Benzekri Abdelmalek

dblp:05/1682 · also Abdelmalek Benzekri · DBLP profile ↗
← Back
31ranked-venue papers
0as first author
9since 2021 · last 2025
0000-0001-8236-8690ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 14 · 7 since 2021Computer networks · 4Software engineering, systems software and programming languages · 4Applied, interdisciplinary, general and emerging computing · 2Artificial intelligence and machine learning · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1
YearPublicationVenuePosition
2025 No Root, No Problem: Automating Linux Least Privilege and Securing Ansible Deployments
Eddie Billoir, Romain Laborde, Daniele Canavese, Yves Rütschlé, Ahmad Samer Wazan, Benzekri Abdelmalek
ESORICS (3)6
2025 GReAT-BeD: Graph Rewriting for Activity Tracking and (Malicious) Behaviour Detection
abstract
Living-off-the-Land is a cyberattack technique where cybercriminals exploit legitimate pre-installed tools within the victims’ system. These attacks are particularly challenging to detect due to their subtle and legitimate appearance, allowing threat actors to ”hide in plain sight.” This paper introduces a novel framework for identifying potentially malicious high-level behaviours using graph rewriting techniques. Our approach employs a three-layered methodology: the low-level layer captures system events and command-line data, the system behavior graph layer aggregates this data into meaningful behaviors, and the Indicators of Attack graph layer identifies high-level attack patterns through graph rewriting rules. We developed a general approach to generate a system behaviour graph from lower-layer as well as 27 rewriting rules to automatically transform this graph into Indicators of Attack representations, capturing complex behaviours and information flows. We implemented the transformation rules in the Attributed Graph Grammar System program and applied them to two use cases to demonstrate the effectiveness of our method in identifying potentially malicious behaviours across various attack scenarios.
Antonin Verdier, Romain Laborde, Benzekri Abdelmalek
KES3
2025 Game of Zones: An Automated Intent-Based Network Micro-segmentation Methodology
abstract
This article presents a novel approach that automates part of the work of network security architects, enabling them to design fine-grained secure network architectures. We have developed a methodology that, starting from high-level security requirements, called intents, and an initial unprotected network architecture, computes the optimal security zones and integrates security functions to protect both inter- and intra-zone communications. We implemented this methodology as a proof-of-concept framework, leveraging the flexibility and expressivity of Answer Set Programming, a form of declarative logic programming.
Daniele Canavese, Romain Laborde, Abir Laraba, Afonso Ferreira, Benzekri Abdelmalek
NOMS5
2024 Enhancing Secure Deployment with Ansible: A Focus on Least Privilege and Automation for Linux
abstract
As organisations increasingly adopt Infrastructure as Code (IaC), ensuring secure deployment practices becomes paramount. Ansible is a well-known open-source and modular tool for automating IT management tasks. However, Ansible is subject to supply-chain attacks that can compromise all managed hosts. This article presents a semi-automated process that improves Ansible-based deployments to have fine-grained control on administrative privileges granted to Ansible tasks. We describe the integration of the RootAsRole framework to Ansible. Finally, we analyse the limit of the current implementation.
Eddie Billoir, Romain Laborde, Ahmad Samer Wazan, Yves Rütschlé, Benzekri Abdelmalek
ARES5
2024 Article 45 of the eIDAS Directive Unveils the need to implement the X.509 4-cornered trust model for the WebPKI
abstract
Article 45 of the new eIDAS Directive (eIDAS 2.0) has caused significant debate on the Internet as it gives European governments the power to make EU-certificated web certificates accepted without the approval of web browsers/OS, which are considered to be the current gatekeepers of the WebPKI ecosystem. This paper goes beyond the current debate between the WebPKI gatekeepers and the European Commission (EC) about the implications of Article 45. It shows how both approaches do not provide full protection to web users. We propose a better approach that Europe can follow to regulate web X.509 certificates: Rather than regulating the issuance of web X.509 certificates, the EC can play the role of a validator that recommends the acceptance of certificates at the web scale.
Ahmad Samer Wazan, Romain Laborde, Benzekri Abdelmalek, Muhammad Imran Taj 0001
ARES3
2024 Identity Management in Cross-Cloud Environments: Towards Self-sovereign Identities Using Current Solutions
Mohamed Amine Ben Haj Salah, Romain Laborde, Benzekri Abdelmalek, Mohamed Ali Kandi, Afonso Ferreira
CRiSIS3
2023 Towards Reliable Collaborative Data Processing Ecosystems: Survey on Data Quality Criteria
abstract
Data quality plays a crucial role in the data governance of organizations, as it is essential to ensure that data are fit for the purpose for which they are intended, whether for operational activities, decision-making processes, or strategic planning. As data silos begin to be integrated to form data spaces, guaranteeing data quality becomes a necessity to achieve a reliable collaborative ecosystem. Nevertheless, the concept of data quality remains ambiguous, with various definitions and interpretations offered in the literature, despite its importance. This lack of consensus has led to the need for a thorough review of the different data quality criteria used in scientific work. Therefore, this paper serves as a systematic survey aimed at exploring and consolidating diverse perspectives on data quality. By thoroughly analyzing existing literature, this study compiles a comprehensive set of 30 agreed-upon data quality criteria, with their respective names and definitions. These criteria act as a valuable resource for organizations seeking to establish effective data quality monitoring practices. Then, we expose challenges raised by collaborative data processing and highlight possible research directions where data quality plays a major role.
Louis Fortune Sahi, Romain Laborde, Mohamed Ali Kandi, Michelle Sibilla, Giorgia Macilotti, Benzekri Abdelmalek, Afonso Ferreira
TrustCom6
2022 On the Validation of Web X.509 Certificates by TLS Interception Products
abstract
The Transport Layer Security (TLS) protocol aims to provide confidentiality and integrity of data. It is based on X.509 Certificates. Our previous research showed that popular Web Browsers exhibit non-standardized behaviour with respect to the certificate validation process[1]. This article extends that work by examining their handling of OCSP Stapling. We also examine several popular HTTPS interception products, including proxies and anti-virus tools, regarding their certificate validation processes. We analyse and compare their behaviour to that described in the relative standards.
Ahmad Samer Wazan, Romain Laborde, David W. Chadwick, Rémi Venant, Benzekri Abdelmalek, Eddie Billoir, Omar Alfandi
IEEE Trans. Dependable Secur. Comput.5
2021 RootAsRole: Towards a Secure Alternative to sudo/su Commands for Home Users and SME Administrators
Ahmad Samer Wazan, David W. Chadwick, Rémi Venant, Romain Laborde, Benzekri Abdelmalek
SEC5
2020 Know Your Customer: Opening a new bank account online using UAAF
abstract
Universal Authentication and Authorization Framework is a user-centric, privacy by design and decentralized system that allows anyone to easily benefit from a reliable digital identity made of multi-purpose and multi-origin attributes. In this article, we present the implementation of this framework in the context of online banking. We demonstrate how it can facilitate enforcing Know Your Customer when opening a new bank account online by allowing users to combine verifiable identity attributes issued by different organizations.
Romain Laborde, Arnaud Oglaza, Ahmad Samer Wazan, François Barrère, Benzekri Abdelmalek, David W. Chadwick, Rémi Venant
CCNC5
2020 A User-Centric Identity Management Framework based on the W3C Verifiable Credentials and the FIDO Universal Authentication Framework
abstract
We present a user-centric and decentralized digital identity system that allows anyone to easily benefit from an enriched digital identity made of multi-purpose and multi-origin attributes. It increases usability by the elimination of user passwords. It also makes this digital identity highly trustworthy both for the user (in terms of privacy and sovereignty) and the service provider who requires highly certified information about the user being enrolled to and/or authenticated on its services. We built our system based on the Universal Authentication Framework specified by the FIDO Alliance and the data model proposed by the W3C Verifiable Credentials WG. The whole system has been implemented in a banking scenario.
Romain Laborde, Arnaud Oglaza, Ahmad Samer Wazan, François Barrère, Benzekri Abdelmalek, David W. Chadwick, Rémi Venant
CCNC5
2017 Which Security Requirements Engineering Methodology Should I Choose?: Towards a Requirements Engineering-based Evaluation Approach
abstract
Since many decades, requirements engineering domain has seen significant enhancements towards adapting the security and risk analysis concepts. In this regard, there exist numerous security requirements engineering methodologies that support elicitation and evaluation of the security requirements. However, selecting a security requirements engineering methodology (SRE) for a given context of use often depends on a set of ad hoc criteria. In this paper, we propose a methodological evaluation methodology that helps in identifying the characteristics of a good SRE methodology.
Sravani Teja Bulusu, Romain Laborde, Ahmad Samer Wazan, François Barrère, Benzekri Abdelmalek
ARES5
2017 TLS Connection Validation by Web Browsers: Why do Web Browsers Still Not Agree?
abstract
The TLS protocol is the primary technology used for securing web transactions. It is based on X.509 certificates that are used for binding the identity of web servers' owners to their public keys. Web browsers perform the validation of X.509 certificates on behalf of Web users. Our previous research in 2009 showed that the validation process of Web browsers is inconsistent and flawed. We showed how this situation might have a negative impact on Web users. From 2009 until now, many new X.509 related standards have been created or updated. In this paper, we performed an increased set of experiments over our 2009 study in order to highlight the improvements and/or regressions in Web browsers' behaviours.
Ahmad Samer Wazan, Romain Laborde, David W. Chadwick, François Barrère, Benzekri Abdelmalek
COMPSAC (1)5
2017 A new approach for managing Android permissions: learning users' preferences
abstract
Today, permissions management solutions on mobile devices employ Identity Based Access Control (IBAC) models. If this approach was suitable when people had only a few games (like Snake or Tetris) installed on their mobile phones, the current situation is different. A survey from Google in 2013 showed that, on average, french users have installed 32 applications on their Android smartphones. As a result, these users must manage hundreds of permissions to protect their privacy. Scalability of IBAC is a well-known issue and many more advanced access control models have introduced abstractions to cope with this problem. However, such models are more complex to handle by non-technical users. Thus, we present a permission management system for Android devices that (1) learns users’ privacy preferences with a novel learning algorithm, (2) proposes them abstract authorization rules, and (3) provides advanced features to manage these high-level rules. Our learning algorithm is compared to two other well-known approaches to show its efficiency. Finally, we prove this whole approach is more efficient than current permission management system by comparing it to Privacy Guard Manager.
Arnaud Oglaza, Romain Laborde, Pascale Zaraté, Benzekri Abdelmalek, François Barrère
EURASIP J. Inf. Secur.4
2017 Trust Management for Public Key Infrastructures: Implementing the X.509 Trust Broker
abstract
A Public Key Infrastructure (PKI) is considered one of the most important techniques used to propagate trust in authentication over the Internet. This technology is based on a trust model defined by the original X.509 (1988) standard and is composed of three entities: the certification authority (CA), the certificate holder (or subject), and the Relying Party (RP). The CA plays the role of a trusted third party between the certificate holder and the RP. In many use cases, this trust model has worked successfully. However, we argue that the application of this model on the Internet implies that web users need to depend on almost anyone in the world in order to use PKI technology. Thus, we believe that the current TLS system is not fit for purpose and must be revisited as a whole. In response, the latest draft edition of X.509 has proposed a new trust model by adding new entity called the Trust Broker (TB). In this paper, we present an implementation approach that a Trust Broker could follow in order to give RPs trust information about a CA by assessing the quality of its issued certificates. This is related to the quality of the CA’s policies and procedures and its commitment to them. Finally, we present our Trust Broker implementation that demonstrates how RPs can make informed decisions about certificate holders in the context of the global web, without requiring large processing resources themselves.
Ahmad Samer Wazan, Romain Laborde, David W. Chadwick, François Barrère, Benzekri Abdelmalek, Mustafa Kaiiali, Adib Habbal
Secur. Commun. Networks5
2016 A Recommender-Based System for Assisting Non-technical Users in Managing Android Permissions
abstract
Today, permissions management solutions on mobile devices employ Identity Based Access Control (IBAC) models. If this approach was suitable when people had only a few games (like Snake or Tetris) installed on their mobile phones, the current situation is different. A survey from Google in 2013 showed that, on average, US users have installed 33 applications on their Android smartphones. As a result, these users must manage hundreds of permissions to protect their privacy. Scalability of IBAC is a well-known issue and many more advanced access control models have introduced abstractions to cope with this problem. However, such models are more complex to handle by non-technical users. Thus, we present a permission management system for Android devices that 1) learns users' privacy preferences, 2) proposes them abstract authorization rules, and 3) provides advanced features to manage these high-level rules. We prove this approach is more efficient than current permission management system by comparing it to Privacy Guard Manager.
Arnaud Oglaza, Romain Laborde, Benzekri Abdelmalek, François Barrère
ARES3
2016 Difficulties to enforce your privacy preferences on Android? Kapuer will help you
abstract
Smartphones and mobile computing have changed our world and we are now over connected. Millions of applications are available to help us in every way possible. However applications can collect data from users for different purposes. Many private data are used to profile users. How to control privacy in this environment? We propose a system called Kapuer that improves the management of applications permissions on Android by combining access control and decision support. We present in this article the Android implementation of Kapuer.
Arnaud Oglaza, Romain Laborde, Pascale Zaraté, Benzekri Abdelmalek, François Barrère
CCNC4
2016 Towards the Weaving of the Characteristics of Good Security Requirements
Sravani Teja Bulusu, Romain Laborde, Ahmad Samer Wazan, François Barrère, Benzekri Abdelmalek
CRiSIS5
2016 How Can I Trust an X.509 Certificate? An Analysis of the Existing Trust Approaches
abstract
A Public Key Infrastructure (PKI) is based on a trust model defined by the original X.509 standard and is composed of three entities: the Certification Authority, the certificate holder (subject) and the Relying Party. The CA plays the role of a trusted third party between the subject and the RP. A trust evaluation problem is raised when an RP receives a certificate from an unknown subject that is signed by an unknown CA. Different approaches have been proposed to handle this trust problem. We argue that these approaches work only in the closed deployment model where RPs are also subjects, but cannot work in the open deployment model where they are not. Our objective is to identify the deficiencies in the existing trust approaches that try to help RPs to make trust decisions about certificates in the Internet, and to introduce the new X.509 approach based on a trust broker.
Ahmad Samer Wazan, Romain Laborde, David W. Chadwick, François Barrère, Benzekri Abdelmalek
LCN5
2015 G-Cloud on Openstack: Adressing access control and regulation requirements
abstract
It is well known that e-Government applications bring several benefits to citizens in terms of efficiency, accessibility and transparency. Today, most of governments tend to propose cloud computing based e-services to their citizens. A key component in these services is the access control management issue. In this paper, we present our research works for building an access control system for the Djiboutian e-Government project that is built using Openstack framework. Specifically, we demonstrate the limitation of the integrated access control system in Openstack for the Djiboutian e-Government access control requirements and for the compliance to the related regulation. Thus, we propose to extend the existing access control system of Openstack by integrating the features of the XACML V3 to the Openstack framework.
Ibrahim Yonis Omar, Romain Laborde, Ahmad Samer Wazan, François Barrère, Benzekri Abdelmalek
ISNCC5
2012 The X.509 trust model needs a technical and legal expert
abstract
The X.509 trust model is based on three entities: the certification authority (CA), the certificate holder and the relying party (RP). The CA plays the role of a trusted third party between the certificate holder and the RP. It guarantees to the RP the correctness of the certificate information. This trust model is based on hypothesis that RPs have a predefined trust relation with a CA and that the trust level in CA can be determined by reading and analyzing a set of technical and legal documents. The X.509 trust model is so complex to RPs because an RP must realize this task for each and every CA chosen by the certificate holders. We introduce a new role of technical and legal expert into the X.509 trust model to help the RP make this task.
Ahmad Samer Wazan, Romain Laborde, François Barrère, Benzekri Abdelmalek
ICC4
2011 A formal model of trust for calculating the quality of X.509 certificate
abstract
Abstract The growing number of Public Key Infrastructure (PKI) and the increasing number of situations where partners of a transaction may carry certificates signed by different certification authority (CA) points out the problematic of trust between the different CAs. Several trust models, like the hierarchy model, cross‐certification model, and bridge CA model were proposed in order to establish and extend the domain of trust of relying parties (RP). However, each model has disadvantages and especially the scalability in large open networks like Internet. In this paper, we provide users with quantitative information of the confidence a relying party can have about a certificate. We call this information quality of certificate (QoCER). QoCER depends on two parameters which are the quality of procedures announced in the certificate policy (CP) and the quality of CA (QoCA) that represents the evaluation of the CA commitment to its policy. QoCA is calculated based on the recommendation of different actors (audit agency, RP, etc.). QoCER is balanced by another information that represents the confidence on QoCA calculation. We present a formal model of trust to calculate these values. Copyright © 2010 John Wiley & Sons, Ltd.
Ahmad Samer Wazan, Romain Laborde, François Barrère, Benzekri Abdelmalek
Secur. Commun. Networks4
2010 A deployment framework for self-contained policies
abstract
One of the key motivations of policy-based management is flexibility and adaptability to existing infrastructure and change management. In the context of security, modern policy languages such as XACML are extensible and support natively the expression of new information and manipulation operations. However, policy engines, which evaluate users' requests according to policies, may not support this new policy information. As a consequence, policy writers have to verify whether the target policy engine can execute his/her policy or not when (s)he writes it. In this article, we present the concept of self-contained policy to solve this deployment issue. A self-contained policy includes all the necessary information required by a policy engine to execute a policy. We propose a service component based architecture to support self-contained policies. An OSGi-Based implementation validates the approach.
Marwan Cheaito, Romain Laborde, François Barrère, Benzekri Abdelmalek
CNSM4
2009 Which Web Browsers Process SSL Certificates in a Standardized Way?
Ahmad Samer Wazan, Romain Laborde, David W. Chadwick, François Barrère, Benzekri Abdelmalek
SEC5
2006 Automated Creation of Inter-organizational Grid Virtual Organizations
abstract
the grid has emerged as a platform that enables inter-organizational internet-based collaboration space recognized as Virtual Organization (VO). Building a VO, in an open environment as the Internet, necessitates tracing its boundaries. As a way to realize that, access control policy may be employed to authorize, control and forbid activities in order to achieve the different partners' mutual benefits. Our goal being the dynamic creation of Virtual Organizations, is then associated with the automated generation of access control policy in a multiple access stakeholders' environment. We proposed in recent works a Virtual Organization model specified using OrBAC (Organization Based Access Control model). In this paper we propose a methodology to dynamically build VOs based on our model. The different methodology steps are explained along with the associated related works which serve for implementing our model.
Bassem Nasser, François Barrère, Benzekri Abdelmalek, Romain Laborde, Michel Kamel
NOMS3
2005 Dynamic Creation of Inter-Organizational Grid Virtual Organizations
abstract
The grid has emerged as a platform that enables inter-organizational Internet-based collaborations in a sharing space called virtual organization (VO). Building a VO, in an open environment as the Internet, necessitates an access control policy to authorize, control and forbid activities in order to achieve the different partners' mutual benefits. Our goal being the dynamic VO creation is then associated with the automated generation of access control policy in a multiple access stakeholders' environment. We proposed in recent works OrBAC-based (organization based access control model) Virtual Organization model which we believe to be the corner stone in the VO creation automated process. In this paper we propose a methodology to dynamically build OrBAC-based VO and we show how our model is integrated in the creation process. The different methodology steps are explained along with the associated related works which serve for implementing our model. Finally we show an example of the model in work.
Bassem Nasser, Romain Laborde, Benzekri Abdelmalek, François Barrère, Michel Kamel
e-Science3
2005 A formal framework (Expression + Analysis) for network security
abstract
Security mechanisms enforcement consists in configuring devices with the aim that they cooperate and guarantee the defined security goals. In the network context, this task is complex due to the number, the nature, and the interdependences of the devices to consider. We propose in this article a formal framework, which models the network security management information in order to verify the appliance of security goals. The framework is divided into two components. First, a formal language allows its user to graphically specify the abstract network security tactics while considering network topologies. Second, an associated evaluation method guarantees the consistency and the correctness of the tactics according to the security goals
Romain Laborde, François Barrère, Benzekri Abdelmalek
NCA3
2004 Security issues of m-commerce over hotspot networks
abstract
The development of WLANs in general and of Wi-Fi (802.11b standard) in particular, emerged these two last years as a technology support of public access to the Internet. We think that the potential role of Wi-Fi hotspots, those wireless networks deployed in public environments such as airports, hotels and conference centres, is enormous and will give a new breath to the mobile commerce market. However, the m-commerce still faces challenges, due to the immaturity of these new technologies and where security represents one of its major issues.
Alia Fourati, Hella Kaffel Ben Ayed, Farouk Kamoun, Benzekri Abdelmalek
WCNC4
2002 A SET Based Approach to Secure the Payment in Mobile Commerce
abstract
In this paper we propose an approach, combining the SET protocol with the TLS/WTLS protocols in order to enforce the security services over WAP 1.X for payment in the m-commerce. We propose to implement the additional services of the SET protocol as the confidentiality of the payment information between the buyer and the payment gateway and the data integrity. However, we use WTLS certificates instead of the SET certificates. This allows to avoid the SET certification heaviness. Moreover, this approach eliminates the "WAP gap" since the payment information would not be decrypted within the WAP gateway nor within the seller side.
Alia Fourati, Hella Kaffel Ben Ayed, Farouk Kamoun, Benzekri Abdelmalek
LCN4
1996 A Z-based Approach to Specifying and Analyzing Complex Systems
abstract
The difficult task of developing safety-critical systems requires the use of methods and tools that allow developers to manage inherent complexity and to meticulously specify, implement, and analyze desired behavior. Development environments based on formal specification techniques supported by CASE tools can facilitate quality development of such systems. We present our proposed environment for the development of high-assurance systems. The environment provides CASE support for developing and analyzing graphical and formal representations of system structure and behavior. We illustrate the use of the environment with a traffic control system.
Jean-Michel Bruel, Robert B. France, Benzekri Abdelmalek
ICECCS3
1993 Estimation Process of Performance Constraints during the design of Real-Time & Embedded Systems
Ramón Puigjaner, Benzekri Abdelmalek, Sandra Ayache
CAiSE2