Ahmed H. Anwar

dblp:129/1516 · also Ahmed Hemida · DBLP profile ↗
← Back
19ranked-venue papers
8as first author
14since 2021 · last 2025
0000-0001-8907-3043ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 13 · 4 first-author · 10 since 2021Systems, architecture and hardware · 1 · 1 first-author · 1 since 2021Security and privacy · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 first-authorApplied, interdisciplinary, general and emerging computing · 1 · 1 first-author
YearPublicationVenuePosition
2025 Defending Internet of Things Against Energy Depletion Attack Using Bayesian Game
abstract
Due to their limited resources, Internet of Things (IoT) networks are vulnerable to attacks like aggressive denial-of-service (DoS) attacks aimed at draining device energy. IoT devices often have non-rechargeable or hard-to-recharge batteries, especially when deployed in hostile areas, making them prime targets for energy depletion attacks such as barrage attacks. To mitigate these threats, security systems must implement lightweight measures. This paper proposes a new game theory-based mechanism to defend IoT devices against energy depletion. Game theory effectively models the adversarial interactions between attackers and defenders. Our approach uses a dynamic game with incomplete information to derive optimal detection, defense, and attack strategies, establishing a Perfect Bayesian Nash Equilibrium (PBNE) to protect IoT device energy under constant attack. This dynamic game involves repeated interactions where at least one player lacks complete information about the other. The proposed model offers a high-performance solution for conserving IoT device energy. Simulation results demonstrate its effectiveness, showing that it can save, on average, 95.19% of the energy expended in receiving packets during an attack and can deter attackers. This approach ensures the sustainability of IoT networks against persistent energy depletion attacks.
Ines Carole Kombou Sihomnou, Abderrahim Benslimane, Ahmed H. Anwar, Gabriel Deugoue, Charles A. Kamhoua
IEEE Internet Things J.3
2024 Mitigating Energy Attacks in Wireless Sensor Networks Using Deception: A Game Theoretic Approach
abstract
Wireless Sensor Networks (WSNs) consist of devices communicating information wirelessly from a monitored field. Sensors are designed with limited energy resources pushing application designers to optimize energy consumption. It is common practice in WSNs to organize nodes in clusters with a device (designed as a cluster head) with superior energy resources. However, this clustered architecture exposes vulnerabilities, particularly to energy depletion attacks targeting the cluster head. Energy depletion attacks pose a significant threat to sensor node survival. To overcome such attacks, we propose a cyber deception defense mechanism based on game theory to model the actions between the attacker agent and the cluster head agent and hence, extract optimal strategies during conflicting interactions between the agents. In this paper, we propose using a game with incomplete information to find the Nash equilibrium point. Cyber deception, particularly the integration of a honeypot system, is employed to enhance the solution’s effectiveness in optimizing cluster head energy in the face of potential attacks. The proposed solution demonstrates its effectiveness in mitigating attacks of varying intensity against the cluster head.
Ines Carole Kombou Sihomnou, Abderrahim Benslimane, Ahmed H. Anwar, Gabriel Deugoue, Charles A. Kamhoua, Chakchai So-In
GLOBECOM3
2024 Countering ARP spoofing attacks in software-defined networks using a game-theoretic approach
Fabrice Mvah, Vianney Kengne Tchendji, Clémentin Tayou Djamégni, Ahmed H. Anwar, Deepak K. Tosh, Charles A. Kamhoua
Comput. Secur.4
2024 Optimizing Effectiveness and Defense of Drone Surveillance Missions via Honey Drones
abstract
This work aims to develop a surveillance mission system using unmanned aerial vehicles (UAVs) or drones when Denial-of-Service (DoS) attacks are present to disrupt normal operations for mission systems. In particular, we introduce the concept of cyber deception using honey drones (HDs) to protect the mission system from DoS attacks. HDs exhibit fake vulnerabilities and employ stronger signal strengths to lure DoS attacks, unlike the legitimate drones called mission drones (MDs) deployed for mission execution. This research formulates an optimization problem to identify an optimal set of signal strengths of HDs and MDs to best prevent the system from DoS attacks while maximizing mission performance under the resource constraints of UAVs. To solve this optimization problem, we leverage deep reinforcement learning (DRL) to achieve these multiple objectives of the mission system concerning system security and performance. Particularly, for efficient and effective parallel processing in DRL, we utilize a DRL algorithm called the Asynchronous Advantage Actor-Critic (A3C) algorithm to model attack-defense interactions. We employ a physical engine-based simulation testbed to consider realistic scenarios and demonstrate valid findings from the realistic testbed. The extensive experiments proved that our HD-based approach could achieve up to a 32% increase in mission completion, a 20% reduction in energy consumption, and a 62% decrease in attack success rates compared to existing defense strategies.
Zelin Wan, Jin-Hee Cho, Ahmed H. Anwar, Charles A. Kamhoua, Munindar P. Singh
ACM Trans. Internet Techn.4
2023 Mitigating Energy Depletion Attack In Wireless Sensor Network Using Signaling Game
abstract
Nowadays, with the evolution of technology, sensor networks have experienced a real boom. Due to their constitutions, sensors suffer from low security and are therefore susceptible to different types of attacks. Wireless sensor networks (WSNs) deployed in hostile environments suffer particularly from energetic attacks, i.e. attacks aimed at shortening the life cycle of sensors. Sensors have limited energy resources; replacing or recharging nodes in hostile environments is difficult. Attacks that cause a drain on the energy level are the most common attacks in a hostile environment and can lead to the death of sensors such as sleep denial attacks. In this paper, we design a game model using a signaling game within clusters that enables both detection and defense against attackers. In this paper, we identify and impose penalties on nodes that practice sleep deprivation torture in WSNs. The simulations showed that the model is able to force the attacker to behave normally in a WSN.
Ines Carole Kombou Sihomnou, Abderrahim Benslimane, Ahmed H. Anwar, Gabriel Deugoue, Frederica Free-Nelson, Charles A. Kamhoua
ICC3
2023 Deception in Drone Surveillance Missions: Strategic vs. Learning Approaches
abstract
Unmanned Aerial Vehicles (UAVs) have been used for surveillance operations, search and rescue missions, and delivery services. Given their importance and versatility, they naturally become targets for cyberattacks. Denial-of-Service (DoS) attacks are commonly considered to exhaust their resources or crash UAVs (or drones). This work proposes a unique proactive defense using honey drones (HD) for UAVs during surveillance operations. These HDs use lightweight virtual machines to lure and redirect potential DoS attacks. Both the choice of target by the attacker and the HD's deceptive tactics are influenced by the strength of the radio signal. However, a critical trade-off exists in that stronger signals can deplete battery life, while weaker signals can negatively affect the connectivity of a drone fleet network. To address this, we formulate an optimization problem to select the best strategies for an attacker or defender in selecting their signal strength level. We propose a novel HD-based defense to identify the optimal setting using deep reinforcement learning (DRL) or game theory and compare their performance with that of non-HD-based methods, such as Intrusion Detection Systems and ContainerDrone. Our experiments demonstrate the unique benefits and superior efficacy of each HD-based defense across various attack scenarios.
Zelin Wan, Jin-Hee Cho, Ahmed H. Anwar, Charles A. Kamhoua, Munindar P. Singh
MobiHoc4
2023 Optimal Honeypot Allocation using Core Attack Graph in Cyber Deception Games
abstract
Honeypots appear today as a defense strategy to trap intelligent cyber attackers who can detect traditional security measures. The scalability of existing algorithms for solving some classes of game theory is very limited due to large-scale networks. This paper opens the door to a new approach to allocate honeypots in the network, to increase attackers’ costs, during the lateral movement of the APT attack. We use the core attack graph that can show the main routes an attacker can take toward the goal. This allows the defender to use a limited number of honeypots focusing its efforts only on critical nodes over the main attacker routes. The effectiveness and scalability of the proposed approach are evaluated over different network topologies, a varying number of honeypots, network size, and density. Numerical results show that the defender reward over the core attack graph is quite similar to that obtained on the original attack graph while significantly reducing the defender’s actions and computation time.
Achile Leonel Nguemkam, Ahmed H. Anwar, Vianney Kengne Tchendji, Deepak K. Tosh, Charles A. Kamhoua
PIMRC2
2023 Resisting Multiple Advanced Persistent Threats via Hypergame-Theoretic Defensive Deception
abstract
Existing defensive deception (DD) approaches apply game theory, assuming that an attacker and defender play the same, full game with all possible strategies. However, in deceptive settings, players may have different beliefs about the game itself. Such structural uncertainty is not naturally handled in traditional game theory. In this work, we formulate an attackdefense hypergame where multiple advanced persistent threat (APT) attackers and a single defender play a repeated game with different perceptions. The hypergame model systematically evaluates how various DD strategies can defend proactively against APT attacks. We present an adaptive method to select an optimal defense strategy using hypergame theory for strategic defense as well as machine learning for adaptive defense. We conducted in-depth experiments to analyze the performance of the eight schemes including ours, baselines, and existing counterparts. We found the DD strategies showed their highest advantages when the hypergame and machine learning are considered in terms of reduced false positives and negatives of the NIDS, system lifetime, and players’ perceived uncertainties and utilities. We also analyze the Hyper Nash Equilibrium of given hypergames and discuss the key findings and insights behind them.
Zelin Wan, Jin-Hee Cho, Ahmed H. Anwar, Charles A. Kamhoua, Munindar P. Singh
IEEE Trans. Netw. Serv. Manag.4
2022 Cyber Deception using Honeypot Allocation and Diversity: A Game Theoretic Approach
abstract
Cyber deception has become the core of advanced enterprise-level defense systems. It is also being used for early detection by many experts. In this paper, we propose a novel approach for cyber deception using honeypot allocation and software diversity to enhance network security. The network defender chooses where to place the honeypots given a limited budget of resources. Also, we consider an interesting tradeoff between the level of software diversity to be implemented in the network and the operational cost incurred due to using different types of honeypots. To this end, we formulate a game-theoretic approach to characterize the honeypot allocation policy that protects the most valuable resources of the network. Moreover, we develop a game model between the two players to investigate the diversity tradeoff. Our results show that careful honeypot allocation is critical to protect high-value nodes and validate the proposed software-diversity approach.
Ahmed H. Anwar, Charles A. Kamhoua
CCNC1
2022 Honeypot-Based Cyber Deception Against Malicious Reconnaissance via Hypergame Theory
abstract
Malicious reconnaissance is a critical step for attackers to collect sufficient network knowledge and choose valuable targets for intrusion. Defensive deception (DD) is an essential strategy against threats by misleading attackers' observations and beliefs. Honeypots are widely used for cyber deception that aims to confuse attackers and waste their resources and efforts. Defenders may use low-interaction honeypots or high-interaction honeypots. In this paper, we consider a hybrid honeypot system that balances the use of the two levels of honeypot complexity, where high-interaction honeypots are more capable of deceiving skilled attackers than low-interaction honeypots. We present a two-player hypergame model that characterizes how a defender should deploy low and high-interaction honeypots to defend the network against malicious reconnaissance activities. We model the tradeoff of each player and characterize their best strategies within a hypergame framework that considers the imperfect knowledge of each player toward their opponent. Finally, our numerical results validate the effectiveness of the proposed honeypot system.
Ahmed H. Anwar, Zelin Wan, Jin-Hee Cho, Charles A. Kamhoua, Munindar P. Singh
GLOBECOM1
2022 Honeypot Allocation for Cyber Deception Under Uncertainty
abstract
Cyber deception aims to misrepresent the state of the network to mislead the attackers, falsify their reconnaissance conclusions, and deflect them away from their goals. Honeypots serve as decoy devices inside networks that can capture adversaries for monitoring purposes. We propose a two-phase deception approach based on honeypot allocation. In the first phase, we develop a proactive deceptive honeypot allocation policy, the second phase proposes a reactive deception approach that dynamically allocates honeypots according to IDS updates. Considering a practical scenario, the defender partially monitors the adversary’s activities. To this end, we develop our deception approach using a combination of game-theoretic and reinforcement learning models. We cast the problem of reactive deception as a partially observable Markov decision process (POMDP) based on a game-theoretic dynamic model to accommodate the imperfect monitoring of the actions taken by the attacker. We solve this combined partially observable game model using Monte-Carlo tree search to overcome the game model complexity. We give a game-theoretic analysis to explain the attack-defense policies at equilibrium. Finally, we present numerical results to validate the effectiveness of the proposed deception approach.
Ahmed H. Anwar, Charles A. Kamhoua, Nandi Leslie, Christopher Kiekintveld
IEEE Trans. Netw. Serv. Manag.1
2022 Foureye: Defensive Deception Against Advanced Persistent Threats via Hypergame Theory
abstract
Defensive deception techniques have emerged as a promising proactive defense mechanism to mislead an attacker and thereby achieve attack failure. However, most game-theoretic defensive deception approaches have assumed that players maintain consistent views under uncertainty. They do not consider players’ possible, subjective beliefs formed due to asymmetric information given to them. In this work, we formulate a hypergame between an attacker and a defender where they can interpret the same game differently and accordingly choose their best strategy based on their respective beliefs. This gives a chance for defensive deception strategies to manipulate an attacker’s belief, which is the key to the attacker’s decision-making. We consider advanced persistent threat (APT) attacks, which perform multiple attacks in the stages of the cyber kill chain (CKC) where both the attacker and the defender aim to select optimal strategies based on their beliefs. Through extensive simulation experiments, we demonstrated how effectively the defender can leverage defensive deception techniques while dealing with multi-staged APT attacks in a hypergame in which the imperfect information is reflected based on perceived uncertainty, cost, and expected utilities of both the attacker and defender, the system lifetime (i.e., mean time to security failure), and improved false-positive rates of intrusion detection.
Zelin Wan, Jin-Hee Cho, Ahmed H. Anwar, Charles A. Kamhoua, Munindar P. Singh
IEEE Trans. Netw. Serv. Manag.4
2021 Deep Learning for Cyber Deception in Wireless Networks
abstract
Wireless communications networks are an integral part of intelligent systems that enhance the automation of various activities and operations embarked by humans. For example, the development of intelligent devices imbued with sensors leverages emerging technologies such as machine learning (ML) and artificial intelligence (AI), which have proven to enhance military operations through communication, control, intelligence gathering, and situational awareness. However, growing concerns in cybersecurity imply that attackers are always seeking to take advantage of the widened attack surface to launch adversarial attacks which compromise the activities of legitimate users. To address this challenge, we leverage on deep learning (DL) and the principle of cyber-deception to propose a method for defending wireless networks from the activities of jammers. Specifically, we use DL to regulate the power allocated to users and the channel they use to communicate, thereby luring jammers into attacking designated channels that are considered to guarantee maximum damage when attacked. Furthermore, by directing its energy towards the attack on a specific channel, other channels are freed up for actual transmission, ensuring secure communication. Through simulations and experiments carried out, we conclude that this approach enhances security in wireless communication systems.
Felix O. Olowononi, Ahmed H. Anwar, Danda B. Rawat, Jaime C. Acosta, Charles A. Kamhoua
MSN2
2021 A Game-Theoretic Framework for the Virtual Machines Migration Timing Problem
abstract
In a multi-tenant cloud, a number of Virtual Machines (VMs) are collocated on the same physical machine to optimize performance, power consumption and maximize profit. This, however, increases the risk of a malicious VM performing side-channel attacks and leaking sensitive information from neighboring VMs. As such, this paper develops and analyzes a game-theoretic framework for the VM migration timing problem in which the cloud provider decideswhento migrate a VM to a different physical machine to reduce the risk of being compromised by a collocated malicious VM. The adversary decides the rate at which she launches new VMs to collocate with the victim VMs. Our formulation captures a data leakage model in which the cost incurred by the cloud provider depends on the duration of collocation with malicious VMs. It also captures costs incurred by the adversary in launching new VMs and by the defender in migrating VMs. We establish sufficient conditions for the existence of Nash equilibria for general cost functions, as well as for specific instantiations, and characterize the best response for both players. Furthermore, we extend our model to characterize its impact on the attacker’s payoff when the cloud utilizes intrusion detection systems that detect side-channel attacks. Our theoretical findings are corroborated with extensive numerical results in various settings as well as a proof-of-concept implementation in a realistic cloud setting.
Ahmed H. Anwar, George Atia, Mina Guirguis
IEEE Trans. Cloud Comput.1
2020 Software Diversity for Cyber Deception
abstract
In this paper, we propose a cyber deception approach using software diversity in a honeynet. Honeypot allocation is used as an active cyber deception technique to increase the uncertainty of adversaries and hide the true state of the network. Moreover, software diversity limits the ability of attackers to discover honeypots. Specifically, this paper introduces a diversity-based honeypot allocation approach for network security formulated in a game-theoretic framework. We consider a two-player zero-sum game between the network defender and the adversary. To validate our findings, we measured the potential benefits of diversity on network security and calculated the optimum diversifying strategy in Nash equilibrium using different honeypot types.
Aliou Badra Sarr, Ahmed H. Anwar, Charles A. Kamhoua, Nandi Leslie, Jaime C. Acosta
GLOBECOM2
2019 A game-theoretic framework for dynamic cyber deception in internet of battlefield things
abstract
Cyber deception techniques are crucial to protect networks in battlefield settings and combat malicious cyber attacks. Cyber deception can effectively disrupt the surveillance process outcome of an adversary. In this paper, we propose a novel approach for cyber deception to protect important nodes and trap the adversary. We present a sequential approach of honeypot placement to defend and protect the network vital nodes. We formulate a stochastic game to study the dynamic interactions between the network administrator and the attacker. The defender makes strategic decisions about where to place honeypots to introduce new vulnerabilities to the network. The attacker's goal is to develop an attack strategy to compromise the nodes of the network by exploiting a set of known vulnerabilities. To consider a practical threat model, we assume that the attacker can only observe a noisy version of the network state. To this end, both players solve a partially observable stochastic game (POSG). Finally, we present a discussion on existing techniques to solve the formulated game and possible approaches to reduce the game complexity as part of our ongoing and future research.
Ahmed H. Anwar, Charles A. Kamhoua, Nandi Leslie
MobiQuitous1
2019 Pinball attacks against Dynamic Channel assignment in wireless networks
Ahmed H. Anwar, Janiece Kelly, George Atia, Mina Guirguis
Comput. Commun.1
2018 It's Time to Migrate! A Game-Theoretic Framework for Protecting a Multi-Tenant Cloud against Collocation Attacks
abstract
We present a novel game-theoretic framework for the Virtual Machine (VM) migration timing problem. In a multi-tenant cloud, a number of VMs are collocated on the same physical machine. This increases the risk of a malicious VM performing side-channel attacks and leaking sensitive information. To this end, this paper develops and analyzes a game-theoretic framework for the timing problem in which the cloud provider decides when to migrate a VM to a different physical machine to reduce the risk of being compromised by a collocated malicious VM. The adversary decides the rate at which she launches new VMs to collocate with the victim VMs. Our formulation captures a data leakage model in which the cost incurred by the cloud provider depends on the duration of collocation as well as the overhead in migration. We establish sufficient conditions for the existence of Nash equilibria for general cost functions, as well as for specific instantiations, and characterize the best response for both players. Our theoretical findings are corroborated with extensive numerical results in various settings.
Ahmed H. Anwar, George Atia, Mina Guirguis
IEEE CLOUD1
2018 Adaptive topologies against jamming attacks in wireless networks: A game-theoretic approach
Ahmed H. Anwar, George Atia, Mina Guirguis
J. Netw. Comput. Appl.1