah 0001, Hani F. Ragai, Yehea I. Ismail, Alaa B. El-Rouby |
ASP-DAC | 1 |
| 2011 | Compact lumped element model for TSV in 3D-ICsabstractA wide-band lumped element model for a through silicon via (TSV) is proposed based on electromagnetic simulations. Closed form expressions for the TSV parasitics based on the dimensional analysis method are introduced. The proposed model enables direct extraction of the TSV resistance, self-inductance, oxide capacitance, and parasitic elements due to the finite substrate resistivity. The model's compactness and compatibility with SPICE simulations allows the fast investigation of a TSV impact on a 3-D circuit performance. The parameters' values of the proposed TSV model are fitted to the simulated S-parameters up to 10 GHz with an error less than 5%. It is shown that a TSV capacitance is highly dependent on the positions of ground contacts and has a value of tens of femto farads in a typical current technology. This value is much higher than a minimum device capacitance and requires special design methodologies such as cascaded buffers. Coupling between TSVs will be handled in another paper. Khaled Salah 0001, Alaa B. El-Rouby, Hani F. Ragai, Karim Amin, Yehea I. Ismail |
ISCAS | 1 |
| 2011 | Statistical analysis of H.264 video frame size distributionabstractH.264 video traffic is expected to account for the majority of multimedia traffic to be carried in future heterogeneous networks. Modelling video frame sizes is highly useful in simulation studies, mathematical analysis and generating synthetic video traces for the purpose of testing and compliance. In this study, a statistical analysis is performed to determine an appropriate distribution of video frame sizes generated by the popular H.264 video codec. The study makes use of a number of real video traces with the goal of evaluating and fitting their frame sizes with well-known distributions. In the literature, it is reported that the Gamma and Weibull distributions give the best fit for frame sizes in the most popular video codecs including H.264. Our statistical analysis shows that both Gamma and Weibull distributions are very close to each other in terms of goodness-of-fit results and they give the best fit. The authors also show that the Inverse Gaussian distribution is ranked second after Gamma and Weibull distributions. Finally, they show that the distributions of Pearson Type V and Lognormal are ranked third and fourth in terms of goodness-of-fit. Khaled Salah 0001, Fahd Al-Haidari, M. H. Omar, A. Chaudhry |
IET Commun. | 1 |
| 2011 | A potential low-rate DoS attack against network firewallsabstractAbstract In this paper we identify a potential Denial of Service (DoS) attack that targets the last‐matching rules of the security policy of a firewall. The last‐matching rules are those rules that are located at the bottom of the ruleset of a firewall's security policy, and would require the most processing time by the firewall. If these rules are discovered, an attacker can potentially launch an effective low‐rate DoS attack to trigger worst‐case or near worst‐case processing, thereby overwhelming the firewall and bringing it to its knees. In this paper, we present a probing technique to remotely discover the last‐matching rules of a firewall. We study experimentally the effectiveness of this probing technique taking into account important factors such as the firewall's motherboard architecture and load conditions at network links and hosts. In addition we examine the impact of launching a low‐rate DoS attack on a firewall's performance. The performance is studied in terms of the firewall's CPU utilization and throughput, packet loss, and latency. Copyright © 2009 John Wiley & Sons, Ltd. Khaled Salah 0001, Karim Sattar, Mohammed H. Sqalli, Ehab Al-Shaer |
Secur. Commun. Networks | 1 |
| 2010 | Queuing Analysis of Network FirewallsabstractNetwork firewalls act as the first line of defense against unwanted and malicious traffic targeting private networks connected to the Internet. Predicting the overall firewall performance, especially under attack, becomes crucial to network security engineers and designers in assessing how affective and tolerable a network firewall is, thereby be able to sustain the availability of network services. In this paper, we present an analytical queueing model based on the embedded Markov chain to study and analyze the performance of rule-based firewalls when subjected to normal and DoS attacks. We derive equations for key features and performance measures of engineering and design significance. In addition, we validate our analytical model against real experimental measurements. Khaled Salah 0001 |
GLOBECOM | 1 |
| 2010 | Modeling and analysis of PC-based software routers
Khaled Salah 0001 |
Comput. Commun. | 1 |
| 2010 | On the performance of IP-forwarding for multicore multiprocessor Linux hostsabstractToday's PC-based routers run mostly on Linux and have typical a mainboard with multiple processors and each processor has multiple cores. Such mainboard architecture is known as multicore multiprocessor (MCMP). Linux hosts with an MCMP mainboard can be configured for different network interface card (NIC) affinity modes and packet reception mechanisms. In this study, the authors study and compare the performance under these different modes and reception techniques for routing/forwarding IP packets. In particular, the authors consider two NIC affinity modes: (i) both NICs are affinitised (or bound) to separate cores of the same processor and (ii) both NICs are affinitised to separate cores on separate processors. For each affinity mode, the authors measure the performance for three packet reception mechanisms: NAPI (New API) with a default budget of 300, NAPI with a budget of two and disable–enable (DE) interrupt handling. The authors refer to these mechanisms as NAPI(300), NAPI(2) and DE. The performance is measured and compared in terms of various key performance metrics which include throughput, packet loss, delay, interrupt rates and CPU availability. The authors use the IXIA hardware-based traffic generator to generate traffic with fixed- and variable-size packets. At the Linux host, generated packets are forwarded/routed from one receiving network interface to a different transmitting network interface. Khaled Salah 0001, Mohamed Hamawi, Yasser Hassan |
IET Commun. | 1 |
| 2010 | Multi-Agent pattern recognition mechanism for detecting distributed denial of service attacksabstractDistributed denial of service (DDoS) attacks pose a significant threat to the smooth operations of today's online critical services and applications. Existing mechanisms to detect these attacks have had limited success. With the rapid growth in size and bandwidth of contemporary computer networks, an efficient and effective distributed solution is needed for detecting DDoS attacks. In this study, the authors propose a multiagent pattern recognition mechanism for detecting DDoS attacks, in adistributed fashion. Our proposed solution is very effective in detecting such attacks launched against victim servers residing inside a production network which has multiple gateways to the Internet. Using simulation, the authors show that our proposed mechanism achieves a high degree of accuracy in detecting DDoS attacks, with low false alarm rates, using a reasonable numbers of attack detection agents collaboratively operating in a typical production network. The authors also study the relationship of the number of agents participating in the attack detection process and the false alarm rate of the detection scheme. Zubair A. Baig, Khaled Salah 0001 |
IET Inf. Secur. | 2 |
| 2010 | Distributed security for multi-agent systems - review and applicationsabstractAs two major communication technologies, the internet and wireless, are maturing rapidly to dominate our civilised life, the authors urgently need to re-establish users’ confidence to harvest new potential applications of large-scale distributed systems. Service agents and distributed multi-agent systems (MASs) have shown the potential to help with this move as the lack of trust caused by heavily compromised security issues and concerns coupled with the out-of-date solutions are hindering the progress. The authors therefore seek new remedies to ensure that the continuity in developing new economies is maintained through building new solutions to address today's techno-economical problems. Following a scan of the literature the authors discuss the state-of-the-art progress followed by some observations and remarks for the researchers in the field. Here the authors recognise the need for new ‘distributed security’ solutions, as an overlay service, to rejuvenate and exploit the distributed artificial intelligence (AI) techniques for secure MAS as a natural solution to pave the way to enable a long awaited application paradigm of the near future. Habib F. Rashvand, Khaled Salah 0001, José M. Alcaraz Calero, Lein Harn |
IET Inf. Secur. | 2 |
| 2010 | Performance evaluation comparison of Snort NIDS under Linux and Windows Server
Khaled Salah 0001, A. Kahtani |
J. Netw. Comput. Appl. | 1 |
| 2009 | Resiliency of open-source firewalls against remote discovery of last-matching rulesabstractIn today's networks, firewalls act as the first line of defense against unwanted and malicious traffics. Firewalls themselves can become targets of DoS attacks, thus jeopardizing their primary operation to filter traffic. Typically, packets are checked against a firewall policy consisting (in many cases) of thousands of rules. Last-matching rules are located at the bottom of the ruleset and consume the most CPU processing power of firewalls. If these rules get discovered by an attacker, the attacker can effectively launch a low-rate DoS attack that can bring the firewall to its knees. In prior work [1], we proposed and evaluated a technique to remotely discover the last matching rules of the Linux Netfilter firewall. In this paper, we examine the effectiveness of such technique on the discovery of last-matching rules in two other popular open-source network firewalls, namely Linux IPSets and FreeBSD ipfw. Khaled Salah 0001, Karim Sattar, Zubair A. Baig, Mohammed H. Sqalli, Prasad Calyam |
SIN | 1 |
| 2009 | Implementation and experimental performance evaluation of a hybrid interrupt-handling scheme
Khaled Salah 0001, Abdulhakim Ali Qahtan |
Comput. Commun. | 1 |
| 2009 | Improving snort performance under linuxabstractNetwork intrusion detection systems (NIDS) have become vital components in securing today's computer networks. To be highly effective, NIDS must perform packet inspection of incoming traffic at or near wire speed. Failing to do so will allow malicious packets to sneak through the network undetected, and thus jeopardising network security. Snort is one of the most popular IDS and intrusion prevention system (IPS) applications. Snort is a publicly available open-source NIDS application that typically runs on Linux. In this study, the authors present and discuss the essential software components of Snort and its underlying Linux support architecture. The authors characterise Snort execution and present an analytical queuing model to give insight into understanding the kernel and Snort behaviour as well as to identify key-dominating factors that strongly influence and impact Snort performance. The authors demonstrate that the current default configurations of the packet reception mechanism of the Linux networking subsystem (a.k.a. NAPI) are not suitable for Snort performance and show that the performance of Snort can be improved significantly by tuning certain configuration parameters, specifically by having a small NAPI budge value of 2. The performance is measured in terms of throughput and packet loss. The authors also measure the packet loss encountered at the kernel level as well as the interrupt rate of incoming traffic. Performance was measured when subjecting a PC host running Snort to both normal and malicious traffic, and with different traffic load conditions. Khaled Salah 0001, A. Kahtani |
IET Commun. | 1 |
| 2009 | Comparative packet-forwarding measurement of three popular operating systems
Khaled Salah 0001, Mohamed Hamawi |
J. Netw. Comput. Appl. | 1 |
| 2008 | On the performance of a simple packet rate estimatorabstractThis paper proposes a simple packet rate estimator that can be very useful in predicting the rate of network traffic. The quality and performance of the estimator is evaluated and compared with three popular rate estimators that were originally designed for estimating bit rate. The proposed estimator is highly cost effective as its computation is not carried out upon the arrival of each incoming packet. In addition, the computation is simple and does not depend on the measurement of interarrival times of packets. We evaluate and compare the quality and performance in terms of agility, stability, accuracy and cost. The performance evaluation is conducted using discrete-event simulation that produces synthesized bursty traffic with empirical packet sizes. Khaled Salah 0001, F. Haidari |
AICCSA | 1 |
| 2008 | Assessing readiness of IP networks to support desktop videoconferencing using OPNET
Khaled Salah 0001, Prasad Calyam, Seyed M. Buhari |
J. Netw. Comput. Appl. | 1 |
| 2007 | Modeling and Analysis of Interrupt Disable-Enable SchemeabstractSystem performance of Gigabit network hosts can severely be degraded due to interrupt overhead caused by heavy incoming traffic. One of the most popular solutions to mitigate such overhead is interrupt disabling and then enabling. In this solution, interrupt overhead is significantly reduced by disabling interrupts and only re-enabling them after processing all queued packets. In this paper we investigate analytically the performance of the scheme of interrupt disabling and enabling and compare it with normal interruption and interrupt coalescing. The system performance is analyzed and compared in terms of throughput, latency, and CPU availability for user applications. Khaled Salah 0001, K. El-Badawi |
AINA | 1 |
| 2007 | Performance analysis and comparison of interrupt-handling schemes in gigabit networks
Khaled Salah 0001, K. El-Badawi, F. Haidari |
Comput. Commun. | 1 |
| 2006 | An Analytical Tool to Assess Readiness of Existing Networks for Deploying IP TelephonyabstractDeploying IP telephony or voice over IP (VoIP) is a major and challenging task. This paper describes an analytical approach and tool to assess the readiness of existing IP networks for the deployment of VoIP. The analytical approach utilizes queueing network analysis and investigates two key performance bounds for VoIP: delay and bandwidth. The analytical tool is GUI-based and has an engine that automates the analytical approach. The engine determines the number of VoIP calls that can be sustained by a given generic network while satisfying VoIP QoS requirements and leaving adequate capacity for future growth. As a case study, the paper illustrates how the analytical tool can assess the readiness to deploy VoIP for a typical network of a small enterprise. Khaled Salah 0001, M. Almashari |
ISCC | 1 |
| 2006 | On the deployment of VoIP in Ethernet networks: methodology and case study
Khaled Salah 0001 |
Comput. Commun. | 1 |
| 2006 | On the accuracy of two analytical models for evaluating the performance of Gigabit Ethernet hosts
Khaled Salah 0001 |
Inf. Sci. | 1 |
| 2005 | An Analytical Model for Evaluating Interrupt-Driven System Performance of Gigabit Ethernet Hosts with Finite BufferabstractA novel analytical model based on Markov processes is developed to study the impact of interrupt overhead on operating system performance of network hosts such as PC-based routers, servers, and end hosts 'when subjected to Gigabit network traffic. Under heavy network traffic, the system performance will be negatively affected due to interrupt overhead caused by incoming traffic. In particular, excessive latency and significant degradation in system throughput can be experienced. Also, user applications may livelock as the CPU power is mostly consumed by interrupt handling and protocol processing. In this paper, we present an analytical model to evaluate system performance. The system performance is studied in terms of throughput, latency, stability condition, CPU utilizations of interrupt handling and protocol processing, and CPU availability for user applications. The analysis can be instrumental in choosing system design parameters offline, therefore allows capacity planning and system diagnosis. Analytical results are compared with the ideal limited buffer queueing system without interrupt overhead. Khaled Salah 0001 |
ISCC | 1 |
| 2003 | Performance evaluation of interrupt-driven kernels in gigabit networksabstractThe paper presents models and analytical techniques for studying system behavior of an interrupt-driven kernel due to high packet arrival rate found in gigabit networks. An analytical study is presented describing the impact of high interrupt rate on system performance. The performance is studied in terms of throughput, latency, and system power. Equations are derived for system throughput, latency, power, and stability condition. Results from both reported experimental findings and simulations show that our analytical model is valid and gives a good approximation. To the best of the authors' knowledge, this work is the first of its kind to study analytically the impact of interrupts on system performance. Khaled Salah 0001, K. El-Badawi |
GLOBECOM | 1 |
| 2003 | Evaluating System Performance in Gigabit NetworksabstractWith the current wide deployment of Gigabit Ethernet technology in the backbone and workgroup switches, the network performance bottleneck has shifted for the first time in nearly a decade from the network to the end hosts and servers. This dramatic bandwidth increase calls for optimizations and good design considerations in many key components of the hosts and servers. These key components include network adaptor, operating system, protocol stack, memory, and processing power. More importantly the high bandwidth increase can negatively impact the OS performance due to the interrupt overhead caused by the incoming Gigabit traffic. This paper presents models and analytical techniques for studying such a negative impact. We first present an analytical model for the ideal system when interrupt overhead is ignored. We then present two models which describe the impact of high interrupt rate on system throughput. One model is for network adaptors not equipped with DMA engines, and the other model is for network adaptors equipped with DMA engines. In addition we study the system performance when using different system delivery options of packet data to user applications. Results from both simulations and reported experimental findings show that our analytical models are valid and give a good approximation. Khaled Salah 0001, K. El-Badawi |
LCN | 1 |
| 2003 | Internet Computing
Muhammad Sarfraz 0001, Khaled Salah 0001, Moataz A. Ahmed |
Inf. Sci. | 2 |
| 1999 | Periodic Route Optimization for Handed-Off Connections in Wireless ATM NetworksabstractIn wireless ATM networks, user connections need to be rerouted during handoff as mobile users move among base stations. The rerouting of connections must be done quickly with minimal disruption to traffic. In addition, the resulting routes must be optimal. A reasonable approach is to implement handoff in two phases. In the first phase connections are rapidly rerouted and in the second phase a periodic route optimization procedure is executed. The route optimization should impose minimal signaling and processing load on the ATM switches. In this paper, we propose and study a periodic execution of route optimization for a two-phase handoff scheme. We study two types of execution: non-adaptive and adaptive. For the adaptive optimization, we consider two adaptation schemes that are dependent on network conditions. A simulation model is developed to study system performance. The adaptive route optimization is shown to minimize signaling and processing load while maximizing utilization of reserved resources. Khaled Salah 0001, Elias Drakopoulos, Tzilla Elrad |
LCN | 1 |
| 1998 | A Two-Phase Inter-Switch Handoff Scheme for Wireless ATM NetworksabstractSupporting mobility in wireless ATM networks poses a number of technical issues. An important issue is the ability to reroute on-going virtual connections during handoff as mobile users move among base stations. We propose a two-phase inter-switch handoff scheme using permanent virtual paths reserved between adjacent mobility enhanced switches (MES). The virtual paths are used in the first phase to rapidly reroute user connections. In the second phase, a distributed optimization process is initiated to optimally reroute handoff connections. The proposed handoff scheme yields small handoff latency and optimal routes while decreasing system cost and complexity. The paper also describes wireless control and ATM signaling capabilities required for supporting this scheme. Specific ATM UNI/NNI protocol extensions are presented. Using analysis, we calculate and study the bandwidth requirement for the reserved virtual paths. We also study the second-phase optimization process overhead as well as the effect of other system design parameters. Khaled Salah 0001, Elias Drakopoulos |
ICCCN | 1 |