EDBT 2026 Demo / reviewers in the wild / expert
Farkhund Iqbal
dblp:47/477
· DBLP profile ↗
38ranked-venue papers
5as first author
13since 2021 · last 2024
0000-0001-9081-3598ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 10 · 1 first-author · 2 since 2021Artificial intelligence and machine learning · 9 · 1 first-author · 5 since 2021Databases, data management, data science and information retrieval · 6 · 2 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 4Computer networks · 3 · 1 first-author · 1 since 2021Human-computer interaction and ubiquitous computing · 3 · 2 since 2021Systems, architecture and hardware · 2 · 1 since 2021Software engineering, systems software and programming languages · 1Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 first-author · 1 since 2021Theory of computation · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | Forensic Investigation of Humanoid Social Robot: A Case Study on Zenbo RobotabstractThe Internet of Things (IoT) plays a significant role in our daily lives as interconnection and automation positively impact our societal needs. In contrast to traditional devices, IoT devices require connectivity and data sharing to operate effectively. This interaction necessitates that data resides on multiple platforms and often across different locations, posing challenges from a digital forensic investigator's perspective. Recovering a full trail of data requires piecing together elements from various devices and locations. IoT-based forensic investigations include an increasing quantity of objects of forensic interest, the uncertainty of device relevance in terms of digital artifacts or potential data, blurry network boundaries, and edgeless networks, each of which poses new challenges for the identification of significant forensic artifacts. One example of the positive societal impact of IoT devices is that of Humanoid robots, with applications in public spaces such as assisted living, medical facilities, and airports. These robots use IoT to provide varying functionality but rely heavily on supervised learning to customize their utilization of the IoT to various environments. A humanoid robot can be a rich source of sensitive data about individuals and environments, and this data may assist in digital investigations, delivering additional information during a crime investigation. In this paper, we present our case study on the Zenbo Humanoid Robot, exploring how Zenbo could be a witness to a crime. In our experiments, a forensic examination was conducted on the robot to locate all useful evidence from multiple locations, including root-level directories using logical acquisition. Farkhund Iqbal, Abdulla Kazim, Áine MacDermott, Richard Adeyemi Ikuesan, Musaab Hasan, Andrew Marrington |
ARES | 1 |
| 2024 | Evaluating the Efficacy of Large Language Models in Identifying Phishing AttemptsabstractPhishing, a prevalent cybercrime tactic for decades, remains a significant threat in today's digital world. By leveraging clever social engineering elements and modern technology, cybercrime targets many individuals, businesses, and organizations to exploit trust and security. These cyber-attackers are often disguised in many trustworthy forms to appear as legitimate sources. By cleverly using psychological elements like urgency, fear, social proof, and other manipulative strategies, phishers can lure individuals into revealing sensitive and personalized information. Building on this pervasive issue within modern technology, this paper will aim to analyze the effectiveness of 15 Large Language Models (LLMs) in detecting phishing attempts, specifically focusing on a randomized set of “419 Scam” emails. The objective is to determine which LLMs can accurately detect phishing emails by analyzing a text file containing email metadata based on predefined criteria. The experiment concluded that the following models, ChatGPT 3.5, GPT-3.5-Turbo-Instruct, and ChatGPT, were the most effective in detecting phishing emails. Het Patel, Umair Rehman, Farkhund Iqbal |
HSI | 3 |
| 2024 | Multimodal Religiously Hateful Social Media Memes Classification Based on Textual and Image DataabstractMultimodal hateful social media meme detection is an important and challenging problem in the vision-language domain. Recent studies show high accuracy for such multimodal tasks due to datasets that provide better joint multimodal embedding to narrow the semantic gap. Religiously hateful meme detection is not extensively explored among published datasets. While there is a need for higher accuracy on religiously hateful memes, deep learning–based models often suffer from inductive bias. This issue is addressed in this work with the following contributions. First, a religiously hateful memes dataset is created and published publicly to advance hateful religious memes detection research. Over 2000 meme images are collected with their corresponding text. The proposed approach compares and fine-tunes VisualBERT pre-trained on the Conceptual Caption (CC) dataset for the downstream classification task. We also extend the dataset with the Facebook hateful memes dataset. We extract visual features using ResNeXT-152 Aggregated Residual Transformations–based Masked Regions with Convolutional Neural Networks (R-CNN) and Bidirectional Encoder Representations from Transformers (BERT) uncased for textual encoding for the early fusion model. We use the primary evaluation metric of an Area Under the Operator Characters Curve (AUROC) to measure model separability. Results show that the proposed approach has a higher AUROC score of 78%, proving the model’s higher separability performance and an accuracy of 70%. It shows comparatively superior performance considering dataset size and against ensemble-based machine learning approaches. Abdul Rehman Javed, Farkhund Iqbal, Amanullah Yasin, Gautam Srivastava 0001, Dawid Polap, G. Thippa Reddy, Zunera Jalil |
ACM Trans. Asian Low Resour. Lang. Inf. Process. | 3 |
| 2024 | Data Augmentation-based Novel Deep Learning Method for Deepfaked Images DetectionabstractRecent advances in artificial intelligence have led to deepfake images, enabling users to replace a real face with a genuine one. deepfake images have recently been used to malign public figures, politicians, and even average citizens. deepfake but realistic images have been used to stir political dissatisfaction, blackmail, propagate false news, and even carry out bogus terrorist attacks. Thus, identifying real images from fakes has got more challenging. To avoid these issues, this study employs transfer learning and data augmentation technique to classify deepfake images. For experimentation, 190,335 RGB-resolution deepfake and real images and image augmentation methods are used to prepare the dataset. The experiments use the deep learning models: convolutional neural network (CNN), Inception V3, visual geometry group (VGG19), and VGG16 with a transfer learning approach. Essential evaluation metrics (accuracy, precision, recall, F1-score, confusion matrix, and AUC-ROC curve score) are used to test the efficacy of the proposed approach. Results revealed that the proposed approach achieves an accuracy, recall, F1-score and AUC-ROC score of 90% and 91% precision, with our fine-tuned VGG16 model outperforming other DL models in recognizing real and deepfakes. Farkhund Iqbal, Ahmed Abbasi, Abdul Rehman Javed, Ahmad S. Almadhor, Zunera Jalil, Sajid Anwar 0001, Imad Rida |
ACM Trans. Multim. Comput. Commun. Appl. | 1 |
| 2023 | Identification and Categorization of Unusual Internet of Vehicles Events in Noisy AudioabstractThe volume of multimedia data produced by various smart devices has increased dramatically with the advent of new digital technologies, including in the Internet of Vehicles (IoV). It has become more difficult to extract valuable insights from multimedia data due to several challenges during data analysis. The main problem is the need to quickly and precisely identify abnormalities in multimedia data. This research presents an unusual occurrence of the audio forensics database named UOAFDB and a practical method for identifying and categorizing unusual occurrences in audio files. To study the detection of abnormal audio and the classification of rare sound (e.g., car crash—machine gun, explosion) events for audio forensics, we construct a large audio dataset containing ten rare special events (anomalies) with 15 different background environmental settings (e.g., beach, restaurant, and train). The suggested method determines the optimal amount of features using the best feature extraction methodology available by extracting Mel-frequency cepstral coefficients (MFCCs) features from the audio signals of the newly formed dataset. Modern deep learning algorithms use these features as input to assess performance. Additionally, we apply deep learning methods to the most recent and best available dataset and obtain promising outcomes. The experimental findings demonstrate promising results on the UOAFDB dataset. Farkhund Iqbal, Ahmad Abbasi, Abdul Rehman Javed, Gautam Srivastava 0001, Zunera Jalil, G. Thippa Reddy |
VTC2023-Spring | 1 |
| 2023 | DeepClassRooms: a deep learning based digital twin framework for on-campus class rooms
Muhammad Saad Razzaq, Babar Shah, Farkhund Iqbal, Muhammad Ilyas 0005, Fahad Maqbool, Álvaro Rocha 0001 |
Neural Comput. Appl. | 3 |
| 2023 | Differentially Private Release of Heterogeneous Network for Managing Healthcare DataabstractWith the increasing adoption of digital health platforms through mobile apps and online services, people have greater flexibility connecting with medical practitioners, pharmacists, and laboratories and accessing resources to manage their own health-related concerns. Many healthcare institutions are connecting with each other to facilitate the exchange of healthcare data, with the goal of effective healthcare data management. The contents generated over these platforms are often shared with third parties for a variety of purposes. However, sharing healthcare data comes with the potential risk of exposing patients’ sensitive information to privacy threats. In this article, we address the challenge of sharing healthcare data while protecting patients’ privacy. We first model a complex healthcare dataset using a heterogeneous information network that consists of multi-type entities and their relationships. We then propose DiffHetNet , an edge-based differentially private algorithm, to protect the sensitive links of patients from inbound and outbound attacks in the heterogeneous health network. We evaluate the performance of our proposed method in terms of information utility and efficiency on different types of real-life datasets that can be modeled as networks. Experimental results suggest that DiffHetNet generally yields less information loss and is significantly more efficient in terms of runtime in comparison with existing network anonymization methods. Furthermore, DiffHetNet is scalable to large network datasets. Rashid Hussain Khokhar, Benjamin C. M. Fung, Farkhund Iqbal, Khalil Al-Hussaeni, Mohammed Hussain |
ACM Trans. Knowl. Discov. Data | 3 |
| 2022 | A GPU-based machine learning approach for detection of botnet attacksabstractRapid development and adaptation of the Internet of Things (IoT) has created new problems for securing these interconnected devices and networks. There are hundreds of thousands of IoT devices with underlying security vulnerabilities , such as insufficient device authentication/authorisation making them vulnerable to malware infection . IoT botnets are designed to grow and compete with one another over unsecure devices and networks. Once infected, the device will monitor a Command-and-Control (C&C) server indicating the target of an attack via Distributed Denial of Service (DDoS) attack. These security issues, coupled with the continued growth of IoT, presents a much larger attack surface for attackers to exploit in their attempts to disrupt or gain unauthorized access to networks, systems, and data. Large datasets available online provide good benchmarks for the development of accurate solutions for botnet detection , however model training is often a time-consuming process. Interestingly, significant advancement of GPU technology allows shortening the time required to train such large and complex models. This paper presents a methodology for the pre-processing of the IoT-Bot dataset and classification of various attack types included. We include descriptions of pre-processing actions conducted to prepare data for training and a comparison of results achieved with GPU accelerated versions of Random Forest , k-Nearest Neighbour, Support Vector Machine (SVM) and Logistic Regression classifiers from the cuML library. Using our methodology, the best-trained models achieved at least 0.99 scores for accuracy, precision, recall and f1-score. Moreover, the application of feature selection and training models on GPU significantly reduced the training and estimation times. Michal Motylinski, Áine MacDermott, Farkhund Iqbal, Babar Shah |
Comput. Secur. | 3 |
| 2022 | Distinguishing between fake news and satire with transformers
Jwen Fai Low, Benjamin C. M. Fung, Farkhund Iqbal, Shih-Chia Huang |
Expert Syst. Appl. | 3 |
| 2022 | Exploring the human factors in moral dilemmas of autonomous vehicles
Muhammad Umair Shah, Umair Rehman, Farkhund Iqbal, Hassan Ilahi |
Pers. Ubiquitous Comput. | 3 |
| 2022 | Recommendations for a smart toy parental control tool
Otávio de Paula Albuquerque, Marcelo Fantinato, Patrick C. K. Hung, Sarajane Marques Peres, Farkhund Iqbal, Umair Rehman, Muhammad Umair Shah |
J. Supercomput. | 5 |
| 2021 | An Alternate Account on the Ethical Implications of Autonomous VehiclesabstractGiven the widespread popularity of Autonomous Vehicles (AVs), researchers have been exploring the ethical implications of AVs. Researchers believe that empirical experiments can provide insights into human characterization of ethically sound machine behavior. Previous research indicates that humans generally endorse utilitarian AVs, however, this paper explores an alternative account on the discourse of ethical decision-making in AVs. We refrain from favoring consequentialism or non-consequential ethical theories, and argue that human moral decision-making is pragmatic, or in other words, ethically and rationally bounded. We hold the perspective that our moral preferences shift based on various externalities and biases. To further this concept, we conduct two Amazon Mechanical Turk studies to investigate factors, such as, the `degree of harm', and `level of affection', which influence people's moral decision-making. Our experimental findings seem to suggest that human moral judgements cannot be wholly deontological or utilitarian. We discovered that as the degree of harm decreased, people became less utilitarian (more deontological), and as the level of affection increased, people became less utilitarian (more deontological). These findings offer evidence on the ethical variations in human decision-making processes and refutes the view that aim to advocate application of a specific moral framework based on empirical evidence. The findings also offer useful insights for policymakers to explore the overall public perception on the ethical implications of AV. Muhammad Umair Shah, Umair Rehman, Farkhund Iqbal, Mohammed Hussain, Fazli Wahid |
Intelligent Environments | 3 |
| 2021 | ER-AE: Differentially Private Text Generation for Authorship AnonymizationabstractHaohan Bo, Steven H. H. Ding, Benjamin C. M. Fung, Farkhund Iqbal. Proceedings of the 2021 Conference of the North American Chapter of the Association for Computational Linguistics: Human Language Technologies. 2021. Haohan Bo, Steven H. H. Ding, Benjamin C. M. Fung, Farkhund Iqbal |
NAACL-HLT | 4 |
| 2020 | Blockchain-based chain of custody: towards real-time tamper-proof evidence managementabstractEvidence is a tangible demonstrative artifact that proves a fact and shapes the investigation of various misconduct cases involving for instance corruption, misbehavior, or violation. It is imperative to maintain proper evidence management to guarantee the admissibility of an evidence in a court of law. Chain of custody forms the forensic link of evidence sequence of control, transfer, and analysis to preserve evidence's integrity and to prevent its contamination. Blockchain, a distributed tamper-resistant ledger can be leveraged to offer a decentralized secure digital evidence system. In this paper, we propose a secure chain of custody framework by utilizing the blockchain technology to store evidence metadata while the evidence is stored in a reliable storage medium. The framework is built on top of a private Ethereum blockchain to document every transmission from the moment the evidence is seized, thus ensuring that evidence can only be accessed or possessed by authorized parties. The framework is integrated with the digital evidence system where evidence is physically stored and locked using smart locks. To secure the sequence of evidence submission and retrieval, only an authorized party can possess the key to unlock the evidence. Our proposed framework offers a secure solution that maintains evidence integrity and admissibility among multiple stakeholders such as law enforcement agencies, lawyers, and forensic professionals. The research findings shed light on hidden opportunities for the efficient usage of blockchain in other realms beyond finance and cryptocurrencies. Liza Ahmad, Salam Ismail Rasheed Khanji, Farkhund Iqbal, Faouzi Kamoun |
ARES | 3 |
| 2020 | 4P based forensics investigation framework for smart connected toysabstractSmart Connected Toys (SCTs) have the potential to collect terabytes of sensitive personal, contextual, and usage information which may be a subject of cybercrime or used as a conduit for cybercrime resulting in a digital forensic investigation which requires the examination of the digital artifact stored, processed or transmitted by the SCT. SCT forensics is challenging in most cases due to non-availability of specialized forensics tools and standardized evidence acquisition interface port. We explore the various privacy and security challenges plaguing the SCT industry and the possible safety risk SCT poses to children as a result of a lack of serious consideration technical controls surrounding the collection, processing, and storage of children's information and possible exposure to crime which will require digital forensic investigation. As a result of this gap in research and industry, we investigate current digital forensic solutions for SCTs and present an abstract forensics investigation framework with the focus on using non-conventional means which allow Investigators to successfully "Plan," "Preserve" "Process" and "Present" (4P) as a systematic means to conduct digital forensic analysis on an SCT in a situation where SCT is complicit in a criminal investigation or a subject of crime. Benjamin Yankson, Farkhund Iqbal, Patrick C. K. Hung |
ARES | 2 |
| 2020 | AI and machine learning: A mixed blessing for cybersecurityabstractWhile the usage of Artificial Intelligence and Machine Learning Software (AI/MLS) in defensive cybersecurity has received considerable attention, there remains a noticeable research gap on their offensive use. This paper reviews the defensive usage of AI/MLS in cybersecurity and then presents a survey of its offensive use. Inspired by the System-Fault-Risk (SFR) framework, we categorize AI/MLS-powered cyberattacks by their actions into seven categories. We cover a wide spectrum of attack vectors, discuss their practical implications and provide some recommendations for future research. Faouzi Kamoun, Farkhund Iqbal, Mohamed Amir Esseghir, Thar Baker |
ISNCC | 2 |
| 2020 | Guaranteed lifetime protocol for IoT based wireless sensor networks with multiple constraints
Babar Shah, Farkhund Iqbal, Asad Masood Khattak, Omar Alfandi, Ki-Il Kim |
Ad Hoc Networks | 4 |
| 2020 | On data-driven curation, learning, and analysis for inferring evolving internet-of-Things (IoT) botnets in the wild
Morteza Safaei Pour, Antonio Mangino, Kurt Friday, Matthias Rathbun, Elias Bou-Harb, Farkhund Iqbal, Sagar Samtani, Jorge Crichigno, Nasir Ghani |
Comput. Secur. | 6 |
| 2020 | A secure fog-based platform for SCADA-based IoT critical infrastructureabstractSummary The rapid proliferation of Internet of things (IoT) devices, such as smart meters and water valves, into industrial critical infrastructures and control systems has put stringent performance and scalability requirements on modern Supervisory Control and Data Acquisition (SCADA) systems. While cloud computing has enabled modern SCADA systems to cope with the increasing amount of data generated by sensors, actuators, and control devices, there has been a growing interest recently to deploy edge data centers in fog architectures to secure low‐latency and enhanced security for mission‐critical data. However, fog security and privacy for SCADA‐based IoT critical infrastructures remains an under‐researched area. To address this challenge, this contribution proposes a novel security “toolbox” to reinforce the integrity, security, and privacy of SCADA‐based IoT critical infrastructure at the fog layer. The toolbox incorporates a key feature: a cryptographic‐based access approach to the cloud services using identity‐based cryptography and signature schemes at the fog layer. We present the implementation details of a prototype for our proposed secure fog‐based platform and provide performance evaluation results to demonstrate the appropriateness of the proposed platform in a real‐world scenario. These results can pave the way toward the development of a more secure and trusted SCADA‐based IoT critical infrastructure, which is essential to counter cyber threats against next‐generation critical infrastructure and industrial control systems. The results from the experiments demonstrate a superior performance of the secure fog‐based platform, which is around 2.8 seconds when adding five virtual machines (VMs), 3.2 seconds when adding 10 VMs, and 112 seconds when adding 1000 VMs, compared to the multilevel user access control platform. Thar Baker, Muhammad Asim 0001, Áine MacDermott, Farkhund Iqbal, Faouzi Kamoun, Babar Shah, Omar Alfandi, Mohammad Hammoudeh |
Softw. Pract. Exp. | 4 |
| 2019 | Data-driven Curation, Learning and Analysis for Inferring Evolving IoT Botnets in the WildabstractThe insecurity of the Internet-of-Things (IoT) paradigm continues to wreak havoc in consumer and critical infrastructure realms. Several challenges impede addressing IoT security at large, including, the lack of IoT-centric data that can be collected, analyzed and correlated, due to the highly heterogeneous nature of such devices and their widespread deployments in Internet-wide environments. To this end, this paper explores macroscopic, passive empirical data to shed light on this evolving threat phenomena. This not only aims at classifying and inferring Internet-scale compromised IoT devices by solely observing such one-way network traffic, but also endeavors to uncover, track and report on orchestrated "in the wild" IoT botnets. Initially, to prepare the effective utilization of such data, a novel probabilistic model is designed and developed to cleanse such traffic from noise samples (i.e., misconfiguration traffic). Subsequently, several shallow and deep learning models are evaluated to ultimately design and develop a multi-window convolution neural network trained on active and passive measurements to accurately identify compromised IoT devices. Consequently, to infer orchestrated and unsolicited activities that have been generated by well-coordinated IoT botnets, hierarchical agglomerative clustering is deployed by scrutinizing a set of innovative and efficient network feature sets. By analyzing 3.6 TB of recent darknet traffic, the proposed approach uncovers a momentous 440,000 compromised IoT devices and generates evidence-based artifacts related to 350 IoT botnets. While some of these detected botnets refer to previously documented campaigns such as the Hide and Seek, Hajime and Fbot, other events illustrate evolving threats such as those with cryptojacking capabilities and those that are targeting industrial control system communication and control services. Morteza Safaei Pour, Antonio Mangino, Kurt Friday, Matthias Rathbun, Elias Bou-Harb, Farkhund Iqbal, Khaled B. Shaban, Abdelkarim Erradi |
ARES | 6 |
| 2019 | Drone Forensics: A Case Study on DJI Phantom 4abstractUnmanned Aerial Vehicles (UAVs) (a.k.a drones) have grown in popularity mainly due to its' ease of use, wide variety of uses, availability and inexpensiveness nature of the devices. This rapid proliferation of UAVs has also augmented with several security issues and societal crimes pertaining to the illicit activities, making them rich sources of evidence. Therefore, it is crucial for digital forensics examiners to have the capability to recover, analyze, and authenticate the source of content stored on these devices. In this research, we perform a forensic investigation on an Unmanned Aircraft System, specifically the DJI Phantom 4 Vision, using several smartphone devices such as iPhone 6, iPhone 7 Plus, iPhone 10, Samsung Note 3, Samsung S7, Microsoft Lumia, CKTEL G5 Plus and G-Tide_s4 with different operating systems (iOS, Windows Phone and Android). In addition, we investigate and examine the logical backup acquisition of the iPhone 6, iPhone 7 Plus and iPhone 10 mobile devices using Apple iTunes backup utility. It was found that the DJI Phantom 4 App contains a significant amount of forensics data. Moreover, we acquired useful data from the SD card of mobile devices including controller and the drone. Dua'a Abu Hamdi, Farkhund Iqbal, Saiqa Alam, Abdulla Kazim, Áine MacDermott |
AICCSA | 2 |
| 2019 | A Comparative Analysis of Cyberbullying and Cyberstalking Laws in the UAE, US, UK and CanadaabstractBullying and stalking through cyberspace have become serious phenomena in the Internet era, impacting mainly young users and teenagers. Many tragic incidents have occurred, especially in the West, including self-harm and suicide due to these problems. To protect the victims many countries such as the United Arab Emirates (UAE), the United States (US), the United Kingdom (UK) and Canada have codified laws dealing with cyber-crimes, including cyber-harassment. To determine the adequacy of such laws in addressing these issues, we present in this paper a legal analysis of the existing anti-bullying and stalking laws in the UAE, US, UK, and Canada. The purpose is to gain perspective on the characteristics of the laws and their ability to protect society from various forms of crimes associated with cyberbullying and cyberstalking. The paper also presents recommendations to help combat cyberbullying and cyberstalking and protect our youth from these issues. Haifa Al Hosani, Maryam Yousef, Shaima Al Shouq, Farkhund Iqbal, Djedjiga Mouheb |
AICCSA | 4 |
| 2019 | Drone Forensics: A Case Study on a DJI Mavic AirabstractThe use and sale of Unmanned Aerial Vehicles (UAVs), or drones, have seen an immense amount of growth over the past few years. While capturing mass-market appeal and serving legitimate uses, there have been many incidents where UAVs were used to commit various sinister activities. Digital forensic examiners have consequently come to play a vital role in the emerging field of drone or UAV forensics. In this research we perform a forensic investigation on an Unmanned Aircraft System (UAS), specifically the DJI Mavic Air, using an iOS-based smartphone device. In our study we examine the data that can be extracted from the UAS in addition to investigating and analyzing the logical acquisition of the associated smartphone device created by Apple's iTunes backup utility. Our findings indicate that the mobile application used to control the UAV contains a significant amount of forensic data. Furthermore, we obtained valuable data from the external MicroSD card, the mobile device and the drone. Maryam Yousef, Farkhund Iqbal |
AICCSA | 2 |
| 2019 | Robot Computing for Music Visualization
Pei-Chun Lin, David Mettrick, Patrick C. K. Hung, Farkhund Iqbal |
TAMC | 4 |
| 2019 | Arabic Authorship Attribution: An Extensive Study on Twitter PostsabstractLaw enforcement faces problems in tracing the true identity of offenders in cybercrime investigations. Most offenders mask their true identity, impersonate people of high authority, or use identity deception and obfuscation tactics to avoid detection and traceability. To address the problem of anonymity, authorship analysis is used to identify individuals by their writing styles without knowing their actual identities. Most authorship studies are dedicated to English due to its widespread use over the Internet, but recent cyber-attacks such as the distribution of Stuxnet indicate that Internet crimes are not limited to a certain community, language, culture, ideology, or ethnicity. To effectively investigate cybercrime and to address the problem of anonymity in online communication, there is a pressing need to study authorship analysis of languages such as Arabic, Chinese, Turkish, and so on. Arabic, the focus of this study, is the fourth most widely used language on the Internet. This study investigates authorship of Arabic discourse/text, especially tiny text, Twitter posts. We benchmark the performance of a profile-based approach that uses n -grams as features and compare it with state-of-the-art instance-based classification techniques. Then we adapt an event-visualization tool that is developed for English to accommodate both Arabic and English languages and visualize the result of the attribution evidence. In addition, we investigate the relative effect of the training set, the length of tweets, and the number of authors on authorship classification accuracy. Finally, we show that diacritics have an insignificant effect on the attribution process and part-of-speech tags are less effective than character-level and word-level n -grams. Malik H. Altakrori, Farkhund Iqbal, Benjamin C. M. Fung, Steven H. H. Ding, Abdallah Tubaishat |
ACM Trans. Asian Low Resour. Lang. Inf. Process. | 2 |
| 2019 | Learning Stylometric Representations for Authorship AnalysisabstractAuthorship analysis (AA) is the study of unveiling the hidden properties of authors from textual data. It extracts an author's identity and sociolinguistic characteristics based on the reflected writing styles in the text. The process is essential for various areas, such as cybercrime investigation, psycholinguistics, political socialization, etc. However, most of the previous techniques critically depend on the manual feature engineering process. Consequently, the choice of feature set has been shown to be scenario- or dataset-dependent. In this paper, to mimic the human sentence composition process using a neural network approach, we propose to incorporate different categories of linguistic features into distributed representation of words in order to learn simultaneously the writing style representations based on unlabeled texts for AA. In particular, the proposed models allow topical, lexical, syntactical, and character-level feature vectors of each document to be extracted as stylometrics. We evaluate the performance of our approach on the problems of authorship characterization, authorship identification and authorship verification with the Twitter, blog, review, novel, and essay datasets. The experiments suggest that our proposed text representation outperforms the static stylometrics, dynamic n -grams, latent Dirichlet allocation, latent semantic analysis, distributed memory model of paragraph vectors, distributed bag of words version of paragraph vector, word2vec representations, and other baselines. Steven H. H. Ding, Benjamin C. M. Fung, Farkhund Iqbal, William Kwok-Wai Cheung |
IEEE Trans. Cybern. | 3 |
| 2018 | SafePath: Differentially-private publishing of passenger trajectories in transportation systems
Khalil Al-Hussaeni, Benjamin C. M. Fung, Farkhund Iqbal, Gaby G. Dagher, Eun G. Park |
Comput. Networks | 3 |
| 2018 | Opportunistic mining of top-n high utility patterns
Junqiang Liu, Benjamin C. M. Fung, Jiuyong Li, Farkhund Iqbal |
Inf. Sci. | 5 |
| 2018 | Differentially private multidimensional data publishing
Khalil Al-Hussaeni, Benjamin C. M. Fung, Farkhund Iqbal, Junqiang Liu, Patrick C. K. Hung |
Knowl. Inf. Syst. | 3 |
| 2017 | SONAR: Automatic Detection of Cyber Security Events over the Twitter StreamabstractEveryday, security experts face a growing number of security events that affecting people well-being, their information systems and sometimes the critical infrastructure. The sooner they can detect and understand these threats, the more they can mitigate and forensically investigate them. Therefore, they need to have a situation awareness of the existing security events and their possible effects. However, given the large number of events, it can be difficult for security analysts and researchers to handle this flow of information in an adequate manner and answer the following questions in near-real time: what are the current security events? How long do they last? In this paper, we will try to answer these issues by leveraging social networks that contain a massive amount of valuable information on many topics. However, because of the very high volume, extracting meaningful information can be challenging. For this reason, we propose SONAR: an automatic, self-learned framework that can detect, geolocate and categorize cyber security events in near-real time over the Twitter stream. SONAR is based on a taxonomy of cyber security events and a set of seed keywords describing type of events that we want to follow in order to start detecting events. Using these seed keywords, it automatically discovers new relevant keywords such as malware names to enhance the range of detection while staying in the same domain. Using a custom taxonomy describing all type of cyber threats, we demonstrate the capabilities of SONAR on a dataset of approximately 47.8 million tweets related to cyber security in the last 9 months. SONAR could efficiently and effectively detect, categorize and monitor cyber security related events before getting on the security news, and it could automatically discover new security terminologies with their event. Additionally, SONAR is highly scalable and customizable by design; therefore we could adapt SONAR framework for virtually any type of events that experts are interested in. Quentin Le Sceller, ElMouatez Billah Karbab, Mourad Debbabi, Farkhund Iqbal |
ARES | 4 |
| 2016 | Multimedia File Signature Analysis for Smartphone ForensicsabstractWith the emergence of smartphones and the widespread use of social media services, distribution of multimedia files over the Internet, and using mobile phones, has increased exponentially over the past few years. A significant number of cybercrimes pertain to illicit possession, modification, and distribution of multimedia files. The use of smartphones for this purpose makes these mobile phones rich sources of evidence. Therefore, it is crucial for forensic examiners to have the capability of recovering, analyzing, and authenticating the source of multimedia contents stored on these devices. This paper focuses on the analysis of multimedia files created on the most popular smartphones in order to ascertain the source and examine whether the files are original or edited through these devices. The popular smartphones brands analyzed in this paper include iPhone 5, iPhone 6, Blackberry Z10, Samsung Galaxy Note 3, Nokia Lumia 930, and Lenovo A536. Experimental results on all these brands are also presented. Dua'a Abu Hamdi, Farkhund Iqbal, Thar Baker, Babar Shah |
DeSE | 2 |
| 2015 | Fusion: Privacy-Preserving Distributed Protocol for High-Dimensional Data MashupabstractIn the last decade, several approaches concerning private data release for data mining have been proposed. Data mashup, on the other hand, has recently emerged as a mechanism for integrating data from several data providers. Fusing both techniques to generate mashup data in a distributed environment while providing privacy and utility guarantees on the output involves several challenges. That is, how to ensure that no unnecessary information is leaked to the other parties during the mashup process, how to ensure the mashup data is protected against certain privacy threats, and how to handle the high-dimensional nature of the mashup data while guaranteeing high data utility. In this paper, we present Fusion, a privacy-preserving multi-party protocol for data mashup with guaranteed LKC-privacy for the purpose of data mining. Experiments on real-life data demonstrate that the anonymous mashup data provide better data utility, the approach can handle high dimensional data, and it is scalable with respect to the data size. Gaby G. Dagher, Farkhund Iqbal, Mahtab Arafati, Benjamin C. M. Fung |
ICPADS | 2 |
| 2014 | A forensic analysis framework for recovering encryption keys and BB10 backup decryptionabstractMemory forensics has become an important part of digital forensic investigation. Its importance has increased due to the type of information resides within memory that can be extracted using appropriate tools. This information includes open processes, open dynamically linked libraries (DLLs), encryption keys, function parameters passed at runtime, and login information. In this paper, we propose a forensic analysis framework that uses common disk encryption methods to encrypt a hard disk and then employs forensic analysis tools to extract encryption keys from the memory dump. We use the recovered keys to successfully decrypt content of an original encrypted disk. In addition, we successfully recover the content of an encrypted BlackBerry10 backup file (.bbb), which is encrypted by default, by employing email login information extracted from the memory image. Halima Al Shehhi, Dua'a Abu Hamdi, IzzEddin Asad, Farkhund Iqbal |
PST | 4 |
| 2013 | Towards a unified agent-based approach for real time computer forensic evidence collectionabstractIn this paper we present preliminary results for a real time computer forensics agent that logs computer activity on a Windows computer system for subsequent forensic investigation. The agent, which is developed using the .NET 2010 framework includes six modules. Each module is dedicated to keep track and record a specific category of user activities. For instance, the Windows Event Watcher logs the Windows OS events and the Removable Devices Detector logs any external devices that are plugged in or removed from a system. Currently, the aforementioned two modules are implemented and tested with carefully designed scenarios using Windows XP and Windows 7 operating systems. Shadi Al Awawdeh, Ibrahim M. Baggili, Andrew Marrington, Farkhund Iqbal |
ASONAM | 4 |
| 2013 | Computer Profiling for Preliminary Forensic Examination
Andrew Marrington, Farkhund Iqbal, Ibrahim M. Baggili |
ICDF2C | 2 |
| 2013 | A unified data mining solution for authorship analysis in anonymous textual communications
Farkhund Iqbal, Hamad Binsalleeh, Benjamin C. M. Fung, Mourad Debbabi |
Inf. Sci. | 1 |
| 2012 | Investigating the dark cyberspace: Profiling, threat-based analysis and correlationabstractAn effective approach to gather cyber threat intelligence is to collect and analyze traffic destined to unused Internet addresses known as darknets. In this paper, we elaborate on such capability by profiling darknet data. Such information could generate indicators of cyber threat activity as well as providing in-depth understanding of the nature of its traffic. Particularly, we analyze darknet packets distribution, its used transport, network and application layer protocols and pinpoint its resolved domain names. Furthermore, we identify its IP classes and destination ports as well as geo-locate its source countries. We further investigate darknet-triggered threats. The aim is to explore darknet embedded threats and categorize their severities. Finally, we contribute by exploring the inter-correlation of such threats, by applying association rule mining techniques, to build threat association rules. Specifically, we generate clusters of threats that co-occur targeting a specific victim. Such work proves that specific darknet threats are correlated. Moreover, it provides insights about threat patterns and allows the interpretation of threat scenarios. Claude Fachkha, Elias Bou-Harb, Amine Boukhtouta, Son Dinh, Farkhund Iqbal, Mourad Debbabi |
CRiSIS | 5 |
| 2012 | Mining Criminal Networks from Chat LogabstractCyber criminals exploit opportunities for anonymity and masquerade in web-based communication to conduct illegal activities such as phishing, spamming, cyber predation, cyber threatening, blackmail, and drug trafficking. One way to fight cyber crime is to collect digital evidence from online documents and to prosecute cyber criminals in the court of law. In this paper, we propose a unified framework using data mining and natural language processing techniques to analyze online messages for the purpose of crime investigation. Our framework takes the chat log from a confiscated computer as input, extracts the social networks from the log, summarizes chat conversations into topics, identifies the information relevant to crime investigation, and visualizes the knowledge for an investigator. To ensure that the implemented framework meets the needs of law enforcement officers in real-life investigation, we closely collaborate with the cyber crime unit of a law enforcement agency in Canada. Both the feedback from the law enforcement officers and experimental results suggest that the proposed chat log mining framework is effective for crime investigation. Farkhund Iqbal, Benjamin C. M. Fung, Mourad Debbabi |
Web Intelligence | 1 |