EDBT 2026 Demo / reviewers in the wild / expert
Martine Bellaïche
dblp:06/7909
· DBLP profile ↗
14ranked-venue papers
3as first author
4since 2021 · last 2026
0000-0001-9530-7643ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 6 · 2 first-author · 2 since 2021Computer networks · 4 · 1 first-author · 1 since 2021Systems, architecture and hardware · 3
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Think Fast: Real-Time IoT Intrusion Reasoning Using IDS and LLMs at the Edge Gateway
Saeid Jamshidi, Omar Abdel Wahab 0001, Rolando Herrero, Foutse Khomh, Martine Bellaïche, Samira Keivanpour, Negar Shahabi, Amin Nikanjam, Kawser Wazed Nafi |
IEEE Internet Things J. | 5 |
| 2024 | A Game-theoretic Approach for DDoS Attack Mitigation in IIoT Deterministic NetworkingabstractDeterministic networking (DetNet) is a promising technology that will help achieve the objectives of Industrial Internet of Things (IIoT) by meeting the latency constraints of various applications including the control of remote robots and autonomous vehicles. Nonetheless, adversaries may see in this paradigm a new opportunity for denial of service (DoS) attacks. IIoT control systems are often vulnerable to attacks and can be infected to create botnets capable of launching distributed DoS attacks that target the latency of deterministic IIoT networks, namely delay attacks. On the other hand, the allocation of limited intrusion detection resources within DetNet infrastructures remains a challenge. Conventional attack detection and mitigation solutions do not take the attack strategies into consideration, neither the DetNet network requirements. In this paper, we leverage game theory to design a defense strategy that can be used by the IIoT infrastructure to optimally allocate its security resources. We define the game utility based on system latency, which is crucial for a DetNet network. The proposed approach will enable the DetNet network to mitigate the impact of attacks and increase its resilience. Our results show that the attack impact is reduced by 54% compared to conventional strategies that do not account for the DetNet latency requirements. Thierry M. Ndimis Ndimis Toko, Martine Bellaïche, Talal Halabi |
NOMS | 2 |
| 2023 | A cascaded federated deep learning based framework for detecting wormhole attacks in IoT networks
Rubayyi Alghamdi, Martine Bellaïche |
Comput. Secur. | 2 |
| 2023 | An ensemble deep learning based IDS for IoT using Lambda architectureabstractAbstract The Internet of Things (IoT) has revolutionized our world today by providing greater levels of accessibility, connectivity and ease to our everyday lives. It enables massive amounts of data to be traversed across multiple heterogeneous devices that are all interconnected. This phenomenon makes IoT networks vulnerable to various network attacks and intrusions. Building an Intrusion Detection System (IDS) for IoT networks is challenging as they enable a massive amount of data to be aggregated, which is difficult to handle and analyze in real time mainly because of the heterogeneous nature of IoT devices. This inefficient, traditional IDS approach accentuates the need to develop advanced IDS techniques by employing Machine or Deep Learning. This paper presents a deep ensemble-based IDS using Lambda architecture by following a multi-pronged classification approach. Binary classification uses Long Short Term Memory (LSTM) to differentiate between malicious and benign traffic, while the multi-class classifier uses an ensemble of LSTM, Convolutional Neural Network and Artificial Neural Network classifiers to detect the type of attacks. The model training is performed in the batch layer, while real-time evaluation is carried out through model inferences in the speed layer of the Lambda architecture. The proposed approach gives high accuracy of over 99.93% and saves useful processing time due to the multi-pronged classification strategy and using the lambda architecture. Rubayyi Alghamdi, Martine Bellaïche |
Cybersecur. | 2 |
| 2020 | Towards Security-Based Formation of Cloud Federations: A Game Theoretical ApproachabstractCloud federations allow Cloud Service Providers (CSPs) to deliver more efficient service performance by interconnecting their Cloud environments and sharing their resources. However, the security of the federated service could be compromised if the resources are shared with relatively insecure CSPs, and violations of the Security Service Level Agreement (Security-SLA) might occur. In this paper, we propose a Cloud federation formation model that considers the security level of CSPs. We start by applying the Goal-Question-Metric (GQM) method to develop a set of parameters that quantitatively describes the Security-SLA in the Cloud, and use it to evaluate the security levels of the CSPs and formed federations with respect to a defined Security-SLA baseline, while taking into account CSPs' customers' security satisfaction. Then, we model the Cloud federation formation process as a hedonic coalitional game with a preference relation that is based on the security level and reputation of CSPs. We propose a federation formation algorithm that enables CSPs to join a federation while minimizing their loss in security, and refrain from forming relatively insecure federations. Experimental results show that our model helps maintaining higher levels of security in the formed federations and reducing the rate and severity of Security-SLA violations. Talal Halabi, Martine Bellaïche |
IEEE Trans. Cloud Comput. | 2 |
| 2019 | A deep learning approach for proactive multi-cloud cooperative intrusion detection system
Adel Abusitta 0001, Martine Bellaïche, Michel R. Dagenais, Talal Halabi |
Future Gener. Comput. Syst. | 2 |
| 2019 | Live Placement of Interdependent Virtual Machines to Optimize Cloud Service Profits and Penalties on SLAsabstractThis paper aims to optimize cloud services' net profits and penalties with live placement of interdependent virtual machines (VMs). This optimization is a complex task as it is difficult to achieve a successful compromise between penalties and net profits on service level contracts. This paper studies this optimization problem to minimize services' penalties and maximizing net profits while achieving live migrations of interdependent VMs. This VM's live placement optimization problem is a NP-hard problem with exponential running time. A mathematical model was designed and approximations were conducted with an efficient PCH/PCH' heuristic. This Mixed Integer Non-Linear programming (MNLP) formulation and heuristic for cloud services was tested where the overall services' penalty needs to be minimized, overall net profits have to be maximized, and where efficient live migrations of VMs is a concern. Simulation results show how cloud providers may live place VMs. Finally, our results show that a PCH/PCH' heuristic: (i) finds better solutions than the existing machines' configuration of Google traces; (ii) is suitable for large-sized instances of cloud services; (iii) performs better than FF, FFD, and CPLEX in terms of overall penalties and net profits; and (iv) runs in less than six minutes over the last day's data. Salah-Eddine Benbrahim, Alejandro Quintero, Martine Bellaïche |
IEEE Trans. Cloud Comput. | 3 |
| 2018 | On trustworthy federated clouds: A coalitional game approach
Adel Abusitta 0001, Martine Bellaïche, Michel R. Dagenais |
Comput. Networks | 2 |
| 2018 | A broker-based framework for standardization and management of Cloud Security-SLAs
Talal Halabi, Martine Bellaïche |
Comput. Secur. | 2 |
| 2017 | Towards quantification and evaluation of security of Cloud Service Providers
Talal Halabi, Martine Bellaïche |
J. Inf. Secur. Appl. | 2 |
| 2014 | VANET security surveys
Richard Gilles Engoulou, Martine Bellaïche, Samuel Pierre, Alejandro Quintero |
Comput. Commun. | 2 |
| 2012 | SYN flooding attack detection by TCP handshake anomaliesabstractABSTRACT We present an original approach to identify synchronize (SYN) flooding attacks from the victim's side, on the basis of a classification of the different forms that TCP handshakes can take during a connection set‐up between a client and a server (e.g. for Web traffic). We first identify the unusual handshake sequences that result from an attack and show how such observations can be used for SYN flooding attack detection. We then introduce a data structure to monitor, in real time, the state of the TCP handshake and study its performance. In addition, we explain the management of the data structure for operations such as initialization, adding and removing flows. Finally, we analyse the effectiveness of our TCP handshake monitoring to identify the presence of SYN flooding attacks by applying it to real traffic traces. To allow quick protection and help guarantee a proper defence, the detection is done in real time. Our detection system uses a non‐parametric cumulative sum algorithm (CUSUM), which has the benefit of not requiring a detailed model of the normal and attack traffic while achieving excellent detection levels. Copyright © 2011 John Wiley & Sons, Ltd. Martine Bellaïche, Jean-Charles Grégoire |
Secur. Commun. Networks | 1 |
| 2011 | Avoiding DDoS with active management of backlog queuesabstractTCP (Transmission Control Protocol) is the dominant end to end transport protocol of the Internet, with a wide range of applications including Web, mail or peer to peer traffic. The TCP stack implements a “backlog queue” for new connections, which contains an entry for every client's connection setup received by the server. If the TCP handshake is not completed, the pending half-open connection stays in the backlog queue until a time-out expires and, if that time-out value is too big, the half-open connection stays in the queue longer than necessary. We present a technique to assign and find a suitable connection-establishment time-out value to reduce the risks of an overflow of the backlog queue in situations of SYN flooding attacks. We evaluate from experimental traces that our technique can reduce the size of the backlog queue size up to 50% while preserving normal connections. Martine Bellaïche, Jean-Charles Grégoire |
NSS | 1 |
| 2009 | SYN Flooding Attack Detection Based on Entropy ComputingabstractWe present an original approach to detect SYN flooding attacks from the victim's side, by monitoring unusual handshake sequences. Detection is done in real-time to allow quick protection and help guarantee a proper defence. Our detection system uses an entropy measure to detect changes in the balance of TCP handshakes. Experiment results show that our method can detect SYN flooding attacks with better accuracy and robustness than traditional stateless methods, and with manageable overhead. Martine Bellaïche, Jean-Charles Grégoire |
GLOBECOM | 1 |