EDBT 2026 Demo / reviewers in the wild / expert
Ali AlSabeh
dblp:271/5185
· DBLP profile ↗
14ranked-venue papers
5as first author
13since 2021 · last 2026
0000-0001-7063-4840ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 9 · 3 first-author · 8 since 2021Security and privacy · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | A Testbed to Evaluate Next-Generation Security Solutions in Cyber-Physical Systems using Hardware AccelerationabstractAt the core of modern manufacturing systems lie Cyber-Physical Systems (CPS) that prioritize operational continuity over security, resulting in a rising number of cyberattacks targeting critical infrastructures. This paper presents a work-in-progress testbed that modernizes Smart Manufacturing Systems (SMS) by integrating Domain-Specific Accelerators (DSAs)—Data Processing Units (DPUs) and Programmable Data Plane (PDP) switches—to strengthen Operational Technology (OT) security without compromising availability or reliability. These accelerators provide fine-grained visibility, real-time anomaly detection, and efficient policy enforcement at line rate. Preliminary results show that accelerator-based applications outperform CPU-based implementations by several orders of magnitude. Demonstrated use cases include a DPU that performs memory inspection via Direct Memory Access (DMA) to detect injected anomalies and a PDP that implements inline detection using pre-trained Machine Learning (ML) models. With low processing overhead, the system also enables continuous telemetry collection for digital-twin generation without disrupting critical operations. The testbed, deployed on the South Carolina Cloud (SC Cloud), offers remote access for developing and evaluating next-generation CPS and OT security applications. Ali AlSabeh, Ali Mazloum, Elie F. Kfoury, Ramy F. Harik, Thorsten Wuest, Jorge Crichigno |
CCNC | 2 |
| 2026 | Design and Deployment of a Testbed for SmartNIC and Programmable Data Plane ExperimentationabstractThis paper presents the design and deployment of a virtualized testbed that facilitates experimentation and instruction in programmable network systems. The platform integrates Smart Network Interface Cards (SmartNICs), Programmable Data Plane (PDP) switches, and the Data Plane Development Kit (DPDK), within a cloud-based orchestration framework to reproduce high-performance, real-world networking scenarios. It supports line-rate processing, enabling real-time applications such as telemetry, encrypted traffic inspection, and malware detection. Through a series of use cases, we demonstrate how the testbed enables advanced experimentation by offloading infrastructure functions to the data plane, achieving low latency, high throughput, and high scalability. The system also provides users with guided labs for learners and is accessible via NETLAB+ for remote use. Future work includes federation with national-scale infrastructures such as FABRIC to broaden access and support multi-institutional collaboration. Samia Choueiri, Ali Mazloum, Sergio Elizalde, Amith GSPN, Ali AlSabeh, Elie F. Kfoury, Jorge Crichigno |
CCNC | 6 |
| 2025 | Toward Fingerprinting Encrypted C2 Traffic in the Data Planeabstract• Transport Layer Security (TLS) is the dominant protocol that enables users to securely interact with the Internet. • Threat actors are using TLS to bypass traditional cybersecurity defenses like firewalls and intrusion detection systems. • Modern malware attacks are hiding behind TLS secure channels. • Many malware families that infect users receive malicious instructions from the command and control (C2) server. • As the communication between malware and the C2 server is encrypted, it can easily bypass modern security appliances that rely on deep packet inspection (DPI). • In response to this threat, this project aims at utilizing ML to identify encrypted C2 communication. • The project implements a distributed ML model over two hardware accelerators. • The system achieves 99.3% detection accuracy with a microsecond-level processing latency. Ali Mazloum, Elie F. Kfoury, Ali AlSabeh, Jorge Crichigno |
GLOBECOM | 3 |
| 2025 | Real-Time Flow Statistics Collection Using RDMA and P4 Programmable Data PlanesabstractMeasuring network traffic in real time is essential for applications such as traffic profiling, anomaly detection, resource allocation, and network performance improvement. As network speeds and traffic volumes increase, traditional solutions (e.g., NetFlow, sFlow, Zeek) face challenges in processing and summarizing traffic efficiently, often leading to incomplete measurements. This paper introduces a system that summarizes network traffic and provides per-flow measurements in real time by leveraging P4 Programmable Data Planes (PDPs). The system computes per-flow traffic statistics directly in the data plane at line rate. The statistics are then transmitted to a server using the low-latency, high-throughput RDMA over Converged Ethernet (RoCEv2) protocol. On the server, worker threads process the received reports and update a global data structure that maintain the flows. The system was implemented and tested using an Intel Tofino-based PDP and an RDMA-capable SmartNIC (NVIDIA BlueField-2). Experiments on real packet traces show that the system is capable of analyzing traffic at scale without compromising the accuracy of the measurements, outperforming traditional Network Security Monitors (NSMs). Elie F. Kfoury, Ali Mazloum, Ali AlSabeh, Jorge Crichigno |
ICC | 4 |
| 2025 | Domain Name Security Inspection at Line Rate: Tls Sni Extraction in the Data Plane Using P4 and DpdkabstractA widely adopted approach to monitor HTTPS traffic leverages the Server Name Identification (SNI) extension of TLS. Generally, the hostname is transferred in plain text over the SNI field and Deep Packet Inspection (DPI) is used to parse the TLS header and extract the hostname. However, DPI is often performed on general-purpose processors and utilizes the kernel of the operating system, which results in an overhead to the network, especially under high traffic loads. To this end, this paper proposes offloading the identification of SNI hostnames to the data plane using P4 and the Data Plane Development Kit (DPDK). In the proposed system, a P4 Programmable Data Plane (PDP) switch is the first line of defense where most of the TLS traffic is processed. DPDK is the second line of defense which processes all TLS packets that require processing capabilities beyond what the P4 PDP switch provides. To support line rate pattern matching on the hostname, the DPDK application is offloaded to a SmartNIC, leveraging its Regex engine. Experiments on various recent and public datasets from different regions and platforms reveal that the P4 switch is capable of parsing 85%99 % of hostnames. Furthermore, performance analysis shows that the P4 switch and the DPDK application, respectively, inspect a hostname in around 1 microsecond ($\mu \mathrm{s}$) and$7 \mu ~\mathrm{s}$, achieving an order of magnitude improvement over solution running on general-purpose processors. Ali Mazloum, Ali AlSabeh, Elie F. Kfoury, Jorge Crichigno |
ICC | 2 |
| 2025 | Enabling Line-Rate TLS SNI Inspection in P4 Programmable Data PlanesabstractWith the increasing adoption of the HyperText Transfer Protocol Secure (HTTPS), organizations face new challenges in monitoring traffic to defend against attacks and enforce security policies, such as filtering malicious websites. One widely used technique to monitor HTTPS is by scrutinizing the hostname in the Server Name Identification (SNI) extension during the Transport Layer Security (TLS) handshake. Parsing the SNI typically involves Deep Packet Inspection (DPI), often performed on general-purpose processors, which can create bottlenecks and significantly impact network throughput. In response, this paper introduces a novel framework for parsing and identifying SNI hostnames in the data plane at line-rate using P4. Evaluation results on recent publicly available datasets from various regions and platforms demonstrate that our framework can successfully parse 85%-99% of hostnames in P4. Furthermore, performance analysis reveals that the proposed data plane solution can inspect the hostname in approximately 1 microsecond (μ s), representing orders of magnitude improvement over solutions running on Central Processing Units (CPUs). Ali AlSabeh, Ali Mazloum, Elie F. Kfoury, Jorge Crichigno, Hala Strohmier Berry |
NOMS | 1 |
| 2025 | Security applications in P4: Implementation and lessons learned
Ali Mazloum, Ali AlSabeh, Elie F. Kfoury, Jorge Crichigno |
Comput. Networks | 2 |
| 2025 | A survey on security applications with SmartNICs: Taxonomy, implementations, challenges, and future trendsabstractOver the last decade, network applications have grown exponentially, demanding high-speed interconnects. Unfortunately, chip manufacturers are approaching the upper limits of silicon-based computing with slow improvements in computational performance and energy efficiency. This trend has forced the industry to shift paradigms, moving from monolithic architectures to heterogeneous, domain-specific designs. Moreover, the ever-evolving threats compromise digital services and demand more scalable and flexible solutions to ensure service continuity in production networks. Smart Network Interface Cards (SmartNICs) are a product of this new paradigm, integrating domain-specific engines and general-purpose cores to offload various network infrastructure tasks, including those related to security. This paper provides a comprehensive overview of SmartNICs, with a particular focus on their role in strengthening network defenses. It introduces SmartNIC technology and presents a taxonomy of security applications offloaded to SmartNICs, categorized into Intrusion Detection and Prevention Systems (IDS/IPS), defenses against volumetric attacks, and data confidentiality mechanisms. Additionally, the paper explores vulnerabilities associated with adopting SmartNICs in the cloud, examining the threat model and reviewing proposed remediations in the literature. Finally, it discusses challenges and future trends in SmartNIC security applications, highlighting current initiatives and open research areas. Sergio Elizalde, Ali AlSabeh, Ali Mazloum, Samia Choueiri, Elie F. Kfoury, Jorge Crichigno |
J. Netw. Comput. Appl. | 2 |
| 2025 | Enhancing visibility on a science DMZ with P4-perfSONARabstractThe Science Demilitarized Zone (Science DMZ) is a specialized network designed to facilitate the transfer of large-scale scientific data. One of the key elements of the Science DMZ is perfSONAR, an active performance measurement device that monitors end-to-end paths over multiple domains. Although versatile, perfSONAR faces limitations such as restricted visibility of events and coarse-grained measurements. This paper proposes a scheme that integrates P4 programmable data plane (PDP) switches with perfSONAR. P4 PDP switches are passively installed and operate on real-time traffic copies, providing flexibility to collect fine-grained custom measurements and report events in the data plane. This integration enables perfSONAR to collect per-flow granular statistics of actual traffic, identify a broader range of networking issues, and enhance visibility while reducing the overhead of active tests. Additionally, the scheme uses an adaptive linear prediction (LP) model that dynamically adjusts the rate of reports sent from the P4 PDP switch to perfSONAR, minimizing the storage and processing needed for the latter. Experimental results show that the system reduces the number of reports by a factor of five while maintaining a small and configurable relative mean error (RME). Ali Mazloum, Elie F. Kfoury, Ali AlSabeh, Jorge Crichigno |
J. Netw. Comput. Appl. | 3 |
| 2024 | perfSONAR: Enhancing Data Collection through Adaptive SamplingabstractperfSONAR IS a tool used to monitor and troubleshoot problems in high-speed networks such as Science Demilitarized Zones (DMZs). It is essential to validate that data transfers are performing as expected. However, perfSONAR suffers from the trade-off between the measurement accuracy and the overhead induced by its active testsThis paper presents a scheme that offloads the traffic monitoring to a programmable data plane (PDP) switch. The scheme integrates a PDP switch with perfSONAR, where the switch continuously collects network measurements (e.g., latency, throughput, packet loss rate) and periodically reports the measurements to the perfSONAR archiver. This integration significantly enhances the granularity, visibility, and troubleshooting capabilities of perfSONAR. Additionally, the scheme automates the reporting period according to the variability of the monitored measurements, which eliminates the need of human intervention observed in today’s networks. In contrast to traditional schemes that report all measurements, the proposed approach uses the Linear Prediction (LP) method to only report the samples that reveal a variation on the measurements. Experimental results show that the system reduces the number of reports by five times under stable network conditions and sustains a relative mean error (RME) below 0.06. Ali Mazloum, Ali AlSabeh, Elie F. Kfoury, Jorge Crichigno |
NOMS | 2 |
| 2024 | On DGA Detection and Classification Using P4 Programmable Switches
Ali AlSabeh, Kurt Friday, Elie F. Kfoury, Jorge Crichigno, Elias Bou-Harb |
Comput. Secur. | 1 |
| 2023 | Effective DGA Family Classification Using a Hybrid Shallow and Deep Packet Inspection Technique on P4 Programmable SwitchesabstractDomain Generation Algorithms (DGAs) are one of the most effective strategies for malware to obtain a connection with the adversary's Command and Control (C2) server. Moreover, the growing number of DGA families makes it increasingly challenging for defense strategies to promptly identify the DGA family behind a given compromise. State-of-the-art high-dimensional DGA detection models perform poorly in such multiclass classification scenarios because their domain name-based features fail to distinguish between DGA families. To this extent, this paper proposes a novel framework that harnesses the flexibility, per-packet granularity, and Terabits per second (Tbps) processing capabilities of P4 Programmable Data Plane (PDP) switches to swiftly and accurately classify DGA families. In particular, the P4 PDP switch is leveraged to extract a combination of unique network heuristics and domain name features through shallow and Deep Packet Inspection (DPI) with minimal throughput reduction. Such collected features cannot be tracked on commodity hardware without significantly degrading the throughput in high-speed networks, nor on traditional layer 2/3 switches due to their limited and fixed functionalities. We crawled hundreds of Gigabytes (GBs) of malware samples from different sources to obtain instances of 50 DGA families and show that the proposed approach can promptly classify each family with high accuracy. Such a reliable multiclass classification enables the immediate halting of malicious communications while allowing network operators to initiate appropriate mitigation, incident management, and provisioning strategies. Ali AlSabeh, Kurt Friday, Jorge Crichigno, Elias Bou-Harb |
ICC | 1 |
| 2022 | A survey on security applications of P4 programmable switches and a STRIDE-based vulnerability assessment
Ali AlSabeh, Joseph Khoury, Elie F. Kfoury, Jorge Crichigno, Elias Bou-Harb |
Comput. Networks | 1 |
| 2020 | Exploiting Ransomware Paranoia For Execution PreventionabstractRansomware attacks cost businesses more than $75 billion/year, and it is predicted to cost $6 trillion/year by 2021. These numbers demonstrate the havoc produced by ransomware on a large number of sectors and urge security researches to tackle it. Several ransomware detection approaches have been proposed in the literature that interchange between static and dynamic analysis. Recently, ransomware attacks were shown to fingerprint the execution environment before they attack the system to counter dynamic analysis. In this paper, we exploit the behavior of contemporary ransomware to prevent its attack on real systems and thus avoid the loss of any data. We explore a set of ransomware-generated artifacts that are launched to sniff the surrounding. Furthermore, we design, develop, and evaluate an approach that monitors the behavior of a program by intercepting the called Windows APIs. Consequently, we determine in real-time if the program is trying to inspect its surrounding before the attack, and abort it immediately prior to the initiation of any malicious encryption or locking. Through empirical evaluations using real and recent ransomware samples, we study how ransomware and benign programs inspect the environment. Additionally, we demonstrate how to prevent ransomware with a low false positive rate. We make the developed approach available to the research community at large through GitHub to strongly promote cyber security defense operations and for wide-scale evaluations and enhancements. Ali AlSabeh, Haïdar Safa, Elias Bou-Harb, Jorge Crichigno |
ICC | 1 |