EDBT 2026 Demo / reviewers in the wild / expert
Hai Anh Tran
dblp:52/8082
· DBLP profile ↗
29ranked-venue papers
5as first author
21since 2021 · last 2026
0000-0002-6215-4879ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 21 · 4 first-author · 17 since 2021Artificial intelligence and machine learning · 2 · 1 since 2021Security and privacy · 2 · 2 since 2021Systems, architecture and hardware · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Towards Efficient and Adaptive Traffic Classification: A Knowledge Distillation-Based Personalized Federated Learning FrameworkabstractTraffic classification plays a crucial role in optimizing network management, enhancing security, and enabling intelligent resource allocation in distributed network systems. However, traditional Federated Learning (FL) approaches struggle with domain heterogeneity, as network traffic characteristics vary significantly across different domains due to diverse infrastructure, applications, and usage patterns. This results in degraded performance when applying a single global model across all domains. To overcome this challenge, we propose KD-PFL-TC, a Knowledge Distillation-based Personalized Federated Learning framework for Traffic Classification, aimed to balance global knowledge sharing with personalized model adaptation in heterogeneous network environments. Our approach leverages knowledge distillation to enable collaborative learning without directly sharing raw data, preserving privacy while mitigating the negative effects of domain shifts. Each domain refines its local model by integrating insights from a global model and peer domains while maintaining its unique traffic distribution. To further enhance performance, we introduce an adaptive distillation strategy that dynamically adjusts the influence of global, peer, and local knowledge based on the similarity between traffic distributions, ensuring optimal knowledge transfer designed to each domain’s characteristics. Extensive experiments on real-world traffic datasets show that KDPFLTC maintains 88.0% accuracy under high heterogeneity (vs. 75.0% for FedAvg) while reducing communication overhead by 60%, delivering an efficient and robust solution for large-scale, heterogeneous networks. Hai Anh Tran, Nam-Thang Hoang |
IEEE Trans. Netw. Serv. Manag. | 1 |
| 2025 | POSTER: Multimodal Graph Networks for Systematic Generalization in Code Clone Detection
Cuong Dao, Van Tong, Hai Anh Tran |
AsiaCCS | 3 |
| 2025 | Encrypted Traffic Classification Through Deep Domain Adaptation Network With Smooth Characteristic FunctionabstractEncrypted network traffic classification has become a critical task with the widespread adoption of protocols such as HTTPS and QUIC. Deep learning-based methods have proven to be effective in identifying traffic patterns, even within encrypted data streams. However, these methods face significant challenges when confronted with new applications that were not part of the original training set. To address this issue, knowledge transfer from existing models is often employed to accommodate novel applications. As the complexity of network traffic increases, particularly at higher protocol layers, the transferability of learned features diminishes due to domain discrepancies. Recent studies have explored Deep Adaptation Networks (DAN) as a solution, which extends deep convolutional neural networks to better adapt to target domains by mitigating these discrepancies. Despite its potential, the computational complexity of discrepancy metrics, such as Maximum Mean Discrepancy, limits DAN’s scalability, especially when applied to large datasets. In this paper, we propose a novel DAN architecture that incorporates Smooth Characteristic Functions (SCFs), specifically SCF-unNorm (Unnormalized SCF) and SCF-pInverse (Pseudo-inverse SCF). These functions are designed to enhance feature transferability in task-specific layers, effectively addressing the limitations posed by domain discrepancies and computational complexity. The proposed mechanism provides a means to efficiently handle situations with limited labeled data or entirely unlabeled data for new applications. The aim is to limit the target error by incorporating a domain discrepancy between the source and target distributions along with the source error. Two statistics classes, SCF-unNorm and SCF-pInverse, are used to minimize this domain discrepancy in traffic classification. The experimental results demonstrate that our proposed mechanism outperforms existing benchmarks in terms of accuracy, enabling real-time traffic classification in network systems. Specifically, we achieve up to 99% accuracy with an execution time of only three milliseconds in the considered scenarios. Van Tong, Cuong Dao, Hai Anh Tran, Huynh Thi Thanh Binh, Nam-Thang Hoang, Truong X. Tran |
IEEE Trans. Netw. Serv. Manag. | 3 |
| 2024 | POSTER: Multi-Block Fusion Mechanism for Multi-label Vulnerability Detection in Smart ContractsabstractEthereum smart contracts offer innovative ways to automate transactions and execute agreements within blockchain systems. However, its inherent complexity can lead to exploitable vulnerabilities. With the advent of large language models, many studies put a special focus on identifying vulnerabilities using these models. Nonetheless, language models are ineffective with the lengthy input sequences. To overcome this limitation, this work proposes a novel multi-label vulnerability detection mechanism using pre-trained language model CodeT5+ combined with a unique multi-block fusion. The results demonstrate that the proposed mechanism can achieve up to 0.998 F1-score and require only 0.39 ms of processing time on a collected dataset comprising 421,266 contracts from Ethereum. Van Tong, Cuong Dao, Thep Dong, Hai Anh Tran, Truong X. Tran |
AsiaCCS | 4 |
| 2024 | Continuous Select-and-Prune Incremental Learning for Encrypted Traffic Classification in Distributed SDN NetworksabstractTraffic classification plays an indispensable role in Computer Networks and the Internet of Things. As the cybersecurity landscape evolves, a diverse array of encrypted protocols (e.g., HTTPS, GQUIC, and TLS) is becoming increasingly prevalent. Alongside this, the challenge of encrypted traffic classification has garnered renewed attention, fostered by the increasing adoption of Deep Learning (DL) methodologies. Nonetheless, the fast-paced release of new encrypted protocols necessitates frequent retraining of DL models on reformed datasets encompassing encrypted traffic from both known and unknown applications. This requirement can lead to the issues of catastrophic forgetting, particularly when classifying unknown applications. To address this shortcoming, we propose a novel two-stage Incremental Learning (IL) paradigm based on flow-exemplar selection strategy and model pruning, CoSP, to enable continuous model evolution with unknown applications. Extensive experiments on encrypted traffic datasets in a Software-defined networking environment illustrate that our method outperforms other IL approaches, achieving 1.07% and 0.94% improvements in last accuracy and forgetting, respectively. Son Duong, Hai Anh Tran, Truong X. Tran |
LCN | 2 |
| 2024 | Trustable Network Intrusion Detection System through Wisdomnet and Uncertainty MeasuresabstractIn the dynamic realm of cybersecurity, ensuring network infrastructure security is an imperative task. With organizations increasingly relying on interconnected systems for their operations, robust and trustworthy defenses against malicious activities are necessary. Network Intrusion Detection Systems (NIDS) play a pivotal role in this defense, functioning as vigilant guardians that monitor network traffic for suspicious patterns and potential security threats. This study introduces a trustworthy NIDS designed not only to detect attacks accurately but also to abstain from making predictions in case of doubt. In the cases of unsure predictions, the system chooses to reject the predictions, thus increasing the correctness of the NIDS results. The rejected cases can be deferred to a human administrator for further verification. The methodology utilizes two approaches: WisdomNet trustable neural networks and Uncertainty Estimation with Monte Carlo dropout. The proposed method can be applied to pre-trained NIDS models to enhance their trustworthiness. Evaluation results demonstrate that the method effectively reduces the classification error rate to zero while categorizing challenging or uncertain predictions as ‘reject’ at a substantial rejection rate. Abhinav Vij, Hai Anh Tran, Truong X. Tran |
LCN | 2 |
| 2024 | A novel approach for predicting the spread of APT malware in the network
Cho Do Xuan, Hai Anh Tran, Phuong Thi Lan Nguyen |
Appl. Intell. | 2 |
| 2024 | Troubleshooting solution for traffic congestion control
Van Tong, Sami Souihi, Hai Anh Tran, Abdelhamid Mellouk |
J. Netw. Comput. Appl. | 3 |
| 2023 | An Adaptive Sharding-based Blockchain for Network Slicing in 5GabstractFifth-generation wireless technology, or 5G, promises increased data speeds, lower latency and greater capacity for mobile communications, enabling the growth of the Internet of Things (IoT). Network slicing is an advantageous feature of 5G that enables the creation of multiple virtual networks to meet the performance, security, and reliability needs of different services. This feature, combined with blockchain technology, provides secure and transparent data sharing between devices and networks. In addition, blockchain-enabled network slicing improves 5G network management and creates new business models for industries such as healthcare, transportation, and manufacturing. However, most current blockchain systems are limited in their ability to handle high throughput, which is not equivalent to what 5G can do. Therefore, sharding-based blockchain is proposed as a possible solution to improve the scalability and throughput of blockchain networks. By dividing the network into parts or shards, transactions can be processed simultaneously, allowing for faster transaction verification times and increased network capacity. Although current sharding-based blockchain networks have some limitations, such as static sharding policies that cannot cope with the dynamic blockchain environment, an adaptive sharding blockchain system using Deep Reinforcement Learning (DRL) methods has been proposed to address this situation. The approach allows the system to change or adapt the shard specifications, such as shard size or block size, whenever necessary to ensure maximum throughput while maintaining the security and integrity of the blockchain network. Quang Huy Do, Sami Souihi, Van Tong, Hai Anh Tran, Sara Tucci Piergiovanni |
GLOBECOM | 4 |
| 2023 | Server and Route Selection Optimization for Knowledge-Defined Distributed Network Based on Gambling Theory and LSTM Neural NetworksabstractServer and route selection (SARS) optimization is a critical aspect of traffic engineering to allocate network resources to meet diverse service requirements effectively. Existing studies have primarily focused on finding profitable or optimal solutions for the SARS problem within current time steps, considering specific constraints. However, they often have failed to address the dynamic and uncertainty of future network states. To address this gap, this paper proposes an algorithm named GAL to optimize server costs and response time while accounting for future network dynamics. GAL combines a server selection inspired by the gambling theory and a network routing based on Long Short-Term Memory Networks (LSTM). The server selection method is formulated as a gambling problem and solved using the decision-making Tug-of-War (TOW) dynamic algorithm. The routing mechanism is optimized based on predictions of future network states made by LSTM neural networks, which excel in capturing long-term dependencies. We have implemented GAL through a distributed software-defined networking (SDN) system and obtained good evaluation results regarding average response time and server cost compared to benchmark methods. These results demonstrate that GAL can effectively tackle the SARS optimization problem by considering present constraints and future network dynamics. This study can advance traffic engineering and lays a foundation for more robust resource allocation strategies in dynamic network environments. Son Duong, Nam-Thang Hoang, Van Tong, Hai Anh Tran, Abdelhamid Mellouk, Truong X. Tran |
GLOBECOM | 5 |
| 2023 | Multi Service-Oriented Routing Mechanism for Heterogeneous Multi-Domain Software-Defined NetworkingabstractSoftware-defined networking (SDN) is a novel net-working paradigm for network management and autonomous systems. However, SDN has some challenges with scalability and quality of services (QoS) in distributed multi-domain scenarios due to the unprecedented growth of heterogeneous characteristics services. There is a current gap in a standard routing mechanism for satisfying various service requirements in distributed SDN. Most existing works design a homogeneous routing strategy for heterogeneous services, which might need to be more scalable and efficient for the future of rising heterogeneous online services. This study proposes a multi service-oriented routing mechanism for multi-domain SDN, which aims to help Internet service providers (ISPs) achieve high QoS and service-level agreements (SLAs). The mechanism utilizes a service classification (through a deep learning model) and optimizes network routing (using a new cost function containing both QoS and the server load). The mechanism has been integrated into the Knowledge-defined heterogeneous network architecture and tested on four prevalent considered services: E-commerce, Interactive Data, Video On-demand, and Bulk Data Transfer. The experimental results indicate that the proposed service-oriented routing mechanism outperforms the benchmark in terms of faster server response time while reducing up to 25% of the network congestion. Hoang Ngo, Trung Pham, Nam-Thang Hoang, Van Tong, Hai Anh Tran, Abdelhamid Mellouk, Truong X. Tran |
GLOBECOM | 6 |
| 2023 | Enhancing Encrypted Traffic Classification with Deep Adaptation NetworksabstractNetwork traffic management is crucial in Computer Networks and the Internet of Things. Indeed, classifying network traffic is the foundation for enhancing the quality of management mechanisms. However, traditional traffic classification methods, such as port-based, deep packet inspection, and statistic-based, are limited in identifying new encrypted traffic characteristics. Deep Learning-based classification approaches that consider packet-based features have been explored to address this challenge. Along with other deep learning methods, Transfer Learning, where a new model can inherit knowledge previously learned by a base model, is commonly used to increase classification performance in low data resources. Unfortunately, feature transferability may decline in transfer learning. This paper proposes an encrypted traffic classification mechanism that leverages the Deep Adaptation Network architecture with Mean Embedding Test to overcome this limitation. Our experimental results show that the proposed mechanism surpasses existing benchmarks’ accuracy and can classify encrypted traffic in real-time. Cuong Dao, Van Tong, Nam-Thang Hoang, Hai Anh Tran, Truong X. Tran |
LCN | 4 |
| 2022 | How Tezos blockchain can meet IoT?abstractNowadays, blockchain, revolutionary technology with high security and decentralization is widely applied in many industry segments including healthcare, cryptocurrency and so on. Despite its benefit, it is a challenge for blockchain to effectively operate in large-scale networks without compromising security and decentralization properties due to low throughput. Therefore, in this paper, we consider sharding-based blockchain as a solution to overcome this limitation. The objective is to split the network into different shards to process transactions in parallel and reduce quorum size to reach consensus quickly. However, existing sharding-based blockchain networks implement a consensus algorithm for both main and sub-shards, so it is ineffective with different purposes (e.g., to improve security, reduce resource consumption, etc.). Hence, we propose a system with heterogeneous consensus algorithms in sharding-based blockchain to meet different requirements. Experimental results show that the proposed approach improves up to 54 percent of throughout in comparison with benchmarks. Quang Huy Do, Sami Souihi, Van Van Tong, Hai Anh Tran, Skander Mhadhbi |
GLOBECOM | 4 |
| 2022 | A Blockchain-based SDN East/West InterfaceabstractSoftware-Defined Networking (SDN) architecture was developed to address the shortcomings of traditional network architectures. It allows system administrators to easily manage and configure the network by separating and abstracting the control plane from the data plane. All the knowledge and intelligence of SDN is concentrated in a software entity called the SDN controller, making the network programmable. However, a large-scale SDN architecture, particularly in the IoT domain, requires the implementation of a physically distributed control mechanism. Such a mechanism, based on the East/West interface raises many challenges in terms of scalability, reliability, security, consistency, and traceability. The development of the Blockchain allows addressing some of these challenges. In this paper, we present a design using Blockchain technology to improve SDNs in terms of trackability and discuss the adaptations required for large-scale deployment. Experimental results clearly show that the use of a proof-of-authority consensus algorithm in combination with a Merkle tree approach reduces the impact in terms of latency as well as in terms of Gas consumption. Hai Nam Nguyen, Sami Souihi, Hai Anh Tran, Scott Fowler |
GLOBECOM | 3 |
| 2022 | GADaM: Generic Adaptive Deep-learning-based Multipath Scheduler Selector for Dynamic Heterogeneous EnvironmentabstractMultipath QUIC (MQ-QUIC) and Multipath TCP (MP-TCP), known as multipath protocols, introduced several certain advantages for the next internet generation, such as enabling bandwidth aggregation of links, preventing single-path failure, increasing Quality of Service (QoS), etc. Meanwhile, the pivotal point of the transport protocols is the scheduler. Various multipath schedulers have been proposed, and each of them usually outperforms the others in each specific scenario. To provide a generic approach with the best performance and stability, a novel one is introduced in this paper and aimed to fill this research gap. Indeed, the proposed GADaM prototype is a Generic Adaptive Deep-learning-based Multipath Scheduler Selector. The idea’s prototype is implemented for the MP-QUIC protocol. The extensive results show that our scheduler selector achieved over 95% accuracy on training and 91% accuracy on the testing set in the simulated environment. Tran-Tuan Chu, Mohamed Aymen Labiod, Hai Anh Tran, Abdelhamid Mellouk |
ICC | 3 |
| 2022 | When NLP meets SDN : an application to Global Internet eXchange NetworkabstractSoftware-Defined Networking (SDN) and its extension Intent-Based Networking (IBN) are network paradigms that enable dynamic, programmatically efficient network configuration. IBN allows network operators to express an outcome or business objective without the low-level configurations necessary to program the network to achieve these demands. Existing research proposals for IBN introduce several systems to translate users intents into network infrastructure configurations. Despite the positive aspects of these proposals, they still suffer from many drawbacks. Some require users to learn a new intent definition language. Some others may lack the appropriate grammar to make these frameworks recognize the intent correctly. In this paper, we introduce a framework leveraging the capabilities of Natural Language Processing (NLP) for network management from an operator utterances. In order to understand natural language, our framework uses the sequence-to-sequence (seq2seq) learning model based on recurrent neural networks (LSTM). The model has been improved by using word embedding and user feedback. As a proof of concept, we implement our framework for network management in a Global Internet eXchange Network and evaluate its practicality regarding NLP accuracy and network performance. Manh-Tien-Anh Nguyen, Sondes Bannour Souihi, Hai Anh Tran, Sami Souihi |
ICC | 3 |
| 2022 | State-Dependent Multi-Constraint Topology Configuration for Software-Defined Service Overlay NetworksabstractService Overlay Network (SON) is an efficient solution for ensuring the end-to-end Quality of Service (QoS) in different real-world applications, including Video-on-Demand, Voice over IP, and other value-added Internet-based services. Although SON offers many advantages, such as ease of deployment and resilience to the node failures, it has to face the challenge of overlay network configuration that needs to dynamically adjust to the change in communication requirements. In this paper, we propose a novel method for adaptive overlay topology configuration, called AOTC based on Software-Defined Networks, deep learning, and reinforcement learning. The intuitive motivation is to address the above challenge, maximize the QoS from two aspects of customer preference and network cost. The obtained experimental results demonstrate the superiority of AOTC. Such a method can significantly reduce network cost while providing an improvement of 50% and 60% in terms of average delay and packet loss rate as compared to other traditional approaches. Hai Anh Tran, Abdelhamid Mellouk |
IEEE/ACM Trans. Netw. | 1 |
| 2021 | Machine Learning based Root Cause Analysis for SDN NetworkabstractNowadays, the rapid growth of the Internet makes network management more complex due to various and com-plicated network problems. In the past, network administrators implemented troubleshooting approaches (e.g., ping, traceroute, etc.) manually to identify the root cause of problems. However, it is not effective due to human intervention and an increase of network devices. Consequently, the root cause analysis is considered by the research community. There are existing studies for the root cause analysis without human intervention (e.g., statistical approaches, heuristic algorithms, etc.). However, these approaches show limited performance (e.g., due to complex threshold identifcation, etc.). The emerging of machine learning (ML) and deep learning is a potential solution to overcome this obstacle, offering an opportunity to develop an effective root cause analysis approach. Therefore, in this paper, we propose a root cause analysis approach using ML and time-series network parameters to identify the root cause of problems in the network. In this approach, we consider balancing the accuracy and the time complexity of ML algorithms to select an appropriate ML technique. Moreover, we contribute troubleshooting datasets to identify three kinds of root causes including link failure, switch failure and buffer overload. The experimental results show that the proposal can achieve approximately 97 percent of precision, recall and f1-score in considered scenarios and require less processing time (only require 0.00143 ms for a sample) in comparison with other ML algorithms. Van Tong, Sami Souihi, Hai Anh Tran, Abdelhamid Mellouk |
GLOBECOM | 3 |
| 2021 | A Reinforcement Learning-based solution for Intra-domain Egress SelectionabstractAn ingress router often has multiple potential egress points in an extensive network where it can transmit traffic to external networks. The traditional solution is choosing the closest node (with the shortest path) to the ingress node. This paper claims the drawbacks of this approach in a flexible network system and introduces our proposal called MAB-based Egress Selection. Our approach uses several Reinforcement Learning techniques, which are commonly used to resolve Multi-Armed Bandit (MAB) problem, to allow the ingress router to periodically re-pick egress point, hence optimize the long-term performance of traffic transmission. To formalize the egress selection process as a MAB problem, we use a combined score of delay and loss representing link status as a reward. However, capturing those network metrics encounters some issues due to the distributed control and restricted local view of network nodes. For this purpose, a centralized control architecture, e.g., Software-defined Network (SDN), is a promising candidate. We applied four common algorithms, ε-greedy, Softmax, UCB1 and Single Pull UCB2 (SP-UCB2) for egress selection process. The models are evaluated in two simulated network topologies with different scenarios of network traffic condition. The experimental results show that the UCB algorithms produce the best performance, especially in busy network. Duc-Huy Le, Hai Anh Tran, Sami Souihi |
HPSR | 2 |
| 2021 | An AI-based Traffic Matrix Prediction Solution for Software-Defined NetworkabstractTraffic Matrix (TM) clearly describes the volume and the distribution of traffic flows inside a network. TM plays an important role in many network management fields, such as traffic accounting, short-time traffic scheduling or re-routing, network design, anomaly detection, etc. Hence, an accurate TM prediction strategy is essential to handle those tasks effectively. Fortunately, Artificial Intelligence (AI) has been developing very strongly, thanks to computer technology developments such as GPU and TPU. That offers an opportunity to apply AI to TM prediction methods. However, applying Machine Learning techniques in traditional networks encounters some issues due to the distributed control and restricted local view of network nodes. For this purpose, a centralized control architecture, e.g., Software-defined Network (SDN), is a promising candidate. In this paper, we apply Long Short-Term Memory (LSTM) and its two variants, Bidirectional LSTM (BiLSTM) and Gate Recurrent Unit (GRU), for TM prediction mechanisms of an SDN architecture network. The prediction models have been evaluated using two datasets: the popular GÉANT backbone network traffic data and our dataset generated through a testbed. The experimental results show that our approach yielded promising traffic prediction accuracy. Duc-Huy Le, Hai Anh Tran, Sami Souihi, Abdelhamid Mellouk |
ICC | 2 |
| 2021 | Towards a Novel Congestion Notification Algorithm for a Software-Defined Data Center Networks
Hai Anh Tran, Thi-Thanh-Tu Nguyen, Sami Souihi, Abdelhamid Mellouk |
IM | 1 |
| 2020 | Service-centric Segment Routing Mechanism using Reinforcement Learning for Encrypted TrafficabstractFor the past decade, IP (Internet Protocol) routing approaches utilize TCAM (Ternary Content Addressable Memory) for the rule matching in the switches. These approaches are expensive and require more power consumption. Fortunately, the emerging of segment routing can resolve this drawback by encoding a routing path into the packet header to forward the packets to a destination. However, the standard segment routing algorithm has encountered a main problem. Using the shortest path to forward the packets can lead to a high traffic load on these paths and a performance reduction. It results in a decrease in user's perception and some negative economic impacts for ISPs (Internet Service Providers). Therefore, in this paper, we propose a novel service-centric segment routing mechanism using reinforcement learning in the context of encrypted traffic. Our proposal aims to help ISPs to decrease the influence of the network problems and meet the strict user's requirement related to QoE (Quality of Experience). The obtained results under the considered conditions demonstrate that our approach out-performs the standard segment routing algorithm and requires reasonable computational cost. Van Tong, Sami Souihi, Hai Anh Tran, Abdelhamid Mellouk |
CNSM | 3 |
| 2019 | Quality Estimation Framework for Encrypted Traffic (Q2ET)abstractIn the coming years, the development of the Internet of Things (IoT) will have relevance for transport, environment, health care, smart cities and also multimedia services (Multimedia Internet of Things (MIoT)). Nowadays, many ISP (Internet Service Provider) encrypt the data to make it secure during the transmission. However, it imposes some obstacles for the NSP (Network Service Provider) because of the lack of visibility for operators into network traffic. To resolve these issues, we proposed the Quality Estimation Framework for Encrypted Traffic (Q2ET) containing a classification module and a QoE assessment module. The first module inherited from our previous research works to classify the encrypted network traffic using CNN (Convolutional Neural Network). The second one applies the objective and subjective methods based on the statistical analysis and machine learning methods that combine application and network parameters to calculate user's QoE (Quality of Experience) in terms of MOS (Mean Opinion Score). The Q2ET allows the NSP to monitor the user's QoE to take the appropriate decisions when the QoE degradation happens in the network systems. Lamine Amour, Van Tong, Sami Souihi, Hai Anh Tran, Abdelhamid Mellouk |
GLOBECOM | 4 |
| 2018 | A Novel QUIC Traffic Classifier Based on Convolutional Neural NetworksabstractNowadays, network traffic classification plays an important role in many fields including network management, intrusion detection system, malware detection system, etc. Most of the previous research works concentrate on features extracted in the non-encrypted network traffic. However, these features are not compatible with all kind of traffic characterization. Google's QUIC protocol (Quick UDP Internet Connection protocol) is implemented in many services of Google. Nevertheless, the emergence of this protocol imposes many obstacles for traffic classification due to the reduction of visibility for operators into network traffic, so the port and payload- based traditional methods cannot be applied to identify the QUIC- based services. To address this issue, we proposed a novel technique for traffic classification based on the convolutional neural network which combines the feature extraction and classification phase into one system. The proposed method uses the flow and packet-based features to improve the performance. In comparison with current methods, the proposed method can detect some kind of QUIC-based services such as Google Hangout Chat, Google Hangout Voice Call, YouTube, File transfer and Google play music. Besides, the proposed method can achieve the microaveraging F1-score of 99.24 percent. Van Tong, Hai Anh Tran, Sami Souihi, Abdelhamid Mellouk |
GLOBECOM | 2 |
| 2018 | Empirical study for Dynamic Adaptive Video Streaming Service based on Google Transport QUIC protocolabstractQuick UDP Internet Connections (QUIC) is a new transport protocol developed by Google in 2012. QUIC is considered as a combination of TCP, TLS and HTTP on the top of UDP with some advantages such as reducing connection establishment time, improving congestion control, multiplexing without heads of line blocking and connection migration. In video streaming, Dynamic Adaptive Streaming over HTTP (DASH) is tied with TCP in many years, but the video streaming using HTTP on TCP has some disadvantages in terms of head of line blocking, connection migration, etc. The emergence of QUIC resolves these drawbacks and provides some solutions to reduce the latency and improve the quality of network service with respect to QoE. Therefore, in this paper, we investigate and evaluate the performance of QUIC and traditional transport protocols in the context of video streaming using DASH services. Some QUIC parameters such as maximum congestion window, buffer size and number of emulated connections are considered to choose the appropriate parameters for video streaming. Besides, we compare the performance of QUIC with TCP in terms of some network parameters and some DASH parameters. The experimental results showed that the performance of QUIC with 2 emulated connections is not as good as TCP. When the number of emulated connections is set to 6, the number of changes in quality level and stalling events are lower than the figure for TCP. Consequently, the quality level of QUIC with 6 emulated connections is better than TCP. Moreover, the QoE score of QUIC with 6 emulated connections is higher than the figure for QUIC with 2 emulated connections and TCP. Van Tong, Hai Anh Tran, Sami Souihi, Abdelhamid Mellouk |
LCN | 2 |
| 2018 | Mining Frequent Patterns for Scalable and Accurate Malware Detection System in AndroidabstractNowadays, the high interest of Android applications makes them the target of a huge number of malware. To detect this severe increase of Android malware and help end-users make a better evaluation of apps at install time, several approaches have been proposed such as statistic and dynamic approaches. However, these approaches cannot detect with high accuracy unfamiliar malware types. That inspired us to find a new approach for recognizing a malware basing on the anomalous set of permission it requests. To actualize that idea, we used the theory of frequent patterns, a data mining technique, for mining the frequent combination of requested permissions. We also compare the performance of the proposed system to other malware detection applications. Experimental results show that the proposed system yielded high accuracy with approximately 97 percent of normal applications and 86 percent of abnormal applications. Thi-Tra-My Nguyen, Dong-Son Nguyen, Van Tong, Hai Anh Tran, Abdelhamid Mellouk |
PIMRC | 5 |
| 2018 | A LSTM based framework for handling multiclass imbalance in DGA botnet detection
Hieu Mac, Van Tong, Hai Anh Tran, Linh Giang Nguyen |
Neurocomputing | 4 |
| 2014 | QoE-Based Server Selection for Content Distribution NetworksabstractAs current server capacity and network bandwidth become increasingly overloaded by the rapid growth of high quality emerging multimedia services such as mobile online gaming, social networking or IPTV, a critical factor of success of these multimedia services becomes the end-user perception of quality while them using the service. As a result, user-centered approaches that consider quality of experience (QoE) constitute the current design trend for network systems of content providers and network operators. A content distribution network (CDN) that replicates the content from original servers to the replicated servers close to end users is actually an effective solution to improve network quality. We propose a QoE-based server selection algorithm in the context of a CDN architecture. Using realistic characteristics of the server selection process, we formalize our selection model as a sequential decision problem solved by the multi-armed bandit (MAB) paradigm. By using realistic experiments, we demonstrate that our approach yields significant improvements in term of user perception compared to traditional methods (such as Fastest, Closest and Round Robin). Hai Anh Tran, Said Hoceini, Abdelhamid Mellouk, Julien Perez, Sherali Zeadally |
IEEE Trans. Computers | 1 |
| 2012 | Global state-dependent QoE based routingabstractFor years, wireless network systems have been trying to satisfy end-users and support high quality multimedia applications such as Mobile TV, VoIP, etc. Combining wireless networks with multimedia content distribution needs efficient routing protocols. We develop in this paper a new routing protocol, namely DOQAR (Dynamic Optimized QoE Adaptive Routing), to improve the user perception and optimize the usage of network resources. In our end-to-end model, smartphone users connect to content servers in a wired network across a wireless access network. In order to evaluate the QoE, we use a Multi-Layer Perception-based (MLP) method. Experimental results show a significant performance against other traditional routing protocols. Hai Anh Tran, Abdelhamid Mellouk, Said Hoceini, Brice Augustin |
ICC | 1 |