Benjamin Aziz

dblp:15/2711 · DBLP profile ↗
← Back
42ranked-venue papers
24as first author
10since 2021 · last 2026
0000-0001-5089-2025ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 23 · 13 first-author · 3 since 2021Software engineering, systems software and programming languages · 5 · 3 first-author · 2 since 2021Applied, interdisciplinary, general and emerging computing · 5 · 3 first-author · 4 since 2021Computer networks · 3 · 2 first-authorArtificial intelligence and machine learning · 2 · 1 first-author · 1 since 2021Systems, architecture and hardware · 2 · 2 first-authorDatabases, data management, data science and information retrieval · 1Theory of computation · 1
YearPublicationVenuePosition
2026 Towards a set-theoretic model of security policies for database-defined networks
Benjamin Aziz
Sci. Comput. Program.1
2025 A Deontic Logic Model of Attribute-Based Information Flows in Database-Defined Networks with Application to Healthcare Monitoring
Benjamin Aziz, Ukamaka Oragwu, Safa Tharib
ICISSP (2)1
2025 Requirements Cube: Towards a Matrix-Based Model of Requirements
Benjamin Aziz, Gareth Hewlett, Ukamaka Oragwu, Peter Richards, Safa Tharib, Erica Y. Yang
ICSOFT1
2025 Extending the GeoJSON Standard with Deontic Logic Policies
Benjamin Aziz
WEBIST1
2025 A machine learning approach for detecting cybersecurity vulnerabilities in the internet of medical things
Ukamaka Oragwu, Benjamin Aziz, Shahadate Rezvy
Knowl. Based Syst.2
2024 An Extended Method for Transmitting Secret Messages in Textual Documents Based on Paragraph Resizing
Benjamin Aziz, Estabraq H. Makiyah, Aysha Bukhelli
SECRYPT1
2023 Detecting the Manipulation of Text Structure in Text Steganography Using Machine Learning
abstract
We evaluate in this paper the security of a recent method proposed in literature for the embedding of hidden \ncontent in textual documents using paragraph size manipulation. Our steganalysis is based on machine learning, \nand the classification method we use for the analysis of a document utilises text attributes, such as words per \nparagraph, paragraph proportion based on sentences and other English document features. The embedding \nmodel showed to be resilient against the analysis techniques, where the highest plotted accuracy was 0.601, \nwhich is considered poor. The analysis methods were able to detect around half of the embedded corpus, which \nis equivalent to random guess. We concluded that it is difficult to detect an embedding model that manipulates \nparagraphs of novel texts, as the structure of these texts depend fully on the writer’s style of writing. Thus by \nshifting the sentences up and down paragraphs without changing the order of the sentences and affecting the \ncontext of the text, it yields a reasonably secure method of embedding.
Benjamin Aziz, Aysha Bukhelli
WEBIST1
2022 A Novel Method for Embedding and Extracting Secret Messages in Textual Documents based on Paragraph Resizing
Benjamin Aziz, Aysha Bukhelli, Rinat Khusainov, Alaa Mohasseb
SECRYPT1
2022 Using Feature Analysis to Guide Risk Calculations of Cyber Incidents
Benjamin Aziz, Alaa Mohasseb
WEBIST1
2021 The LeWiS Method: Target Variable Estimation using Cyber Security Intelligence
Leigh Chase, Alaa Mohasseb, Benjamin Aziz
WEBIST3
2020 Towards Secure Data Sharing Processes in Online Social Networks: Trusty
abstract
The development of Web 2.0 has remarkably increased in today's world.These development has also been a reason for the increment of online social networks (OSNs).Web 2.0 is the roof of the online social networks since online social networks are built on Web 2.0.Users are given an environment in which they can communicate with others without considering other users locations.The way of communication in OSNs is done via sharing various contents of data, such as photos, texts, and videos.Sharing data sometimes cause privacy problems in OSNs, especially in the case that the content involves different users information on itself.Users are notified after the content is shared and they are allowed to remove tags.The content is still available in OSNs platforms, users, therefore, find a way to punish other users with being unfriend, or they quit from OSNs.However, both cases are contradictory with the main of OSNs.By considering the above issues, we develop a framework in which users' opinions are taken on data sharing process and based on the final decision, which is taken by the user who posts the content, punishing or rewarding technique is used.We also evaluate the proposed work with users interactions.
Gulsum Akkuzu, Benjamin Aziz, Mo Adda
ICSOFT2
2020 SMS Spam Identification and Risk Assessment Evaluations
abstract
Short Message Service (SMS) constitutes one of the most used communication medium.It has become an integral part of people's lives and like other communication media, SMS texts have been used for propagating spam messages.Despite the fact that a broad range of spam techniques have been proposed to reduce the frequency of such incidents, many difficulties are still present due to text ambiguity; there, the same words can be used in seemingly similar texts which makes it more difficult to identify spam messages.In this paper, we propose an approach for identifying and classifying spam SMS based on the Syntactical features and patterns of the message.The proposed approach consists of three main parts, namely Data Pre-processing, Features Extraction, and Classification.Experimental results show that the proposed approach achieves a good level of accuracy.In addition, to show the effectiveness of handling class imbalance on the classification performance, two additional experiments were conducted using the implementation of the SMOTE algorithm.There, the results depicted that handling class imbalance help in improving identification and classification accuracy.Furthermore, based on the above, a risk model has been proposed that addresses the risk probability and the impact of spam SMS.
Alaa Mohasseb, Benjamin Aziz, Andreas Kanavos
WEBIST2
2020 Smart routing: Towards proactive fault handling of software-defined networks
abstract
In recent years, the emerging paradigm of software-defined networking has become a hot and thriving topic in both the industrial and academic sectors. Software-defined networking offers numerous benefits against legacy networking systems by simplifying the process of network management through reducing the cost of network configurations. Currently, data plane fault management is limited to two mechanisms: proactive and reactive. These fault management and recovery techniques are activated only after a failure occurrence and hence packet loss is highly likely to occur. This is due to convergence time where new network paths will need to be allocated in order to forward the affected traffic rather than drop it. Such convergence leads to temporary service disruption and unavailability. Practically, not only the speed of recovery mechanisms affects the convergence, but also the delay caused by the process of failure detection. In this paper, we define a new approach for data plane fault management in software-defined networks where the goal is to eliminate the convergence process altogether rather than accelerate the failure detection and recovery. We propose a new framework, called Smart Routing, which allows the network controller to receive forewarning signs on failures and hence avoid risky paths before the failure incidents occur. The proposed approach aims to decrease service disruption, which in turn increases network service availability. We validate our framework through a set of experiments that demonstrate how the underlying model runs and its impact on improving service availability. We take as example of the applicability of the new framework three types of topologies covering real and simulated networks.
Ali Malik, Benjamin Aziz, Mo Adda, Chih-Heng Ke
Comput. Networks2
2020 Modeling and Analyzing an Industry 4.0 Communication Protocol
abstract
The increasing complexity and criticality of industrial automation systems, embodied by the concept of Industry 4.0, which brings together concepts, such as cyber-physical systems, the Internet of Things, big data, and artificial intelligence, call for more formality in specifying the technology standards underlying these systems. We define in this article a formal model of an Industry 4.0 machine-to-machine communication protocol, Hermes, used in specifying electronic board transfers in an assembly line. Our analysis of the formal specification reveals that despite the robustness of the protocol, many testing scenarios have been ignored in the protocol standard and in particular, scenarios that include simultaneous machine errors. Therefore, this article paves the way for a better informed testing strategy in Industry 4.0 systems that implement the protocol.
Benjamin Aziz
IEEE Internet Things J.1
2020 Cyber security incidents analysis and classification in a case study of Korean enterprises
abstract
Abstract The increasing amount and complexity of Cyber security attacks in recent years have made text analysis and data mining techniques an important factor in discovering features of such attacks and detecting future security threats. In this paper, we report on the results of a recent case study that involved the analysis of a community data set collected from five small and medium companies in Korea. The data set represents Cyber security incidents and response actions. We investigated in the study the kind of problems concerned with the prediction of response actions to future incidents from features of past incidents. Our analysis is based on text mining methods, such as n-gram and bag-of-words, as well as on machine learning algorithms for the classification of incidents and their response actions. Based on the results of the study, we also suggest an experience-sharing model, which we use to demonstrate how companies may share their trained classifiers without the sharing of their individual data sets in a collaborative environment.
Alaa Mohasseb, Benjamin Aziz, Jeyong Jung, Julak Lee
Knowl. Inf. Syst.2
2019 Fuzzy Logic Decision based Collaborative Privacy Management Framework for Online Social Networks
abstract
Online Social Networks (OSNs) have become one of the most popular implement for interacting with people all over the world and sharing data with them.These data sometimes may be a co-owned data which involves multiple users, sharing co-owned data can cause privacy violation if co-owners are not happy with the owner's sharing privacy settings.To tackle privacy issues on co-owned data, collaborative privacy management has become a popular research area in recent years.In this work, we provide a fuzzy logic decision based collaborative privacy management framework for OSNs.We use data sensitivity value and confidence value in targeted group as input variables of fuzzy system.We also use trust values between users since our framework needs to calculate trust loss and gains for reputation value.
Gulsum Akkuzu, Benjamin Aziz, Mo Adda
ICISSP2
2019 Predicting CyberSecurity Incidents using Machine Learning Algorithms: A Case Study of Korean SMEs
abstract
The increasing amount and complexity of cyber security attacks in recent years have made text analysis and data-mining based techniques an important factor in detecting security threats. However, despite the popularity of text and other data mining techniques, the cyber security community has remained somehow reluctant in adopting an open approach to security-related data. In this paper, we analyze a dataset that has been collected from five Small and Medium companies in South Korea, this dataset represents cyber security incidents and response actions. We investigate how the data representing different incidents collected from multiple companies can help improve the classification accuracy and help the classifiers in distinguishing between different types of incidents. A model has been developed using text mining methods, such as n-gram, bag-of-words and machine learning algorithms for the classification of incidents and their response actions. Experimental results have demonstrated good performance of the classifiers for the prediction of different types of response and malware.
Alaa Mohasseb, Benjamin Aziz, Jeyong Jung, Julak Lee
ICISSP2
2018 Towards a mutation analysis of IoT protocols
Benjamin Aziz
Inf. Softw. Technol.1
2017 Enhancing IoT Security and Privacy with Distributed Ledgers - A Position Paper -
abstract
The Internet of Things has a number of well-publicised security flaws, resulting in numerous recent attacks.In this paper we lay out a framework for looking at how distributed ledgers and Blockchain technology can be used to enhance the security, privacy and manageability of IoT devices and networks.A significant concern is the inability to process blockchains on small devices.We propose an architecture for IoT security and privacy based on blockchains that addresses this and other issues.We look at related work and propose areas of further research.
Paul Fremantle, Benjamin Aziz, Tom Kirkham
IoTBDS2
2017 New Computing Model for Securing Mobile Agents in IP Networks
abstract
This paper deals with the prevention of security issues on mobile agents in IP Networks.We propose a new security computing model based on trusted server to avert Eavesdropping and Alternation attacks.The new protocol will be implemented using IBM mobile agent platform, Aglet.The new framework consists of components that provide support to the mobile agent while it is touring hosts in the agent space.It also protects the confidentiality and integrity of parts of the mobile agent.We conduct performance analysis over different types of mobile agents over a real IP Traces under malicious actions.
Jean Tajer, Mo Adda, Benjamin Aziz
IoTBDS3
2017 Finding most reliable paths for software defined networks
abstract
In this paper, we introduce a new approach that computes the shortest-reliable end-to-end paths for centrally controlled networks like software-defined networks (SDNs). The proposed method aims to find the correlation between the routing mechanism and reliability with the purpose of decreasing the required time of backup path installation through reducing the number of required rules at the moment of failure towards guarantee the fast restoration of the affected path, hence leading to the reduction of the overhead on SDN network controller and the probability of the loss of packets. We also investigate the correlation between the network topology and its reliability and demonstrate the benefits from this relation through experiments using well-known SDN network simulation tools.
Ali Malik, Benjamin Aziz, Mohamed Bahy Bader-El-Den
IWCMC2
2016 Search-Based SQL Injection Attacks Testing Using Genetic Programming
Benjamin Aziz, Mohamed Bahy Bader-El-Den, Cerana Hippolyte
EuroGP1
2016 A Utility-Based Reputation Model for the Internet of Things
Benjamin Aziz, Paul Fremantle, Rui Wei, Álvaro Enrique Arenas
SEC1
2016 A formal model and analysis of an IoT protocol
Benjamin Aziz
Ad Hoc Networks1
2016 Modelling Fine-Grained Access Control Policies in Grids
Benjamin Aziz
J. Grid Comput.1
2015 Incremental Development of RBAC-Controlled E-Marking System Using the B Method
abstract
Role Based Access Control (RBAC) models are access policies that associate access rights to roles of subjects on objects. The incremental development of software by adding new features and the insertion of new access rules potentially render the model inconsistent and create security flaws. This paper proposes modeling RBAC models using the B language such that it is possible to reevaluate the consistency of the models following model changes. It shows the mechanism of formalizing RBAC policies of an Electronic Marking System (EMS) using B specifications and illustrates the verification of the consistency of the RBAC specification, using model checking and proof obligations.
Nasser Al-Hadhrami, Benjamin Aziz, Shantanu Sardesai, Lotfi Ben Othmane
ARES2
2014 A Formal Model and Analysis of the MQ Telemetry Transport Protocol
abstract
We present a formal model of the MQ Telemetry Transport version 3.1 protocol based on a timed message-passing process algebra. We explain the modeling choices that we made, including pointing out ambiguities in the original protocol specification, and we carry out a static analysis of the formal protocol model, which is based on an approximation of a name-substitution semantics for algebra. The analysis reveals that the protocol behaves correctly as specified against the first two quality of service modes of operation providing at most once and at least once delivery semantics to the subscribers. However, we find that the third and highest quality of service semantics is prone to error and at best ambiguous in certain aspects of its specification. Finally, we suggest an enhancement of this level of QoS for the protocol.
Benjamin Aziz
ARES1
2014 A Formal Model for Forensic Storage Media Preparation Tools
abstract
This paper defines a model of a special type of digital forensics tools, known as digital media preparation forensic tools, using the formal refinement language Event-B. The complexity and criticality of many types of computer and Cyber crime nowadays combined with improper or incorrect use of digital forensic tools calls for the evidence produced by such tools to be able to meet the minimum admissibility standards the legal system requires, in general implying that it must be generated from reliable and robust tools. Despite the fact that some research and effort has been spent on the validation of digital media preparation forensic tools by means of testing (e.g. within NIST), the verification of such tools and the formal specification of their expected behaviour remains largely under-researched. The goal of this work is to provide a formal specification against which the implementations of such tools can be analysed and tested in the future.
Benjamin Aziz, Philippe Massonet, Christophe Ponsard
SECRYPT1
2013 Reputation-Controlled Business Process Workflows
abstract
This paper presents a model solution for controlling the execution of BPEL business processes based on reputation constraints at the level of the services, the service providers and the BPEL workflow. The reputation constraints are expressed as part of an SLA and are then enforced at runtime by a reputation monitoring system. We use our model to demonstrate how trust requirements based on such reputation constraints can be upheld in a real world example of a distributed map processing defined as a BPEL workflow.
Benjamin Aziz, Geoff W. Hamilton
ARES1
2013 Using a Goal-Driven Approach in the Investigation of a Questioned Contract
Clive Blackwell, Shareeful Islam, Benjamin Aziz
IFIP Int. Conf. Digital Forensics3
2011 Correcting a Delegation Protocol for Grids
Benjamin Aziz
TrustBus1
2011 Verifying a delegation protocol for grid systems
Benjamin Aziz, Geoff W. Hamilton
Future Gener. Comput. Syst.1
2010 A Secure and Scalable Grid-Based Content Management System
abstract
We present in this paper a secure and scalable Grid-based content management system for the management of high-volume multimedia data in the domain of the publishing industry. This is achieved by leveraging on existing individual solutions, such as the Alfresco content management system, the SRM standard for building scalable solutions based on the Grid and the GridTrust services for building trustworthy and secure Grid systems. Our solution brings closer the use of the Grid to the enterprise community within the context of a real world use case scenario. The solution facilitates the fine-grained usage control of the storage resources and a reputation-based matching between resource policies and users' past behaviour.
Benjamin Aziz, Álvaro Enrique Arenas, Giovanni Cortese, Bruno Crispo, Silvio Causetti
ARES1
2010 An Event-B Approach to Data Sharing Agreements
Álvaro Enrique Arenas, Benjamin Aziz, Juan Bicarregui, Michael D. Wilson
IFM2
2010 Management of Security Policies in Virtual Organisations
Benjamin Aziz, Álvaro Enrique Arenas, Ian Johnson, Matej Artac, Ales Cernivec
SECRYPT1
2010 Reputation management in collaborative computing systems
abstract
Abstract In collaborative systems, a set of organizations shares their computing resources, such as compute cycles, storage space or on‐line services, in order to establish Virtual Organizations (VOs) aimed at achieving common tasks. The formation and operation of Virtual Organizations involve establishing trust among their members and reputation is one measure by which such trust can be quantified and reasoned about. In this paper, we contribute to research in the area of trust for collaborative computing systems along two directions: first, we provide a survey on the main reputation‐based systems that fulfil the trust requirements for collaborative systems, including reputation systems designed for e‐commerce, agent‐based environments, and Peer‐to‐Peer computing and Grid‐based systems. Second, we present a model for reputation management for Grid Virtual Organizations that is based on utility computing and that can be used to rate users according to their resource usage and resources and their providers according to the quality of service they deliver. We also demonstrate, through Grid simulations, how the model can be used in improving completion and welfare in Virtual Organizations. Copyright © 2009 John Wiley & Sons, Ltd.
Álvaro Enrique Arenas, Benjamin Aziz, Gheorghe Cosmin Silaghi
Secur. Commun. Networks2
2009 Configuring storage-area networks using mandatory security
abstract
Storage-area networks are a popular and efficient way of building large storage systems both in an enterprise environment and for multi-domain storage service providers. In both environments the network and the storage has to be configured to ensure that the data is maintained securely and can be delivered efficiently. In this paper, we describe a model of mandatory security for SAN services that incorporates the notion of risk as a measure of the robustness of the SAN's configuration and that formally defines a vulnerability common in systems with mandatory security, i.e. cascaded threats. Our abstract SAN model is flexible enough to reflect the data requirements, tractable for the administrator, and can be implemented as part of an automatic configuration system. The implementation is given as part of a prototype written in OPL.
Benjamin Aziz, Simon N. Foley, John Herbert, Garret Swart
J. Comput. Secur.1
2008 Modelling Security Properties in a Grid-based Operating System with Anti-Goals
abstract
In this paper, we discuss the use of formal requirements-engineering techniques in capturing security requirements for a Grid-based operating system. We use KAOS goal model to represent two security goals for Grid systems, namely authorisation and single-sign on authentication. We apply goal-refinement to derive security requirements for these two security goals and we develop a model of anti-goals and show how system vulnerabilities and threats to the security goals can arise from such anti-models.
Álvaro Enrique Arenas, Benjamin Aziz, Juan Bicarregui, Brian Matthews, Erica Y. Yang
ARES2
2008 Reputation Management in Grid-based Virtual Organisations
Álvaro Enrique Arenas, Benjamin Aziz, Gheorghe Cosmin Silaghi
SECRYPT2
2008 Controlling Usage in Business Process Workflows through Fine-Grained Security Policies
Benjamin Aziz, Álvaro Enrique Arenas, Fabio Martinelli, Ilaria Matteucci, Paolo Mori
TrustBus1
2005 Trading Off Security in a Service Oriented Architecture
Garret Swart, Benjamin Aziz, Simon N. Foley, John Herbert
DBSec2
2004 Configuring Storage Area Networks for Mandatory Security
abstract
Storage-area networks are a popular and efficient way of building large storage systems both in an enterprise environment and for multi-domain storage service providers. In both environments the network and the storage has to be configured to ensure that the data is maintained securely and can be delivered efficiently. In this paper we describe a model of mandatory security for multi-domain storage services that is flexible enough to reflect the data requirements, tractable for the administrator, and implementable as part of an automatic configuration system. We describe the model abstractly, its implementation as part of a prototype SAN configuration system written in OPL, and illustrate its operation on a set of sample configurations. These keywords were added by machine and not by the authors. This process is experimental and the keywords may be updated as the learning algorithm improves.
Benjamin Aziz, Simon N. Foley, John Herbert, Garret Swart
DBSec1