Boubakr Nour

dblp:201/1271 · DBLP profile ↗
← Back
39ranked-venue papers
13as first author
19since 2021 · last 2026
0000-0001-5609-856XORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 29 · 11 first-author · 14 since 2021Security and privacy · 3 · 3 since 2021Systems, architecture and hardware · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2026 Context and Semantics-Aware Mapping of Unstructured Tickets to MITRE ATT&CK TTPs
Hnin Pann Phyu, Boubakr Nour, Makan Pourzandi, Chadi Assi, Mourad Debbabi
ICC2
2026 Automating Threat-Aligned Testflows Generation Using Ontology-Grounded RAG From CTI Reports
abstract
The increasing sophistication and complexity of Advanced Persistent Threats (APTs) pose significant challenges to security practitioners. To proactively protect against these threats, security practitioners rely on the generation of testflows, structured sequences of actions designed to verify whether the tactics and behaviors of an APT are present within their organization. However, manually creating such testflows is time-consuming, error-prone, and highly dependent on expert knowledge. Moreover, existing automated approaches suffer from several limitations, including validity, efficiency, and insufficient domain adaptation. To address these challenges, this paper introduces CTI-RAGFlow, to automate the generation of relevant, valid, and effective testflows from unstructured threat reports tailored to specific organizational environments. CTI-RAGFlow introduces three key contributions: (i) a dual-ontology approach, that integrates both a system ontology representing the operational environment and a cybersecurity ontology capturing adversary tactics, techniques, and procedures, improving the precision and accuracy of generated testflows; (ii) a fact-based context retrieval mechanism that combines a hypergraph structured knowledge base with a Retrieval-Augmented Generation pipeline using Large Language Models; and (iii) a fully automated testflow generation process that minimizes manual effort, reduces human error, and facilitates the generation of valid testflow. We evaluate CTI-RAGFlow against three widely used LLM models (e.g., base and fine-tuned models) using publicly available CTI reports for three well-known APTs (e.g., APT41, APT29, APT28). The results show that CTI-RAGFlow outperforms the baselines in terms of semantic relevance, coverage, validity, and effectiveness in verifying multi-stage cyberattack scenarios.
Faissal Ahmadou, Boubakr Nour, Makan Pourzandi, Mourad Debbabi, Chadi Assi
IEEE Trans. Netw. Serv. Manag.2
2025 Threatify: APT Threat Variant Generation Using Graph-Based Machine Learning
abstract
Ensuring cybersecurity in an ever-evolving threat landscape requires proactive identification and understanding of potential threats. Conventional detection and prediction solutions often fall short as they predominantly focus on known attack vectors. Advanced Persistent Threats (APTs) are becoming increasingly sophisticated and stealthy, resulting in new threat variants that are undetectable by these detection solutions. This paper introduces THREATIFY, a novel approach to predicting the most probable threat variants from existing APTs and previously seen attack campaigns. Our approach automates the generation of threat variants using graph-based machine learning based on the attack definition, past attack campaigns, and the security context between different techniques. THREATIFY leverages a security knowledge base of realistic attack scenarios and cybersecurity expertise to model, generate, and predict new forms of potential future threats by combining inter-(i.e. within the same APT attack) and intra-(i.e. between different APTs) techniques used by threat actors. It is crucial to emphasize that THREATIFY does not merely mix techniques from different APTs; rather, it constructs a logical and pragmatic kill chain based on their security context. THREATIFY is able to predict new attack steps, find relevant techniques to be substituted by, and merge APTs techniques in the current security context, and thus create previously unexplored threat variants. Our extensive experimental results demonstrate the efficacy of our approach in generating relevant and novel threat variants with a similarity score of 92%, uniqueness of 82%, validity of 95%, and reduction rate of 96%, including those that have never occurred before.
Boubakr Nour, Makan Pourzandi, Mourad Debbabi
IEEE Trans. Netw. Serv. Manag.1
2024 CCSM: Building Cross-Cluster Security Models for Edge-Core Environments Involving Multiple Kubernetes Clusters
abstract
With the emergence of 5G networks and their large scale applications such as IoT and autonomous vehicles, telecom operators are increasingly offloading the computation closer to customers (i.e., on the edge). Such edge-core environments usually involve multiple Kubernetes clusters potentially owned by different providers. Confidentiality concerns could prevent those providers from sharing data freely with each other, which makes it challenging to perform common security tasks such as security verification across different clusters. In this work, we propose a solution for building cross-cluster security models to enable various security analyses, while preserving confidentiality for each cluster. We design a six-step methodology to model both the cross-cluster communication and cross-cluster event dependency, and we apply those models to different security use cases. We implement our solution based on a 5G edge-core environment that involves multiple Kubernetes clusters, and our experimental results demonstrate its efficiency (e.g., less than 8 seconds of processing time for a model with 3,600 edges and nodes) and accuracy (e.g., more than 96% for cross-cluster event prediction).
Mahmood Gholipourchoubeh, Hugo Kermabon-Bobinnec, Suryadipta Majumdar, Yosr Jarraya, Lingyu Wang 0001, Boubakr Nour, Makan Pourzandi
CODASPY6
2024 A Network-based Compute Reuse Architecture for IoT Applications
abstract
In this work, we explore the use of the computation reuse concept at the edge server. We design a network-based computation reuse architecture for IoT applications. The architecture caches previously executed results and utilizes them to address newly arrived similar tasks without performing computation from scratch. By doing so, we eliminate redundant computations, enhance resource utilization, and reduce task completion time. We deployed this architecture and assessed its performance at both the networking and application levels. From the networking perspective, we achieved an up to 80% reduction in task completion time and up to 60% reduction in resource utilization, alongside a 63% decrease in energy consumption. From the application perspective, we achieved up to 90% in computation correctness and accuracy.
Boubakr Nour, Soumaya Cherkaoui
GLOBECOM1
2024 Matching-based Service Offloading for Compute-less Driven IoT Networks
abstract
In this paper, we present matching-based services offloading schemes for compute-less IoT networks. We adopt the matching theory to match service offloading to the appropriate edge server(s). Specifically, we design, Whistle, a vertical many-to-many offloading scheme that aims to offload the most invoked and highly reusable services to the appropriate edge servers. We further extend Whistle to provide horizontal one-to-many computation reuse sharing among edge servers which leads to bouncing less computation back to the cloud. We evaluate the efficiency and effectiveness of Whistle with a real-world dataset. The obtained findings show that Whistle is able to accelerate the task completion time by 20%, reduce the computation up to 77%, and decrease the communication up to 71%. Theoretical analyses also prove the stability of the designed schemes.
Boubakr Nour, Soumaya Cherkaoui
GLOBECOM1
2024 ChainPatrol: Balancing Attack Detection and Classification with Performance Overhead for Service Function Chains Using Virtual Trailers
Momen Oqaily, Hinddeep Purohit, Yosr Jarraya, Lingyu Wang 0001, Boubakr Nour, Makan Pourzandi, Mourad Debbabi
USENIX Security Symposium5
2024 Threat Modeling of AI-as-a-Service Framework
abstract
Artificial intelligence will be one of the key enablers of 6G technology. Compared to today's networks where we mostly benefit from ubiquitous communication capabilities, 6G is expected to transform the network into a powerfully distributed AI platform and exposes its AI capabilities to consumers. This is expected to be enabled by the AI-as-a-Service (AIaaS) framework. The latter unlocks new possibilities for network management and orchestration in the context of 6G by enabling network service providers to leverage AI capabilities as a service effectively. Thus, it is extremely important for the AIaaS framework to be intelligently protected against potential threats and malicious attacks. In this paper, we performed a comprehensive threat analysis of the AIaaS framework, identifying potential security threats and discussing mitigation strategies.
Utku Gülen, Ömer Faruk Tuna, Boubakr Nour, Zakaria Laaroussi, Leyli Karaçay, Ferhat Karakoç
WiMob3
2024 ACE-WARP: A Cost-Effective Approach to Proactive and Non-Disruptive Incident Response in Kubernetes Clusters
abstract
A large-scale cluster of containers managed with an orchestrator like Kubernetes are behind many cloud-native applications today. However, the weaker isolation provided by containers means attackers can potentially exploit a vulnerable container and then escape its isolation to cause more severe damages to the underlying infrastructure and its hosted applications. Defending against such an attack using existing attack detection solutions can be challenging. Due to the well known high false positive rate of such solutions, taking aggressive actions upon every alert can lead to unacceptable service disruption. On the other hand, waiting for security administrators to perform in-depth analysis and validation could render the mitigation too late to prevent irreversible damages. In this paper, we propose ACE-WARP, a cost-effective proactive and non-disruptive incident response to address such security challenges for Kubernetes clusters. First, our approach is proactive in the sense that it performs mitigation based on predicted (instead of real) attacks, which prevents irreversible damages. Second, our approach is also non-disruptive since the mitigation is achieved through live migration of containers, which causes no service disruption even in the case of false positives. Finally, to realize the full potential of this approach in containers migration, we formulate the inherent trade-off between security and cost (delay) as a multi-objective optimization problem. Our evaluation results show that ACE-WARP can successfully mitigate up to 81% of the attacks, and our optimization algorithm achieves up to 30% more threat reduction and 7% less delay while being 37 times faster compared to a standard optimization solution.
Sima Bagheri, Hugo Kermabon-Bobinnec, Mohammad Ekramul Kabir, Suryadipta Majumdar, Lingyu Wang 0001, Yosr Jarraya, Boubakr Nour, Makan Pourzandi
IEEE Trans. Inf. Forensics Secur.7
2024 AUTOMA: Automated Generation of Attack Hypotheses and Their Variants for Threat Hunting Using Knowledge Discovery
abstract
Threat hunting is a proactive security defense line exercised to uncover attacks that could circumvent conventional detection mechanisms. It is based on an iterative approach to generate, inspect, and revise attack hypotheses. The quality of these hypotheses is essential to prove/refute the existence of an attack. Today, attack hypotheses are often generated manually by security analysts. The generation process requires elusive expertise, is costly, and is prone to produce a large number of irrelevant hypotheses without considering the attack variants. In this paper, we address the aforementioned challenges by designing AUTOMA, a solution that automates the generation of relevant hypotheses and their variants using knowledge discovery. AUTOMA incorporates the system telemetry in combination with a knowledge base of existing attacks, techniques, and their relationships to mine the most relevant hypotheses. In order to increase the relevance of the generated hypotheses, AUTOMA examines these hypotheses by applying matching-based similarity, success, likelihood, and criticality evaluations. These evaluations are based on the past occurrences of the techniques part of a hypothesis in the system telemetry and the knowledge base. Additionally, AUTOMA uses sequence success, sequence alignment, and hierarchical similarity approach for generating potential attack variants of a hypothesis taking into account the dynamism and stealthiness of attackers in coming up with alternative attack steps. We extensively evaluate the effectiveness and efficiency of AUTOMA using a real dataset for 284 attack campaigns distributed over 57 advanced persistent threats. The obtained results show that AUTOMA is able to generate the relevant hypothesis (top 3), with a large reduction rate (up to 99%), and fast execution time (up to 8 minutes for proposing the relevant hypothesis and 10 seconds for variants generation).
Boubakr Nour, Makan Pourzandi, Rushaan Kamran Qureshi, Mourad Debbabi
IEEE Trans. Netw. Serv. Manag.1
2022 PbCP: A profit-based cache placement scheme for next-generation IoT-based ICN networks
Oussama Serhane, Khadidja Yahyaoui, Boubakr Nour, Rasheed Hussain, S. M. Ahsan Kazmi, Hassine Moungla
Comput. Commun.3
2021 QoS in IoT Networks based on Link Quality Prediction
abstract
The success of the Internet of Things (IoT) depends on the ability to provide reliable communication to the billions of devices that are used in many applications. In essence, estimating the quality of wireless links ensures the optimization of several protocols, reduces the end-to-end latency, and increases the reliability and the network lifetime. In this paper, we study the link quality in the Time Slotted Channel Hopping (TSCH) network by analyzing the received signal strength (RSSI) and error rates. The objective is to understand the temporal properties of these parameters which is important to select the appropriate channels for the critical applications and to enhance the Quality of Service (QoS) of the network. We apply machine learning techniques to a real dataset collected from a testbed IoT network deployed at Grenoble, France. We define five classes and present a classification of the 16 channels by comparing the performances of KNN (k-Nearest Neighbor) and LSTM (Long Short-Term Memory) algorithms.
Chérifa Boucetta, Boubakr Nour, Albéric Cusin, Hassine Moungla
ICC2
2021 Whispering: Joint Service Offloading and Computation Reuse in Cloud-Edge Networks
abstract
Due to the proliferation of Internet of Things (IoT) and application/user demands that challenge communication and computation, edge computing has emerged as the paradigm to bring computing resources closer to users. In this paper, we present Whispering, an analytical model for the migration of services (service offloading) from the cloud to the edge, in order to minimize the completion time of computational tasks offloaded by user devices and improve the utilization of resources. We also empirically investigate the impact of reusing the results of previously executed tasks for the execution of newly received tasks (computation reuse) and propose an adaptive task offloading scheme between edge and cloud. Our evaluation results show that Whispering achieves up to 35% and 97% (when coupled with computation reuse) lower task completion times than cases where tasks are executed exclusively at the edge or the cloud.
Boubakr Nour, Spyridon Mastorakis, Abderrahmen Mtibaa
ICC1
2021 Energy-aware Cache Placement Scheme for IoT-based ICN Networks
abstract
The Internet of Things (IoT) is overrunning different domains and applications, where the use of wireless sensors and mobile devices is indispensable in such a mobile environment. These heterogeneous devices may generate a tremendous amount of content. Information-Centric Network (ICN) paradigm has been proposed to meet today’s users and application requirements. The in-network caching is a fundamental feature supported by design in ICN that improves network performance by providing ubiquitous caching in the network layer. Since most IoT devices are resource-constrained with limitations in communication, processing, energy, and memory; the energy-efficiency is a prime concern in IoT deployment. Different factors may affect energy efficiency in ICN-based wireless IoT networks such as transport (communication), caching, and energy limitation. This research paper attempts to focus on the in-network caching in wireless IoT to maximize the energy-efficiency. We propose an Energy-aware caching placement scheme (EaCP) that aims to maximize the energy-saving by trading-off between content transmission energy and content caching energy. Compared to other strategies, the simulation results show significant improvements while ensuring low data replication and a high cache hit ratio.
Oussama Serhane, Khadidja Yahyaoui, Boubakr Nour, Hassine Moungla
ICC3
2021 A Latin rectangles-based TSCH scheduling and interference mitigation design
Chérifa Boucetta, Boubakr Nour, Michel Sortais, Hassine Moungla
Comput. Networks2
2021 Edge and fog computing for IoT: A survey on current research activities & future directions
Mohammed Laroui, Boubakr Nour, Hassine Moungla, Moussa Ali Cherif, Hossam Afifi, Mohsen Guizani
Comput. Commun.2
2021 Editorial: Information-Centric Network enabler communication for Internet of Things
Boubakr Nour, Hassine Moungla, Ammar Rayes
Future Gener. Comput. Syst.1
2021 CCIC-WSN: An Architecture for Single-Channel Cluster-Based Information-Centric Wireless Sensor Networks
abstract
The promising vision of information-centric networking (ICN) and of its realization, named data networking (NDN), has attracted extensive attention in recent years in the context of the Internet of Things (IoT) and wireless sensor networks (WSNs). However, a comprehensive NDN/ICN-based architectural design for WSNs, including specially tailored naming schemes and forwarding mechanisms, has yet to be explored. In this article, we present single-channel cluster-based information-centric WSN (CCIC-WSN), an NDN/ICN-based framework to fulfill the requirements of cluster-based WSNs, such as communication between child nodes and cluster heads (CHs), association of new child nodes with CHs, discovery of the namespace of newly associated nodes, and child node mobility. Through an extensive simulation study, we demonstrate that CCIC-WSN achieves 71%-90% lower energy consumption and 74%-96% lower data retrieval delays than recently proposed frameworks for NDN/ICN-based WSNs under various evaluation settings.
Muhammad Atif Ur Rehman, Rehmat Ullah 0001, Byung-Seo Kim, Boubakr Nour, Spyridon Mastorakis
IEEE Internet Things J.4
2021 A Survey of ICN Content Naming and In-Network Caching in 5G and Beyond Networks
abstract
Internet usability is expanded form just human-to-human interactions toward different communication types, while the communication itself is shifting from the host-centric model to the content-centric paradigm. The 5G and beyond networks promise not only to support such changes but also to provide massive data exchange and connectivity with high reliability. The next-generation networking technologies are the key enabled for 5G that aim at building a new ecosystem. One promising piece of this ecosystem is the information-centric network (ICN), which is a future network architecture that tends to tackle the current host-centric model issues. It natively supports several features, including abstraction content naming and transparent in-network content caching that contribute to improve network performance, reduce traffic, and improve the latency. In this article, we first provide a potential road map by introducing different next-generation active technologies to enable the big picture of 5G, including mobile-edge computing (MEC), software-defined networking (SDN), and network function virtualization (NFV). Then, we discuss the need for ICN and its coexistence within this ecosystem. Later, we present an in-depth review of the recent content naming schemes and a comprehensive review of in-network content caching solutions. We classify these solutions into different classes based on the used technologies and their working principle. Finally, we highlight some research challenges and propose promising directions for the research community.
Oussama Serhane, Khadidja Yahyaoui, Boubakr Nour, Hassine Moungla
IEEE Internet Things J.3
2020 Mobile Vehicular Edge Computing Architecture using Rideshare Taxis as a Mobile Edge Server
abstract
We propose to utilize rideshare taxis as infrastructure for both communication and computation. Rideshare overlays become hence Mobile Edge Nodes. End-users utilize near rideshare taxis as edge servers to receive video chunks for live video streaming. The set cover problem (SCP) is used to formulate the rideshare taxis coverage optimization inside the city. It provides the maximum number of rideshare taxis that cover end-users routes which guarantee the efficiency of communication services. Simulation results show that the proposed architecture dramatically enhances the quality of service and the overall communication performance in terms of execution time and energy consumption.
Mohammed Laroui, Boubakr Nour, Hassine Moungla, Hossam Afifi, Moussa Ali Cherif
CCNC2
2020 In-Network Caching in ICN-based Vehicular Networks: Effectiveness & Performance Evaluation
abstract
Many research efforts have been proposed from physical, networking, to application layers over Vehicular Ad hoc Networks (VANETs) to provide more safety and convenience to passengers. However, due to the highly dynamic topologies and frequent disconnections in VANET, various challenges are faced due to the use of IP that effects the data delivery and user experiences. Therefore, a new paradigm namely Information-Centric Networking (ICN) has been proposed aiming to replace the traditional Internet Protocol by using the content name as the pillar element and providing a distributed in-network caching to enhance the data dissemination & access, and reduce the network load & response latency. The use of ICN in a vehicular environment may require different caching placement strategies and replacement policies. To this end, we study, in this paper, the effectiveness of in-network caching for VANET, we simulate and compare various strategies in different scenarios. Furthermore, we provide different research guidelines to enhance the use of caching in such a challenging network.
Hakima Khelifi, Senlin Luo, Boubakr Nour, Hassine Moungla
ICC3
2020 CnS: A Cache and Split Scheme for 5G-enabled ICN Networks
abstract
The tremendous growth of today's connecting devices and generated content lead to an increasing load of current Internet infrastructure with challenging requirements. 5G technology promises to provide high bandwidth and ultra reliable low-latency communications, while Information-Centric Networking (ICN) promises to replace the current host-centric paradigm. ICN provides ubiquitous and transparent in-network content caching in order to enhance network performance and reduce content retrieval latency. In this regard, several cache strategies have been proposed, most of them are neither distributed in nature nor scalable in large-scale networks. In this paper, we design a distributed and efficient content caching scheme for 5G-enabled ICN networks, namely Cache and Split (CnS). CnS is designed to make a trade-off between the cache utilization and the content delivery time based on the number of received demands and content popularity. We evaluate our scheme using various performance metrics against different caching strategies. The obtained results prove an improvement in the cache utilization, with fast data retrieval, and enhancements in the content cache distribution.
Oussama Serhane, Khadidja Yahyaoui, Boubakr Nour, Hassine Moungla
ICC3
2020 A Collaborative Multi-Metric Interface Ranking Scheme for Named Data Networks
abstract
Named Data Networking (NDN) uses the content name to enable content sharing in a network using Interest and Data messages. In essence, NDN supports communication through multiple interfaces, therefore, it is imperative to think of the interface that better meets the communication requirements of the application. The current interface ranking is based on single static metric such as minimum number of hops, maximum satisfaction rate, or minimum network delay. However, this ranking may adversely affect the network performance. To fill the gap, in this paper, we propose a new multi-metric robust interface ranking scheme that combines multiple metrics with different objective functions. Furthermore, we also introduce different forwarding modes to handle the forwarding decision according to the available ranked interfaces. Extensive simulation experiments demonstrate that the proposed scheme selects the best and suitable forwarding interface to deliver content.
Boubakr Nour, Hakima Khelifi, Rasheed Hussain, Hassine Moungla, Safdar Hussain Bouk
IWCMC1
2020 A Label-based Producer Mobility Support in 5G-enabled ICN Networks
abstract
The 5G networks are considered as new wireless technologies that promise to provides Ultra-Reliable Low Latency Communication. In doing so, it uses various coverage techniques with high access point density that rise various complexity in the handle and manage the mobility of users. Information-Centric Network (ICN) is an emerging paradigm that promises to replace the current IP network. The content in ICN is first-class citizens instead of the host. ICN names the content rather than the owner, and the demands are driven by the receiver. Although this change contributes to the ease of consumers' mobility, producer mobility is considered as a challenging issue in ICN. In this paper, we study the issue of producer mobility, discuss the existing issues and challenges, and then design a Label-based technique that takes the benefits of location-free naming to enhance the producer mobility in a seamless and easy manner. The simulation results show the high performance of our proposed architecture in terms of seamless handover and low data miss.
Oussama Serhane, Khadidja Yahyaoui, Boubakr Nour, Hassine Moungla
IWCMC3
2020 A unified hybrid information-centric naming scheme for IoT applications
Boubakr Nour, Kashif Sharif, Fan Li 0001, Hassine Moungla, Yang Liu 0038
Comput. Commun.1
2019 An IoT Scheduling and Interference Mitigation Scheme in TSCH Using Latin Rectangles
abstract
Time Slotted Channel Hopping (TSCH) is one of the most used MAC mechanisms introduced by the new amendment IEEE 802.15.4e. It combines both slotted access with channel hopping technique to allow multiple communications while exploiting the 16 available channels of 2.4GHz band. The channel hopping mechanism of 802.15.4e considers an interference-free environment and does not specify how to build and manage a schedule for communication purpose. In this paper, we propose a new distributed channel hopping scheme that exploits Latin rectangles to avoid interference and collisions. In essence, the scheduling of links is performed by Latin rectangles where rows are channel offsets and columns are slot offsets. Thus, the frequency of communication is derived using Latin rectangles. Consequently, interference and multi-path fading are mitigated with more reliability and robustness. The efficiency of the proposed scheme has been validated by extensive simulation.
Chérifa Boucetta, Boubakr Nour, Hassine Moungla, Laaziz Lahlou
GLOBECOM2
2019 A QoS-Aware Cache Replacement Policy for Vehicular Named Data Networks
abstract
Vehicular Named Data Network (VNDN) uses Named Data Network (NDN) as a communication enabler. The communication is achieved using the content name instead of the host address. NDN integrates content caching at the network level rather than the application level. Hence, the network becomes aware of content caching and delivering. The content caching is a fundamental element in VNDN communication. However, due to the limitations of the cache store, only the most used content should be cached while the less used should be evicted. Traditional caching replacement policies may not work efficiently in VNDN due to the large and diverse exchanged content. To solve this issue, we propose an efficient cache replacement policy that takes the quality of service into consideration. The idea consists of classifying the traffic into different classes, and split the cache store into a set of sub-cache stores according to the defined traffic classes with different storage capacities according to the network requirements. Each content is assigned a popularity-density value that balances the content popularity with its size. Content with the highest popularity-density value is cached while the lowest is evicted. Simulation results prove the efficiency of the proposed solution to enhance the overall network quality of service.
Hakima Khelifi, Senlin Luo, Boubakr Nour, Hassine Moungla
GLOBECOM3
2019 Coexistence of ICN and IP Networks: An NFV as a Service Approach
abstract
In contrast to the current host-centric architecture, Information-Centric Networking (ICN) adopts content naming instead of host address and in-network caching to enhance the content delivery, improve the data distribution, and satisfy users' requirements. As ICN is being incrementally deployed in different real-world scenarios, it will exist with IP-based services in a hybrid network setting. Full deployment of ICN and total replacement of IP protocol is not feasible at the current stage since IP is dominating the Internet. On the other hand, re-designing TCP/IP applications from ICN perspective is a time-consuming task and requires a careful investigation from both business and technical point of view. Thus, the coexistence of ICN and IP is one of the suitable solutions. Towards this end, we propose a simple yet efficient coexistence solution based on Network Function Virtualization (NFV) technology. We define a set of communication regions and control virtual functions. A gateway node is used as an intermediate entity to fetch and deliver content over regions. The simulation results show that the proposed approach is valid and allow content fetching and delivering from different ICN and/to IP regions in an efficient manner.
Boubakr Nour, Fan Li 0001, Hakima Khelifi, Hassine Moungla, Adlen Ksentini
GLOBECOM1
2019 A Federated Filtering Framework for Internet of Medical Things
abstract
Based on the dominant paradigm, all the wearable IoT devices used in the healthcare sector also known as the internet of medical things (IOMT) are resource constrained in power and computational capabilities. The IoMT devices are continuously pushing their readings to the remote cloud servers for real-time data analytics, that causes faster drainage of the device battery. Moreover, other demerits of continuous centralizing of data include exposed privacy and high latency. This paper presents a novel Federated Filtering Framework for IoMT devices which is based on the prediction of data at the central fog server using shared models provided by the local IoMT devices. The fog server performs model averaging to predict the aggregated data matrix and also computes filter parameters for local IoMT devices. Two significant theoretical contributions of this paper are the global tolerable perturbation error (ToiF) and the local filtering parameter (δ); where the former controls the decision-making accuracy due to eigenvalue perturbation and the later balances the tradeoff between the communication overhead and perturbation error of the aggregated data matrix (predicted matrix) at the fog server. Experimental evaluation based on real healthcare data demonstrates that the proposed scheme saves upto 95% of the communication cost while maintaining reasonable data privacy and low latency.
Sunny Sanyal, Dapeng Wu 0002, Boubakr Nour
ICC3
2019 Adaptive Range-based Anomaly Detection in Drone-assisted Cellular Networks
abstract
Stimulated by the emerging Internet of Things (IoT) applications and their massive generated data, the cellular providers are introducing various IoT functionalities into their networks architecture. They should integrate intelligent and autonomous mechanisms that are able to detect sudden and anomalous behavior issues. In this paper, we present an adaptive anomaly detection approach in cellular networks consisting of two parts: the detection of overloaded base-stations using machine learning algorithm (LSTM - Long Short-Term Memory) and the deployment of drones as mobile base-stations that support and back up the overloaded cells. The proposed approach is validated using real dataset extracted from the CDR of Milan combined with semi-synthetic eHealth data. Initially, The LSTM algorithm analyzes the impact of eHealth applications on cellular networks and identifies cells with peak demands. Then, drones are deployed to collect the requested data from these cells. The obtained results show that the use of drones improves the quality of service and provides a better network performance.
Chérifa Boucetta, Boubakr Nour, Seif Eddine Hammami, Hassine Moungla, Hossam Afifi
IWCMC2
2019 A Name-to-Hash Encoding Scheme for Vehicular Named Data Networks
abstract
In contrast to the host-centric model where the communication is directed using the destination address, Information-Centric Networking (ICN) adopts the content name as the pillar network element to provide data discovery and delivery process, as well as in other network functionalities. Named Data Networking (NDN) is an active ICN project that uses hierarchical unbounded names. These names are used in both interest and data packets and other data structures that may consume more memory with long lookup time. This paper targets the naming aspect in vehicular named data networks and proposes a Name-to-Hash Encoding scheme. The idea consists of hashing each name components separately to a fixed length, then perform a heuristic Wu-Manber-like algorithm lookup process. The former process enhances the NDN to consume less memory compared to hierarchical names, the latter process provides a fast lookup time. We have evaluated the proposed scheme against different related solutions using real domain datasets. Both theoretical analysis and experiments prove that the proposed scheme is efficient in terms of complexity, memory consumption, and lookup time.
Hakima Khelifi, Senlin Luo, Boubakr Nour, Hassine Moungla
IWCMC3
2019 LQCC: A Link Quality-based Congestion Control Scheme in Named Data Networks
abstract
Information-Centric Networking (ICN) is a new communication paradigm that replaces the host addresses by the name of content; Named Data Networking (NDN) is a promising ICN architecture that has attracted research attention in recent years. NDN is a receiver-driven architecture implements pull-based communication in the form of one-interest-one-data. This model poses different challenges, especially from the transport layer perspective. In contact to IP-based networks where the congestion is handled in an end-to-end manner, NDN cannot apply the same concept, while most of the existing solutions are based on hop-by-hop connection. In this paper, we present a new congestion control mechanism for NDN based on link quality estimation. We focus our efforts to provide fast data transmission, decrease packet dropping rate, and maximize the link utilization. The simulation results show that our solution outperforms the NDN schemes in terms of throughput and drop packets.
Hakima Khelifi, Senlin Luo, Boubakr Nour, Hassine Moungla
WCNC3
2019 A survey of Internet of Things communication using ICN: A use case perspective
Boubakr Nour, Kashif Sharif, Fan Li 0001, Sujit Biswas, Hassine Moungla, Mohsen Guizani, Yu Wang 0003
Comput. Commun.1
2019 A Scalable Blockchain Framework for Secure Transactions in IoT
abstract
Internet of Things (IoT) and blockchain (BC) technologies have been dominating their respective research domains for some time. IoT offers automation at the finest level in different fields, while BC provides secure transaction processing for asset exchanges. The capability of IoT devices to generate transactions prompts their integration with BC as the next logical step. The biggest challenges in this integration are the scalability of ledger and rate of transaction execution in BC. On one hand, due to their large numbers, IoT devices will generate transactions at a rate which current block chain solutions cannot handle. On the other hand, implementing BC peers onto IoT devices is impossible due to resource constraints. This prohibits direct integration of both technologies in their current state. In this paper, we propose a solution to address these challenges by using a local peer network to bridge the gap. It restricts the number of transactions which enters the global BC by implementing a scalable local ledger, without compromising on the peer validation of transactions at local and global level. The testbed evaluations show significant reduction in the block weight and ledger size on global peers. The solution also indirectly improves the transaction processing rate of all peers due to load distribution.
Sujit Biswas, Kashif Sharif, Fan Li 0001, Boubakr Nour, Yu Wang 0003
IEEE Internet Things J.4
2018 An Optimized Proactive Caching Scheme Based on Mobility Prediction for Vehicular Networks
abstract
Information-centric networking (ICN), a new networking paradigm in which the focal point is a named data, has been proposed recently as an evolving concept to the actual host-centric model of the Internet that relies mainly on host addresses. In vehicular networks, where vehicles are generally moving network elements and follow a content-oriented fashion, it will be fitting to use the ICN paradigm to improve the content dissemination and reduce the content retrieval latency. By applying this concept to such networks, we focus in this paper on the content delivery issue and propose an optimized caching scheme that proactively predicts the moving direction of a vehicle and brings into the next encountered RSU cache only the required content of interest to that vehicle. According to the obtained results from different measured metrics, the proposed solution outperforms in many ways other proposed schemes in the literature. For instance, our scheme improves drastically the cache utilization, enhances the network delay, and boosts the content diversity and distribution.
Hakima Khelifi, Senlin Luo, Boubakr Nour, Akrem Sellami, Hassine Moungla, Farid Naït-Abdesselam
GLOBECOM3
2018 Driving Path Stability in VANETs
abstract
Vehicular Ad Hoc Network has attracted both research and industrial community due to its benefits in facilitating human life and enhancing the security and comfort. However, various issues have been faced in such networks such as information security, routing reliability, dynamic high mobility of vehicles, that influence the stability of communication. To overcome this issue, it is necessary to increase the routing protocols performances, by keeping only the stable path during the communication. The effective solutions that have been investigated in the literature are based on the link prediction to avoid broken links. In this paper, we propose a new solution based on machine learning concept for link prediction, using LR and Support Vector Regression (SVR) which is a variant of the Support Vector Machine (SVM) algorithm. SVR allows predicting the movements of the vehicles in the network which gives us a decision for the link state at a future time. We study the performance of SVR by comparing the generated prediction values against real movement traces of different vehicles in various mobility scenarios, and to show the effectiveness of the proposed method, we calculate the error rate. Finally, we compare this new SVR method with Lagrange interpolation solution.
Mohammed Laroui, Akrem Sellami, Boubakr Nour, Hassine Moungla, Hossam Afifi, Sofiane Boukli Hacene
GLOBECOM3
2018 NCP: A near ICN Cache Placement Scheme for IoT-Based Traffic Class
abstract
Information-Centric Networking is considered as one of the most promising architecture for IoT. The use of content-centric approach may improve the content access & dissemination, reduce the content retrieval latency, and enhance the network performance. The use of in-network caching in ICN enhances the data availability in the network, overcomes the issue of single-point failure, and improves IoT devices power efficiency. In this paper, we present a Near-ICN Cache Placement (NCP) scheme for IoT taking traffic class into consideration. NCP is designed to select the optimal replica cache by minimizing: the cost of moving the data from content producer to replica nodes, the cost of caching the content in the replica and the cost of delivery the content to consumers. Hence, we presented a multi-objective optimization problem, with a heuristic caching selection algorithm. We evaluated NCP with various performance metrics against different caching schemes. The obtained results show improvement in the cache utilization, with fast data retrieval, and enhancement in the network cache distribution & diversity.
Boubakr Nour, Kashif Sharif, Fan Li 0001, Hassine Moungla, Ahmed E. Kamal 0001, Hossam Afifi
GLOBECOM1
2017 A Distributed ICN-Based IoT Network Architecture: An Ambient Assisted Living Application Case Study
abstract
The distributed Information-Centric Networking architecture has shown enormous potential to replace the host centric Internet architecture. A number of solutions such as Named Data Networking have become available. Building application services and integrating other technological design on top of ICNs is a challenging task, and has many open issues, hence an efficient distributed architecture needs to be developed. In this paper, we address the case of using IoT architecture targeted for ambient assisted living applications, on top of named data networking. We have proposed a complete architecture and implementation details for device & service networking, communication model, management, and naming. Within each model we have proposed mechanisms which support node mobility, hand-off, packet design, and push & pull data services without changing NDN data exchange model. This architecture is flexible, scalable, and can be adapted to other application specific IoT networks. We also have implemented the proposal on NDN simulator, and evaluated different services. The communication overhead and mobility implications have been studied to show effectiveness of new services with negligible cost to the network.
Boubakr Nour, Kashif Sharif, Fan Li 0001, Hassine Moungla
GLOBECOM1
2017 M2HAV: A Standardized ICN Naming Scheme for Wireless Devices in Internet of Things
Boubakr Nour, Kashif Sharif, Fan Li 0001, Hassine Moungla, Yang Liu 0038
WASA1