EDBT 2026 Demo / reviewers in the wild / expert
Joseph Khoury
dblp:16/6389
· DBLP profile ↗
16ranked-venue papers
5as first author
12since 2021 · last 2026
0000-0002-6219-2875ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 5 · 2 first-author · 5 since 2021Computer networks · 4 · 4 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1Theory of computation · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Beyond Arbitrary Thresholds: Conformal Prediction for Trustworthy CAN Bus Intrusion Detection
Anthony Nasry Massaad, Aleksandar Avdalovic, Peyton Andras, Joseph Khoury, Elias Bou-Harb |
ICC | 4 |
| 2025 | Enhancing Network Security Management in Water Systems using FM-based Attack AttributionabstractWater systems are vital components of modern infrastructure, yet they are increasingly susceptible to sophisticated cyber attacks with potentially dire consequences on public health and safety. While state-of-the-art machine learning techniques effectively detect anomalies, contemporary model-agnostic attack attribution methods using LIME, SHAP, and LEMNA are deemed impractical for large-scale, interdependent water systems. This is due to the intricate interconnectivity and dynamic interactions that define these complex environments. Such methods primarily emphasize individual feature importance while falling short of addressing the crucial sensor-actuator interactions in water systems, which limits their effectiveness in identifying root cause attacks. To this end, we propose a novel model-agnostic Factorization Machines (FM)-based approach that capitalizes on water system sensor-actuator interactions to provide granular explanations and attributions for cyber attacks. For instance, an anomaly in an actuator pump activity can be attributed to a top root cause attack candidates, a list of water pressure sensors, which is derived from the underlying linear and quadratic effects captured by our approach. We validate our method using two real-world water system specific datasets, SWaT and WADI, demonstrating its superior performance over traditional attribution methods. In multi-feature cyber attack scenarios involving intricate sensor-actuator interactions, our FM-based attack attribution method effectively ranks attack root causes, achieving approximately 20% average improvement over SHAP and LEMNA. Additionally, our approach maintains strong performance in single-feature attack scenarios, demonstrating versatility across different types of cyber attacks. Notably, our approach maintains a low computational overhead equating to an O(n) time complexity, making it suitable for real-time applications in critical water system infrastructure. Our work underscores the importance of modeling feature interactions in water systems, offering a robust tool for operators to diagnose and mitigate root cause attacks more effectively. Aleksandar Avdalovic, Joseph Khoury, Ahmad F. Taha, Elias Bou-Harb |
NOMS | 2 |
| 2025 | Internet-Wide Analysis, Characterization, and Family Attribution of IoT Malware: A Comprehensive Longitudinal StudyabstractThis study presents a large-scale empirical analysis of real-life Internet-of-Things (IoT) malware by conducting a comprehensive analysis of 160,000 malicious executables detected by specialized IoT honeypots over five years. Our findings contribute to improving the knowledge of IoT malware characteristics and inter-relationships, which in return, contribute towards strengthening cybersecurity measures for IoT threat detection/mitigation. To achieve these goals, we leverage various malware analysis techniques to extract useful information from the executable files. Our analysis demonstrate that in contrast to non-IoT malware, we were able to extract unsolicited IP addresses and command strings from the majority of the analyzed IoT malware binaries using off-the-shelf de-obfuscation techniques/tools. Additionally, by correlating the extracted information and performing consequent similarity analysis using NLP-based features, we were able to reveal closely related samples with shared implementation across the adversarial infrastructure. Thus, contributing to labeling previously unseen/unknown IoT malware samples while uncovering emerging, possibly new variants. Finally, given such findings, we discuss the applications of a real-time IoT honeypot, which enables capturing real-time commands from malware-infected IoT devices while enabling timely and effective IoT-malware detection, analysis, labeling, and mitigation. Sadegh Torabi, Dorde Klisura, Joseph Khoury, Elias Bou-Harb, Chadi Assi, Mourad Debbabi |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2024 | Characterizing and Analyzing LEO Satellite Cyber Landscape: A Starlink Case StudyabstractUshering into the ‘New Space Era’, characterized by a reduction in launch expenses and simultaneous proliferation of commercial and governmental entities involved, the prominence of Low Earth Orbit (LEO) satellite technology in the sphere of Internet connectivity has risen to the forefront. However, due to current limitations under the overarching principle of ‘security-through-obscurity’, few to no research efforts have shed light on the intricacies of these networks. To this end, this paper harnesses a multilayer empirical approach in an effort to conduct an exploratory characterization and scrutiny of the cybersecurity landscape of Starlink, the largest LEO network. Using our built-in arsenal of data feeds, composed of large dark IP addresses, passive measurement sensors, BGP collectors, coupled with publicly available sources, we unveil on the Starlink cyberspace (i) Internet-scale exploitations, (ii) illicit scanning events originating from 8,675 unique Starlink end-users, (iii) suspicious Port 0 and IKE scans, (iv) Mirai-based infections, (v) source address spoofing, (vi) 8,714 vulnerabilities ranging between medium and critical, and (vii) interesting RTBH announcements associated with possible mitigation techniques. Nasser Tieby, Joseph Khoury, Elias Bou-Harb |
ICC | 2 |
| 2024 | Jbeil: Temporal Graph-Based Inductive Learning to Infer Lateral Movement in Evolving Enterprise NetworksabstractLateral Movement (LM) is one of the core stages of advanced persistent threats which continues to compromise the security posture of enterprise networks at large. Recent research work have employed Graph Neural Network (GNN) techniques to detect LM in intricate networks. Such approaches employ transductive graph learning, where fixed graphs with full nodes' visibility are employed in the training phase, along with ingesting benign data. These two assumptions in real-world setups (i) do not take into consideration the evolving nature of enterprise networks where dynamic features and connectivity prevail among hosts, users, virtualized environments, and applications, and (ii) hinder the effectiveness of detecting LM by solely training on normal data, especially given the evasive, stealthy, and benign-like behaviors of contemporary malicious maneuvers. Additionally, (iii) complex networks typically do not have the entire visibility of their run-time network processes, and if they do, they often fall short in dynamically tracking LM due to latency issues with passive data analysis.To this end, this paper proposes Jbeil, a data-driven framework for self-supervised deep learning on evolving networks represented as sequences of authentication timed events. The premise of the work lies in applying an encoder on a continuous-time evolving graph to produce the embedding of the visible graph nodes for each time epoch, and a decoder that leverages these embeddings to perform LM link prediction on unseen nodes. Additionally, we enclose a threat sample augmentation mechanism within Jbeil to ensure a well-informed notion on advanced LM attacks. We evaluate Jbeil using authentication timed events from the Los Alamos network which achieves an AUC score of 99.73% and a recall score of 99.25% in predicting LM paths, even when 30% of the nodes/edges are not present in the training phase. Additionally, we assess different realistic attack scenarios and demonstrate the potential of Jbeil in predicting LM paths with an AUC score of 99% in its inductive and transductive settings, out performing the state-of-the-art by a significant margin. Joseph Khoury, Dorde Klisura, Hadi Zanddizari, Gonzalo De La Torre Parra, Peyman Najafirad, Elias Bou-Harb |
SP | 1 |
| 2024 | EV Charging Infrastructure Discovery to Contextualize Its Deployment SecurityabstractElectric Vehicle Charging Stations (EVCSs) have been shown to be susceptible to remote exploitation due to manufacturer-induced vulnerabilities, demonstrated by recent attacks on this ecosystem. What is more alarming is that compromising these high-wattage IoT systems can be leveraged to perform coordinated oscillatory load attacks against the power grid which could lead to the instability of this critical infrastructure. In this paper, we investigate a previously sidelined aspect of EVCS security. We analyze the deployment security of EVCSs and highlight operator-induced vulnerabilities rendering the ecosystem exposed to remote intrusions. We create an advanced discovery technique that leverages Web interface artifacts to dynamically discover new charging station vendors. As a result, we uncover 33,320 charging station management systems in the wild. Consequently, we study the deployment security of the charging stations and identify that 28,046 EVCSs were found to be vulnerable to eavesdropping, and around 24% of the studied EVCSs are deployed with default configurations exposing the ecosystem to a Mirai-like attack vector. Aligned with this finding, we discover that the EVCS ecosystem has been targeted by nefarious IoT malware such as Mirai and its variants. This demonstrates that further security measures should be implemented by vendors and operators to ensure the security of this vital ecosystem. Consequently, we provide a comprehensive recommendation for securing the deployment of EVCSs. Khaled Sarieddine, Mohammad Ali Sayed, Chadi Assi, Ribal Atallah, Sadegh Torabi, Joseph Khoury, Morteza Safaei Pour, Elias Bou-Harb |
IEEE Trans. Netw. Serv. Manag. | 6 |
| 2023 | Unraveling Network-Based Pivoting Maneuvers: Empirical Insights and Challenges
Martin Husák, Shanchieh Jay Yang, Joseph Khoury, Dorde Klisura, Elias Bou-Harb |
ICDF2C (2) | 3 |
| 2023 | Helium-based IoT Devices: Threat Analysis and Internet-scale ExploitationsabstractWith the explosive growth of resource-constrained smart devices and the widespread deployment of Internet-of-Things (IoT) devices, there is an ever-increasing demand for low-energy and cost-effective wireless communication solutions to serve a wide variety of systems and processes. To this end, blockchain-enabled Helium devices were conceived to enable Internet services and to support third-party IoT devices. This decentralized paradigm allows individuals and entities to freely engage, monetize and deploy wireless Helium hotspots, offering Internet coverage through piggy-backing packets via their existing network and Internet infrastructure (e.g., fiber optics at home). Currently, there are close to 1M operational Helium devices deployed in 189 countries, which are owned by 425K accounts. Given this evolving paradigm, in this paper, we take a first step to explore the plausible attack vectors which could potentially impact the confidentiality, integrity, and availability of such Helium hotspots. Along this vein, we then scrutinize 2.9 TB of one-way unsolicited Internet traffic arriving at 0.5M monitored dark IP addresses to identify 869,822 darknet events pertained to 6K Helium hotspots (as infected devices and DoS victims). By further leveraging active and passive methodologies coupled with public exploitation databases, we uncover medium to critical severity vulnerabilities attributed to 62K online Helium hotspots. Veronica Rammouz, Joseph Khoury, Dorde Klisura, Morteza Safaei Pour, Mostafa Safaei Pour, Claude Fachkha, Elias Bou-Harb |
WiMob | 2 |
| 2022 | A Near Real-Time Scheme for Collecting and Analyzing IoT Malware Artifacts at ScaleabstractThe chronic proliferation of Internet of Things (IoT) botnet malware activities coupled with an unprecedented rise in security vulnerabilities convene a new world of opportunities for perpetrators and unveil a new set of hurdles in deriving relevant IoT malware intelligence. Such shortfall within the IoT paradigm exacerbates the capabilities for largely identifying the prevailing IoT malware threats, the origin of the IoT attacks, as well as, the security deficit associated with the IoT paradigm. Previous work has vastly studied IoT malware activities in the wild but has not profiled at a large scale malicious activities to collect in near real-time central IoT artifacts much-needed to understand and eventually elevate the security posture of the IoT ecosystem. Joseph Khoury, Morteza Safaei Pour, Elias Bou-Harb |
ARES | 1 |
| 2022 | Interpretable Federated Transformer Log Learning for Cloud Threat Forensics
Gonzalo De La Torre Parra, Luis Selvera, Joseph Khoury, Hector Irizarry, Elias Bou-Harb, Peyman Najafirad |
NDSS | 3 |
| 2022 | HoneyComb: A Darknet-Centric Proactive Deception Technique For Curating IoT Malware Forensic ArtifactsabstractConventional IoT honeypots are known to suffer from scalability and management issues, while accumulating stringent costs. Further, their passive nature hinders the wide-scale gathering of much-needed IoT malware artifacts, impeding their measurements, analysis, and ultimately their use to infer and react to IoT maliciousness at large. To this end, in this work, we introduce HoneyComb, a proactive deception technique to curate IoT malware forensics by leveraging IoT scans captured on the darknet (i.e., Internet telescope). HoneyComb is built on the premise that we can position a large darknet network (i.e., comprising of 16.7 million IPs) as a large honeypot to interact with malware-infected IoT devices at scale. Such a large vantage point is capable of offering an incomparable hefty look into the IoT cyber security posture compared to the typical, much-restricted, currently-available IoT honeypots. In essence, the inferred IoT scans from the darknet along with the existing discrepancy in the validation algorithms of IoT malware stateless scanning modules, enable HoneyComb to initiate crafted deceiving packets (i.e., TCP SYN-ACK packets) to delude and interconnect with malware-infected IoT devices in the wild. During 48 hours of empirical measurements, the proposed scheme logged 1,432,518 interactions originating from 37,323 malware-infected IoT devices worldwide. Additionally, our findings revealed intriguing insights concerning the propagation behavior of IoT malware where 11,340 infected devices delivered the malware binaries using 1,398 unique URLs, whereas 2,114 used HexString dumping to drop their binaries, while the rest reported sensitive information (e.g., credentials) to their servers. Finally, while we observe that newly emerged IoT malware such as ZHTRAP is more capable in the takeover process due to its innovative techniques and offensive competencies, we frame HoneyComb as a complementary scheme, which would aid in addressing a number of evolving IoT-centric security endeavours, including large-scale malware attribution and C&C takedowns. Morteza Safaei Pour, Joseph Khoury, Elias Bou-Harb |
NOMS | 2 |
| 2022 | A survey on security applications of P4 programmable switches and a STRIDE-based vulnerability assessment
Ali AlSabeh, Joseph Khoury, Elie F. Kfoury, Jorge Crichigno, Elias Bou-Harb |
Comput. Networks | 2 |
| 2020 | A Hybrid Game Theory and Reinforcement Learning Approach for Cyber-Physical Systems SecurityabstractCyber-Physical Systems (CPS) are monitored and controlled by Supervisory Control and Data Acquisition (SCADA) systems that use advanced computing, sensors, control systems, and communication networks. At first, CPS and SCADA systems were protected and secured by isolation. However, with recent industrial technology advances, the increased connectivity of CPSs and SCADA systems to enterprise networks has uncovered them to new cybersecurity threats and made them a primary target for cyber-attacks with the potential of causing catastrophic economic, social, and environmental damage. Recent research focuses on new methodologies for risk modeling and assessment using game theory and reinforcement learning.This paperwork proposes to frame CPS security on two different levels, strategic and battlefield, by meeting ideas from game theory and Multi-Agent Reinforcement Learning (MARL). The strategic level is modeled as imperfect information, extensive form game. Here, the human administrator and the malware author decide on the strategies of defense and attack, respectively. At the battlefield level, strategies are implemented by machine learning agents that derive optimal policies for run-time decisions. The outcomes of these policies manifest as the utility at a higher level, where we aim to reach a Nash Equilibrium (NE) in favor of the defender. We simulate the scenario of a virus spreading in the context of a CPS network. We present experiments using the MiniCPS simulator and the OpenAI Gym toolkit and discuss the results. Joseph Khoury, Mohamed Nassar 0001 |
NOMS | 1 |
| 2019 | An Efficient Random Access Light Field Video Compression Utilizing Diagonal Inter-View PredictionabstractA more realistic Virtual and Augmented Reality is promised by the emergence of Light Field (LF) technology. Considering LF technology benefits come with an exponential increase in the amount of data required as well as the complexity of view access, the need for efficient compression and random access schemes is essential. In this study, a novel and efficient pseudo-sequence based LF video compression scheme is proposed that offers the best trade-off between coding and access complexity. The philosophy behind our proposed prediction structure is maximally utilizing the low-level frames in hierarchy prediction structure to achieve better random access at a minimal expense of compression efficiency. Nusrat Mehajabin, Sichen Roger Luo, Hao Wei Yu, Joseph Khoury, Jashandeep Kaur, Mahsa T. Pourazad |
ICIP | 4 |
| 2019 | On The Use of Software Defined Wireless Network in Vehicular Fog Computing EnvironmentsabstractThe integration of sensors and units in vehicle manufacturing is constantly increasing the data volume generated by vehicles. This requires to support services to handle these data and provide a continuous response to application requests such as collision warnings, lane changing, traffic information, routing information, multimedia streaming, and many others. Add to that the need for achieving the required quality of service is of immense importance. Fog devices deployed along the road are used as a solution to service vehicles. Vehicular ad hoc network (VANET) environment have the property of dynamically changing its cluster connectivity because of the different mobility patterns, which makes it a challenge for vehicular users to access their services. Many preliminary works proposed the use of Software Defined Wireless Network (SDWN) in VANET. In this paper, we study and analyze the use of SDWN in vehicular fog computing environment taking into consideration the suspected high delay between the SDWN controller that is located on the cloud and its switches, the high traffic coming to the controller, the high vehicle speed, and the range of RSU coverage. We have used Mininet-Wifi to implement a vehicular fog computing architecture and simulate different scenarios. Obtained results showed that using SDWN in a VANET environment might not be the best solution in many cases. Joseph Khoury, Hani Sami, Haïdar Safa, Wassim El-Hajj |
IWCMC | 1 |
| 2008 | A Groebner basis approach to solve a Conjecture of Nowicki
Joseph Khoury |
J. Symb. Comput. | 1 |