EDBT 2026 Demo / reviewers in the wild / expert
Saed Alrabaee
dblp:121/3499
· DBLP profile ↗
31ranked-venue papers
10as first author
23since 2021 · last 2026
0000-0001-8842-493XORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 12 · 7 first-author · 6 since 2021Human-computer interaction and ubiquitous computing · 10 · 2 first-author · 10 since 2021Applied, interdisciplinary, general and emerging computing · 10 · 2 first-author · 10 since 2021Computer networks · 5 · 3 since 2021Artificial intelligence and machine learning · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | A Design Science Research Architecture for XR-Based Pre-Visit Cultural Heritage Learning Applications
Mousa Al-Kfairy, Omar Alfandi, Saed Alrabaee |
CSEDU (1) | 3 |
| 2025 | Digital Transformation of Education: An Integrated Framework for Metaverse, Blockchain, and AI-Driven Learning
Mousa Al-Kfairy, Omar Alfandi, Ravi S. Sharma 0003, Saed Alrabaee |
CSEDU (1) | 4 |
| 2025 | Navigating Ethical Dilemmas in the Implementation of AI-Driven Educational TechnologiesabstractArtificial Intelligence (AI) is transforming education by offering innovative tools that enhance teaching, learning, and administrative processes. However, its integration introduces significant ethical challenges that demand critical attention. This systematic literature review (SLR) explores key ethical concerns associated with AI-driven educational technologies, including data privacy, algorithmic bias, student autonomy, and inclusivity. It systematically analyzing existing literature to provide actionable guidelines for promoting ethical AI use, emphasizing transparency, fairness, and accountability. The review also examines the impact of AI on the dynamics of instructor-student relationships, highlighting both opportunities for personalized learning and risks of reduced human interaction. By addressing these challenges and proposing strategies for responsible AI implementation, this study aims to guide educational institutions in navigating the complexities of AI adoption while fostering equitable and meaningful learning experiences. Muhusina Ismail, Nisha Thorakkattu Madathil, Meera Alalawi, Shamma Alalawi, Saed Alrabaee |
EDUCON | 5 |
| 2025 | Detection of Tor network obfuscated traffic using Bidirectional Generative Adversarial NetworkabstractCensorship systems face significant challenges in detecting anonymity-preserving traffic due to advanced obfuscation techniques employed by Tor pluggable transports like Obfs4 and Snowflake. Conventional detection approaches exhibit diminished effectiveness in operational environments where obfuscated traffic constitutes a minute fraction of overall network communications. We present a Cost-Sensitive Bidirectional Generative Adversarial Network (CS-BiGAN) that addresses these challenges through enhanced feature representation learning and classification resilience under extreme class imbalance. Our methodology incorporates a custom dataset collection framework capturing representative traffic patterns from multiple obfuscation protocols, coupled with a cost-sensitive learning mechanism to mitigate class disparity effects. Comprehensive evaluation demonstrates that CS-BiGAN achieves 98.25% accuracy under balanced conditions, with protocol-specific F1-scores of 99.29% for Obfs4 and 97.16% for Snowflake. The model’s distinguishing characteristic is the sustained performance under severe base rate imbalances (1000:1:1:1) that reflect real-world network conditions, maintaining F1-scores exceeding 90.80% for minority classes on average. This performance substantially surpasses existing approaches, establishing practical applicability in operational environments. Our findings offer insights relevant to both censorship system deployment and the advancement of robust obfuscation methodologies designed to circumvent detection mechanisms. Ban Al-Omar, Zouheir Trabelsi, Saed Alrabaee |
Comput. Networks | 3 |
| 2025 | Enhancing Federated Feature Selection Through Synthetic Data and Zero Trust IntegrationabstractFederated Learning (FL) allows healthcare organizations to train models using diverse datasets while maintaining patient confidentiality collaboratively. While promising, FL faces challenges in optimizing model accuracy and communication efficiency. To address these, we propose an algorithm that combines feature selection with synthetic data generation, specifically targeting medical datasets. Our method eliminates irrelevant local features, identifies globally relevant ones, and uses synthetic data to initialize model parameters, improving convergence. It also employs a zero-trust model, ensuring that data remain on local devices and only learned weights are shared with the central server, enhancing security. The algorithm improves accuracy and computational efficiency, achieving communication efficiency gains of 4 to 14 through backward elimination and threshold variation techniques. Tested on a federated diabetic dataset, the approach demonstrates significant improvements in the performance and trustworthiness of FL systems for medical applications. Nisha Thorakkattu Madathil, Saed Alrabaee, Abdelkader Nasreddine Belkacem |
IEEE J. Sel. Areas Commun. | 2 |
| 2024 | Evaluating and Boosting Cybersecurity Awareness With an AI-Integrated Mobile AppabstractThis innovative practice full paper describes cyber-security Awareness With an AI-Integrated Mobile Application. In the current digital age, where technology and interactions are closely intertwined, the importance of cybersecurity awareness has escalated. It is essential for protecting individuals, organi-zations, and national security. This awareness enables people to make well-informed decisions and apply effective measures against cyberattacks. Human errors and behaviors often in-advertently lead to vulnerabilities, risking exposure to cyber threats. This paper focuses on developing an AI -enhanced mobile application tailored for diverse user groups: children under 14, teenagers between 14 and 18, adults over 18 (including university students, graduates, and the unemployed), and employees. The application aims to evaluate and offer extensive cybersecurity education content divided into three levels for each category, including lessons, videos, stories, scenarios, and exercises to enhance individual awareness levels. Additionally, it leverages AI to provide engaging cybersecurity responses, assess individuals, and support users with chatbot assistance. This strategy educates and empowers users, contributing to a more secure digital landscape. Meera Alalawi, Nisha Thorakkattu Madathil, Simon Kebede Darota, Winner Abula, Saed Alrabaee, Suhib Bani Melhem |
FIE | 5 |
| 2024 | Empowering Future Cyber Defenders: Advancing Cybersecurity Education in Engineering and Computing with Experiential LearningabstractThis research-to-practice full paper describes a cybersecurity education framework aimed at addressing the proliferation of cyber threats such as SQL injection, cross-site scripting, DDoS attacks, and phishing, which necessitate innovative approaches to safeguard global information security. This research proposes an adaptive cybersecurity curriculum incorporating experiential learning strategies such as interactive simulations, hands-on labs, and case studies, initially validated within university environments. Future research will assess their adaptability and effectiveness of these strategies for K-12 education. Advanced concepts like artificial intelligence are distilled into engaging, age-appropriate modules to build both practical and theoretical cybersecurity skills. An experimental study validated the curriculum's effectiveness with test scores increasing from 63.20% to 84.34% and students reporting heightened engagement and deeper conceptual understanding. The experiential level-adaptive design equips learners of all ages with the expertise to proactively secure digital assets and cultivate cybersecurity awareness. Integrating this curriculum across K-12 and higher education will enable academic institutions to produce cybersecurity graduates capable of addressing the evolving complexities of the threat landscape. Muhusina Ismail, Saed Alrabaee |
FIE | 2 |
| 2024 | Revisiting Binary Code Authorship Analysis
Saed Alrabaee, Mousa Al-Kfairy, Mohammad Bany Taha, Omar Alfandi, Fatma Taher |
NSS | 1 |
| 2024 | A Comparative Study on Source Code Attribution Using AI: Datasets, Features, and Techniques
Shamma Alalawi, Saed Alrabaee, Wasif Khan, Issam Al-Azzoni, Medha Mohan Ambali Parambil |
SecureComm (1) | 2 |
| 2024 | Harnessing the Power of Quantum Computing for URL Classification: A Comprehensive Study
Tariq Qayyum, Asadullah Tariq, M. Waqas Haseeb Khan, Saed Alrabaee, Zouheir Trabelsi, Farag M. Sallabi, Mohamed Adel Serhani |
SecureComm (1) | 4 |
| 2024 | Strategic cybersecurity
Saleh H. Aldaajeh, Saed Alrabaee |
Comput. Secur. | 2 |
| 2024 | A Comprehensive Evaluation of Machine Learning Algorithms for Web Application Attack Detection with Knowledge Graph Integration
Muhusina Ismail, Saed Alrabaee, Kim-Kwang Raymond Choo, Luqman Ali, Saad Harous |
Mob. Networks Appl. | 2 |
| 2024 | A Deep Learning Approach to Discover Router Firmware VulnerabilitiesabstractIndustrial Internet of Things (IoT)-connected devices are now nearly ubiquitous in the world, and routers are a central point for connecting these Industrial IoT devices. As a router's firmware controls the basic functions of Industrial IoT devices, it is considered the heart of IoT. An Industrial IoT cyberattack can cause huge damage to the connected devices and harm to their owners. Thus, router firmware vulnerability detection has recently become an emerging issue in this domain. As a result, an efficient and precise detection tool is a necessity to this domain. However, the firmware dataset collection is the most challenging step as there are no open-source datasets available online. A manual effort was required to verify the states of samples in both the Common Vulnerabilities and Exposures and the National Vulnerability Database databases as either vulnerable or benign. After verification, 1450 samples were collected. This article investigates the effectiveness of using convolutional neural networks (CNNs) and computer vision techniques to analyze home router firmware. The collected firmware samples were read as an array of byte strings, divided into subarrays based on the image's dimensions, and then layered on top of one another to produce the firmware images. The images were divided by manufacturer and used as inputs for various CNN models to test their accuracy. Three statistical filtering algorithms were used on each manufacturer's set to produce multiple versions of each set, totaling 24 datasets across four manufacturers, with six datasets per manufacturer (four filtered images and two grayscale and RGB images). The image filter algorithms used include local binary pattern (LBP), histogram of oriented gradients (HOG), and Gabor filter used on the LBP and HOG sets. After testing all the combinations of the filtered/normal datasets with the CNN training model, the HOG filter was the most accurate, with an average accuracy of 85.81% across all tests and models, with results as high as 97.94% when used with the appropriate CNN model. Amjad Abu-Mahfouz, Saed Alrabaee, Mahmoud Khasawneh, Marton Gergely, Kim-Kwang Raymond Choo |
IEEE Trans. Ind. Informatics | 2 |
| 2023 | AI in Education: Improving Quality for Both Centralized and Decentralized FrameworksabstractEducation is essential for achieving many Sustainable Development Goals (SDGs). Therefore, the education system focuses on empowering more educated people and improving the quality of the education system. One of the latest technologies to enhance the quality of education is Artificial Intelligence (AI)-based Machine Learning (ML). As a result, ML has a significant influence on the education system. ML is currently widely applied in the education system for various tasks, such as creating models by monitoring student performance and activities that accurately predict student outcomes, their engagement in learning activities, decision-making, problem-solving capabilities, etc. In this research, we provide a survey of machine learning frameworks for both distributed (clusters of schools and universities) and centralized (university or school) educational institutions to predict the quality of students' learning outcomes and find solutions to improve the quality of their education system. Additionally, this work explores the application of ML in teaching and learning for further improvements in the learning environment for centralized and distributed education systems. Nisha Thorakkattu Madathil, Saed Alrabaee, Mousa Al-Kfairy, Rafat Damseh, Abdelkader Nasreddine Belkacem |
EDUCON | 2 |
| 2023 | Investigating Online Searching Behavior Based on Google Trends in MENA Region Before and After COVID-19abstractThe outbreak of the coronavirus disease (COVID-19) has had a profound impact on education worldwide. The rise of remote learning is one of the most significant changes in this regard, as many schools and universities were forced to close down by regional health authorities. This has also caused people to become more conservative in trade-offs between healthcare and education. Google Trends is the most common tool for analyzing online search behaviors. It is a free resource that provides information on the trends and changes in users' online interests over time based on certain terms and subjects. The online search queries on Google can be used to assess users' behaviors concerning online learning to forecast their choices regarding online education. This paper examines the frequency of users' web searches for online communication tools, courses, and learning terms. We statistically compared users in the Middle East and North Africa regions by using the volumes of searches recorded on Google Trends from January 2016 to August 2022. Moreover, we used machine learning techniques to identify differences among the keywords used. The findings statistically show that COVID-19 has led to an increase in the extent of students' attention to and interest in online learning. Abdelkader Nasreddine Belkacem, Nuraini Jamil, Saed Alrabaee |
FIE | 3 |
| 2023 | The Good, The Bad, and The Ugly About Insta Shopping: A Qualitative StudyabstractInstagram, as many social media platforms, has been increasingly used by users to shop for goods and products from business or other individuals. Recently, studies have shed lights on acceptance and usage of Insta shopping from users’ perspectives by following popular technology models, such as technology acceptance model (TAM) and unified theory of acceptance and use of technology (UTAUT). However, more rich and in-depth insights about using Instagram for commercial purposes within a certain context are yet to be discovered. Therefore, this study aims at discovering experiences and interactions with Insta shopping, the factors and the drivers that impact users’ acceptance of Insta shopping, the weight of each factor (degree of consensus among participants), and their direction (positive, negative, or both). The study followed a qualitative approach, by creating four homogeneous focus groups (six participants each) of IT students in United Arab Emirates (UAE) universities. The data analysis approach considered is an axial coding technique as part of the grounded theory, which includes open coding, axial coding, and selective coding stages. The results revealed that the time factor, trust in Insta shops (and its drivers such as reviews, word of mouth, trading license, and others), distrust (and its drivers such as fake comments and reviews, extremely low prices, and others), and the associated risks (financial for losing money, security because of online payments, and some privacy issues) can impact users’ behaviors toward Insta shopping. Also, the study classified participants’ viewpoints and experiences’ themes into advantages, disadvantages, and issues that are associated with Insta shopping. The study indicated theoretical and practical implications and suggests future research directions. Ahmed Shuhaiber, Mousa Al-Kfairy, Saed Alrabaee |
IEEE Trans. Comput. Soc. Syst. | 3 |
| 2023 | Efficient Resource Management of Micro-Services in VANETsabstractWhile vehicular ad hoc Networks (VANETs) are relatively well-studied, a number of challenges remain, particularly as autonomous vehicles become more commonplace. For example, devices on a vehicle such as, On-Board Units (OBUs) may have resource constraints which render them incapable of supporting computationally expensive cryptography operations required to achieve various security features. One potential solution is to offload computationally expensive tasks to other nodes in the VANET; however, the dynamic nature of the setup (such as the, mobility of the requesting vehicles and other nodes) compounds the challenge of resource management. In this context, we propose a scheme that uses Ciphertext-Policy Attribute-Based Encryption (CP-ABE) to achieve data confidentiality in VANETs despite such challenges. Specifically, we build a cluster of vehicles to perform CP-ABE operations without relying on other nodes in the VANET. We use Kubernetes, an open-source container orchestration system, to build vehicle cluster(s) to handle distributed micro-tasks. In this scheme, we use a set of factors that impact the computation operations in cluster vehicle components (i.e., the OBU). Each factor, including the distance between the data owner vehicle and the target vehicle, the duration of each target vehicle in the cluster, and the resource of each vehicle in the cluster, has a weight based on its influence in computational operations. The Euclidean method is used to calculate the weight value for each factor. Based on the final total weight for each vehicle, our approach distributes the tasks between vehicles. We evaluate our results by comparing our approach with the mechanism of Kubernetes for task distribution, which only considers the resources in each vehicle. We also consider several scenarios with varying factors to evaluate their impact on the execution time of CP-ABE on OBUs in addition to using simulations to evaluate the performance of our approach in terms of transmission and propagation overheads for vehicles in the cluster. Mohammad Bany Taha, Saed Alrabaee, Kim-Kwang Raymond Choo |
IEEE Trans. Intell. Transp. Syst. | 2 |
| 2022 | Efforts and Suggestions for Improving Cybersecurity EducationabstractIn this growing technology epoch, one of the main concerns is about the cyber threats. To tackle this issue, highly skilled and motivated cybersecurity professionals are needed, who can prevent, detect, respond, or even mitigate the effect of such threats. However, the world faces workforce shortage of qualified cybersecurity professionals and practitioners. To solve this dilemma several cybersecurity educational programs have arisen. Before it was just a couple of courses in a computer science graduate program. Now a day’s different cybersecurity courses are introduced at the high school level, undergraduate computer science and information systems programs, even in the government level. Due to some peculiar nature of cybersecurity, educational institutions face many issues when designing a cybersecurity curriculum or cybersecurity activities. Saed Alrabaee, Mousa Al-Kfairy, Ezedin Barka |
EDUCON | 1 |
| 2022 | Safe: Cryptographic Algorithms and Security Principles GamificationabstractThe COVID-19 pandemic has caused dramatic changes in our daily lives. Cyber-attacks have been increasing because of the shift from on-site to online studying and working. Many users have been victims of those attacks without knowing or did not know how to respond to them. Today, there are many cyber-security awareness initiatives; however, they do not seem impactful as victims increase. Unfortunately, these initiatives use traditional education methodology that is considered insufficient nowadays due to the significant growth in technology. Digital native students who came to the world having technology all around them find learning strategies unattractive and disengaging. Hence, staying connected with technology development and changing learning methodologies accordingly is essential. This paper gives an overview of the solution being developed. A cyber-security educational game that includes 11 levels, each level goes over a certain topic, in which players will not be able to pass the level unless they have a certain score of competence in the designated topic. Our project aims to provide a gamified interactive learning experience that educates, develops, enhances creativity and decision-making skills in the field of Information Security. Latifa Al Kaabi, Wadha Al Ketbi, Aysha Al Khoori, Maitha Al Shamsi, Saed Alrabaee |
EDUCON | 5 |
| 2022 | The role of national cybersecurity strategies on the improvement of cybersecurity education
Saleh H. Aldaajeh, Heba Saleous, Saed Alrabaee, Ezedin Barka, Frank Breitinger, Kim-Kwang Raymond Choo |
Comput. Secur. | 3 |
| 2022 | A stratified approach to function fingerprinting in program binaries using diverse features
Saed Alrabaee |
Expert Syst. Appl. | 1 |
| 2021 | Boosting Students and Teachers Cybersecurity Awareness During COVID-19 PandemicabstractThe COVID-19 Coronavirus originating from Wuhan, China has become a global pandemic. In order to protect their country's residents, governments worldwide have ordered schools and companies to close and for people to quarantine at home. This has resulted in a dramatic increase in the use of digital devices and activity on the internet. Cybercriminals around the globe have seen this pandemic as an opportunity to initiate cyberattacks. This paper reviews the cyber threats that threaten users globally, as well as some of the attacks that have already occurred during the COVID-19 pandemic. We then make suggestions to countermeasure these attacks and what can be done in the future to improve cybersecurity awareness and prevent them from occurring again. Saed Alrabaee, Raed Manna |
EDUCON | 1 |
| 2021 | BinDeep: Binary to Source Code Matching Using Deep LearningabstractMapping a binary function taken from a compiled binary to the same function in the original source code has many security applications, such as discovering reused free open source code in malware binaries. To facilitate malware analysis, we present BINDEEP, a framework that learns the semantic relationships among binary functions based on assembly code. It also learns semantic information about the source functions in order to carry out function matching. We demonstrate how BINDEEP can be applied to fingerprint the origin of functions in malware binaries, and then benchmark its performance against that of five competing systems (i.e., RESOURCE, the Binary Analysis Tool (BAT), BinPro, Statistical Machine Translation (SMT), and FOSSIL). The findings show that BINDEEP is more robust and achieves significant improvement over these existing systems when confronted with changes introduced by code transformation methods or the use of different compilers and optimization levels. Furthermore, BINDEEP is able to discover source packages in malware binaries, such as Zeus and Citadel, that match those listed in existing security reports. Saed Alrabaee, Kim-Kwang Raymond Choo, Mohammad Qbea'h, Mahmoud Khasawneh |
TrustCom | 1 |
| 2020 | An Analytical Scanning Technique to Detect and Prevent the Transformed SQL Injection and XSS Attacks
Mohammad Qbea'h, Saed Alrabaee, Djedjiga Mouheb |
ICISSP | 2 |
| 2020 | CPA: Accurate Cross-Platform Binary Authorship Characterization Using LDAabstractBinary authorship characterization refers to the process of identifying stylistic characteristics that are related to the author of an anonymous binary code. The aim is to automate the laborious and error-prone reverse engineering task of discovering information related to the author(s) of binary code. This paper presents CPA, a novel approach for characterizing the authors of program binaries. Instead of using generic features such as n-grams, CPA proposes a set of new features based on collections of various aspects of author style, including author code traits, code structure characteristics, and author expertise in solving coding tasks. It employs the Latent Dirichlet Allocation (LDA) algorithm to generate author style signatures to help identify similar author style characteristics in other binaries. We evaluated CPA on large datasets extracted from selected opensource C/C++ projects in GitHub and Google Code Jam events, and it successfully attributed a large number of authors with a significantly higher F1score: around 91% when the number of authors was 1,500. In addition, the false positive rate was low, around 1.5%. When the code was subjected to refactoring techniques or code transformation or was processed using different compilers/compilation settings, there was no significant drop in accuracy, demonstrating the robustness of our tool. Finally, in the case of code written by multiple authors, CPA was able to identify the authors with a high F1score, around 89%. Saed Alrabaee, Mourad Debbabi, Lingyu Wang 0001 |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2019 | BinEye: Towards Efficient Binary Authorship Characterization Using Deep Learning
Saed Alrabaee, ElMouatez Billah Karbab, Lingyu Wang 0001, Mourad Debbabi |
ESORICS (2) | 1 |
| 2019 | Applied Comparative Evaluation of the Metasploit Evasion ModuleabstractThe great revitalization of information and communication technologies has facilitated broad connectivity to the Internet. However, this convenience in terms of connectivity comes with costly caveats, including internet fraud, information damage or theft, and cybersecurity issues. Most individuals rely on anti-virus software for protection. This anti-virus software has long been a foe to malware authors, but there are brief moments when new techniques slip through the cracks, and even the most sophisticated engines sometimes fail. A new tool, namely Metasploits new evasion modules, claims to exploit that. In this study, we compare and evaluate legacy evasion techniques with the novel tactics presented by Metasploits lead researcher Wei Chen. We consider the benefits and pitfalls of each technique and evaluate the new modules successes (or failures!). Peter Casey, Mateusz Topor, Emily Hennessy, Saed Alrabaee, Moayad Aloqaily, Azzedine Boukerche |
ISCC | 4 |
| 2019 | Decoupling coding habits from functionality for effective binary authorship attributionabstractBinary authorship attribution refers to the process of identifying the author of a given anonymous binary file based on stylistic characteristics. It aims to automate the laborious and error-prone reverse engineering task of discovering information related to the author(s) of a binary code. Existing works typically employ machine learning methods to extract features that are unique for each author and subsequently match them against a given binary to identify the author. However, most existing works share a common critical limitation, i.e., they cannot distinguish between features representing program functionality and those representing authorship (e.g., authors’ coding habits). Such distinction is crucial for effective authorship attribution because what is unique in a particular binary may be attributed to either author, compiler, or function. In this study, we present BinAuthor a system capable of decoupling program functionality from authors’ coding habits in binary code. To capture coding habits, BinAuthor leverages a set of features that are based on collections of functionality-independent choices made by authors during coding. Our evaluation demonstrates that BinAuthor outperforms existing methods in several aspects. First, it successfully attributes a larger number of authors with a significantly higher accuracy (around [Formula: see text]) based on the large datasets extracted from selected open-source C[Formula: see text] projects in GitHub, Google Code Jam events, Planet Source Code contests, and several programming projects. Second, BinAuthor is more robust than previous methods; there is no significant drop in accuracy when the code is subjected to refactoring techniques, simple obfuscation, and processed with different compilers. Finally, decoupling authorship from functionality allows us to apply BinAuthor to real malware binaries (Citadel, Zeus, Stuxnet, Flame, Bunny, and Babar) to automatically generate evidence on similar coding habits. Saed Alrabaee, Paria Shirani, Lingyu Wang 0001, Mourad Debbabi, Aiman Hanna |
J. Comput. Secur. | 1 |
| 2018 | On Leveraging Coding Habits for Effective Binary Authorship Attribution
Saed Alrabaee, Paria Shirani, Lingyu Wang 0001, Mourad Debbabi, Aiman Hanna |
ESORICS (1) | 1 |
| 2018 | FOSSIL: A Resilient and Efficient System for Identifying FOSS Functions in Malware BinariesabstractIdentifying free open-source software (FOSS) packages on binaries when the source code is unavailable is important for many security applications, such as malware detection, software infringement, and digital forensics. This capability enhances both the accuracy and the efficiency of reverse engineering tasks by avoiding false correlations between irrelevant code bases. Although the FOSS package identification problem belongs to the field of software engineering, conventional approaches rely strongly on practical methods in data mining and database searching. However, various challenges in the use of these methods prevent existing function identification approaches from being effective in the absence of source code. To make matters worse, the introduction of obfuscation techniques, the use of different compilers and compilation settings, and software refactoring techniques has made the automated detection of FOSS packages increasingly difficult. With very few exceptions, the existing systems are not resilient to such techniques, and the exceptions are not sufficiently efficient. To address this issue, we propose FOSSIL , a novel resilient and efficient system that incorporates three components. The first component extracts the syntactical features of functions by considering opcode frequencies and applying a hidden Markov model statistical test. The second component applies a neighborhood hash graph kernel to random walks derived from control-flow graphs, with the goal of extracting the semantics of the functions. The third component applies z-score to the normalized instructions to extract the behavior of instructions in a function. The components are integrated using a Bayesian network model, which synthesizes the results to determine the FOSS function. The novel approach of combining these components using the Bayesian network has produced stronger resilience to code obfuscation. We evaluate our system on three datasets, including real-world projects whose use of FOSS packages is known, malware binaries for which there are security and reverse engineering reports purporting to describe their use of FOSS, and a large repository of malware binaries. We demonstrate that our system is able to identify FOSS packages in real-world projects with a mean precision of 0.95 and with a mean recall of 0.85. Furthermore, FOSSIL is able to discover FOSS packages in malware binaries that match those listed in security and reverse engineering reports. Our results show that modern malware binaries contain 0.10--0.45 of FOSS packages. Saed Alrabaee, Paria Shirani, Lingyu Wang 0001, Mourad Debbabi |
ACM Trans. Priv. Secur. | 1 |
| 2016 | Power trading in cognitive radio networks
Mahmoud Khasawneh, Saed Alrabaee, Anjali Agarwal, Nishith Goel, Marzia Zaman |
J. Netw. Comput. Appl. | 2 |