Abdelouahid Derhab

dblp:08/6647 · DBLP profile ↗
← Back
51ranked-venue papers
12as first author
12since 2021 · last 2026
0000-0002-6498-1528ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 15 · 5 first-author · 1 since 2021Security and privacy · 11 · 2 first-author · 2 since 2021Applied, interdisciplinary, general and emerging computing · 8 · 1 first-author · 5 since 2021Systems, architecture and hardware · 6 · 2 first-author · 1 since 2021Artificial intelligence and machine learning · 4 · 1 since 2021Databases, data management, data science and information retrieval · 2 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1
YearPublicationVenuePosition
2026 Virtual Machine Placement in Cloud Data Centers Using Enhanced Binary Manta Ray Foraging Optimization Algorithm
Riad Bouaita, Samir Sellami, Noureddine Seddari, Abdelouahid Derhab, Waleed Halboob, Eleonora Bottani, Walid Laouar
J. Grid Comput.4
2025 Client-side Efficient Privacy-Preserving Remote Backpropagation for Deep Learning-based Pervasive Health Monitoring
abstract
Producing powerful deep learning models generally requires a large amount of data, often sourced from a large community of participants. In pervasive health monitoring, privacy concerns arise from the sensitive nature of the healthrelated data shared with remote clouds for training deep models. In this context, different privacy-preserving training solutions can be found in the literature. This paper targets conventional backpropagation algorithm, and addresses privacy preservation under constrained client-side environments and high-accuracy requirement in the context of pervasive health monitoring. It proposes an enhanced privacy-preserving remote training solution based on homomorphic encryption and reversible obfuscation under a non-colluding two-server architecture. The proposed solution can effectively protect sensitive client information from the serverside, with no leakage from gradients or weights during training, while none of the model parameters are revealed to the client. Moreover, the introduced fully reversible obfuscations do not alter training computations, and maintain low computational and communication overhead.
Amine Boulemtafes, Abdelouahid Derhab, Yacine Challal
AICCSA2
2024 DDoS attack forecasting based on online multiple change points detection and time series analysis
Rahmoune Bitit, Abdelouahid Derhab, Mohamed Guerroumi, Farrukh Aslam Khan
Multim. Tools Appl.2
2024 Detection and Analysis of Fake News Users' Communities in Social Media
abstract
The widespread use of social media platforms has led to an increase in the dissemination of fake news with the intention of manipulating public opinion and causing chaos and panic among the population. To address this issue, we focus on detecting the organized groups that participate together in fake news campaigns without prior knowledge of the news content or the profiles of social accounts. To this end, we propose aspatial–temporal similarity graph, a novel graph structure that connects social accounts that participate in the early stage of similar fake news campaigns. A community detection algorithm is applied on the similarity graph to cluster the users into communities. We propose acommunity labeling algorithmto label the communities as benign or malicious based on the output of a fake news classifier. Evaluation results show that the community labeling algorithm can correctly label the communities with an accuracy of$99.61\%$. In addition, we perform a statistical comparison analysis to identify the structural community features that are statistically significant between benign and malicious communities.
Abdelouahab Amira, Abdelouahid Derhab, Samir Hadjar, Mustapha Merazka, Md. Golam Rabiul Alam, Mohammad Mehedi Hassan
IEEE Trans. Comput. Soc. Syst.2
2023 SwiftR: Cross-platform ransomware fingerprinting using hierarchical neural networks on hybrid features
ElMouatez Billah Karbab, Mourad Debbabi, Abdelouahid Derhab
Expert Syst. Appl.3
2023 PRIviLY: Private Remote Inference over fulLY connected deep networks for pervasive health monitoring with constrained client-side
Amine Boulemtafes, Abdelouahid Derhab, Yacine Challal
J. Inf. Secur. Appl.2
2023 Increasing Continuous Engagement With Open Government Data: Learning From the Saudi Experience
abstract
A number of countries are today implementing open government data (OGD) initiatives. Yet many of these initiatives are failing to attract the levels of continuous use they need to deliver an acceptable return on investment. This raises the obvious question of why this should be the case. To answer this question, it is important to understand the factors that most strongly influence user behaviour in OGD adoption. Qualitative data were used to identify the factors that play a key role in influencing the intention to engage with ODG. A quantitative approach was then used to evaluate the extent to which these factors drive/limit behaviour. The study's findings showed that there are four factors that play a significant role in intention to use OGD. It is also believed that the findings will be useful in helping policymakers in all jurisdictions formulate and implement strategies that successfully drive up continuous OGD engagement.
Ibrahim Mutambik, Abdullah Almuqrin, Yulong Liu 0001, Waleed Halboob, Abdullah Alakeel, Abdelouahid Derhab
J. Glob. Inf. Manag.6
2023 Two-Stage Intrusion Detection System in Intelligent Transportation Systems Using Rule Extraction Methods From Deep Neural Networks
abstract
In recent years, intrusion detection systems (IDSs) are offering effective solutions to protect various types of cyber-attacks in different networks such as Internet of Vehicles (IoVs) network in Intelligent Transportation Systems (ITS). Deep learning models have largely been leveraged by these intrusion detection systems to achieve better effectiveness results. However, deep learning models are black boxes, which limits their acceptability in decision systems. Also, they require powerful processing capabilities such as GPU, which limit their deployments in resource-constrained devices in IoV environment. To deal with these issues, we propose a two-stage IDS in ITS to discover suspicious network activity of In-Vehicles Networks (IVN) and vehicles to everything (V2X) networks. Our proposed IDS system uses rule extraction methods from deep learning models, i.e., deep neural networks in two stages. In the first stage, we analyze network traffic to distinguish between normal and attack traffic. If the traffic is found malicious, the second stage is invoked to identify the type of attack. To this end, we propose three variants of rule extraction. The first and the second variants are homogeneous, and they apply$DeepRed$and$HypInv$rule extraction methods in both stages respectively. The third variant is heterogeneous, and it applies$HypInv$in the first stage to perform binary classification, and$DeepRed$in the second stage to perform attack classification. The key idea is to combine the advantages of rule extraction technique and two-stage IDS architecture to resource consumption and improve classification accuracy. The proposed IDS model was tested using four benchmark datasets, i.e. ISCXIDS2012, CIC-IDS2017, and CSE-CIC-IDS2018 datasets are used for external network communications and the car hacking dataset are used for in-vehicle communications. The evaluation results show that the homogeneous$DeepRed$is the optimal one in all cases of IDS system with an accuracy scores ranging between 92.43%-98.32% under CIC-IDS2017 dataset, between 91.32%-99.46% under CSE-CIC-IDS2018 dataset, and between 96.05%-99.21% under Car-hacking dataset.
Samah Almutlaq, Abdelouahid Derhab, Mohammad Mehedi Hassan, Kuljeet Kaur
IEEE Trans. Intell. Transp. Syst.2
2022 Keynote Speaker 6: Intrusion detection systems using machine learning for the security of autonomous vehicles
abstract
The emergence of smart cars has revolutionized the automotive industry. Today's vehicles are equipped with different types of electronic control units (ECUs) that enable autonomous functionalities like self-driving, self-parking, lane keeping, and collision avoidance. The ECUs are connected to each other through an in-vehicle network, named Controller Area Network. In this talk, we will present the different cyber attacks that target autonomous vehicles and explain how an intrusion detection system (IDS) using machine learning can play a role in securing the Controller Area Network. We will also discuss the main research contributions for the security of autonomous vehicles. Specifically, we will describe our IDS, named Histogram-based Intrusion Detection and Filtering framework. Next, we will talk about the machine learning explainability issue that limits the acceptability of machine learning in autonomous vehicles, and how it can be addressed using our novel intrusion detection system based on rule extraction methods from Deep Neural Networks.
Abdelouahid Derhab
SIN1
2022 Histogram-Based Intrusion Detection and Filtering Framework for Secure and Safe In-Vehicle Networks
abstract
In this paper, we propose H-IDFS, a Histogram-based Intrusion Detection and Filtering framework, which assembles the CAN packets into windows, and computes their corresponding histograms. The latter are fed to a multi-class IDS classifier to identify the class of the traffic windows. If the window is found malicious, the filtering system is invoked to filter out the normal CAN packets from each malicious window. To this end, we propose a novel one-class SVM, namedOCSVM-attackthat is trained on normal traffic and considers the invariant and quasi-invariant features of the attack. Experimental results on two CAN datasets: OTIDS and Car-Hacking, show the superiority of the proposed H-IDFS, as it achieves an accuracy of 100% for window classification, and correctly filters out between 94.93% and 100% of normal packets from malicious windows.
Abdelouahid Derhab, Mohamed Belaoued, Irfan Mohiuddin, Fajri Kurniawan, Muhammad Khurram Khan
IEEE Trans. Intell. Transp. Syst.1
2021 PReDIHERO - Privacy-Preserving Remote Deep Learning Inference based on Homomorphic Encryption and Reversible Obfuscation for Enhanced Client-side Overhead in Pervasive Health Monitoring
abstract
Homomorphic Encryption is one of the most promising techniques to deal with privacy concerns, which is raised by remote deep learning paradigm, and maintain high classification accuracy. However, homomorphic encryption-based solutions are characterized by high overhead in terms of both computation and communication, which limits their adoption in pervasive health monitoring applications with constrained client-side devices. In this paper, we propose PReDIHERO, an improved privacy-preserving solution for remote deep learning inferences based on homomorphic encryption. The proposed solution applies a reversible obfuscation technique that successfully protects sensitive information, and enhances the client-side overhead compared to the conventional homomorphic encryption approach. The solution tackles three main heavyweight client-side tasks, namely, encryption and transmission of private data, refreshing encrypted data, and outsourcing computation of activation functions. The efficiency of the client-side is evaluated on a healthcare dataset and compared to a conventional homomorphic encryption approach. The evaluation results show that PReDIHERO requires increasingly less time and storage in comparison to conventional solutions when inferences are requested. At two hundreds inferences, the improvement ratio could reach more than 30 times in terms of computation overhead, and more than 8 times in terms of communication overhead. The same behavior is observed in sequential data and batch inferences, as we record an improvement ratio of more than 100 times in terms of computation overhead, and more than 20 times in terms of communication overhead.
Amine Boulemtafes, Abdelouahid Derhab, Nassim Ait Ali Braham, Yacine Challal
AICCSA2
2021 BMC-SDN: Blockchain-Based Multicontroller Architecture for Secure Software-Defined Networks
abstract
Multicontroller software‐defined networks have been widely adopted to enable management of large‐scale networks. However, they are vulnerable to several attacks including false data injection, which creates topology inconsistency among controllers. To deal with this issue, we propose BMC‐SDN, a security architecture that integrates blockchain and multicontroller SDN and divides the network into several domains. Each SDN domain is managed by one master controller that communicates through blockchain with the masters of the other domains. The master controller creates blocks of network flow updates, and its redundant controllers validate the new block based on a proposed reputation mechanism. The reputation mechanism rates the controllers, i.e., block creator and voters, after each voting operation using constant and combined adaptive fading reputation strategies. The evaluation results demonstrate a fast and optimal detection of fraudulent flow rule injection.
Abdelouahid Derhab, Mohamed Guerroumi, Mohamed Belaoued, Omar Cheikhrouhou
Wirel. Commun. Mob. Comput.1
2020 An OWASP Top Ten Driven Survey on Web Application Protection Methods
Ouissem Ben Fredj, Omar Cheikhrouhou, Moez Krichen, Habib Hamam, Abdelouahid Derhab
CRiSIS5
2020 CyberSecurity Attack Prediction: A Deep Learning Approach
abstract
Cybersecurity attacks are exponentially increasing, making existing detection mechanisms insufficient and enhancing the necessity to design more relevant prediction models and approaches. This issue is still an open research problem since existing attack prediction models are failing to follow the huge amount of attacks and their variety. Recently, machine learning approaches and especially deep learning techniques have received much attention from researchers since their unparalleled high performance in several prediction-based fields. In this context, this paper explores the application of deep learning techniques for predicting cybersecurity attacks. Particularly, it proposes a new LSTM (Long Short-Term Memory), RNN (Recurrent Neural Network), and MLP (Multilayer Perceptron) based models carefully designed to predict the type of attack potentially to hap-pen. The proposed models were validated using a recently available dataset called CTF showing encouraging results especially for the LSTM model with an f-measure greater than 93%.
Ouissem Ben Fredj, Alaeddine Mihoub, Moez Krichen, Omar Cheikhrouhou, Abdelouahid Derhab
SIN5
2020 Scalable and robust unsupervised Android malware fingerprinting using community-based network partitioning
ElMouatez Billah Karbab, Mourad Debbabi, Abdelouahid Derhab, Djedjiga Mouheb
Comput. Secur.3
2020 Scalable and robust unsupervised android malware fingerprinting using community-based network partitioning
ElMouatez Billah Karbab, Mourad Debbabi, Abdelouahid Derhab, Djedjiga Mouheb
Comput. Secur.3
2020 A review of privacy-preserving techniques for deep learning
Amine Boulemtafes, Abdelouahid Derhab, Yacine Challal
Neurocomputing2
2020 Survey of false data injection in smart power grid: Attacks, countermeasures and challenges
Souhila Aoufi, Abdelouahid Derhab, Mohamed Guerroumi
J. Inf. Secur. Appl.2
2020 Deep learning approaches for anomaly-based intrusion detection systems: A survey, taxonomy, and open issues
Arwa Aldweesh, Abdelouahid Derhab, Ahmed Z. Emam
Knowl. Based Syst.2
2020 NSNAD: negative selection-based network anomaly detection approach with relevant feature subset
Naila Belhadj Aissa, Mohamed Guerroumi, Abdelouahid Derhab
Neural Comput. Appl.3
2020 Intrusion Detection System for Internet of Things Based on Temporal Convolution Neural Network and Efficient Feature Engineering
abstract
In the era of the Internet of Things (IoT), connected objects produce an enormous amount of data traffic that feed big data analytics, which could be used in discovering unseen patterns and identifying anomalous traffic. In this paper, we identify five key design principles that should be considered when developing a deep learning-based intrusion detection system (IDS) for the IoT. Based on these principles, we design and implement Temporal Convolution Neural Network (TCNN), a deep learning framework for intrusion detection systems in IoT, which combines Convolution Neural Network (CNN) with causal convolution. TCNN is combined with Synthetic Minority Oversampling Technique-Nominal Continuous (SMOTE-NC) to handle unbalanced dataset. It is also combined with efficient feature engineering techniques, which consist of feature space reduction and feature transformation. TCNN is evaluated on Bot-IoT dataset and compared with two common machine learning algorithms, i.e., Logistic Regression (LR) and Random Forest (RF), and two deep learning techniques, i.e., LSTM and CNN. Experimental results show that TCNN achieves a good trade-off between effectiveness and efficiency. It outperforms the state-of-the-art deep learning IDSs that are tested on Bot-IoT dataset and records an accuracy of 99.9986% for multiclass traffic detection, and shows a very close performance to CNN with respect to the training time.
Abdelouahid Derhab, Arwa Aldweesh, Ahmed Z. Emam, Farrukh Aslam Khan
Wirel. Commun. Mob. Comput.1
2019 An Improved Key Graph based Key Management Scheme for Smart Grid AMI systems
abstract
In this paper, we focus on versatile and scalable key management for Advanced Metering Infrastructure (AMI) in Smart Grid (SG). We show that a recently proposed key graph based scheme for AMI systems (VerSAMI) suffers from efficiency flaws in its broadcast key management protocol. Then, we propose a new key management scheme (iVerSAMI) by modifying VerSAMI's key graph structure and proposing a new broadcast key update process. We analyze security and performance of the proposed broadcast key management in details to show that iVerSAMI is secure and efficient in terms of storage and communication overheads.
Mourad Benmalek, Yacine Challal, Abdelouahid Derhab
WCNC3
2019 Authentication for Smart Grid AMI Systems: Threat Models, Solutions, and Challenges
abstract
Advanced Metering Infrastructure (AMI) has been regarded as a foundational part of the Smart Grid (SG). Consequently, AMI security is of critical importance. In this paper, we describe and investigate the current proposed authentication schemes and techniques for AMI. We discuss the challenges and desired objectives of authentication. We also provide a review of the recent proposed schemes for AMI along with their advantages and drawbacks towards meeting the discussed challenges and objectives. Based on the current survey, we identify open issues and suggest possible future research directions.
Mourad Benmalek, Yacine Challal, Abdelouahid Derhab
WETICE3
2019 Toward an optimal solution against Denial of Service attacks in Software Defined Networks
Muhammad Imran 0005, Muhammad Hanif Durad, Farrukh Aslam Khan, Abdelouahid Derhab
Future Gener. Comput. Syst.4
2019 Accurate detection of sitting posture activities in a secure IoT based assisted living environment
Muhammad Tariq 0001, Hammad Majeed, Mirza Omer Beg, Farrukh Aslam Khan, Abdelouahid Derhab
Future Gener. Comput. Syst.5
2019 Blockchain Technologies for the Internet of Things: Research Issues and Challenges
abstract
This paper presents a comprehensive survey of the existing blockchain protocols for the Internet of Things (IoT) networks. We start by describing the blockchains and summarizing the existing surveys that deal with blockchain technologies. Then, we provide an overview of the application domains of blockchain technologies in IoT, e.g., Internet of Vehicles, Internet of Energy, Internet of Cloud, Edge computing, etc. Moreover, we provide a classification of threat models, which are considered by blockchain protocols in IoT networks, into five main categories, namely identity-based attacks, manipulation-based attacks, cryptanalytic attacks, reputation-based attacks, and service-based attacks. In addition, we provide a taxonomy and a side-by-side comparison of the state-of-the-art methods toward secure and privacy-preserving blockchain technologies with respect to the blockchain model, specific security goals, performance, limitations, computation complexity, and communication overhead. Based on the current survey, we highlight open research challenges and discuss possible future research directions in the blockchain technologies for IoT.
Mohamed Amine Ferrag, Makhlouf Derdour, Mithun Mukherjee 0001, Abdelouahid Derhab, Leandros Maglaras, Helge Janicke
IEEE Internet Things J.4
2019 Trust models of internet of smart things: A survey, open issues, and future directions
Ayesha Altaf, Haider Abbas, Faiza Iqbal, Abdelouahid Derhab
J. Netw. Comput. Appl.4
2019 Authentication and Authorization for Mobile IoT Devices Using Biofeatures: Recent Advances and Future Trends
abstract
Biofeatures are fast becoming a key tool to authenticate the IoT devices; in this sense, the purpose of this investigation is to summarise the factors that hinder biometrics models’ development and deployment on a large scale, including human physiological (e.g., face, eyes, fingerprints-palm, or electrocardiogram) and behavioral features (e.g., signature, voice, gait, or keystroke). The different machine learning and data mining methods used by authentication and authorization schemes for mobile IoT devices are provided. Threat models and countermeasures used by biometrics-based authentication schemes for mobile IoT devices are also presented. More specifically, we analyze the state of the art of the existing biometric-based authentication schemes for IoT devices. Based on the current taxonomy, we conclude our paper with different types of challenges for future research efforts in biometrics-based authentication schemes for IoT devices.
Mohamed Amine Ferrag, Leandros Maglaras, Abdelouahid Derhab
Secur. Commun. Networks3
2019 A comprehensive security analysis of LEACH++ clustering protocol for wireless sensor networks
Farrukh Aslam Khan, Ashfaq Hussain Farooqi, Abdelouahid Derhab
J. Supercomput.3
2018 VerSAMI: Versatile and Scalable key management for Smart Grid AMI systems
Mourad Benmalek, Yacine Challal, Abdelouahid Derhab, Abdelmadjid Bouabdallah
Comput. Networks3
2017 Sound and Static Analysis of Session Fixation Vulnerabilities in PHP Web Applications
abstract
Web applications use authentication mechanisms to provide user-friendly content to users. However, some dangerous techniques like session fixation attacks target these mechanisms, by making the legitimate user use a session identifier that is controlled by the attacker. In this way, he can then impersonate the legitimate user without the need to know his credentials. In this paper, we present SAWFIX, a PHP static analyzer that checks web applications for session fixation vulnerabilities. To the best of our knowledge, SAWFIX is the first analyzer that checks exhaustively for this type of vulnerabilities, while the other methods only ensure partial correctness that is limited to a fraction of possible executions. SAWFIX is based on abstract interpretation, which is a theory for approximating the semantics of programs and allows designing static analyzers that are fully automatic and sound by construction. We implemented a prototype of our approach and tested it on several complex web applications. We obtained promising results in terms of detection accuracy and processing time, which reflects the efficiency of our system.
Abdelouahab Amira, Abdelraouf Ouadjaout, Abdelouahid Derhab, Nadjib Badache
CODASPY3
2017 Efficient and privacy-aware multi-party classification protocol for human activity recognition
Zakaria Gheid, Yacine Challal, Xun Yi, Abdelouahid Derhab
J. Netw. Comput. Appl.4
2016 Cypider: building community-based cyber-defense infrastructure for android malware detection
ElMouatez Billah Karbab, Mourad Debbabi, Abdelouahid Derhab, Djedjiga Mouheb
ACSAC3
2016 Survey on cybersecurity issues in wireless mesh networks based eHealthcare
abstract
Information and Communication Technologies (ICT) based applications for Ambient Assisted Living (AAL) help elderly or individual people living home alone. AAL system reliability is mostly based on the recent emerging class of network that is known as wireless mesh network (WiMesh). In WiMesh the information security is the most difficult problem to tackle because the medium is open to cyber-attacks. Moreover, when we talk about AAL where the complete personal information is digitized and stored, the need for implementation and maintenance of strict security measures is essential. In this article, we present a critical literature survey on communication security issues in e-health care environments. We highlight and explore the representative state of the art security prototypes for eHealthcare environments and also provide the details of their security characteristics. In addition, we discuss in detail the challenges and opportunities of these systems.
Kashif Saleem, Khan Zeb, Abdelouahid Derhab, Haider Abbas, Jalal Al-Muhtadi, Mehmet A. Orgun, Amjad Gawanmeh
HealthCom3
2016 MMSMAC: A multi-mode medium access control protocol for Wireless Sensor Networks
abstract
In this paper, we propose a new Medium Access Control (MAC) protocol for Wireless Sensor Networks (WSNs) called MMSMAC (Multi-Mode Sensor MAC protocol), which can operate and switch among three modes: synchronous, asynchronous, and hybrid, according to the application requirements. In the synchronous mode, MMSMAC organizes the sensor nodes under even and odd clusters. Each sensor node has its own active/sleep and send/receive periods according to its cluster identifier, which ensures better load balancing among nodes. In the asynchronous mode, sensor nodes communicate freely without the utilization of even and odd clusters. In this mode, we also propose another mechanism to circumvent the hidden host problem. In the hybrid mode, the features of synchronous and asynchronous modes are combined. Simulation results and analysis show that each of the MMSMAC modes shows convincing performance gains and outperforms B-MAC and CSMA/TDMA protocols.
Mohamed Guerroumi, Abdelouahid Derhab, Al-Sakib Khan Pathan, Nadjib Badache, Samira Moussaoui
WCNC2
2015 On resilience of Wireless Mesh routing protocol against DoS attacks in IoT-based ambient assisted living applications
abstract
The future of ambient assisted living (AAL) especially eHealthcare almost depends on the smart objects that are part of the Internet of things (IoT). In our AAL scenario, these objects collect and transfer real-time information about the patients to the hospital server with the help of Wireless Mesh Network (WMN). Due to the multi-hop nature of mesh networks, it is possible for an adversary to reroute the network traffic via many denial of service (DoS) attacks, and hence affect the correct functionality of the mesh routing protocol. In this paper, based on a comparative study, we choose the most suitable secure mesh routing protocol for IoT-based AAL applications. Then, we analyze the resilience of this protocol against DoS attacks. Focusing on the hello flooding attack, the protocol is simulated and analyzed in terms of data packet delivery ratio, delay, and throughput. Simulation results show that the chosen protocol is totally resilient against DoS attack and can be one of the best candidates for secure routing in IoT-based AAL applications.
Shaker Alanazi, Jalal Al-Muhtadi, Abdelouahid Derhab, Kashif Saleem, Afnan N. AlRomi, Hanan S. Alholaibah, Joel J. P. C. Rodrigues
HealthCom3
2015 Multivariate correlation analysis and geometric linear similarity for real-time intrusion detection systems
abstract
Abstract In this paper, we propose an intrusion detection system (IDS) based on four approaches: (i) statistical‐based IDS to reduce detection time; (ii) intertwining data acquisition phase and data preprocessing phase to ensure real‐time detection; (iii) geometric linear similarity measure that improves detection accuracy compared with existing measures; and (iv) multivariate correlation analysis that extracts a subset of strongly correlated features to construct a normal behavioral graph. Based on this graph, we derive the normal profile composed of high‐level features. We use NSL‐KDD dataset to analyze and evaluate the efficiency of the proposed IDS at detecting denial‐of‐service (DOS) attacks. Experimental results show that the proposed IDS can achieve good results in terms of detection rate and false positive rate. For some DOS attacks, 100%detection rate is achieved with 1.55%false positive. We also use KDD99 dataset to compare the proposed IDS with two statistical‐based methods and some data mining and machine learning‐based methods. Comparison study shows that the proposed IDS achieves the best tradeoff between detection rate (99.76%) and false positive rate (0.6%). It also requires just a few microseconds to classify the connection as normal or attack with low CPU usage and low memory consumption. Copyright © 2014 John Wiley & Sons, Ltd.
Abdelouahid Derhab, Abdelghani Bouras
Secur. Commun. Networks1
2015 Distributed Low-Latency Data Aggregation Scheduling in Wireless Sensor Networks
abstract
This article considers the data aggregation scheduling problem, where a collision-free schedule is determined in a distributed way to route the aggregated data from all the sensor nodes to the base station within the least time duration. The algorithm proposed in this article (Distributed algorithm for Integrated tree Construction and data Aggregation (DICA)) intertwines the tree formation and node scheduling to reduce the time latency. Furthermore, while forming the aggregation tree, DICA maximizes the available choices for parent selection at every node, where a parent may have the same, lower, or higher hop count to the base station. The correctness of the DICA is formally proven, and upper bounds for time and communication overhead are derived. Its performance is evaluated through simulation and compared with six delay-aware aggregation algorithms. The results show that DICA outperforms competing schemes. The article also presents a general hardware-in-the-loop framework (DAF) for validating data aggregation schemes on Wireless Sensor Networks (WSNs). The framework factors in practical issues such as clock synchronization and the sensor node hardware. DICA is implemented and validated using this framework on a test bed of sensor motes that runs TinyOS 2.x, and it is compared with a distributed protocol (DAS) that is also implemented using the proposed framework.
Miloud Bagaa, Mohamed F. Younis, Djamel Djenouri, Abdelouahid Derhab, Nadjib Badache
ACM Trans. Sens. Networks4
2014 Low delay and secure M2M communication mechanism for eHealthcare
abstract
Currently, the eHealthcare information management is the most critical and hot research topic. Especially with the involvement of new and promising telecommunication technologies like Machine to Machine (M2M) Communication. In M2M communication the devices interact and exchange information with each other in an autonomous manner to accomplish the required tasks. Mostly machine communicate to another machine wirelessly. The wireless communication opens the medium for enormous vulnerabilities and make it very easy for hackers to access the confidential information and can perform malicious activities. In this paper, we propose a Machine to Machine (M2M) Low Delay and Secure (LDS) communication system for e-healthcare community based on random distributive key management scheme and modified Kerberos realm to ensure data security. The system is capable to perform the tasks in an autonomous and intelligent manner that minimizes the workload of medical staffs, and improves the quality of patient care as well as the system performance. We show how the different actors in the e-healthcare community can interact with each other in a secure manner. The system handles dynamic assignments of doctors to specific patients. The proposed architecture further provides security against false attack, false triggering and temper attack. Finally, the simulation type implementation is performed on Visual Basic .net 2013 that shows the feasibility of the proposed Low Delay and Secure (LDS) algorithm.
Kashif Saleem, Abdelouahid Derhab, Jalal Al-Muhtadi
Healthcom2
2014 Third line of defense strategy to fight against SMS-based malware in android smartphones
abstract
In this paper, we inspire from two analogies: the warfare kill zone and the airport check-in system, to design and deploy a new line in the defense-in-depth strategy, called the third line. This line is represented by a security framework, named the Intrusion Ambushing System and is designed to tackle the issue of SMS-based malware in the Android-based Smartphones. The framework exploits the security features offered by Android operating system to prevent the malicious SMS from going out of the phone and detect the corresponding SMS-based malware. We show that the proposed framework can ensure full security against SMS-based malware. In addition, an analytical study demonstrates that the framework offers optimal performance in terms of detection time and execution cost in comparison to intrusion detection systems based on static and dynamic analysis.
Abdelouahid Derhab, Kashif Saleem, Ahmed E. Youssef
IWCMC1
2014 Intertwined path formation and MAC scheduling for fast delivery of aggregated data in WSN
Miloud Bagaa, Mohamed F. Younis, Abdelouahid Derhab, Nadjib Badache
Comput. Networks3
2012 MOB-TOSSIM: An Extension Framework for TOSSIM Simulator to Support Mobility in Wireless Sensor and Actuator Networks
abstract
Recently, there has been considerable research on using mobility in wireless sensor and actor networks (WSANs) to assist in the deployment of nodes and meet the sensing, communication, and actuation coverage requirements. One of the well-know simulators used to evaluate the performance of wireless sensor networks is TOSSIM. It has the advantage that its code can also run in real systems, and hence it allows better comparison between experimental and simulation results. However, it is designed to simulate only static sensor networks. In this paper, we propose a classification scheme that categorizes the mobility models in WSANs. Based on this classification, we design and implement MOB-TOSSIM, the first extension framework to TOSSIM that supports mobility in WSNs and WSANs. MOB-TOSSIM implements three components: (1) a set of probabilistic and controlled mobility models, (2) an extended and modified version of Power TOSSIM that includes the energy consumption due to mobility and radio transmission, and (3) a radio component based on a realistic propagation model. Experiment results show that MOB-TOSSIM is scalable with respect to network size and node speed, as it incurs an acceptable additional execution time compared to TOSSIM.
Abdelouahid Derhab, Fatma Ounini, Badis Remli
DCOSS1
2012 Semi-structured and unstructured data aggregation scheduling in wireless sensor networks
abstract
This paper focuses on data aggregation scheduling problem in wireless sensor networks (WSNs), to minimize time latency. Prior works on this problem have adopted a structured approach, in which a tree-based structure is used as an input for the scheduling algorithm. As the scheduling performance mainly depends on the supplied aggregation tree, such an approach cannot guarantee optimal performance. To address this problem, we propose approaches based on Semi-structured Topology (DAS-ST) and Unstructured Topology (DAS-UT). The approaches are based on two key design features, which are: (1) simultaneous execution of aggregation tree construction and scheduling, and (2) parent selection criteria that maximize the choices of parents for each node and maximize time slot reuse. We prove that the latency of DAS-ST is upper-bounded by ([2π/arccos(1/1+ϵ)]+4)R+Δ-4, where R is the network radius, Δ is the maximum node degree, and 0.05 <; ϵ ≤ 1. Simulations results show that DAS-UT outperforms DAS-ST and four competitive state-of-the-art aggregation scheduling algorithms in terms of latency and network lifetime.
Miloud Bagaa, Abdelouahid Derhab, Noureddine Lasla, Abdelraouf Ouadjaout, Nadjib Badache
INFOCOM2
2012 Half-Symmetric Lens based localization algorithm for wireless sensor networks
abstract
The area-based localization algorithms use only the location information of some reference nodes, called anchors, to give the residence area of the remaining nodes. The current algorithms use triangle, ring or circle as a geometric shape to determine the sensors' residence area. Existing works suffer from two major problems: (1) in some cases, they might issue wrong decisions about nodes' presence inside a given area, or (2) they require high anchor density to achieve a low location estimation error. In this paper, we deal with the localization problem by introducing a new way to determine the sensors' residence area which shows a better accuracy than the existing algorithms. Our new localization algorithm, called HSL (Half Symmetric Lens based localization algorithm for WSN), is based on the geometric shape of half-symmetric lens. We also uses the Voronoi diagram in HSL to mitigate the problem of unlocalizable sensor nodes. Finally, we conduct extensive simulations to evaluate the performance of HSL. Simulation results show that HSL has better locatable ratio and location accuracy compared to representative state-of-the-art area-based algorithms.
Noureddine Lasla, Abdelouahid Derhab, Abdelraouf Ouadjaout, Miloud Bagaa, Adlen Ksentini, Nadjib Badache
LCN2
2008 Balancing the tradeoffs between scalability and availability in mobile ad hoc networks with a flat hashing-based location service
Abdelouahid Derhab, Nadjib Badache
Ad Hoc Networks1
2008 Self-stabilizing algorithm for high service availability in spite of concurrent topology changes in ad hoc mobile networks
Abdelouahid Derhab, Nadjib Badache
J. Parallel Distributed Comput.1
2008 A Self-Stabilizing Leader Election Algorithm in Highly Dynamic Ad Hoc Mobile Networks
abstract
The classical definition of a self-stabilizing algorithm assumes generally that there are no faults in the system long enough for the algorithm to stabilize. Such an assumption cannot be applied to ad hoc mobile networks characterized by their highly dynamic topology. In this paper, we propose a self-stabilizing leader election algorithm that can tolerate multiple concurrent topological changes. By introducing the time-interval-based computation concept, the algorithm ensures that a network partition can within a finite time converge to a legitimate state even if topological changes occur during the convergence time. Our simulation results show that our algorithm can ensure that each node has a leader over 99 percent of the time. We also give an upper bound on the frequency at which network components merge to guarantee the convergence.
Abdelouahid Derhab, Nadjib Badache
IEEE Trans. Parallel Distributed Syst.1
2006 On Promoting Ad-Hoc Collaboration Among Messengers
abstract
The explosion growth in the market place for handheld wireless devices has enabled new opportunities for wireless applications. Currently, handheld devices are restricted to being clients that make requests to servers and receive responses over the network. But as mobile ad-hoc networks become the trend, such devices will need to become active participants that serve requests from other devices and convey data to other devices as well. In this paper we present our vision of the future role that handheld devices will play in a mobile ad-hoc network configuration. We present this vision as part of the MESSENGER, project that develops data management mechanisms for UDDI registries of Web services using mobile users and their software agents, and then describe its extension for exchanging descriptions of Web services during ad-hoc collaboration sessions. User agents are in charge of interacting with peer users over an ad-hoc network, and collaborating on feeding UDDI registries with recent content
Zakaria Maamar, Qusay H. Mahmoud, Abdelouahid Derhab
AINA (1)3
2006 Localized Hybrid Data Delivery Scheme using K-hop Clustering Algorithm in Ad Hoc Networks
abstract
In mobile ad hoc networks, as nodes move freely, network partitions occur frequently, which significantly degrades the performance of data access. Data replication is a promising approach to improve data availability in mobile ad hoc networks. In this paper, we propose a localized hybrid data delivery scheme that combines the push-based and the pull-based approaches. This scheme is constructed by implementing a localized clustering algorithm that constructs groups, in which each node is at most K hops away from a group leader. This construction permits to bind the query access delay by K hops. The localized clustering algorithm dynamically creates groups to adapt to topology changes. It can also predict when the group will partition. So, it can replicate data items on nodes of the future separate group before the partitioning occurs. The proposed localized scheme helps to increase data availability while improving query delay and update cost
Abdelouahid Derhab, Nadjib Badache
MASS1
2006 Ad-Hoc Collaboration Between Messengers: Operations and Incentives
abstract
This paper discusses how ad-hoc collaboration boosts the operation of a set of messengers. This discussion continues the research we earlier initiated in theMESSENGER project, which develops data management mechanisms for UDDI registries of Web services using mobile users and software agents. In the current operation mode of messengers, descriptions of Web services are first, collected from UDDI registries and later on, distributed to other UDDI registries. This distribution mode of Web services descriptions does not foster the tremendous opportunities that both wireless technologies and mobile devices offer. When mobile devices are in the vicinity of each other, they can form a mobile ad-hoc network, which enables the exchange of data between these devices without any preexisting communication infrastructure. By authorizing messengers to engage in collaboration, collecting additional descriptions of Web services from other messengers can happen, too.
Zakaria Maamar, Qusay H. Mahmoud, Abdelouahid Derhab, Wathiq Mansoor
MDM3
2006 ELS: Energy-Aware Some-for-Some Location Service for Ad Hoc Mobile Networks
Abdelouahid Derhab, Nadjib Badache, Karim Tari, Sihem Sami
WASA1