Ahmed M. Azab

dblp:09/2166 · DBLP profile ↗
← Back
19ranked-venue papers
6as first author
3since 2021 · last 2023
0000-0002-4451-7808ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 14 · 5 first-author · 2 since 2021Systems, architecture and hardware · 2Human-computer interaction and ubiquitous computing · 2 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 1 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 first-author
YearPublicationVenuePosition
2023 Motor Imagery Classification Enhancement using Generative Adversarial Networks for EEG Spectrum Image Generation
abstract
The development of practical Brain-Computer Interface (BCI) systems has been hindered by significant issues related to data, specifically the lack of sufficient data needed for training. To address this challenge, generating synthetic data that mimics real recorded data has been proposed to augment the real data. One promising technique for data augmentation is through the use of Generative Adversarial Networks (GANs), which have been successfully applied in many other fields. This paper proposes a novel GAN-based approach for generating synthetic spectrum images of Motor Imagery (MI) Electroencephalogram (EEG). The proposed GAN is examined with two Convolutional Neural Network (CNN) architectures in the context of MI classification. Using the public dataset BCI competition IV, our findings reveal that the generated EEG spectrum images using GANs exhibit temporal, spectral, and spatial characteristics similar to the real ones. The average classification accuracy of right-hand versus left-hand MI using the proposed GAN/CNN models has improved to 76.71% with an enhancement of 2.5% in comparison to using the CNN applied to the real data only. These results suggest that using GANs could improve MI BCI systems with limited data.
Ahmed G. Habashi, Ahmed M. Azab, Seif Eldawlatly, Gamal M. Aly
CBMS2
2023 Automatic Permission Check Analysis for Linux Kernel
abstract
Permission checks play an essential role in operating system security by providing access control to privileged functionalities. However, it is challenging for kernel developers to scalably verify the soundness of existing checks due to the large codebase and complexity of the kernel. In fact, Linux kernel contains millions of lines of code with hundreds of permission checks, and even worse its complexity is fast-growing. This paper presents PeX, a static permission check error detector for Linux, which takes as input a kernel source code and reports any missing, inconsistent, and redundant permission checks. PeX uses KIRIN (Kernel InteRface based Indirect call aNalysis), a novel, precise, and scalable indirect call analysis technique. Over the interprocedural control flow graph built by KIRIN, PeX automatically identifies permission checks and infers the mappings between permission checks and privileged functions. For each privileged function, PeX examines all possible paths to the function to check if necessary permission checks are correctly enforced. We evaluated PeX on the latest stable Linux kernel v4.18.5 for three types of permission checks: Discretionary Access Controls (DAC), Capabilities, and Linux Security Modules (LSM). PeX reported 45 new permission check errors, 17 of which have been confirmed by the kernel developers.
Jinmeng Zhou, Wenbo Shen, Changhee Jung, Ahmed M. Azab, Ruowen Wang, Peng Ning, Kui Ren 0001
IEEE Trans. Dependable Secur. Comput.6
2021 KALD: Detecting Direct Pointer Disclosure Vulnerabilities
abstract
Modern operating system kernels deploy Kernel Address Space Layout Randomization (KASLR) to mitigate control-flow hijacking attacks. KASLR randomizes the base addresses of the kernel's code and data segments. However, it randomizes both with a single offset and does not randomize the internal layout of either of these segments, so relative addresses remain known to adversaries. If the kernel discloses a single code or global data pointer, an adversary can therefore infer the entire layout of the kernel's code segment and bypass KASLR. In this paper, we present Kernel Address Leak Detector (KALD), a tool that finds direct disclosure vulnerabilities by statically analyzing the kernel source code. KALD can analyze the source code of modern operating system kernels and find previously unreported leaks. KALD compiles a list of functions that can leak information to user-space accessible locations, and it uses the results of a points-to analysis to determine whether individual invocations of such functions can disclose kernel pointers. We show that KALD successfully detects several direct disclosure vulnerabilities in the Linux kernel and that it is flexible enough to be useful in practice.
Brian Belleville, Wenbo Shen, Stijn Volckaert, Ahmed M. Azab, Michael Franz
IEEE Trans. Dependable Secur. Comput.4
2019 Learning Binary Representation for Automatic Patch Detection
abstract
Binary-only bug search has already drawn a lot attentions recently, due to the increasing growth of security breaches. Most of existing work focuses on searching by checking the similarity of code snippets. It is further required to check whether the function is patched or not. Unfortunately, this is still a manual effort for all existing code search based approaches. In this paper, we propose a novel approach for automatic patch detection. we build a patch detector by learning the feature representation from the patched code in the binary format. We utilize the feature encoding technique to make the binary code trainable, and build our neural network model to learn the patch feature for increasing detection accuracy. We have implemented a prototype called PATCHDETECTOR, and systematically evaluated its performance in terms of the accuracy and efficiency by using 1,600 OpenSSL binaries of 216,000 functions. Experimental results have shown that PATCHDETECTOR can effectively detect whether the target binary function is patched or not with the detection accuracy of 92% on average.
Rundong Zhou, Yanhui Zhao, Jia Ma, Xudong Jin, Ahmed M. Azab, Peng Ning
CCNC9
2019 A Lightweight Framework for Fine-Grained Lifecycle Control of Android Applications
abstract
The lifecycle of Android apps is dynamically managed by the system in an ad hoc manner, which leads to apps' abusing lifecycle entry points to automatically start up and gaming the priority-based memory management mechanism to evade being killed. Such apps exhibit diehard behaviors that keep them long-running in the background, resulting in excessive battery consumption and device performance degradation. Existing battery-saving features are far from being effective in restricting diehard behaviors, due to the lack of systematic, fine-grained control of app lifecycle.
Yuru Shao, Ruowen Wang, Ahmed M. Azab, Z. Morley Mao
EuroSys4
2019 Robust Common Spatial Patterns Estimation Using Dynamic Time Warping to Improve BCI Systems
abstract
Common spatial patterns (CSP) is one of the most popular feature extraction algorithms for brain-computer interfaces (BCI). However, CSP is known to be very sensitive to artifacts and prone to overfitting. This paper proposes a novel dynamic time warping (DTW)-based approach to improve CSP covariance matrix estimation and hence improve feature extraction. Dynamic time warping is widely used for finding an optimal alignment between two time-dependent signals under predefined conditions. The proposed approach reduces within class temporal variations and non-stationarity by aligning the training trials to the average of the trials from the same class. The proposed DTW-based CSP approach is applied to the support vector machines (SVM) classifier and evaluated using one of the publicly available motor imagery datasets. The results showed that the proposed approach, when compared to the classical CSP, improved the classification accuracy from 78% to 83% on average. Importantly, for some subjects, the improvement was around 10%.
Ahmed M. Azab, Lyudmila Mihaylova, Hamed Ahmadi, Mahnaz Arvaneh
ICASSP1
2019 PeX: A Permission Check Analysis Framework for Linux Kernel
Wenbo Shen, Changhee Jung, Ahmed M. Azab, Ruowen Wang
USENIX Security Symposium5
2018 Weighted Multi-task Learning in Classification Domain for Improving Brain-Computer Interface
abstract
One of the major limitations of brain computer interface (BCI) is its long calibration time. Due to between sessions/subjects nonstationarity, typically a big amount of training data needs to be collected at the beginning of each session in order to tune the parameters of the system for the target user. In this paper, a number of novel weighted multi-task transfer learning algorithms are proposed in the classification domain to reduce the calibration time without sacrificing the classification accuracy of the BCI system. The proposed algorithms use data from other subjects and combine them to estimate the classifier parameters for the target subject. This combination is done based on how similar the data from each subject is to the few trials available from the target subject. The proposed algorithms are evaluated using dataset 2a from BCI competition IV. According to the results, the proposed algorithms lead to reduce the calibration time by 75% and enhance the average classification accuracy at the same time.
Mahnaz Arvaneh, Lyudmila Mihaylova, Ahmed M. Azab
SMC3
2017 PrivWatcher: Non-bypassable Monitoring and Protection of Process Credentials from Memory Corruption Attacks
abstract
Commodity operating systems kernels are typically implemented using low-level unsafe languages, which leads to the inevitability of memory corruption vulnerabilities. Multiple defense techniques are widely adopted to mitigate the impact of memory corruption on executable code and control data. Nevertheless, there has not been much attention to defend against corruption of non-control data despite the fact that previous incidents of kernel exploitation showed that corrupting non-control data is a real threat.
Ahmed M. Azab, Guruprasad Ganesh, Peng Ning
AsiaCCS2
2017 SPOKE: Scalable Knowledge Collection and Attack Surface Analysis of Access Control Policy for Security Enhanced Android
abstract
SEAndroid is a mandatory access control (MAC) framework that can confine faulty applications on Android. Nevertheless, the effectiveness of SEAndroid enforcement depends on the employed policy. The growing complexity of Android makes it difficult for policy engineers to have complete domain knowledge on every system functionality. As a result, policy engineers sometimes craft over-permissive and ineffective policy rules, which unfortunately increased the attack surface of the Android system and have allowed multiple real-world privilege escalation attacks. We propose SPOKE, an SEAndroid Policy Knowledge Engine, that systematically extracts domain knowledge from rich-semantic functional tests and further uses the knowledge for characterizing the attack surface of SEAndroid policy rules. Our attack surface analysis is achieved by two steps: 1) It reveals policy rules that cannot be justified by the collected domain knowledge. 2) It identifies potentially over-permissive access patterns allowed by those unjustified rules as the attack surface.
Ruowen Wang, Ahmed M. Azab, William Enck, Ninghui Li 0001, Peng Ning, Wenbo Shen, Yueqiang Cheng
AsiaCCS2
2017 NORAX: Enabling Execute-Only Memory for COTS Binaries on AArch64
abstract
Code reuse attacks exploiting memory disclosure vulnerabilities can bypass all deployed mitigations. One promising defense against this class of attacks is to enable execute-only memory (XOM) protection on top of fine-grained address space layout randomization (ASLR). However, recent works implementing XOM, despite their efficacy, only protect programs that have been (re)built with new compiler support, leaving commercial-off-the-shelf (COTS) binaries and source-unavailable programs unprotected. We present the design and implementation of NORAX, a practical system that retrofits XOM into stripped COTS binaries on AArch64 platforms. Unlike previous techniques, NORAX requires neither source code nor debugging symbols. NORAX statically transforms existing binaries so that during runtime their code sections can be loaded into XOM memory pages with embedded data relocated and data references properly updated. NORAX allows transformed binaries to leverage the new hardware-based XOM support—a feature widely available on AArch64 platforms (e.g., recent mobile devices) yet virtually unused due to the incompatibility of existing binaries. Furthermore, NORAX is designed to co-exist with other COTS binary hardening techniques, such as in-place randomization (IPR). We apply NORAX to the commonly used Android system binaries running on SAMSUNG Galaxy S6 and LG Nexus 5X devices. The results show that NORAX on average slows down the execution of transformed binaries by 1.18% and increases their memory footprint by 2.21%, suggesting NORAX is practical for real-world adoption.
Yaohui Chen 0001, Dongli Zhang, Ruowen Wang, Ahmed M. Azab, Long Lu, Hayawardh Vijayakumar, Wenbo Shen
IEEE Symposium on Security and Privacy5
2016 SKEE: A lightweight Secure Kernel-level Execution Environment for ARM
Ahmed M. Azab, Kirk Swidowski, Rohan Bhutkar, Jia Ma, Wenbo Shen, Ruowen Wang, Peng Ning
NDSS1
2015 EASEAndroid: Automatic Policy Analysis and Refinement for Security Enhanced Android via Large-Scale Semi-Supervised Learning
Ruowen Wang, William Enck, Douglas S. Reeves, Xinwen Zhang, Peng Ning, Dingbang Xu, Wu Zhou 0001, Ahmed M. Azab
USENIX Security Symposium8
2014 SEER: practical memory virus scanning as a service
abstract
Virus Scanning-as-a-Service (VSaaS) has emerged as a popular security solution for virtual cloud environments. However, existing approaches fail to scan guest memory, which can contain an emerging class of Memory-only Malware. While several host-based memory scanners are available, they are computationally less practical for cloud environments. This paper proposes SEER as an architecture for enabling Memory VSaaS for virtualized environments. SEER leverages cloud resources and technologies to consolidate and aggregate virus scanning activities to efficiently detect malware residing in memory. Specifically, SEER combines fast memory snapshotting and computation deduplication to provide practical and efficient off-host memory virus scanning. We evaluate SEER and demonstrate up to an 87% reduction in data size that must be scanned and up to 72% savings in overall scan time, compared to naively applying file-based scanning approaches. Furthermore, SEER provides a 50% reduction in scan time when using a warm cache. In doing so, SEER provides a practical solution for cloud vendors to transparently and periodically scan virtual machine memory for malware.
Jason Gionta, Ahmed M. Azab, William Enck, Peng Ning, Xiaolan Zhang 0001
ACSAC2
2014 Hypervision Across Worlds: Real-time Kernel Protection from the ARM TrustZone Secure World
abstract
TrustZone-based Real-time Kernel Protection (TZ-RKP) is a novel system that provides real-time protection of the OS kernel using the ARM TrustZone secure world. TZ-RKP is more secure than current approaches that use hypervisors to host kernel protection tools. Although hypervisors provide privilege and isolation, they face fundamental security challenges due to their growing complexity and code size. TZ-RKP puts its security monitor, which represents its entire Trusted Computing Base (TCB), in the TrustZone secure world; a safe isolated environment that is dedicated to security services. Hence, the security monitor is safe from attacks that can potentially compromise the kernel, which runs in the normal world. Using the secure world for kernel protection has been crippled by the lack of control over targets that run in the normal world. TZ-RKP solves this prominent challenge using novel techniques that deprive the normal world from the ability to control certain privileged system functions. These functions are forced to route through the secure world for inspection and approval before being executed. TZ-RKP's control of the normal world is non-bypassable. It can effectively stop attacks that aim at modifying or injecting kernel binaries. It can also stop attacks that involve modifying the system memory layout, e.g, through memory double mapping. This paper presents the implementation and evaluation of TZ-RKP, which has gone through rigorous and thorough evaluation of effectiveness and performance. It is currently deployed on the latest models of the Samsung Galaxy series smart phones and tablets, which clearly demonstrates that it is a practical real-world system.
Ahmed M. Azab, Peng Ning, Jitesh Shah, Rohan Bhutkar, Guruprasad Ganesh, Jia Ma, Wenbo Shen
CCS1
2011 SICE: a hardware-level strongly isolated computing environment for x86 multi-core platforms
abstract
SICE is a novel framework to provide hardware-level isolation and protection for sensitive workloads running on x86 platforms in compute clouds. Unlike existing isolation techniques, SICE does not rely on any software component in the host environment (i.e., an OS or a hypervisor). Instead, the security of the isolated environments is guaranteed by a trusted computing base that only includes the hardware, the BIOS, and the System Management Mode (SMM). SICE provides fast context switching to and from an isolated environment, allowing isolated workloads to time-share the physical platform with untrusted workloads. Moreover, SICE supports a large range (up to 4GB) of isolated memory. Finally, the most unique feature of SICE is the use of multicore processors to allow the isolated environments to run concurrently and yet securely beside the untrusted host. We have implemented a SICE prototype using an AMD x86 hardware platform. Our experiments show that SICE performs fast context switching (67 microseconds) to and from the isolated environment and that it imposes a reasonable overhead (3% on all but one benchmark) on the operation of an isolated Linux virtual machine. Our prototype demonstrates that, subject to a careful security review of the BIOS software and the SMM hardware implementation, current hardware architecture already provides abstractions that can support building strong isolation mechanisms using a very small SMM software foundation of about 300 lines of code.
Ahmed M. Azab, Peng Ning, Xiaolan Zhang 0001
CCS1
2010 HyperSentry: enabling stealthy in-context measurement of hypervisor integrity
abstract
This paper presents HyperSentry, a novel framework to enable integrity measurement of a running hypervisor (or any other highest privileged software layer on a system). Unlike existing solutions for protecting privileged software, HyperSentry does not introduce a higher privileged software layer below the integrity measurement target, which could start another race with malicious attackers in obtaining the highest privilege in the system. Instead, HyperSentry introduces a software component that is properly isolated from the hypervisor to enable stealthy and in-context measurement of the runtime integrity of the hypervisor. While stealthiness is necessary to ensure that a compromised hypervisor does not have a chance to hide the attack traces upon detecting an up-coming measurement, in-context measurement is necessary to retrieve all the needed inputs for a successful integrity measurement.
Ahmed M. Azab, Peng Ning, Zhi Wang 0004, Xuxian Jiang, Xiaolan Zhang 0001, Nathan C. Skalsky
CCS1
2009 HIMA: A Hypervisor-Based Integrity Measurement Agent
abstract
Integrity measurement is a key issue in building trust in distributed systems. A good solution to integrity measurement has to provide both strong isolation between the measurement agent and the measurement target and time of check to time of use (TOCTTOU) consistency (i.e., the consistency between measured version and executed version throughout the lifetime of the target). Unfortunately, none of the previous approaches provide (or can be easily modified to provide) both capabilities. This paper presents HIMA, a hypervisor-based agent that measures the integrity of virtual machines (VMs) running on top of the hypervisor, which provides both capabilities identified above. HIMA performs two complementary tasks: (1) active monitoring of critical guest events and (2) guest memory protection. The former guarantees that the integrity measures are refreshed whenever the guest VM memory layout changes (e.g., upon creation of processes), while the latter ensures that integrity measurement of user programs cannot be bypassed without HIMA's knowledge. This paper also reports the experimental evaluation of a HIMA prototype using both micro-benchmark and application benchmark; the experimental results indicate that HIMA is a practical solution for real world applications.
Ahmed M. Azab, Peng Ning, Emre Can Sezer, Xiaolan Zhang 0001
ACSAC1
2009 Remote attestation to dynamic system properties: Towards providing complete system integrity evidence
abstract
Remote attestation of system integrity is an essential part of trusted computing. However, current remote attestation techniques only provide integrity proofs of static properties of the system. To address this problem we present a novel remote dynamic attestation system named ReDAS (Remote Dynamic Attestation System) that provides integrity evidence for dynamic system properties. Such dynamic system properties represent the runtime behavior of the attested system, and enable an attester to prove its runtime integrity to a remote party. ReDAS currently provides two types of dynamic system properties for running applications: structural integrity and global data integrity. In this work, we present the challenges of remote dynamic attestation, provide an in-depth security analysis and introduce a first step towards providing a complete runtime dynamic attestation framework. Our prototype implementation and evaluation with real-world applications show that we can improve on current static attestation techniques with an average performance overhead of 8%.
Chongkyung Kil, Emre Can Sezer, Ahmed M. Azab, Peng Ning, Xiaolan Zhang 0001
DSN3