EDBT 2026 Demo / reviewers in the wild / expert
Abdelaziz Amara Korba
dblp:130/8830
· DBLP profile ↗
22ranked-venue papers
9as first author
19since 2021 · last 2026
0000-0001-7605-4660ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 10 · 3 first-author · 10 since 2021Security and privacy · 4 · 3 first-author · 1 since 2021Artificial intelligence and machine learning · 2 · 2 since 2021Systems, architecture and hardware · 1 · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Privacy-Preserving Edge-Offloaded Split Federated Learning for In-vehicle Intrusion Detection
Abdelaziz Amara Korba, Bouziane Brik |
IWCMC | 1 |
| 2026 | Collaborative privacy-preserving network intrusion detection: A federated multi-agent reinforcement learning approachabstractMachine learning has significantly advanced Intrusion Detection Systems in cybersecurity. However, current ML-based IDS solutions often struggle to keep pace with evolving attack patterns and new types of threats, as most models require complete retraining. Additionally, training these models requires large datasets, which are difficult to obtain due to privacy concerns. Moreover, in real-world environments, attacks occur with varying frequencies across organizations, resulting in non-identically distributed (non-IID) data, diminishing detection effectiveness. To address these challenges, we propose a novel Federated Multi-Agent Reinforcement Learning architecture. This architecture consists of a two-level reinforcement learning framework composed of N independent RL agents at the first level, each trained in a federated manner using a class-level FedAvg aggregation scheme to detect a specific attack type, while the second level features a decision agent that aggregates their outputs for final classification. Each RL agent employs an enhanced Deep Q-Network (DQN) incorporating cost-sensitive learning and a weighted mean square loss function to handle class imbalance and adapt to heterogeneous non-IID data. Reinforcement learning enables adaptation to evolving attack patterns, while federated learning addresses data scarcity and privacy concerns. Additionally, the modular design reduces model bias and enables seamless updates in response to new attacks. Experimental results using the CIC-IDS-2017 dataset confirm FMARL’s robustness, adaptability, and efficiency, achieving 99% accuracy across most configurations, maintaining a minimum of 97% accuracy even in extreme non-IID scenarios, with a notably low false positive rate. Amine Tellache, Abdelaziz Amara Korba, Amdjed Mokhtari, Yacine Ghamri-Doudane |
Comput. Commun. | 2 |
| 2026 | Towards better random forests with tree weighting, accuracy and diversity-preserving pruningabstractRandom forests are widely recognized for their robustness and generalization across diverse datasets. However, their performance can be hindered by the inclusion of redundant or weakly contributing trees, which may dilute ensemble accuracy and reduce model diversity. This paper presents WRFO , a novel approach for Weighted Random Forest Optimization. WRFO aims to improve random forests mainly through dynamic (1) tree weighting and (2) accuracy and diversity-preserving pruning. WRFO leverages particle swarm optimization to selectively preserve the most informative trees where the latter are assigned higher weights based on their diversity and predictive contribution. This results in a leaner, more accurate, and more diverse ensemble. We present comprehensive experiments on 24 UCI benchmark datasets as well as on a real-world scenario for network intrusion detection. The obtained results demonstrate the effectiveness of WRFO in real-world scenarios and show that it consistently outperforms three state-of-the-art Random Forest methods. Nour El Islem Karabadji, Ali Assi 0002, Abdelaziz Amara Korba, Ahmed Abdulaziz Al Nuaim, Hassina Seridi-Bouchelaghem, Mohamed Elati, Wajdi Dhifli |
Expert Syst. Appl. | 3 |
| 2026 | LLM-assisted end-to-end binary decompilation: a hierarchical generation and semantic reconstruction approach
Yousuf Al-Ruqaishi, Abdelaziz Amara Korba, Sharifa Al Khanjari |
J. Supercomput. | 2 |
| 2026 | $\mathsf {DARTIC}$: Decentralized Anonymous Reputation at Scale for Trustworthy CrowdsourcingabstractInternational audience Mouhamed Amine Bouchiha, Mourad Rabah, Ronan Champagnat, Abdelaziz Amara Korba, Yacine Ghamri-Doudane |
IEEE Trans. Serv. Comput. | 4 |
| 2025 | Advancing Autonomous Incident Response: Leveraging LLMs and Cyber Threat IntelligenceabstractEffective incident response (IR) is critical for mitigating cyber threats, yet security teams are overwhelmed by alert fatigue, high false-positive rates, and the vast volume of unstructured Cyber Threat Intelligence (CTI) documents. While CTI holds immense potential for enriching security operations, its extensive and fragmented nature makes manual analysis time-consuming and resource-intensive. To bridge this gap, we introduce a novel Retrieval-Augmented Generation (RAG)-based framework that leverages Large Language Models (LLMs) to automate and enhance IR by integrating dynamically retrieved CTI. Our approach introduces a hybrid retrieval mechanism that combines NLP-based similarity searches within a CTI vector database with standardized queries to external CTI platforms, facilitating context-aware enrichment of security alerts. The augmented intelligence is then leveraged by an LLM-powered response generation module, which formulates precise, actionable, and contextually relevant incident mitigation strategies. We propose a dual evaluation paradigm, wherein automated assessment using an auxiliary LLM is systematically cross-validated by cybersecurity experts. Empirical validation on real-world and simulated alerts demonstrates that our approach enhances the accuracy, contextualization, and efficiency of IR, alleviating analyst workload and reducing response latency. This work underscores the potential of LLM-driven CTI fusion in advancing autonomous security operations and establishing a foundation for intelligent, adaptive cybersecurity frameworks. Amine Tellache, Abdelaziz Amara Korba, Amdjed Mokhtari, Horea Moldovan, Yacine Ghamri-Doudane |
GLOBECOM | 2 |
| 2025 | BotDetect: A Decentralized Federated Learning Framework for Detecting Financial Bots on the EVM BlockchainsabstractThe rapid growth of decentralized finance (DeFi) has led to the widespread use of automated agents, or bots, within blockchain ecosystems like Ethereum, Binance Smart Chain, and Solana. While these bots enhance market efficiency and liquidity, they also raise concerns due to exploitative behaviors that threaten network integrity and user trust. This paper presents a decentralized federated learning (DFL) approach for detecting financial bots within Ethereum Virtual Machine (EVM)-based blockchains. The proposed framework leverages federated learning, orchestrated through smart contracts, to detect malicious bot behavior while preserving data privacy and aligning with the decentralized nature of blockchain networks. Addressing the limitations of both centralized and rule-based approaches, our system enables each participating node to train local models on transaction history and smart contract interaction data, followed by on-chain aggregation of model updates through a permissioned consensus mechanism. This design allows the model to capture complex and evolving bot behaviors without requiring direct data sharing between nodes. Experimental results demonstrate that our DFL framework achieves high detection accuracy while maintaining scalability and robustness, providing an effective solution for bot detection across distributed blockchain networks. Ahmed Mounsf Rafik Bendada, Abdelaziz Amara Korba, Mouhamed Amine Bouchiha, Yacine Ghamri-Doudane |
ICC | 2 |
| 2025 | Zero-Day Botnet Attack Detection in IoV: A Modular Approach Using Isolation Forests and Particle Swarm OptimizationabstractThe Internet of Vehicles (IoV) is transforming transportation by enhancing connectivity and enabling autonomous driving. However, this increased interconnectivity introduces new security vulnerabilities. Bot malware and cyberattacks pose significant risks to Connected and Autonomous Vehicles (CAVs), as demonstrated by real-world incidents involving remote vehicle system compromise. To address these challenges, we propose an edge-based Intrusion Detection System (IDS) that monitors network traffic to and from CAVs. Our detection model is based on a meta-ensemble classifier capable of recognizing known (N day) attacks and detecting previously unseen (zero-day) attacks. The approach involves training multiple Isolation Forest (IF) models on Multi-access Edge Computing (MEC) servers, with each IF specialized in identifying a specific type of botnet attack. These IFs, either trained locally or shared by other MEC nodes, are then aggregated using a Particle Swarm Optimization (PSO) based stacking strategy to construct a robust meta-classifier. The proposed IDS has been evaluated on a vehicular botnet dataset, achieving an average detection rate of $92.80 \%$ for N -day attacks and $77.32 \%$ for zero-day attacks. These results highlight the effectiveness of our solution in detecting both known and emerging threats, providing a scalable and adaptive defense mechanism for CAVs within the IoV ecosystem. Abdelaziz Amara Korba, Nour El Islem Karabadji, Yacine Ghamri-Doudane |
ISCC | 1 |
| 2025 | Fuse and Federate: Enhancing EV Charging Station Security with Multimodal Fusion and Federated LearningabstractThe rapid global adoption of electric vehicles (EVs) has established electric vehicle supply equipment (EVSE) as a critical component of smart grid infrastructure. While essential for ensuring reliable energy delivery and accessibility, EVSE systems face significant cybersecurity challenges, including network reconnaissance, backdoor intrusions, and distributed denial-of-service (DDoS) attacks. These emerging threats, driven by the interconnected and autonomous nature of EVSE, require innovative and adaptive security mechanisms that go beyond traditional intrusion detection systems (IDS). Existing approaches, whether network-based or host-based, often fail to detect sophisticated and targeted attacks specifically crafted to exploit new vulnerabilities in EVSE infrastructure. This paper proposes a novel intrusion detection framework that leverages multimodal data sources, including network traffic and kernel events, to identify complex attack patterns. The framework employs a distributed learning approach, enabling collaborative intelligence across EVSE stations while preserving data privacy through federated learning. Experimental results demonstrate that the proposed framework outperforms existing solutions, achieving a detection rate above $98 \%$ and a precision rate exceeding $97 \%$ in decentralized environments. This solution addresses the evolving challenges of EVSE security, offering a scalable and privacypreserving response to advanced cyber threats. Rabah Rahal, Abdelaziz Amara Korba, Yacine Ghamri-Doudane |
ISCC | 2 |
| 2025 | Towards Trustworthy Agentic IoEV: AI Agents for Explainable Cyberthreat Mitigation and State AnalyticsabstractThe Internet of Electric Vehicles (IoEV) envisions a tightly coupled ecosystem of electric vehicles (EVs), charging infrastructure, and grid services, yet remains vulnerable to cyberattacks, unreliable battery-state predictions, and opaque decision processes that erode trust and performance. To address these challenges, we introduce a novel Agentic Artificial Intelligence (AAI) framework tailored for IoEV, where specialized agents collaborate to deliver autonomous threat mitigation, robust analytics, and interpretable decision support. Specifically, we design an AAI architecture comprising dedicated agents for cyber-threat detection and response at charging stations, real-time State of Charge (SoC) estimation, and State of Health (SoH) anomaly detection, all coordinated through a shared, explainable reasoning layer; develop interpretable threat-mitigation mechanisms that proactively identify and neutralize attacks on both physical charging points and learning components; propose resilient SoC and SoH models that leverage continuous and adversarial-aware learning to produce accurate, uncertainty-aware forecasts with human-readable explanations; and implement a three-agent pipeline, where each agent uses LLM-driven reasoning and dynamic tool invocation to interpret intent, contextualize tasks, and execute formal optimizations for user-centric assistance. Finally, we validate our framework through comprehensive experiments across diverse IoEV scenarios, demonstrating significant improvements in security and prediction accuracy. All datasets, models, and code will be released publicly. Meryem Malak Dif, Mouhamed Amine Bouchiha, Abdelaziz Amara Korba, Yacine Ghamri-Doudane |
LCN | 3 |
| 2025 | Mitigating IoT botnet attacks: An early-stage explainable network-based anomaly detection approachabstractAs the Internet of Things (IoT) continues to expand, botnet-driven threats pose a growing and severe risk to the security of IoT-enabled infrastructures. These threats exploit large numbers of compromised devices to establish covert control channels and, eventually, launch large-scale cyberattacks such as Distributed Denial of Service (DDoS), capable of severely disrupting critical services and causing substantial economic damage. This paper highlights the urgent need for detecting botnets at an early stage, particularly by identifying stealthy command and control (C&C) traffic that precedes the execution of such attacks. We propose an anomaly-based detection framework that combines semi-supervised learning with explainable Artificial Intelligence (XAI). Unlike most existing approaches, our method requires only benign traffic for training, thereby enabling the detection of previously unseen or evolving botnet threats without relying on labeled malicious data. The framework supports multiple traffic representations, including raw bytes, packet-level data, and unidirectional or bidirectional flows, enriched with diverse network features to enhance detection coverage and adaptability. Experimental evaluations using the IoT-23 dataset demonstrate a 99.51% detection rate and a 1.09% false positive rate for stealthy C&C communications, underscoring the method’s effectiveness and robustness. The integration of XAI enhances transparency and interpretability, enabling security professionals to better understand model decisions and refine detection strategies. Abdelaziz Amara Korba, Alaeddine Diaf, Mouhamed Amine Bouchiha, Yacine Ghamri-Doudane |
Comput. Commun. | 1 |
| 2024 | BARTPredict: Empowering IoT Security with LLM-Driven Cyber Threat PredictionabstractThe integration of Internet of Things (IoT) technology in various domains has led to operational advancements, but it has also introduced new vulnerabilities to cybersecurity threats, as evidenced by recent widespread cyberattacks on IoT devices. Intrusion detection systems are often reactive, triggered by specific patterns or anomalies observed within the network. To address this challenge, this work proposes a proactive approach to anticipate and preemptively mitigate malicious activities, aiming to prevent potential damage before it occurs. This paper proposes an innovative intrusion prediction framework empowered by Pre-trained Large Language Models (LLMs). The framework incorporates two LLMs: a fine-tuned Bidirectional and Auto-Regressive Transformers (BART) model for predicting network traffic and a fine-tuned Bidirectional Encoder Representations from Transformers (BERT) model for evaluating the predicted traffic. By harnessing the bidirectional capabilities of BART the framework then identifies malicious packets among these predictions. Evaluated using the CICIoT2023 IoT attack dataset, our framework showcases a notable enhancement in predictive performance, attaining an impressive 98% overall accuracy, providing a powerful response to the cybersecurity challenges that confront IoT networks. Alaeddine Diaf, Abdelaziz Amara Korba, Nour El Islem Karabadji, Yacine Ghamri-Doudane |
GLOBECOM | 2 |
| 2024 | AI-Driven Fast and Early Detection of IoT Botnet Threats: A Comprehensive Network Traffic Analysis ApproachabstractIn the rapidly evolving landscape of cyber threats targeting the Internet of Things (IoT) ecosystem, and in light of the surge in botnet-driven Distributed Denial of Service (DDoS) and brute force attacks, this study focuses on the early detection of IoT bots. It specifically addresses the detection of stealth bot communication that precedes and orchestrates attacks. This study proposes a comprehensive methodology for analyzing IoT network traffic, including considerations for both unidirectional and bidirectional flow, as well as packet formats. It explores a wide spectrum of network features critical for representing network traffic and characterizing benign IoT traffic patterns effectively. Moreover, it delves into the modeling of traffic using various semi-supervised learning techniques. Through extensive experimentation with the IoT-23 dataset-a comprehensive collection featuring diverse botnet types and traffic scenarios-we have demonstrated the feasibility of detecting botnet traffic corresponding to different operations and types of bots, specifically focusing on stealth command and control (C2) communications. The results obtained have demonstrated the feasibility of identifying C2 communication with a $100 \%$ success rate through packet-based methods and $94 \%$ via flow-based approaches, with a false positive rate of $1.53 \%$. Abdelaziz Amara Korba, Aleddine Diaf, Yacine Ghamri-Doudane |
IWCMC | 1 |
| 2024 | A Life-long Learning Intrusion Detection System for 6G-Enabled IoVabstractThe introduction of 6G technology into the Internet of Vehicles (IoV) promises to revolutionize connectivity with ultra-high data rates and seamless network coverage. However, this technological leap also brings significant challenges, particularly for the dynamic and diverse IoV landscape, which must meet the rigorous reliability and security requirements of 6G networks. Furthermore, integrating 6G will likely increase the IoV’s susceptibility to a spectrum of emerging cyber threats. Therefore, it is crucial for security mechanisms to dynamically adapt and learn new attack patterns, keeping pace with the rapid evolution and diversification of these threats - a capability currently lacking in existing systems. This paper presents a novel intrusion detection system leveraging the paradigm of life-long (or continual) learning. Our methodology combines class-incremental learning with federated learning, an approach ideally suited to the distributed nature of the IoV. This strategy effectively harnesses the collective intelligence of Connected and Automated Vehicles (CAVs) and edge computing capabilities to train the detection system. To the best of our knowledge, this study is the first to synergize class-incremental learning with federated learning specifically for cyber attack detection. Through comprehensive experiments on a recent network traffic dataset, our system has exhibited a robust adaptability in learning new cyber attack patterns, while effectively retaining knowledge of previously encountered ones. Additionally, it has proven to maintain high accuracy and a low false positive rate. Abdelaziz Amara Korba, Souad Sebaa, Malik Mabrouki, Yacine Ghamri-Doudane, Karima Benatchba |
IWCMC | 1 |
| 2024 | Multi-agent Reinforcement Learning-based Network Intrusion Detection SystemabstractIntrusion Detection Systems (IDS) play a crucial role in ensuring the security of computer networks. Machine learning has emerged as a popular approach for intrusion detection due to its ability to analyze and detect patterns in large volumes of data. However, current ML-based IDS solutions often struggle to keep pace with the ever-changing nature of attack patterns and the emergence of new attack types. Additionally, these solutions face challenges related to class imbalance, where the number of instances belonging to different classes (normal and intrusions) is significantly imbalanced, which hinders their ability to effectively detect minor classes. In this paper, we propose a novel multi-agent reinforcement learning (RL) architecture, enabling automatic, efficient, and robust network intrusion detection. To enhance the capabilities of the proposed model, we have improved the DQN algorithm by implementing the weighted mean square loss function and employing cost-sensitive learning techniques. Our solution introduces a resilient architecture designed to accommodate the addition of new attacks and effectively adapt to changes in existing attack patterns. Experimental results realized using CIC-IDS-2017 dataset, demonstrate that our approach can effectively handle the class imbalance problem and provide a fine-grained classification of attacks with a very low false positive rate. In comparison to the current state-of-the-art works, our solution demonstrates superiority in both detection rate and false positive rate. Amine Tellache, Amdjed Mokhtari, Abdelaziz Amara Korba, Yacine Ghamri-Doudane |
NOMS | 3 |
| 2023 | Reinforcement Learning-Based Security Orchestration for 5G-V2X Network Slicing at Cross-BordersabstractAs part of the 5G, Connected and Automated Vehicles (CAVs) will benefit from Network Slicing (NS) in several tailored 5G- Vehicle-to-Everything (V2X) services running on the same physical infrastructure. However, the use of 5G- NS may also increase the risk of cyber-attacks that could compromise 5G-V2X network slices (5G-V2X-NSs) and cause significant harm to CAV's passengers. This risk is particularly high at cross-borders, where CAVs move from their Home Mobile Network Operator (H-MNO) to a Visited MNO (V-MNO), with similar 5G-V2X-NSs in place. Therefore, deploying security services to neutralize 5G- V2X NS threats in this scenario is mandatory. However, if H-MNO and V-MNO act independently, deploying these security services could be inefficient and may result in increased memory, processing, and network resource consumption. Thus, MNOs should collaborate to orchestrate their security services to neutralize 5G-V2X NS attacks and optimize their costs efficiently. In this context, this paper proposes a novel approach to enhance the security of 5G-V2X NS at cross-borders using Reinforcement Learning (RL) based security orchestration. Specifically, we trained and deployed an RL agent interacting with both H-MNO and V-MNO. The RL agent efficiently deploys security services to effectively remove threats, optimize resource utilization, and minimize the impact on 5G-V2X-NSs. The performance results show that the RL-based security orchestration neutralizes threats with an average success rate of almost 100%. Additionally, resource consumption is minimal at less than 8 %, and the acceptable impact on 5G- V2X - NSs is negligible, averaging less than 12 %. Abdelwahab Boualouache, Abdelaziz Amara Korba, Sidi-Mohammed Senouci, Yacine Ghamri-Doudane, Thomas Engel 0001 |
GLOBECOM | 2 |
| 2023 | Federated Learning for Zero-Day Attack Detection in 5G and Beyond V2X NetworksabstractDeploying Connected and Automated Vehicles (CAVs) on top of 5G and Beyond networks (5GB) makes them vulnerable to increasing vectors of security and privacy attacks. In this context, a wide range of advanced machine/deep learning-based solutions have been designed to accurately detect security attacks. Specifically, supervised learning techniques have been widely applied to train attack detection models. However, the main limitation of such solutions is their inability to detect attacks different from those seen during the training phase, or new attacks, also called zero-day attacks. Moreover, training the detection model requires significant data collection and labeling, which increases the communication overhead, and raises privacy concerns. To address the aforementioned limits, we propose in this paper a novel detection mechanism that leverages the ability of the deep auto-encoder method to detect attacks relying only on the benign network traffic pattern. Using federated learning, the proposed intrusion detection system can be trained with large and diverse benign network traffic, while preserving the CAVs' privacy, and minimizing the communication overhead. The in-depth experiment on a recent network traffic dataset shows that the proposed system achieved a high detection rate while minimizing the false positive rate, and the detection delay. Abdelaziz Amara Korba, Abdelwahab Boualouache, Bouziane Brik, Rabah Rahal, Yacine Ghamri-Doudane, Sidi-Mohammed Senouci |
ICC | 1 |
| 2023 | Accuracy and diversity-aware multi-objective approach for random forest construction
Nour El Islem Karabadji, Abdelaziz Amara Korba, Ali Assi 0002, Hassina Seridi-Bouchelaghem, Sabeur Aridhi, Wajdi Dhifli |
Expert Syst. Appl. | 2 |
| 2021 | Detecting DDoS Attacks in IoT EnvironmentabstractWith the great potential of internet of things (IoT) infrastructure in different domains, cyber-attacks are also rising commensurately. Distributed denials of service (DDoS) attacks are one of the cyber security threats. This paper will focus on DDoS attacks by adding the design of an intrusion detection system (IDS) tailored to IoT systems. Moreover, machine learning techniques will be investigated to distinguish the data representing flows of network traffic, which include both normal and DDoS traffic. In addition, these techniques will be used to help make a refined detection model for identifying different types of DDoS attacks. Furthermore, the performance of machine learning-based proposed solution is validated using N-BaIoT dataset and compared through different evaluation metrics. The experimental results show that the proposed IDS not only detects DDoS attacks types but also has a high detection rate and low false positive rate, which argues the usefulness of the proposed approach in comparison with several existing DDoS attacks detection techniques. Yasmine Labiod, Abdelaziz Amara Korba, Nassira Ghoualmi-Zine |
Int. J. Inf. Secur. Priv. | 2 |
| 2020 | Anomaly-based framework for detecting power overloading cyberattacks in smart grid AMI
Abdelaziz Amara Korba, Nouredine Tamani, Yacine Ghamri-Doudane, Nour El Islem Karabadji |
Comput. Secur. | 1 |
| 2016 | Hybrid Intrusion Detection Framework for Ad hoc networksabstractIn this paper, a cluster-based hybrid security framework called HSFA for ad hoc networks is proposed and evaluated. The proposed security framework combines both specification and anomaly detection techniques to efficiently detect and prevent wide range of routing attacks. In the proposed hierarchical architecture, cluster nodes run a host specification-based intrusion detection system to detect specification violations attacks such as fabrication, replay, etc. While the cluster heads run an anomaly-based intrusion detection system to detect wormhole and rushing attacks. The proposed specification-based detection approach relies on a set of specifications automatically generated, while anomaly-detection uses statistical techniques. The proposed security framework provides an adaptive response against attacks to prevent damage to the network. The security framework is evaluated by simulation in presence of malicious nodes that can launch different attacks. Simulation results show that the proposed hybrid security framework performs significantly better than other existing mechanisms. Abdelaziz Amara Korba, Mehdi Nafaa, Salim Ghanemi |
Int. J. Inf. Secur. Priv. | 1 |
| 2016 | An efficient intrusion detection and prevention framework for ad hoc networksabstractPurpose Wireless multi-hop ad hoc networks are becoming very attractive and widely deployed in many kinds of communication and networking applications. However, distributed and collaborative routing in such networks makes them vulnerable to various security attacks. This paper aims to design and implement a new efficient intrusion detection and prevention framework, called EIDPF, a host-based framework suitable for mobile ad hoc network’s characteristics such as high node’s mobility, resource-constraints and rapid topology change. EIDPF aims to protect an AODV-based network against routing attacks that could target such network. Design/methodology/approach This detection and prevention framework is composed of three complementary modules: a specification-based intrusion detection system to detect attacks violating the protocol specification, a load balancer to prevent fast-forwarding attacks such as wormhole and rushing and adaptive response mechanism to isolate malicious node from the network. Findings A key advantage of the proposed framework is its capacity to efficiently avoid fast-forwarding attacks and its real-time detection of both known and unknown attacks violating specification. The simulation results show that EIDPF exhibits a high detection rate, low false positive rate and no extra communication overhead compared to other protection mechanisms. Originality/value It is a new intrusion detection and prevention framework to protect ad hoc network against routing attacks. A key strength of the proposed framework is its ability to guarantee a real-time detection of known and unknown attacks that violate the protocol specification, and avoiding wormhole and rushing attacks by providing a load balancing route discovery. Abdelaziz Amara Korba, Mehdi Nafaa, Salim Ghanemi |
Inf. Comput. Secur. | 1 |