EDBT 2026 Demo / reviewers in the wild / expert
Mohammad Ali Salahuddin 0001
dblp:52/3563 · also Mohammad A. Salahuddin 0001
· DBLP profile ↗
37ranked-venue papers
7as first author
19since 2021 · last 2026
0000-0002-5431-3278ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 20 · 4 first-author · 12 since 2021Systems, architecture and hardware · 1 · 1 since 2021Security and privacy · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | 5Guard: Isolation-Aware End-to-End Slicing of 5G NetworksabstractNetwork slicing logically partitions the 5G infrastructure to cater to diverse verticals with varying requirements. However, resource sharing exposes the slices to threats and performance degradation, making slice isolation essential. Fully isolating slices is resource-prohibitive, prompting the need for isolation-aware network slicing, where each slice is assigned a tailored isolation level to balance security, usability, and overhead. This paper investigates end-to-end 5G network slicing with resource isolation from the perspective of the infrastructure provider, ensuring compliance with the customers' service-level agreements. We formulate the online 5G isolation-aware network slicing (5G-INS) as a mixed-integer programming problem, modeling realistic slice isolation levels and integrating slice prior itization. To solve 5G-INS, we propose 5Guard, a novel adaptive framework that leverages an ensemble of custom optimization algorithms to achieve the best solution within resource budget and time constraints. Our results show that 5Guard increases profit by up to 15.1% and admission by up to 33.5% in a real-world large-scale network compared to the best-performing individual. Furthermore, we analyze the trade-offs between isolation levels, their impact on resource utilization, and the effects of slice placement, demonstrating significant advantages over baseline approaches that enforce uniform isolation policies. Mehdi Bolourian, Noura Limam, Mohammad Ali Salahuddin 0001, Raouf Boutaba |
IEEE Trans. Mob. Comput. | 3 |
| 2025 | MicroOpt: Model-Driven Slice Resource Optimization in 5G and Beyond NetworksabstractA pivotal attribute of 5G networks is their capability to cater to diverse application requirements. This is achieved by creating logically isolated virtual networks, or slices, with distinct service level agreements (SLAs) tailored to specific use cases. However, efficiently allocating resources to maintain slice SLA is challenging due to varying traffic and quality-of-service (QoS) requirements. Traditional peak traffic-based resource allocation leads to over-provisioning, as actual traffic rarely peaks. Additionally, the complex relationship between resource allocation and QoS in end-to-end slices spanning different network segments makes conventional optimization techniques impractical. Existing approaches in this domain use mathematical network models (e.g., queueing models) or simulations, and various optimization methods but struggle with optimality, tractability, and generalizability across different slice types. In this paper, we propose MicroOpt, a novel framework that leverages a differentiable neural network-based slice model with gradient descent for resource optimization and Lagrangian decomposition for QoS constraint satisfaction. We evaluate MicroOpt against two state-of-the-art approaches using an open-source 5G testbed with real-world traffic traces. Our results demonstrate up to 21.9% improvement in resource allocation compared to these approaches across various scenarios, including different QoS thresholds and dynamic slice traffic. Mahdieh Ahmadi, Bo Sun 0004, Mohammad Ali Salahuddin 0001, Raouf Boutaba, Aladdin Saleh |
IEEE Trans. Netw. Serv. Manag. | 4 |
| 2024 | Signalling Load-aware Conditional Handover in 5G Non-Terrestrial NetworksabstractLow Earth orbit (LEO) satellites-based non-terrestrial networks (NTN) are envisioned to complement the fifth-generation (5G) terrestrial networks (TN), enabling global cellular services. However, the high mobility and large coverage of these satellites result in frequent and numerous inter-satellite handovers, leading to signalling storms that degrade the satellite gNodeB services. To address this, we mathematically formulate the handover problem and propose a novel signalling load-aware handover protocol based on conditional handover. We evaluate the effectiveness of the protocol using a customized discrete-event simulator and compare it against a set of baseline conditional handover schemes. Our findings show that the proposed protocol significantly reduces signalling peaks and balances the load more effectively, enhancing the robustness and efficiency of handover in 5G NTN. The simulator is made publicly available. Mohammad Ali Salahuddin 0001, Yunli Wang, Noura Limam, Bo Sun 0004, Diogo Barradas, Raouf Boutaba |
CNSM | 2 |
| 2024 | Secure and Efficient Group Handover Protocol in 5G Non-Terrestrial NetworksabstractThe growing low-Earth orbit (LEO) satellite con-stellations have become an essential part of the fifth-generation (5G) non-terrestrial network (NTN) market. These satellites can enable direct-to-cell connectivity for mobile devices and support various applications with ubiquitous coverage for 5G and beyond networks. However, satellite-based NTNs bring several challenges to the 5G handover protocol design. The high mobility of satellites can lead to signaling storms and security compromises during handovers. This paper addresses these challenges by proposing a secure and efficient group hand over protocol. The protocol's effectiveness is evaluated on a custom discrete-event simulator and compared against the baseline 5G hand over scheme. The simulator is made publicly available. A. Akbariazirani, Mohammad Ali Salahuddin 0001, Diogo Barradas, Noura Limam, Raouf Boutaba |
ICC | 4 |
| 2024 | Generalizable 5G RAN/MEC Slicing and Admission Control for Reliable Network OperationabstractThe virtualization and distribution of 5G Radio Access Network (RAN) functions across radio unit (RU), distributed unit (DU), and centralized unit (CU) in conjunction with multi-access edge computing (MEC) enable the creation of network slices tailored for various applications with distinct quality of service (QoS) demands. Nonetheless, given the dynamic nature of slice requests and limited network resources, optimizing long-term revenue for infrastructure providers (InPs) through real-time admission and embedding of slice requests poses a significant challenge. Prior works have employed Deep Reinforcement Learning (DRL) to address this issue, but these approaches require re-training with the slightest topology changes due to node/link failure or overlook the joint consideration of slice admission and embedding problems. This paper proposes a novel method, utilizing multi-agent DRL and Graph Attention Networks (GATs), to overcome these limitations. Specifically, we develop topology-independent admission and slicing agents that are scalable and generalizable across diverse metropolitan networks. Results demonstrate substantial revenue gains-up to 35.2% compared to heuristics and 19.5% when compared to other DRL-based methods. Moreover, our approach showcases robust performance in different network failure scenarios and substrate networks not seen during training without the need for re-training or re-tuning. Additionally, we bring interpretability by analyzing attention maps, which enables InPs to identify network bottlenecks, increase capacity at critical nodes, and gain a clear understanding of the model decision-making process. Mahdieh Ahmadi, Arash Moayyedi, Mohammad Ali Salahuddin 0001, Raouf Boutaba, Aladdin Saleh |
IEEE Trans. Netw. Serv. Manag. | 4 |
| 2024 | AutoML4ETC: Automated Neural Architecture Search for Real-World Encrypted Traffic ClassificationabstractDeep learning (DL) has been successfully applied to encrypted network traffic classification in experimental settings. However, in production use, it has been shown that a DL classifier’s performance inevitably decays over time. Re-training the model on newer datasets has been shown to only partially improve its performance. Manually re-tuning the model architecture to meet the performance expectations on newer datasets is time-consuming and requires domain expertise. We propose AutoML4ETC, a novel tool to automatically design efficient and high-performing neural architectures for encrypted traffic classification. We define a novel, powerful search space tailored specifically for the early classification of encrypted traffic using packet header bytes. We show that with different search strategies over our search space, AutoML4ETC generates neural architectures that outperform the state-of-the-art encrypted traffic classifiers on several datasets, including public benchmark datasets and real-world TLS and QUIC traffic collected from the Orange mobile network. In addition to being more accurate, AutoML4ETC’s architectures are significantly more efficient and lighter in terms of the number of parameters. Finally, we make AutoML4ETC publicly available for future research. Navid Malekghaini, Elham Akbari, Mohammad Ali Salahuddin 0001, Noura Limam, Raouf Boutaba, Bertrand Mathieu, Stephanie Moteau, Stéphane Tuffin |
IEEE Trans. Netw. Serv. Manag. | 3 |
| 2023 | A Critical Study of Few-Shot Learning for Encrypted Traffic ClassificationabstractOver the past twenty years, a plethora of methods have been proposed for encrypted traffic classification (ETC), while the Server name indication (SNI) is deemed to solve the problem of classification for TLS traffic. However, SNI-based classification has its pitfalls and the SNI will likely be pushed into the encrypted tunnel in the future. In this work, we envision a futuristic scenario in which encrypted SNI is the norm and labeled traffic flows are scarce. In such settings, we tackle the problem of traffic classification at ISP level using few-shot learning. By means of six real-world ISP-level datasets collected between 2019 and 2021 and two publicly available client-side datasets, we study the performance of a few-shot learner on TLS data, including its cross-dataset generalizability. We further investigate the effect of the number of required labeled samples on the learner's performance. Our experiments show that the dataset-specificity of deep learners carries over to few-shot meta-learning, and calls for addressing the problem of generalizability for deep learning architectures. Elham Akbari, Sheikh A. Tahmid, Navid Malekghaini, Mohammad Ali Salahuddin 0001, Noura Limam, Raouf Boutaba, Bertrand Mathieu, Stephanie Moteau, Stéphane Tuffin |
CNSM | 4 |
| 2023 | Meta-ATMoS+: A Meta-Reinforcement Learning Framework for Threat Mitigation in Software-Defined NetworksabstractAs cyber threats become increasingly common, automated threat mitigation solutions are more necessary than ever. Conventional threat mitigation frameworks are difficult to tune for different network environments, but frameworks utilizing deep reinforcement learning (RL) have been proven to be an effective approach that can adapt to different networks automatically. Existing RL-based frameworks have shown to be generalizable to different network sizes and threats, and robust to false positives. However, training RL agents for these frameworks can be challenging in a production environment as the training process is time-consuming and disruptive to the production network. Hence, a staging environment is required to effectively train them. In this paper, we propose Meta-ATMoS+, a meta-RL framework for threat mitigation in software-defined networks. We leverage Model-Agnostic Meta-Learning (MAML) to find an initialization for the RL agent that generalizes to a variety of different network configurations. We show that the RL agent with MAML-learned initialization can accomplish few-shot learning on a target network with comparable performance to training on a staging environment. Few-shot learning not only allows the model to be trainable directly in the production environment but also enables human-in-the-loop RL for the mitigation of threats that do not have an easily-definable reward function. Hauton Tsang, Mohammad Ali Salahuddin 0001, Noura Limam, Raouf Boutaba |
LCN | 2 |
| 2023 | Generalizable GNN-based 5G RAN/MEC Slicing and Admission Control in Metropolitan NetworksabstractThe 5G RAN functions can be virtualized and distributed across the radio unit (RU), distributed unit (DU), and centralized unit (CU) to facilitate flexible resource management. Complemented by multi-access edge computing (MEC), these components create network slices tailored for applications with diverse quality of service (QoS) requirements. However, as the requests for various slices arrive dynamically over time and the network resources are limited, it is non-trivial for an infrastructure provider (InP) to optimize its long-term revenue from real-time admission and embedding of slice requests. Prior works have leveraged Deep Reinforcement Learning (DRL) to address this problem, however, these solutions either require re-training when facing topology changes or do not consider the slice admission and embedding problems jointly. In this paper, we use multi-agent DRL and Graph Attention Networks (GATs) to address these limitations. Specifically, we propose novel topology-independent admission and slicing agents that are scalable and generalizable to large and different metropolitan networks. Results show that the proposed approach converges faster and achieves up to 35.2% and 20% gain in revenue compared to heuristics and other DRL-based approaches, respectively. Additionally, we demonstrate that our approach is generalizable to scenarios and substrate networks previously unseen during training, as it maintains superior performance without re-training or re-tuning. Arash Moayyedi, Mahdieh Ahmadi, Mohammad Ali Salahuddin 0001, Raouf Boutaba, Aladdin Saleh |
NOMS | 3 |
| 2023 | Generalizable Resource Scaling of 5G Slices using Constrained Reinforcement LearningabstractNetwork slicing is a key enabler for 5G to support various applications. Slices requested by service providers (SPs) have heterogeneous quality of service (QoS) requirements, such as latency, throughput, and jitter. It is imperative that the 5G infrastructure provider (InP) allocates the right amount of resources depending on the slice’s traffic, such that the specified QoS levels are maintained during the slice’s lifetime while maximizing resource efficiency. However, there is a non-trivial relationship between the QoS and resource allocation. In this paper, this relationship is learned using a regression-based model. We also leverage a risk-constrained reinforcement learning agent that is trained offline using this model and domain randomization for dynamically scaling slice resources while maintaining the desired QoS level. Our novel approach reduces the effects of network modeling errors since it is model-free and does not require QoS metrics to be mathematically formulated in terms of traffic. In addition, it provides robustness against uncertain network conditions, generalizes to different real-world traffic patterns, and caters to various QoS metrics. The results show that the state-of-the-art approaches can lead to QoS degradation as high as 44.5% when tested on previously unseen traffic. On the other hand, our approach maintains the QoS degradation below a preset 10% threshold on such traffic, while minimizing the allocated resources. Additionally, we demonstrate that the proposed approach is robust against varying network conditions and inaccurate traffic predictions. Mahdieh Ahmadi, Mohammad Ali Salahuddin 0001, Raouf Boutaba, Aladdin Saleh |
NOMS | 3 |
| 2023 | FogJam: A Fog Service for Detecting Traffic Congestion in a Continuous Data Stream VANET
Maycon Leone Maciel Peixoto, Edson Mota, Adriano H. O. Maia, Wellington Lobato, Mohammad Ali Salahuddin 0001, Raouf Boutaba, Leandro A. Villas |
Ad Hoc Networks | 5 |
| 2023 | Deep learning for encrypted traffic classification in the face of data drift: An empirical study
Navid Malekghaini, Elham Akbari, Mohammad Ali Salahuddin 0001, Noura Limam, Raouf Boutaba, Bertrand Mathieu, Stephanie Moteau, Stéphane Tuffin |
Comput. Networks | 3 |
| 2023 | Spotting Anomalies at the Edge: Outlier Exposure-Based Cross-Silo Federated Learning for DDoS DetectionabstractDistributed Denial-of-Service (DDoS) attacks are expected to continue plaguing service availability in emerging networks which rely on distributed edge clouds to offer critical, latency-sensitive applications. However, edge servers increase the network attack surface, which is exacerbated with the massive number of connected Internet of Things (IoT) devices that can be weaponized to launch DDoS attacks. Therefore, it is crucial to detect DDoS attacks early, i.e., at the network edge. In this paper, we empower the network edge with intelligent DDoS detection by learning from similarities between different data and DDoS attacks available across the edge servers. To this end, we develop a novel Outlier Exposure (OE)-enabled cross-silo Federated Learning framework, namely FedOE. FedOE enables distributed training of OE-based ML models using a limited number of labeled outliers (i.e., attack flows) experienced at edge servers. We propose a novel OE-based Autoencoder (oAE) that can better discriminate anomalies in comparison to the widely adopted traditional Autoencoder, using a tailored, OE-based loss function. We evaluate oAE in FedOE and demonstrate its ability to generalize to zero-day attacks, with just 50 labeled attack flows per edge server. The results show that oAE achieves a high F1-score for most DDoS attacks, outclassing its non-OE counterpart. Vahid Pourahmadi, Hyame Assem Alameddine, Mohammad Ali Salahuddin 0001, Raouf Boutaba |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2023 | Coordinated Slicing and Admission Control Using Multi-Agent Deep Reinforcement Learningabstract5G Cloud Radio Access Networks (C-RANs) facilitate new forms of flexible resource management as dynamic RAN function splitting and placement. Virtualized RAN functions can be placed at different sites in the substrate network based on resource availability and slice constraints. Due to limited resources in the substrate network and variability in revenue of slices, the Infrastructure Provider (InP) must perform network slicing in a strategic manner, and accept or reject slice-requests to maximize long-term revenue. In this paper, we propose to use multi-agent Deep Reinforcement Learning (DRL) to jointly solve the problems of network slicing and slice Admission Control (AC). Multi-agent DRL along with reward shaping is a promising choice, which is well-suited to problems where multiple distinct tasks have to be performed optimally. The proposed DRL approach can learn the dynamics of slice-request traffic and effectively address these joint problems. We compare multi-agent DRL to approaches that use: (i) simple heuristics to address the problems, and (ii) DRL to address either slicing or AC. Our results show that the proposed approach achieves up to 30% and 5.18% gain in long-term InP revenue when compared to approaches (i) and (ii), respectively. Additionally, we show that multi-agent DRL is preferable to a single-agent DRL approach for the joint problems in terms of convergence time and InP revenue. Finally, we evaluate the robustness of the trained agents in scenarios that differ from training, such as different arrival rates and real dynamic traffic patterns. Arash Moayyedi, Mahdieh Ahmadi, Mohammad Ali Salahuddin 0001, Raouf Boutaba, Aladdin Saleh |
IEEE Trans. Netw. Serv. Manag. | 4 |
| 2022 | Multi-Agent Deep Reinforcement Learning for Slicing and Admission Control in 5G C-RANabstract5G Cloud Radio Access Networks (C-RANs) facilitate new forms of flexible resource management as dynamic RAN function splitting and placement. Virtualized RAN functions can be placed at different sites in the substrate network according to resource availability and slice constraints. Due to limited resource availability in the substrate network, the Infrastructure Provider (InP) must perform network slicing in a strategic manner, and accept or reject slice-requests in order to maximize long-term revenue. In this paper, we propose to use multi-agent Deep Reinforcement Learning (DRL) to jointly solve the problems of network slicing and slice Admission Control (AC). Multi-agent DRL is a promising choice since it is well-suited to problems where multiple distinct tasks have to be performed optimally. The proposed DRL approach can learn the dynamics of slice-request traffic and effectively address these joint problems. We compare multi-agent DRL to approaches that use: (i) simple heuristics to address the problems, and (ii) DRL to address either slicing or AC. Our results show that the proposed approach achieves up to 18% and 3.8% gain in long-term InP revenue when compared to approaches (i) and (ii), respectively. Additionally, we show that multi-agent DRL is preferable to a single-agent DRL approach that addresses the problems jointly. Finally, we evaluate the robustness of the trained model in terms of its ability to generalize to scenarios that deviate from training. Arash Moayyedi, Mohammad Ali Salahuddin 0001, Raouf Boutaba, Aladdin Saleh |
NOMS | 3 |
| 2022 | Chronos: DDoS Attack Detection Using Time-Based AutoencoderabstractCognitive network management is becoming quintessential to realize autonomic networking. However, the wide spread adoption of the Internet of Things (IoT) devices, increases the risk of cyber attacks. Adversaries can exploit vulnerabilities in IoT devices, which can be harnessed to launch massive Distributed Denial of Service (DDoS) attacks. Therefore, intelligent security mechanisms are needed to harden network security against these threats. In this paper, we propose Chronos, a novel time-based anomaly detection system. The anomaly detector, primarily an Autoencoder, leverages time-based features over multiple time windows to efficiently detect anomalous DDoS traffic. We develop a threshold selection heuristic that maximizes the F1-score across various DDoS attacks. Further, we compare the performance of Chronos against state-of-the-art approaches. We show that Chronos marginally outperforms another time-based system using a less complex anomaly detection pipeline, while out classing flow-based approaches with superior precision. In addition, we showcase the robustness of Chronos in the face of zero-day attacks, noise in training data, and a small number of training packets, asserting its suitability for online deployment. Mohammad Ali Salahuddin 0001, Vahid Pourahmadi, Hyame Assem Alameddine, Md. Faizul Bari, Raouf Boutaba |
IEEE Trans. Netw. Serv. Manag. | 1 |
| 2021 | RDP-based Lateral Movement detection using Machine Learning
Tim Bai, Haibo Bian, Mohammad Ali Salahuddin 0001, Abbas Abou Daya, Noura Limam, Raouf Boutaba |
Comput. Commun. | 3 |
| 2021 | Efficient Replica Migration Scheme for Distributed Cloud Storage SystemsabstractWith the wide adoption of large-scale internet services and big data, the cloud has become the ideal environment to satisfy the ever-growing storage demand. In this context, data replication has been touted as the ultimate solution to improve data availability and reduce access time. However, replica management systems usually need to migrate and create a large number of data replicas over time between and within data centers, incurring a large overhead in terms of network load and availability. In this paper, we propose CRANE, an effiCient Replica migrAtion scheme for distributed cloud Storage systEms. CRANE complements any replica placement algorithm by efficiently managing replica creation in geo-distributed infrastructures in order to (1) minimize the time needed to copy the data to the new replica location, (2) avoid network congestion, and (3) ensure the minimum desired availability for the data. Through simulation and experimental results, we show that CRANE provides a sub-optimal solution for the replica migration problem with lower computational complexity than its integer linear program formulation. We also show that, compared to OpenStack Swift, CRANE is able to reduce by up to 60 percent the replica creation and migration time and by up to 50 percent the inter-data center network traffic while ensuring the minimum required data availability. Amina Mseddi, Mohammad Ali Salahuddin 0001, Mohamed Faten Zhani, Halima Elbiaze, Roch H. Glitho |
IEEE Trans. Cloud Comput. | 2 |
| 2021 | Uncovering Lateral Movement Using Authentication LogsabstractNetwork infiltrations due to advanced persistent threats (APTs) have significantly grown in recent years. Their primary objective is to gain unauthorized access to network assets, compromise system and data. APTs are stealthy and remain dormant for an extended period of time, which makes their detection challenging. In this article, we leverage machine learning (ML) to detect hosts in a network that are a target of an APT attack. We evaluate a number of ML classifiers to detect susceptible hosts in the Los Alamos National Lab dataset. We (i) scrutinize graph-based features extracted from host authentication logs, (ii) use feature engineering to reduce dimensionality, (iii) explore balancing the training dataset using over- and under-sampling techniques, (iv) evaluate numerous supervised ML techniques and their ensemble, (v) compare our classification model to the state-of-the-art approaches that leverage the same dataset, and show that our model outperforms them with respect to prediction performance and overhead, and (vi) perturb the attack patterns to study the influence of change in attack frequency and scale on classification performance, and propose a solution for such adversarial behavior. Haibo Bian, Tim Bai, Mohammad Ali Salahuddin 0001, Noura Limam, Abbas Abou Daya, Raouf Boutaba |
IEEE Trans. Netw. Serv. Manag. | 3 |
| 2020 | Time-based Anomaly Detection using AutoencoderabstractDistributed Denial of Service (DDoS) attacks continue to draw significant attention, especially with the recent surge in cyber attacks that targeted the healthcare, education and financial sectors, during the COVID-19 pandemic. The expansion of virtualization and softwarization technologies, and the surge in Internet of Things (IoT) devices, increase the attack surface and the impact of attacks on networks. In this paper, we present a novel time-based anomaly detection system that leverages an Autoencoder. We explore the impact of different time-windows on detecting multiple DDoS attacks that are difficult to detect via the widely used flow-based features. We train and evaluate our Autoencoder on the recent CICDDoS2019 dataset, and show that our approach achieves an anomaly detection F1-score of over 99% for most attacks and greater than 95% for all attacks. Mohammad Ali Salahuddin 0001, Md. Faizul Bari, Hyame Assem Alameddine, Vahid Pourahmadi, Raouf Boutaba |
CNSM | 1 |
| 2020 | ATMoS: Autonomous Threat Mitigation in SDN using Reinforcement LearningabstractMachine Learning has revolutionized many fields of computer science. Reinforcement Learning (RL), in particular, stands out as a solution to sequential decision making problems. With the growing complexity of computer networks in the face of new emerging technologies, such as the Internet of Things and the growing complexity of threat vectors, there is a dire need for autonomous network systems. RL is a viable solution for achieving this autonomy. Software-defined Networking (SDN) provides a global network view and programmability of network behaviour, which can be employed for security management. Previous works in RL-based threat mitigation have mostly focused on very specific problems, mostly non-sequential, with ad-hoc solutions. In this paper, we propose ATMoS, a general framework designed to facilitate the rapid design of RL applications for network security management using SDN. We evaluate our framework for implementing RL applications for threat mitigation, by showcasing the use of ATMoS with a Neural Fitted Q-learning agent to mitigate an Advanced Persistent Threat. We present the RL model’s convergence results showing the feasibility of our solution for active threat mitigation. Iman Akbari, Ezzeldin Tahoun, Mohammad Ali Salahuddin 0001, Noura Limam, Raouf Boutaba |
NOMS | 3 |
| 2020 | BotChase: Graph-Based Bot Detection Using Machine LearningabstractBot detection using machine learning (ML), with network flow-level features, has been extensively studied in the literature. However, existing flow-based approaches typically incur a high computational overhead and do not completely capture the network communication patterns, which can expose additional aspects of malicious hosts. Recently, bot detection systems that leverage communication graph analysis using ML have gained attention to overcome these limitations. A graph-based approach is rather intuitive, as graphs are true representation of network communications. In this paper, we propose BotChase, a two-phased graph-based bot detection system that leverages both unsupervised and supervised ML. The first phase prunes presumable benign hosts, while the second phase achieves bot detection with high precision. Our prototype implementation of BotChase detects multiple types of bots and exhibits robustness to zero-day attacks. It also accommodates different network topologies and is suitable for large-scale data. Compared to the state-of-the-art, BotChase outperforms an end-to-end system that employs flow-based features and performs particularly well in an online setting. Abbas Abou Daya, Mohammad Ali Salahuddin 0001, Noura Limam, Raouf Boutaba |
IEEE Trans. Netw. Serv. Manag. | 2 |
| 2019 | Host in Danger? Detecting Network Intrusions from Authentication LogsabstractRecently, network infiltrations due to advanced persistent threats (APTs) have grown significantly, resulting in considerable losses to businesses and organizations. APTs are stealthy attacks with the primary objective of gaining unauthorized access to network assets. They often remain dormant for an extended period of time, which makes their detection challenging. In this paper, we leverage machine learning (ML) to detect hosts in a network that are targeted by an APT attack. We evaluate a number of ML classifiers to detect susceptible hosts in the Los Alamos National Lab dataset. We explore (i) graph-based features extracted from multiple data sources i.e., network flows and host authentication logs, (ii) feature engineering to reduce dimensionality, and (iii) balancing the training dataset using numerous over- and under-sampling techniques. Finally, we compare our model to the state-of-the-art approaches that leverage the same dataset, and show that our model outperforms them with respect to prediction performance and overhead. Haibo Bian, Tim Bai, Mohammad Ali Salahuddin 0001, Noura Limam, Abbas Abou Daya, Raouf Boutaba |
CNSM | 3 |
| 2019 | A Graph-Based Machine Learning Approach for Bot Detection
Abbas Abou Daya, Mohammad Ali Salahuddin 0001, Noura Limam, Raouf Boutaba |
IM | 2 |
| 2019 | A Machine Learning Approach for RDP-based Lateral Movement DetectionabstractDetecting cyber threats has been an on-going research endeavor. In this era, advanced persistent threats (APTs) can incur significant cost for organizations and businesses. The ultimate goal of cyber security is to thwart attackers from achieving their malicious intent, whether it is credential stealing, infrastructure takeover, or program sabotage. Every cyber attack goes through several stages before its termination. Lateral movement (LM) is one of those stages which is of particular importance. Remote Desktop Protocol (RDP) is a method used in LM to successfully authenticate to an unauthorized host that leaves footprints on both host and network logs. In this paper, we propose to detect evidence of LM with an anomaly detection approach that leverages Windows RDP event logs. We evaluate various supervised machine learning (ML) techniques for classifying RDP sessions with high precision and recall. We also compare the performance of our proposed approach to a state-of-the-art approach and demonstrate that our ML model outperforms in classifying RDP sessions in Windows event logs. Tim Bai, Haibo Bian, Abbas Abou Daya, Mohammad Ali Salahuddin 0001, Noura Limam, Raouf Boutaba |
LCN | 4 |
| 2018 | ADS: Adaptive and dynamic scaling mechanism for multimedia conferencing services in the cloudabstractMultimedia conferencing is used extensively in a wide range of applications, such as online games and distance learning. These applications need to efficiently scale the conference size as the number of participants fluctuates. Cloud is a technology that addresses the scalability issue. However, the proposed cloud-based solutions have several shortcomings in considering the future demand of applications while meeting both Quality of Service (QoS) requirements and efficiency in resource usage. In this paper, we propose an Adaptive and Dynamic Scaling mechanism (ADS) for multimedia conferencing services in the cloud. This mechanism enables scalable and elastic resource allocation with respect to the number of participants. ADS produces a cost efficient scaling schedule while considering the QoS requirements and the future demand of the conferencing service. We formulate the problem using Integer Linear Programming (ILP) and design a heuristic for it. Simulation results show that ADS mechanism elastically scales conferencing services. Moreover, the ADS heuristic is shown to outperform a greedy algorithm from a resource-efficiency perspective. Abbas Soltanian, Diala Naboulsi, Mohammad Ali Salahuddin 0001, Roch H. Glitho, Halima Elbiaze, Constant Wette Tchouati |
CCNC | 3 |
| 2017 | NFV and SDN-based cost-efficient and agile value-added video services provisioning in content delivery networksabstractDue to the recent surge in end-users demands, value-added video services (e.g. in-stream video advertisements) need to be provisioned in a cost-efficient and agile manner in Content Delivery Networks (CDNs). Network Function Virtualization (NFV) is an emerging technology that aims to reduce costs and bring agility by decoupling network functions from the underlying hardware. It is often used in combination with Software Defined Network (SDN), a technology to decouple control and data planes. This paper proposes an NFV and SDN-based architecture for a cost-efficient and agile provisioning of value-added video services in CDNs. In the proposed architecture, the application-level middleboxes that enable value-added video services (e.g. mixer, compressor) are provisioned as Virtual Network Functions (VNFs) and chained using application-level SDN switches. HTTP technology is used as the pillar of the implementation architecture. We have built a prototype and deployed it in an OPNFV test lab and in SAVI, a Canadian distributed test bed for future Internet applications. The performance is also evaluated. Narjes T. Jahromi, Sami Yangui, Adel Larabi, Mohammad Ali Salahuddin 0001, Roch H. Glitho, Richard Brunner, Halima Elbiaze |
CCNC | 5 |
| 2017 | Popularity and Correlation-Aware Content Placement for Hierarchical Surrogates in Cloud-Based CDNsabstractContent placement (CP) algorithms are an integral component of Cloud-based Content Delivery Networks (CCDNs) that select a subset of content from the myriad catalogue, to be placed on surrogates to meet end-user requests with quality of service (QoS). It is challenging to conjure popularity of content, due to size of the catalogue, the heavy and long tail nature of the popularity distribution function and complexity arising from Online Social Networking (OSN) relationships. Therefore, we leverage hierarchical organization of surrogates to push and store content that is preemptively and strategically chosen, such that popular and correlated content always remains within QoS distance of each other. We design an Integer Linear Programming (ILP) model and solve it optimally and nearoptimally using CPLEX and Particle Swarm Optimization-based heuristic, respectively. We compare our model with state-of- the-art CP algorithm to show the benefits of popularity and correlation aware CP. Mohammad Ali Salahuddin 0001, Amina Mseddi, Halima Elbiaze, Roch H. Glitho |
GLOBECOM | 1 |
| 2017 | Managing a cluster of IoT brokers in support of smart city applicationsabstractPublish/subscribe brokers enable the efficient dissemination of events to a large number of subscribers in support of smart city applications. These events convey data gathered from devices and published to named logical channels called topics. Software-Defined Networking (SDN) can provide the advantage of balancing the load between brokers by switching topics between brokers. However, this switching results in network overhead. Besides, supporting data and decision fusion applications is a challenging task since sensory data has to be fused before being forwarded to subscribers. Therefore, we propose an algorithm utilized by the SDN controller to minimize the load difference between brokers while respecting a reconfiguration limit in support of data and decision fusion applications. We formulate minimizing brokers' load difference within a reconfiguration budget with the constraint of indivisible topics as an Integer Linear Programing (ILP) problem. We show that the problem is NP-Hard and propose a heuristic driven by long-term statistics of topics. The proposed heuristic is evaluated with realistic simulation traffic traces and compared against a threshold-based baseline heuristic driven by instantaneous statistics of topics. Results show that the proposed heuristic performs up to 2000% better load distribution than the baseline heuristic and at least 27% less topic switching. Shadha Tabatabai, Ihab Mohammed, Ala I. Al-Fuqaha, Mohammad Ali Salahuddin 0001 |
PIMRC | 4 |
| 2016 | A Hybrid Regression Model for Video Popularity-Based Cache Replacement in Content Delivery NetworksabstractContent Delivery Networks (CDN) and their globally dispersed caches host a myriad of User Generated Videos (UGV) to meet end-user requests with quality of service. To efficiently utilize the limited storage of the caches, it is imperative to improve the hit ratio of UGVs. In contrast to the traditional static content, UGV popularity is highly dynamic and dependent on end-user behavior. Therefore, we devise a novel popularity prediction model for UGV, using a hybrid regression model. Our hybrid regression model dynamically adapts the popularity of UGV that is built from a historical training dataset. We reduce error in predicting popularity by up to 14%, when compared to pure offline and online approaches, with a small increase in the execution time and memory overhead. Our novel popularity prediction model accounts for end- user behavior by considering the end-user video watch time and the number of shares for the UGVs. To improve cache performance in CDN, we employ a cache replacement strategy that leverages our popularity prediction model to efficiently evict the less popular UGVs for more popular content. We compare our novel cache replacement strategy with the traditional and state-of-the-art cache replacement strategies and show an increase in the average hit ratio of up to 74% and 7%, respectively, for UGVs with shortterm popularity. Emira Ben Abdelkrim, Mohammad Ali Salahuddin 0001, Halima Elbiaze, Roch H. Glitho |
GLOBECOM | 2 |
| 2016 | A Cloud Platform-as-a-Service for multimedia conferencing service provisioningabstractMultimedia conferencing is the real-time exchange of multimedia content between multiple parties. It is the basis of a wide range of applications (e.g., multimedia multiplayer game). Cloud-based provisioning of the conferencing services on which these applications rely will bring benefits, such as easy service provisioning and elastic scalability. However, it remains a big challenge. This paper proposes a PaaS for conferencing service provisioning. The proposed PaaS is based on a business model from the state of the art. It relies on conferencing IaaSs that, instead of VMs, offer conferencing substrates (e.g., dial-in signaling, video mixer and audio mixer). The PaaS enables composition of new conferences from substrates on the fly. This has been prototyped in this paper and, in order to evaluate it, a conferencing IaaS is also implemented. Performance measurements are also made. Ahmad F. B. Alam, Abbas Soltanian, Sami Yangui, Mohammad Ali Salahuddin 0001, Roch H. Glitho, Halima Elbiaze |
ISCC | 4 |
| 2016 | Scheduling Energy Harvesting Roadside Units in Vehicular Ad Hoc NetworksabstractThe use of renewable energy at roadside units (RSUs) in vehicular ad hoc networks is a great alternative to the electric grid, since it lowers the carbon footprint, and the cost of deployment and maintenance. This paper describes a scheduler for serving vehicles by RSUs that use energy harvesting, with the aim to maximize the number of served vehicles. We start by defining an integer linear programming model for finding the optimal offline schedule. The model is shown to be NP-hard and hence we propose a greedy heuristic to solve it. We compare the optimal solution and near- optimal offline heuristic with an energy-efficient scheduler for RSUs. Our simulation results show that the proposed scheduler for energy harvesting RSUs can reduce the service delay of vehicles. It also provides good performance with respect to the percentage of served vehicles, in comparison to energy-efficient scheduler in grid-powered RSUs. Wassim Sellil Atoui, Mohammad Ali Salahuddin 0001, Wessam Ajib, Mounir Boukadoum |
VTC Fall | 2 |
| 2015 | A resource allocation mechanism for video mixing as a cloud computing service in multimedia conferencing applicationsabstractMultimedia conferencing is the conversational exchange of multimedia content between multiple parties. It has a wide range of applications (e.g. Massively Multiplayer Online Games (MMOGs) and distance learning). Many multimedia conferencing applications use video extensively, thus video mixing in conferencing settings is of critical importance. Cloud computing is a technology that can solve the scalability issue in multimedia conferencing, while bringing other benefits, such as, elasticity, efficient use of resources, rapid development, and introduction of new applications. However, proposed cloud-based multimedia conferencing approaches so far have several deficiencies when it comes to efficient resource usage while meeting Quality of Service (QoS) requirements. We propose a solution to optimize resource allocation for cloud-based video mixing service in multimedia conferencing applications, which can support scalability in terms of number of users, while guaranteeing QoS. We formulate the resource allocation problem mathematically as an Integer Linear Programming (ILP) problem and design a heuristic for it. Simulation results show that our resource allocation model can support more participants compared to the state-of-the-art, while honoring QoS, with respect to end-to-end delay. Abbas Soltanian, Mohammad Ali Salahuddin 0001, Halima Elbiaze, Roch H. Glitho |
CNSM | 2 |
| 2015 | Social Network Analysis Inspired Content Placement with QoS in Cloud Based Content Delivery NetworksabstractContent Placement (CP) problem in Cloud based Content Delivery Networks (CCDNs) leverage resource elasticity to build cost effective CDNs that guarantee QoS. In this paper, we present our novel CP model, which optimally places content on surrogates in the cloud, to achieve (a) minimum cost of leasing storage and bandwidth resources for data coming into and going out of the cloud zones and regions, (b) guarantee Service Level Agreement (SLA), and (c) minimize degree of QoS violations. The CP problem is NP Hard, hence we design a unique push based heuristic, called Weighted Social Network Analysis (W SNA) for CCDN providers. W-SNA is based on Betweeness Centrality (BC) from SNA and prioritizes surrogates based on their relationship to the other vertices in the network graph. To achieve our unique objectives, we further prioritize surrogates based on weights derived from storage cost and content requests. We compare our heuristic to current state of the art Greedy Site (GS) and purely Social Network Analysis (SNA) heuristics, which are relevant to our work. We show that W-SNA outperforms GS and SNA in minimizing cost and QoS. Moreover, W-SNA guarantees SLA but also minimizes the degree of QoS violations. To the best of our knowledge, this is the first model and heuristic of its kind, which is timely and gives a fundamental pre allocation scheme for future online and dynamic resource provision for CCDNs. Mohammad Ali Salahuddin 0001, Halima Elbiaze, Wessam Ajib, Roch H. Glitho |
GLOBECOM | 1 |
| 2015 | Software-Defined Networking for RSU Clouds in Support of the Internet of VehiclesabstractWe propose a novel roadside unit (RSU) cloud, a vehicular cloud, as the operational backbone of the vehicle grid in the Internet of Vehicles (IoV). The architecture of the proposed RSU cloud consists of traditional and specialized RSUs employing software-defined networking (SDN) to dynamically instantiate, replicate, and/or migrate services. We leverage the deep programmability of SDN to dynamically reconfigure the services hosted in the network and their data forwarding information to efficiently serve the underlying demand from the vehicle grid. We then present a detailed reconfiguration overhead analysis to reduce reconfigurations, which are costly for service providers. We use the reconfiguration cost analysis to design and formulate an integer linear programming (ILP) problem to model our novel RSU cloud resource management (CRM). We begin by solving for the Pareto optimal frontier (POF) of nondominated solutions, such that each solution is a configuration that minimizes either the number of service instances or the RSU cloud infrastructure delay, for a given average demand. Then, we design an efficient heuristic to minimize the reconfiguration costs. A fundamental contribution of our heuristic approach is the use of reinforcement learning to select configurations that minimize reconfiguration costs in the network over the long term. We perform reconfiguration cost analysis and compare the results of our CRM formulation and heuristic. We also show the reduction in reconfiguration costs when using reinforcement learning in comparison to a myopic approach. We show significant improvement in the reconfigurations costs and infrastructure delay when compared to purist service installations. Mohammad Ali Salahuddin 0001, Ala I. Al-Fuqaha, Mohsen Guizani |
IEEE Internet Things J. | 1 |
| 2013 | Context severity based opportunistic service reprioritization for IEEE 802.11p VANETsabstractIEEE 802.11p Wireless Access for Vehicular Environments (WAVE) is the approved communication protocol for Vehicular Ad-hoc Networks (VANETs) and Intelligent Transportation System (ITS) applications. WAVE offers service differentiation by prioritizing packets based on an application's requested QoS. These priorities are static and do not account for network load or vehicle's context severity. In this paper, we propose a novel opportunistic service reprioritization (OSR) technique for IEEE 802.11p (WAVE). It dynamically promotes and/or demotes vehicle's load to different access categories, by taking into account the vehicle's context severity and network link layer bounds. We show the feasibility of our approach by formulating the opportunistic service reprioritization technique as a Linear Programming (LP) problem and solve it to guarantee optimal QoS with respect to severity for all access categories. We compare our opportunistic service reprioritization technique with WAVE and show significant improvement. The weighted average delay in OSR outperforms classical WAVE, on average by 90%. Mohammad Ali Salahuddin 0001, Ala I. Al-Fuqaha, Frederic Jacquelin, Yohan Shim |
IWCMC | 1 |
| 2011 | An efficient artificial landmark-based system for indoor and outdoor identification and localizationabstractCurrent technologies for localization such as Global Positioning Systems (GPS) and Inertial Measurement Unit (IMU) have limitations in terms of accuracy, cost, signal attenuation and need for re-calibration over time, which leads to a compromise in performance and accuracy. In this paper, we present a novel Artificial Landmark-Based Identification System (ALIS), which can be used in both indoor and outdoor localization applications. ALIS is a multi-part landmark-based localization approach, which uses template matching techniques to find multiple landmark patterns in an image to estimate distance from the landmark. A novel combination of pre- and post-processing techniques is used to improve template matching results. The image is enhanced by using high boost filtering and histogram equalization techniques, which sharpen the feature edges and improves the image contrast, respectively. Instead of simple averaging techniques, a novel dynamic exclusion heuristic is utilized, which converges the distance estimation results closer to the actual physical distance. Significant contributions of this paper are in the use of server assistance in pattern identification, Graphic Processing Unit (GPU) for faster parallel processing of computationally intensive algorithms, and multiple pattern identification for better distance estimation. Mohammad Ali Salahuddin 0001, Ala I. Al-Fuqaha, Vinay B. Gavirangaswamy, Marko Ljucovic, Muhammad T. Anan |
IWCMC | 1 |