Mosab Hamdan

dblp:266/1958 · DBLP profile ↗
← Back
2ranked-venue papers in the field
0as first author
2since 2021 · last 2025
0000-0002-1008-3028ORCID · verified

Domains — venue-derived; a paper can count in several

Big Data, Cloud & Distributed Data Systems · 2
YearPublicationVenuePosition
2025 A Multi-Layer Phishing Defense Framework for Trusted Cloud Environments
abstract
Phishing attacks remain a persistent threat to the confidentiality and trust of cloud environments, enabling credential theft and unauthorized access to sensitive resources. This paper presents PhishDefender, a multi-layer phishing defense framework that enhances trustworthy cloud services through the integration of ensemble machine learning, policy enforcement, and threat intelligence validation. Built on the UCI Phishing Website dataset, the ensemble model combining Logistic Regression, Random Forest, Gradient Boosting, AdaBoost, XGBoost, Multilayer Perceptron and Deep Neural Network achieved 97.82% accuracy, 97.91% precision, 97.74% recall, 97.82% F1-score and a ROC-AUC of 0.988, with an average inference time of ≈ 1.05 seconds. These results demonstrate high separability between legitimate and phishing URLs while maintaining practical performance for deployment in real-time cloud applications. The framework further extends detection outcomes into actionable policy responses (Allow, Alert, Report, Block) verified against external threat feeds, forming a layered defense aligned with zero-trust architecture principles. Its lightweight and modular design enables deployment on standard or cloud-hosted infrastructure, offering a reproducible and scalable approach for organizations seeking to enhance trust, resilience, and compliance in distributed cloud ecosystems.
Alias Davis, Samah Abdelsalam, Mustafa Ghaleb, Mohammed Salih Mohammed Gismalla, E. I. Eltahir, Mosab Hamdan
BDCAT6
2025 Zero Trust Architecture for Ransomware Defense in Virtualized Environment
abstract
The ongoing surge of ransomware has underscored the need to shift from perimeter-based security to Zero Trust models. This paper investigates a Zero Trust Architecture (ZTA) approach to containing ransomware in a virtualized environment using least-privilege controls, micro-segmentation, and continuous monitoring. We develop an open-source, lightweight security architecture comprising Wazuh for real-time auditing and alerts, audited for system logging, and the Uncomplicated Firewall (UFW) for network segmentation within a VirtualBox laboratory network, consisting of Ubuntu as the victim and Kali as the attacker virtual machines. A simulated ransomware attack is conducted to evaluate detection latency, data impact, system overhead, and alert accuracy. The prototype ZTA framework detected ransomware activity in an average of ≈ 5.3 seconds. This detection limited encryption to approximately 20% of files prior to the activation of containment measures, while maintaining minimal CPU and memory overhead and exhibiting a low rate of false positives. These findings illustrate the successful early containment of ransomware via the implementation of Zero Trust controls. Although evaluated in a laboratory environment, the methodology is applicable to trustworthy and secure cloud or hybrid systems by improving data protection, facilitating compliance-oriented audits, and minimizing the impact of attacks.
Atharva Dhumal, Mustafa Ghaleb, Samah Abdelsalam, Arghir-Nicolae Moldovan, Mosab Hamdan
BDCAT5