EDBT 2026 Demo / reviewers in the wild / expert
Mosab Khayat
dblp:230/3628 · also Mosab A. Khayat
· DBLP profile ↗
4ranked-venue papers
2as first author
2since 2021 · last 2023
0000-0002-6166-9889ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 2 · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 2 first-author
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Network and information security
2 papers |
Network security · 100% | |
| Computer graphics and multimedia
2 papers |
Visualization and visual analytics · 100% | |
| Computer architecture, parallel and distributed computing, and storage systems
1 paper |
Parallel and multicore computing · 77% Distributed systems · 23% | |
| Computer networks
1 paper |
Network measurement and analytics · 100% |
Topics — the 8 heaviest of 9, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Network security › intrusion detection and prevention
intrusion detection |
1.2 | 2 | 2023 | PRISM: A Hierarchical Intrusion Detection Architecture for Large-Scale Cyber Networks · IEEE Trans. Dependable Secur. Comput. 2023 Guard: Attack-Resilient Adaptive Load Balancing in Distributed Streaming Systems · IEEE Trans. Dependable Secur. Comput. 2022 |
Network security › intrusion detection and prevention › intrusion detection › attack detection
multi-stage attack detection |
0.7 | 1 | 2023 | PRISM: A Hierarchical Intrusion Detection Architecture for Large-Scale Cyber Networks · IEEE Trans. Dependable Secur. Comput. 2023 |
Network security › intrusion detection and prevention › intrusion detection
attack detection |
0.6 | 1 | 2022 | Guard: Attack-Resilient Adaptive Load Balancing in Distributed Streaming Systems · IEEE Trans. Dependable Secur. Comput. 2022 |
Parallel and multicore computing › load balancing
adaptive load balancing |
0.6 | 1 | 2022 | Guard: Attack-Resilient Adaptive Load Balancing in Distributed Streaming Systems · IEEE Trans. Dependable Secur. Comput. 2022 |
Visualization and visual analytics › visual analytics
social media visual analytics |
0.4 | 1 | 2020 | VASSL: A Visual Analytics Toolkit for Social Spambot Labeling · IEEE Trans. Vis. Comput. Graph. 2020 |
Visualization and visual analytics › visualization evaluation
visual analytics evaluation |
0.4 | 1 | 2020 | The Validity, Generalizability and Feasibility of Summative Evaluation Methods in Visual Analytics · IEEE Trans. Vis. Comput. Graph. 2020 |
Network measurement and analytics › sampling
traffic sampling |
0.2 | 1 | 2023 | PRISM: A Hierarchical Intrusion Detection Architecture for Large-Scale Cyber Networks · IEEE Trans. Dependable Secur. Comput. 2023 |
Distributed systems
fault tolerance |
0.2 | 1 | 2022 | Guard: Attack-Resilient Adaptive Load Balancing in Distributed Streaming Systems · IEEE Trans. Dependable Secur. Comput. 2022 |
Methods — techniques the papers use, named apart from their topics
stream management · 1.3hidden markov model · 1.3attacker behavior modeling · 1.3unsupervised machine learning · 1.1user study · 0.9topic modeling · 0.9sentiment analysis · 0.9dimensionality reduction · 0.9taxonomy · 0.4survey · 0.4
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2023 | PRISM: A Hierarchical Intrusion Detection Architecture for Large-Scale Cyber NetworksabstractThe increase in scale of cyber networks and the rise in sophistication of cyber-attacks have introduced several challenges in intrusion detection. The primary challenge is the requirement to detect complex multi-stage attacks in realtime by processing the immense amount of traffic produced by present-day networks. In this paper we present PRISM, a hierarchical intrusion detection architecture that uses a novel attacker behavior model-based sampling technique to minimize the realtime traffic processing overhead. PRISM has a unique multi-layered architecture that monitors network traffic distributedly to provide efficiency in processing and modularity in design. PRISM employs a Hidden Markov Model-based prediction mechanism to identify multi-stage attacks and ascertain the attack progression for a proactive response. Furthermore, PRISM introduces a stream management procedure that rectifies the issue of alert reordering when collected from distributed alert reporting systems. To evaluate the performance of PRISM, multiple metrics have been proposed, and various experiments have been conducted on multi-stage attack datasets. The results exhibit up to 7.5x improvement in processing overhead as compared to a standard centralized IDS without the loss of prediction accuracy while demonstrating the ability to predict different attack stages promptly. Yahya Javed, Mosab Khayat, Ali A. Elghariani, Arif Ghafoor |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2022 | Guard: Attack-Resilient Adaptive Load Balancing in Distributed Streaming SystemsabstractThe performance of distributed streaming systems relies on how even the workload is distributed among their machines. However, data and query workloads are skewed and change rapidly. Therefore, multiple adaptive load-balancing mechanisms have been proposed in the literature to rebalance distributed streaming systems according to the changes in their workloads. This paper introduces a novel attack model that targets adaptive load-balancing mechanisms of distributed streaming systems. The attack reduces the throughput and the availability of the system by making it stay in a continuous state of rebalancing. This paper proposesGuard, a component that detects and blocks attacks that target the adaptive load balancing of distributed streaming systems. Guard uses an unsupervised machine-learning technique to detect malicious users that are involved in the attack. Guard does not block any user unless it detects that the user is malicious. Guard does not depend on a specific application. Experimental evaluation for a high-intensity attack illustrates that Guard improves the throughput and the availability of the system by 85% and 86%, respectively. Moreover, Guard improves the minimum availability that the attacker achieves by 325%. Anas Daghistani, Mosab Khayat, Muhamad Felemban, Walid G. Aref, Arif Ghafoor |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2020 | The Validity, Generalizability and Feasibility of Summative Evaluation Methods in Visual AnalyticsabstractMany evaluation methods have been used to assess the usefulness of Visual Analytics (VA) solutions. These methods stem from a variety of origins with different assumptions and goals, which cause confusion about their proofing capabilities. Moreover, the lack of discussion about the evaluation processes may limit our potential to develop new evaluation methods specialized for VA. In this paper, we present an analysis of evaluation methods that have been used to summatively evaluate VA solutions. We provide a survey and taxonomy of the evaluation methods that have appeared in the VAST literature in the past two years. We then analyze these methods in terms of validity and generalizability of their findings, as well as the feasibility of using them. We propose a new metric called summative quality to compare evaluation methods according to their ability to prove usefulness, and make recommendations for selecting evaluation methods based on their summative quality in the VA domain. Mosab Khayat, Morteza Karimzadeh, David S. Ebert, Arif Ghafoor |
IEEE Trans. Vis. Comput. Graph. | 1 |
| 2020 | VASSL: A Visual Analytics Toolkit for Social Spambot LabelingabstractSocial media platforms are filled with social spambots. Detecting these malicious accounts is essential, yet challenging, as they continually evolve to evade detection techniques. In this article, we present VASSL, a visual analytics system that assists in the process of detecting and labeling spambots. Our tool enhances the performance and scalability of manual labeling by providing multiple connected views and utilizing dimensionality reduction, sentiment analysis and topic modeling, enabling insights for the identification of spambots. The system allows users to select and analyze groups of accounts in an interactive manner, which enables the detection of spambots that may not be identified when examined individually. We present a user study to objectively evaluate the performance of VASSL users, as well as capturing subjective opinions about the usefulness and the ease of use of the tool. Mosab Khayat, Morteza Karimzadeh, Jieqiong Zhao, David S. Ebert |
IEEE Trans. Vis. Comput. Graph. | 1 |