EDBT 2026 Demo / reviewers in the wild / expert
Chafika Benzaid
dblp:62/2209 · also Chafika Benzaïd
· DBLP profile ↗
47ranked-venue papers
12as first author
32since 2021 · last 2026
0000-0001-5841-2014ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 26 · 5 first-author · 20 since 2021Security and privacy · 8 · 1 first-author · 7 since 2021Systems, architecture and hardware · 4 · 3 first-author · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Triarchy-Based for DDoS-Resilient IoT Networks
Amir Javadpour 0001, Forough Ja'fari, Tarik Taleb, Chafika Benzaid |
ICC | 4 |
| 2026 | Deep Learning-Powered Behavioral Authentication and Anomaly Detection for UAV Systems
Bahia Zebbane, Sana Medjadba, Chafika Benzaid |
WCNC | 3 |
| 2026 | EaaS/PIN Synergy: Advances and Challenges Secure Path VerificationabstractThe proliferation of resource-constrained devices in Internet of Things (IoT) environments has amplified the demand for scalable, secure, and efficient cryptographic services. While Encryption-as-a-Service (EaaS) models enable offloading cryptographic tasks to trusted infrastructure, critical challenges remain regarding path integrity, trust management, and resilience to adversarial threats in multi-domain networks. This paper introduces EaaS/PIN, a unified framework that combines cryptographically verifiable path integrity, user-centric trust scoring, collaborative threat intelligence, and machine learning-driven path selection across distributed Autonomous Systems (ASs). The framework integrates: (i) a novel anonymity protocol to conceal complete routes from intermediary ASs, (ii) lightweight, customizable encryption suitable for IoT and edge environments, (iii) real-time, AI-based path recommendation leveraging dynamic trust and performance metrics, and (iv) a blockchain-inspired audit mechanism for tamper-evident reporting and accountability. Comprehensive mathematical modeling, algorithms, and a detailed case study focused on secure data transmission in a multi-AS smart city network demonstrate that EaaS/PIN significantly enhances routing security, reduces latency, and ensures transparent and verifiable operations even under adversarial conditions. Experimental results confirm robust detection of path manipulation and compromised ASs, as well as measurable performance gains over baseline solutions. The proposed framework paves the way for scalable, user-aware, and resilient cryptographic services in next-generation heterogeneous network infrastructures. Amir Javadpour 0001, Forough Ja'fari, Tarik Taleb, Chafika Benzaid |
IEEE Internet Things J. | 4 |
| 2026 | Moving target defense for DDos mitigation with shuffling of critical edge(s) connections
Amir Javadpour 0001, Forough Ja'fari, Tarik Taleb, Chafika Benzaid |
J. Inf. Secur. Appl. | 4 |
| 2026 | Moving target defense in 5G and beyond networks: A comprehensive survey and research directions
Amir Javadpour 0001, Forough Ja'fari, Tarik Taleb, Chafika Benzaid |
J. Inf. Secur. Appl. | 4 |
| 2026 | Beyond Reinforcement Learning for network security: A comprehensive survey and tutorial
Amir Javadpour 0001, Forough Ja'fari, Tarik Taleb, Fatih Turkmen, Chafika Benzaid |
J. Inf. Secur. Appl. | 5 |
| 2025 | Improving the Security of Service Mesh in KubernetesabstractBringing flexibility and scalability to 5G networks has expanded networking technology to facilitate the split of service into microservices and how they can communicate. The network layer dedicated to this communication is called service mesh, and it has become a new target for cyber adversaries. The existing service mesh infrastructures, such as Istio and NGINX, apply the mutual TLS (mTLS) protocol to the connections in the service mesh layer to protect the confidentiality of the data transferred in this layer. However, the main challenge of implementing mTLS is its resource restriction, which significantly conflicts with the scalability and flexibility goals. Therefore, this paper proposes an Encryption as a Service (EaaS) framework that can be implemented on Kubernetes, mitigating man-in-themiddle, (distributed) denial of service, and eavesdropping attacks against service mesh. The implementation results show that the proposed framework decreases the adversary's success rate by at least 45% compared to the cases of having microservices apply the cryptographic processes by themselves. Amir Javadpour 0001, Forough Ja'fari, Tarik Taleb, Chafika Benzaid, Luís Rosa 0001, Luís Cordeiro |
ICPADS | 4 |
| 2025 | A Multi-Layered Zero Trust Microsegmentation Solution for Cloud-Native 5G & Beyond NetworksabstractZero Trust (ZT) is poised as a promising paradigm to effectively deal with the envisioned security risks of cloud-native 5G and beyond (B5G) architectures. However, integrating a ZT security model into B5G is still in its nascent stages, with most proposals remaining largely theoretical or limited to a single domain. This paper presents THAALOUB, a novel ZT framework that empowers 3GPP-compliant, end-to-end ZT security in cloud-native B5G networks. The framework leverages the advanced security features of Service Mesh and Container Network Interface (CNI) technologies to enable a multi-layered ZT microsegmentation security model. Moreover, it adopts an intent-based access control approach to foster proactive ZT security management. The experimental results show THAALOUB's high effectiveness in enhancing B5G security stance with minimal impact on latency and resource usage. Chafika Benzaid, Nawal Guerd, Nour El Houda Rehouma, Khaled Zeraoulia, Tarik Taleb |
WCNC | 1 |
| 2025 | SRST: A secure and resilient synchronization of time for WSNs in IoT applications
Amin Saiah, Chafika Benzaid, Mohamed F. Younis, Nadjib Badache |
Ad Hoc Networks | 2 |
| 2025 | Toward Securing IIoT: An Innovative Privacy-Preserving Anomaly Detector Based on Federated LearningabstractIn the light of the growing connectivity and sensitivity of industrial data, cyberattacks and data breaches are becoming more common in the Industrial Internet of Things (IIoT). To cope with such threats, this study presents an anomaly detection system based on a novel Federated Learning (FL) framework. This system detects anomalies such as cyberattacks and protects industrial data privacy by processing data locally and training anomaly detection models on industrial agents without sharing raw data. The proposed FL framework incorporates two key components to enhance both privacy and efficiency. The first component is Homomorphic Encryption (HE), which is integrated into the framework to further protect sensitive data transmissions such as model parameters. HE enhances privacy in FL by preventing adversaries from inferring private industrial data through attacks, such as model inversion attacks. The second component is an innovative dynamic agent selection scheme, wherein a selection threshold is calculated based on agent delays and data size. The purpose of this new scheme is to mitigate the straggler effect and the communication bottleneck that occur in traditional FL architectures, such as synchronous and asynchronous architectures. It ensures that agents are not unfairly selected by the different delays resulting from heterogeneous data in IIoT environments, while simultaneously improving model performance and convergence speed. The proposed framework exhibits superior performance over baseline approaches in terms of accuracy, precision, F1-scores, communication costs, convergence speeds, and fairness rate. Samira Kamali Poorazad, Chafika Benzaid, Tarik Taleb |
IEEE Internet Things J. | 2 |
| 2025 | An optimized reinforcement learning based MTD mutation strategy for securing edge IoT against DDoS attackabstractDistributed Denial of Service (DDoS) attacks are among the most destructive and challenging threats to mitigate for computer networks, particularly in edge IoT environments. Moving Target Defense (MTD) is a promising security mechanism that undermines the adversary’s gathered information by dynamically altering the attack surface. A selection of network nodes is chosen for mutation, and these changes hinder the adversary from achieving their objectives. However, identifying the optimal set of nodes for effectively and efficiently mitigating a DDoS attack remains a significant challenge. Existing MTD approaches have only considered a single factor—either the node’s vulnerability level or connectivity—and often lack generality and scalability for real-world IoT implementations. In this paper, we propose an enhanced MTD approach called CVbMA (Connection- and Vulnerability-based MTD Approach) that jointly considers both the vulnerability levels and connection weights of nodes to inform mutation strategies. To ensure practical applicability and adaptability, we develop a cost-aware Reinforcement Learning (RL) framework that incorporates explicit mutation costs into the reward function and utilizes neural ranking and model compression for scalability. Extensive evaluations are conducted using both Mininet-based simulations and a physical IoT testbed with real attack traces and heterogeneous devices. Comprehensive benchmarking and ablation studies against state-of-the-art MTD baselines demonstrate that the proposed framework significantly reduces the adversary’s success rate and incidents of server crashes, while maintaining low overhead and achieving high adaptivity. A detailed analysis of real-world deployments highlights the robustness of systems under operational constraints, including fluctuating latency, hardware diversity, and asynchronous events. Limitations and future enhancements, including topology-aware RL, adaptive mutation scheduling, and continuous model updates, are discussed. The results affirm the practical, scalable, and robust potential of cost-sensitive RL-based MTD for next-generation IoT security. Amir Javadpour 0001, Forough Ja'fari, Chafika Benzaid, Tarik Taleb |
J. Inf. Secur. Appl. | 3 |
| 2024 | Multi-Model based Federated Learning Against Model Poisoning Attack: A Deep Learning Based Model Selection for MEC SystemsabstractFederated Learning (FL) enables training of a global model from distributed data. However, the singular-model based operation of FL is open with uploading poisoned models compatible with the global model structure and can be exploited as a vulnerability to conduct model poisoning attacks. This paper proposes a multi-model based FL as a proactive mechanism to enhance the opportunity of model poisoning attack mitigation. A master model is trained by a set of slave models. To enhance the opportunity of attack mitigation, the structure of client models dynamically change and the supporter FL protocol is provided. For a MEC system, the model selection problem is modeled as an optimization to minimize loss and recognition time, while meeting a robustness confidence. A deep reinforcement learning based model selection is proposed. For a DDoS attack detection scenario, results illustrate a competitive accuracy gain under poisoning attack with the scenario that the system is without attack, and also a potential of recognition time improvement. Somayeh Kianpisheh, Chafika Benzaid, Tarik Taleb |
GLOBECOM | 2 |
| 2024 | A Novel Buffered Federated Learning Framework for Privacy-Driven Anomaly Detection in IIoTabstractIndustrial Internet of Things (IIoT) is highly sensitive to data privacy and cybersecurity threats. Federated Learning (FL) has emerged as a solution for preserving privacy, enabling private data to remain on local IIoT clients while cooperatively training models to detect network anomalies. However, both synchronous and asynchronous FL architectures exhibit limitations, particularly when dealing with clients with varying speeds due to data heterogeneity and resource constraints. Synchronous architecture suffers from straggler effects, while asynchronous methods encounter communication bottlenecks. Additionally, FL models are prone to adversarial inference attacks aimed at disclosing private training data. To address these challenges, we propose a Buffered FL (BFL) framework empowered by homomorphic encryption for anomaly detection in heterogeneous IIoT environments. BFL utilizes a novel weighted average time approach to mitigate both straggler effects and communication bottlenecks, ensuring fairness between clients with varying processing speeds through collaboration with a buffer-based server. The performance results, derived from two datasets, show the superiority of BFL compared to state-ofthe-art FL methods, demonstrating improved accuracy and convergence speed while enhancing privacy preservation. Samira Kamali Poorazad, Chafika Benzaid, Tarik Taleb |
GLOBECOM | 2 |
| 2024 | 5G Slice Mutation to Overcome Distributed Denial of Service Attacks Using Reinforcement Learningabstract5G slices are susceptible to indirect Distributed Denial of Service (DDoS) attacks, where overwhelming traffic directed to one slice can also disrupt other slices sharing the same infrastructure Many current mitigation methods rely on a detection phase, which may not be effective against unknown or sophisticated attacks. Moving Target Defense (MTD) is a security mechanism that invalidates the adversary's collected information, and it can be deployed without the detection phase. In this paper, we propose a Slice Mutation technique based on Reinforcement Learning (SMRL) that reduces the impact of DDoS attacks on 5G slices while keeping the number of allocated slices acceptable. SMRL proposes a general RL model that considers ternary and ranking numbers to improve learning performance. We tested SMRL on computer networks attacked by a real botnet called Mirai and assessed its performance using various measures, including a new functionality analysis method The results indicate that SMRL decreases the number of slices impacted by a DDoS attack and enhances the distribution of slices among infrastructure resources by 46 % and 20 %, respectively. Amir Javadpour 0001, Forough Ja'fari, Tarik Taleb, Chafika Benzaid |
SIN | 4 |
| 2024 | A Federated Continual Learning Framework for Sustainable Network Anomaly Detection in O-RANabstractThe distributed and disaggregated nature of 5G and beyond (B5G) networks has spurred interest in federated learning (FL) for empowering privacy-preserving collaborative network anomaly detection at the edge. However, FL is prone to catastrophic forgetting (CF), where prior knowledge is forgotten while sequentially learning new attack patterns from a stream of data. Few studies addressed CF issue in network anomaly detection using Continual Learning (CL), but focusing on centralized models rather than FL and overlooking integration in B5G. To fill this gap, we propose TenaxDoS, a novel framework that combines FL with a replay memory-based CL strategy to foster sustainable and cooperative network anomaly detection in an Open Radio Access Network (O-RAN) environment in B5G networks. The experimental results on a dataset from a real 5G test network show TenaxDoS's superior overall performance, stability and effective mitigation of CF, yielding a remembering of past knowledge of above 98.8%. Chafika Benzaid, Fahim Muhtasim Hossain, Tarik Taleb, Pedro Merino 0001, Michael Dieudonne |
WCNC | 1 |
| 2024 | A comprehensive survey on cyber deception techniques to improve honeypot performanceabstractHoneypot technologies are becoming increasingly popular in cybersecurity as they offer valuable insights into adversary behavior with a low rate of false detections. By diverting the attention of potential attackers and siphoning off their resources, honeypots are a powerful tool for protecting critical assets within a network. However, the cybersecurity landscape constantly evolves, and professional attackers are always working to uncover and bypass honeypots. Once an adversary successfully identifies a deception mechanism in place, they may change their tactics, potentially causing significant harm to the network. Maintaining a high level of deception is crucial for honeypots to remain undetectable. This paper explores various deception techniques designed specifically for honeypots to enhance their performance while making them impervious to detection. Previous research has not provided a detailed comparison of these techniques, particularly those tailored to honeynets. Therefore, we categorize the presented techniques into relevant classes, subject them to a comparative analysis, and evaluate their effectiveness in simulation scenarios. We also present a mathematical model that comprehensively represents and compares various honeynet research endeavors. In addition, we provide insightful suggestions that highlight the existing research gaps in this field and offer a roadmap for future expansion. This includes extending deception techniques to emulate vulnerabilities inherent in 5G and software-defined networks, which address the evolving challenges of the cybersecurity landscape. The findings and insights presented in this paper are valuable to honeypot developers and cybersecurity researchers alike, providing a vital resource for advancing the field and fortifying network defenses against ever-evolving threats. Amir Javadpour 0001, Forough Ja'fari, Tarik Taleb, Mohammad Shojafar, Chafika Benzaid |
Comput. Secur. | 5 |
| 2024 | Encryption as a Service (EaaS): Introducing the Full-Cloud-Fog Architecture for Enhanced Performance and SecurityabstractThe main goal of Encryption as a Service (EaaS) is to deliver cryptography services to limited-resource devices. However, due to the massive number of devices connecting EaaS platforms, they face challenging issues, such as high service delays and uncovered requests. The existing EaaS architectures lack in adequately taking advantage of both cloud and fog layers, by which the performance can be improved. Therefore, this article proposes a novel EaaS architecture called full-cloud-fog that focuses on increasing the EaaS throughput by locating the frequently accessed components on the fog layer and resolving resource allocations utilizing the cloud nodes. We have analyzed the security aspects of the proposed architecture and then implemented it in a real testbed. The evaluation results show that the proposed full-cloud-fog architecture improves the EaaS throughput by 81%. Amir Javadpour 0001, Forough Ja'fari, Tarik Taleb, Chafika Benzaid, Bin Yang 0010, Yue Zhao 0027 |
IEEE Internet Things J. | 4 |
| 2024 | Encryption as a Service for IoT: Opportunities, Challenges, and SolutionsabstractThe widespread adoption of Internet of Things (IoT) technology has introduced new cybersecurity challenges. Encryption services are being offloaded to cloud and fog platforms to mitigate these risks. Encryption as a Service (EaaS) emerges as a remedy, offering cryptographic solutions tailored to the resource constraints of IoT devices. This study thoroughly examines existing EaaS platforms, categorizing them based on encryption algorithms and service offerings. Additionally, we outline various EaaS architecture types depending on the placement of key components. Practical implementations of these platforms are explored through different testbeds. A key focus lies in dissecting the challenges that EaaS faces, particularly in the context of IoT, while suggesting potential remedies. This work stands out as an all-encompassing exploration, bridging the gap left by previous surveys. Amir Javadpour 0001, Forough Ja'fari, Tarik Taleb, Yue Zhao 0027, Bin Yang 0010, Chafika Benzaid |
IEEE Internet Things J. | 6 |
| 2024 | FortisEDoS: A Deep Transfer Learning-Empowered Economical Denial of Sustainability Detection Framework for Cloud-Native Network SlicingabstractNetwork slicing is envisaged as the key to unlocking revenue growth in 5 G and beyond (B5G) networks. However, the dynamic nature of network slicing and the growing sophistication of DDoS attacks rises the menace of reshaping a stealthy DDoS into an Economical Denial of Sustainability (EDoS) attack. EDoS aims at incurring economic damages to service provider due to the increased elastic use of resources. Motivated by the limitations of existing defense solutions, we propose FortisEDoS, a novel framework that aims at enabling elastic B5G services that are impervious to EDoS attacks. FortisEDoS integrates a new deep learning-powered DDoS anomaly detection model, dubbed CG-GRU, that capitalizes on the capabilities of emerging graph and recurrent neural networks in capturing spatio-temporal correlations to accurately discriminate malicious behavior. Furthermore, FortisEDoS leverages transfer learning to effectively defeat EDoS attacks in newly deployed slices by exploiting the knowledge learned in a previously deployed slice. The experimental results demonstrate the superiority of CG-GRU in achieving higher detection performance of more than 92% with lower computation complexity. They show also that transfer learning can yield an attack detection sensitivity of above 91%, while accelerating the training process by at least 61%. Further analysis shows that FortisEDoS exhibits intuitive explainability of its decisions, fostering trust in deep learning-assisted systems. Chafika Benzaid, Tarik Taleb, Ashkan Sami, Othmane Hireche |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2023 | A Deep Transfer Learning-Powered EDoS Detection Mechanism for 5G and Beyond Network SlicingabstractNetwork slicing is recognized as a key enabler for 5G and beyond (B5G) services. However, its dynamic nature and the growing sophistication of DDoS attacks put it at risk of Economical Denial of Sustainability (EDoS) attack, causing economic losses to service provider due to the increased elastic use of resources. Motivated by the limitations of existing solutions, we propose FortisEDoS, a novel framework that aims at enabling EDoS-aware elastic B5G services. FortisEDoS integrates a new deep learning-based DDoS anomaly detection model, called CG-GRU, that leverages the capabilities of emerging graph and recurrent neural networks in capturing spatio-temporal correlations to accurately identify malicious behavior, allowing proactive mitigation of EDoS attacks. Moreover, FortisEDoS uses transfer learning to effectively counteract EDoS attacks in newly deployed slices by leveraging the knowledge acquired in previously deployed slice. The experimental results show the superiority of transfer learning-powered CG-GRU in achieving higher detection performance with lower computation overhead, compared to other baseline methods. Chafika Benzaid, Tarik Taleb, Ashkan Sami, Othmane Hireche |
GLOBECOM | 1 |
| 2023 | Cybersecurity Fusion: Leveraging Mafia Game Tactics and Reinforcement Learning for Botnet DetectionabstractMafia, also known as Werewolf, is a game of uncertainty between two teams, which aims to eliminate the other team's players from the game. The similarities between detecting the Mafia members in this game and botnet detection in a computer network motivate us to solve the botnet detection problem using this game's winning strategies. None of the state-of-the-art researches have used the Mafia game strategies to detect the network's malicious nodes. In this paper, we first propose the Mafia detection strategies, which are applied using linear relation and reinforcement learning techniques. We then use the suggested strategies in a network infected by the Mirai botnet, using Mininet, to evaluate the performance of botnet detection. The average results show that the suggested strategies are 11% more accurate than the existing ones for the Mafia game. Additionally, the true positive and true negative detection rates of a network modeled by the proposed Mafia game are 71% and 91%, respectively. Amir Javadpour 0001, Forough Ja'fari, Tarik Taleb, Sayyed Hamid Reza Ahmadi 0001, Chafika Benzaid |
GLOBECOM | 5 |
| 2023 | Enhancing 5G Network Slicing: Slice Isolation Via Actor-Critic Reinforcement Learning with Optimal Graph FeaturesabstractNetwork slicing within 5G networks encounters two significant challenges: catering to a maximum number of requests while ensuring slice isolation. To address these challenges, we present an innovative actor-critic Reinforcement Learning (RL) model named ‘Slice Isolation based on RL’ (SIRL). This model employs five optimal graph features to construct the problem environment, the structure of which is adapted using a ranking scheme. This scheme effectively reduces feature dimensionality and enhances learning performance. SIRL was assessed through a comparative analysis with nine state-of-the-art RL models, utilizing four evaluation metrics. The average results demonstrate that SIRL outperforms other models with a 70% higher coverage rate of requests and an 8% reduction in damage resulting from DoS/DDoS attacks. Amir Javadpour 0001, Forough Ja'fari, Tarik Taleb, Chafika Benzaid |
GLOBECOM | 4 |
| 2023 | Moving Target Defense based Secured Network Slicing System in the O-RAN ArchitectureabstractThe open radio access network (O-RAN) architecture's native virtualization and embedded intelligence facilitate RAN slicing and enable comprehensive end-to-end services in post-5G networks. However, any vulnerabilities could harm security. Therefore, artificial intelligence (AI) and machine learning (ML) security threats can even threaten O-RAN benefits. This paper proposes a novel approach to estimating the optimal number of predefined VNFs for each slice while addressing secure AI/ML methods for dynamic service admission control and power minimization in the O-RAN architecture. We solve this problem on two-time scales using mathematical methods for determining the predefined number of VNFs on a large time scale and the proximal policy optimization (PPO), a Deep Reinforcement Learning algorithm, for solving dynamic service admission control and power minimization for different slices on a small-time scale. To secure the ML system for O-RAN, we implement a moving target defense (MTD) strategy to prevent poisoning attacks by adding uncertainty to the system. Our experimental results show that the proposed PPO-based service admission control approach achieves an admission rate above 80% and that the MTD strategy effectively strengthens the robustness of the PPO method against adversarial attacks. Mojdeh Karbalaee Motalleb, Chafika Benzaid, Tarik Taleb, Vahid Shah-Mansouri |
GLOBECOM | 2 |
| 2023 | Blockchain and Deep Learning-Based IDS for Securing SDN-Enabled Industrial IoT EnvironmentsabstractThe industrial Internet of Things (IIoT) involves the integration of Internet of Things (IoT) technologies into industrial settings. However, given the high sensitivity of the industry to the security of industrial control system networks and IIoT, the use of software-defined networking (SDN) technology can provide improved security and automation of communication processes. Despite this, the architecture of SDN can give rise to various security threats. Therefore, it is of paramount importance to consider the impact of these threats on SDN-based IIoT environments. Unlike previous research, which focused on security in IIoT and SDN architectures separately, we propose an integrated method including two components that work together seamlessly for better detecting and preventing security threats associated with SDN-based IIoT architectures. The two components consist in a convolutional neural network-based Intrusion Detection System (IDS) implemented as an SDN application and a Blockchain-based system (BS) to empower application layer and network layer security, respectively. A significant advantage of the proposed method lies in jointly minimizing the impact of attacks such as command injection and rule injection on SDN-based IIoT architecture layers. The proposed IDS exhibits superior classification accuracy in both binary and multiclass categories. Samira Kamali Poorazad, Chafika Benzaid, Tarik Taleb |
GLOBECOM | 2 |
| 2023 | A Mathematical Model for Analyzing Honeynets and Their Cyber Deception TechniquesabstractAs a way of obtaining useful information about the adversaries behavior with a low rate of false detection, honeypots have made significant advancements in the field of cybersecurity. They are also powerful in wasting the adversaries resources and attracting their attention from other critical assets in the network. A deceptive network with multiple honeypots is called a honeynet. The honeypots in a honeynet aim to cooperate in order to increase their deception power. Professional adversaries utilize strong detection mechanisms to discover the existence of the honeypots in a network. When an adversary finds that a deception mechanism is deployed, it may change their behavior and cause malicious effects on the network. Therefore, a honeynet has to be deceptive enough in order not to be identified. This paper aims to review the techniques that are designed for the honeynets to make them improve their deception performance. The recent related surveys do not focus on the honeynet-specific techniques, and also have no comparison analysis. The main presented techniques in this paper are fully investigated through comparative analysis and simulation scenarios. Some suggestions on the research gap are also provided. The results of this paper can be used by the honeynet developers and researchers to improve their work. Amir Javadpour 0001, Forough Ja'fari, Tarik Taleb, Chafika Benzaid |
ICECCS | 4 |
| 2023 | Linear Complexity for k-Coverage Sensor Redundancy Determination in IoTabstractSensors play a crucial role in the IoT frameworks by enabling devices to collect and transmit data in k-coverage situations. However, maintaining k-coverage in a region of Interest (RoI) requires the concurrent activation of many sensors where at least$k$nodes (k > 1), should cover each location in the sensing region. Due to overlaps in their sensing disks, sensors may be redundant and consume energy unnecessarily, in most k-coverage scenarios. In this paper, we propose SRA-Rot-klmax; a new redundancy algorithm that can affordably determine redundant sensors with a linear running time complexity even in k-coverage situations. A sensor is redundant in SRA- Rot-klmax, if its neighbors belong to particular sub-regions within its sensing disk denoted Flower areas (FA). A logical rotation with a certain angle value$a$is preformed to determine all possible Flower areas of a sensing disk and their local coverage degree klmax. Finally, according to klmax of each sensor, the coverage degree of the entire RoI is obtained. Simulations show that the proposed algorithm outperforms well-known k-coverage protocols in terms of energy conservation, network lifetime, and coverage performance. Manel Chenait, Chafika Benzaid, Bahia Zebbane |
ISNCC | 2 |
| 2023 | AI/ML for beyond 5G systems: Concepts, technology enablers & solutions
Tarik Taleb, Chafika Benzaid, Rami Akrem Addad, Konstantinos Samdanis |
Comput. Networks | 2 |
| 2023 | Reinforcement Learning-Based Slice Isolation Against DDoS Attacks in Beyond 5G NetworksabstractNetwork slicing in 5G networks can be modeled as a Virtual Network Embedding (VNE) problem, wherein the slice requests must be efficiently mapped on the core network. This process faces two major challenges: covering the maximum number of requests and providing slice isolation. Slice isolation is a mechanism for protecting the slices against Distributed Denial of Service (DDoS) attacks. To overcome these two challenges, we have proposed a novel actor-critic Reinforcement Learning (RL) model, called Slice Isolation-based Reinforcement Learning (SIRL), using five optimal graph features to create the problem environment, the form of which is changed based on a ranking scheme. The ranking procedure reduces the dimension of the features and improves learning performance. We evaluated SIRL by comparing it against four non-RL and nine state-of-the-art RL models. The average results show that the ratio of the covered requests and the damage caused by a DDoS attack of SIRL is 54% higher and 23% lower than that of the other models, respectively. It also has an acceptable learning performance and generality, regarding the reported results that show SIRL agents trained and tested with different networks outperform the other agents by 97%. Amir Javadpour 0001, Forough Ja'fari, Tarik Taleb, Chafika Benzaid |
IEEE Trans. Netw. Serv. Manag. | 4 |
| 2022 | TopoTrust: A Blockchain-based Trustless and Secure Topology Discovery in SDNsabstractThe Software Defined Network (SDN) architecture decouples the control functionality from the forwarding devices and implements it in a separate entity known as the controller. This raises new concerns on securing the control messages exchanged between the controller and the forwarding devices. In this paper, we propose TopoTrust, a novel fully trustless authenticity and integrity verification mechanism that relies on a Blockchain protocol to detect network topology poisoning attacks, namely Host Tracking Service (HTS) and OpenFlow Discovery Protocol (OFDP). The key merit of TopoTrust is its ability to operate in a zero trust SDN environment where no controller or switch is trusted. The evaluation of our protocol shows that it can successfully detect any spoofing-based and packet tampering attacks; and up to 96% and 100% of Fast Relocation and Link Fabrication attacks respectively within a short detection time, while introducing small overhead to the network. Mohamed Lamine Adjou, Chafika Benzaid, Tarik Taleb |
IWCMC | 2 |
| 2022 | Transfer Learning based GPS Spoofing Detection for Cellular-Connected UAVsabstractUnmanned Aerial Vehicles (UAVs) are set to become an integral part of 5G and beyond systems with the promise of assisting cellular communications and enabling advanced applications and services, such as public safety, caching, and virtual/mixed reality-based remote inspection. However, safe and secure navigation of UAVs is a key requisite for their integration in the airspace. The GPS spoofing is one of the major security threats to remotely and autonomously controlled UAVs. In this paper, we propose a machine learning-based, mobile network-assisted UAV monitoring and control system that allows live monitoring of UAVs' locations and intelligent detection of spoofed positions. We introduce the Convolutional Neural Network (CNN) in the edge UAV Flight Controller (UFC) to locate a UAV and detect any GPS spoofing by comparing differences between the theoretical path loss computed by UFC and the corresponding path loss reported by the connected base station (BS). To reduce the detection latency as well as to increase the detection accuracy, transfer learning is leveraged to transfer the CNN knowledge between edge servers when the UAV handovers from one BS to another. The performance evaluation shows that the proposed solution can successfully detect spoofed GPS positions with an accuracy rate above 88% using only one BS. Yongchao Dang, Chafika Benzaid, Tarik Taleb, Bin Yang 0010, Yulong Shen 0001 |
IWCMC | 2 |
| 2022 | Deep data plane programming and AI for zero-trust self-driven networking in beyond 5GabstractAlong with the high demand for network connectivity from both end-users and service providers, networks have become highly complex; and so has become their lifecycle management. Recent advances in automation, data analysis, artificial intelligence, distributed ledger technologies (e.g., Blockchain), and data plane programming techniques have sparked the hope of the researchers’ community in exploring and leveraging these techniques towards realizing the much-needed vision of trustworthy self-driving networks (SelfDNs). In this vein, this article proposes a novel framework to empower fully distributed trustworthy SelfDNs across multiple domains. The framework vision is achieved by exploiting (i) the capabilities of programmable data planes to enable real-time in-network telemetry collection; (ii) the potential of P4 – as an important example of data plane programming languages – and AI to (re)write the source code of network components in a fashion that the network becomes capable of automatically translating a policy intent into executable actions that can be enforced on the network components; and (iii) the potential of blockchain and federated learning to enable decentralized, secure and trustable knowledge sharing between domains. A relevant use case is introduced and discussed to demonstrate the feasibility of the intended vision. Encouraging results are obtained and discussed. Othmane Hireche, Chafika Benzaid, Tarik Taleb |
Comput. Networks | 2 |
| 2022 | Deep-Ensemble-Learning-Based GPS Spoofing Detection for Cellular-Connected UAVsabstractUnmanned aerial vehicles (UAVs) are an emerging technology in the 5G-and-beyond systems with the promise of assisting cellular communications and supporting IoT deployment in remote and density areas. Safe and secure navigation is essential for UAV remote and autonomous deployment. Indeed, the opensource simulator can use commercial software-defined radio tools to generate fake global positioning system (GPS) signals and spoof the UAV GPS receiver to calculate wrong locations, deviating from the planned trajectory. Fortunately, the existing mobile positioning system can provide additional navigation for cellular-connected UAVs and verify the UAV GPS locations for spoofing detection, but it needs at least three base stations (BSs) at the same time. In this article, we propose a novel deep-ensemble-learning-based, mobile-network-assisted UAV monitoring and tracking system for cellular-connected UAV spoofing detection. The proposed method uses path losses between BSs and UAVs communication to indicate the UAV trajectory deviation caused by GPS spoofing. To increase the detection accuracy, three statistics methods are adopted to remove environmental impacts on path losses. In addition, deep ensemble learning methods are deployed on the edge cloud servers and use the multilayer perceptron (MLP) neural networks to analyze path losses statistical features for making a final decision, which has no additional requirements and energy consumption on UAVs. The experimental results show the effectiveness of our method in detecting GPS spoofing, achieving above 97% accuracy rate under two BSs, while it can still achieve at least 83% accuracy under only one BS. Yongchao Dang, Chafika Benzaid, Bin Yang 0010, Tarik Taleb, Yulong Shen 0001 |
IEEE Internet Things J. | 2 |
| 2020 | INSPIRE-5Gplus: intelligent security and pervasive trust for 5G and beyond networksabstractThe promise of disparate features envisioned by the 3GPP for 5G, such as offering enhanced Mobile Broadband connectivity while providing massive Machine Type Communications likely with very low data rates and maintaining Ultra Reliable Low Latency Communications requirements, create a very challenging environment for protecting the 5G networks themselves and associated assets. To overcome such complexity, future 5G networks must employ a very high degree of network and service management automation, which is a security challenge by itself as well as an opportunity for smarter and more efficient security functions. In this paper, we present the smart, trustworthy and liable 5G security platform being designed and developed in the INSPIRE-5Gplus1 project. This platform takes advantage of new techniques such as Machine Learning (ML), Artificial Intelligence (AI), Distributed Ledger Technologies (DLT), network softwarization and Trusted Execution Environment (TEE) for closed-loop and end-to-end security management following a zero-touch model in 5G and Beyond 5G networks. To this end, we specifically elaborate on two key aspects of our platform, namely security management with Security Service Level Agreements (SSLAs) and liability management, in addition to the description of the overall architecture. Jordi Ortiz 0001, Ramon Sanchez-Iborra, Jorge Bernal Bernabé, Antonio F. Skarmeta, Chafika Benzaid, Tarik Taleb, Pol Alemany, Raul Muñoz 0001, Ricard Vilalta, Chrystel Gaber, Jean-Philippe Wary, Dhouha Ayed, Pascal Bisson, Maria Christopoulou, Georgios Xilouris, Edgardo Montes de Oca, Gürkan Gür, Gianni Santinelli, Vincent Lefebvre, Antonio Pastor 0001, Diego R. López |
ARES | 5 |
| 2020 | GPS Spoofing Detector with Adaptive Trustable Residence Area for Cellular based-UAVsabstractThe envisioned key role of Unmanned Aerial Vehicles (UAVs) in assisting the upcoming mobile networks calls for addressing the challenge of their secure and safe integration in the airspace. The GPS spoofing is a prominent security threat of UAVs. In this paper, we propose a 5G-assisted UAV position monitoring and anti-GPS spoofing system that allows live detection of GPS spoofing by leveraging Uplink received signal strength (RSS) measurements to cross-check the position validity. We introduce the Adaptive Trustable Residence Area (ATRA); a novel strategy to determine the trust area within which the UAV's GPS position should be located in order to be considered as non-spoofed. The performance evaluation shows that the proposed solution can successfully detect spoofed GPS positions with a rate of above 95%. Yongchao Dang, Chafika Benzaid, Yulong Shen 0001, Tarik Taleb |
GLOBECOM | 2 |
| 2020 | Energy-aware Collision Avoidance stochastic Optimizer for a UAVs setabstractUnmanned aerial vehicles (UAVs) is one of the promising technology in the future. A recent study claims that by 2026, the commercial UAVs, for both corporate and customer applications, will have an annual impact of 31 billion to 46 billion on the country's GDP. Shortly, many UAVs will be flying everywhere. For this reason, there is a need to suggest efficient mechanisms for preventing the collisions among the UAVs. Traditionally, the collisions are prevented using dedicated sensors, however, those would generate uncertainty in their reading due to their external conditions sensitivity. From another side, the use of those sensors could create an extra overhead on the UAVs in terms of cost and energy consumption. To deal with these challenges, in this paper, we have suggested a solution that leverages the chance-constrained optimization technique for avoiding the collision in an energy-efficient manner. Building on the expressions for the non-central Chi-square CDF and expected value, and through the convexification of the resulting expressions, the chance-constrained optimization program is transformed into a convex Mixed Binary Nonlinear one. The resulting program allows us to find the optimal safety distance that extends UAVs life-time and allows every UAV to move with a guaranteed probability of collision between any pair of UAVs. Sihem Ouahouah, Jonathan Prados-Garzon, Tarik Taleb, Chafika Benzaid |
IWCMC | 4 |
| 2020 | Robust Self-Protection Against Application-Layer (D)DoS Attacks in SDN EnvironmentabstractThe expected high bandwidth of 5G and the envisioned massive number of connected devices will open the door to increased and sophisticated attacks, such as application-layer DDoS attacks. Application-layer DDoS attacks are complex to detect and mitigate due to their stealthy nature and their ability to mimic genuine behavior. In this work, we propose a robust application-layer DDoS self-protection framework that empowers a fully autonomous detection and mitigation of the application-layer DDoS attacks leveraging on Deep Learning (DL) and SDN enablers. The DL models have been proven vulnerable to adversarial attacks, which aim to fool the DL model into taking wrong decisions. To overcome this issue, we build a DL-based application-layer DDoS detection model that is robust to adversarial examples. The performance results show the effectiveness of the proposed framework in protecting against application-layer DDoS attacks even in the presence of adversarial attacks. Chafika Benzaid, Mohammed Boukhalfa, Tarik Taleb |
WCNC | 1 |
| 2018 | Energy and Delay Aware Physical Collision Avoidance in Unmanned Aerial VehiclesabstractSeveral solutions have been proposed in the literature to address the Unmanned Aerial Vehicles (UAVs) collision avoidance problem. Most of these solutions consider that the ground controller system (GCS) determines the path of a UAV before starting a particular mission at hand. Furthermore, these solutions expect the occurrence of collisions based only on the GPS localization of UAVs as well as via object-detecting sensors placed on board UAVs. The sensors' sensitivity to environmental disturbances and the UAVs' influence on their accuracy impact negatively the efficiency of these solutions. In this vein, this paper proposes a new energy- and delay-aware physical collision avoidance solution for UAVs. The solution is dubbed EDCUAV. The primary goal of EDC-UAV is to build in-flight safe UAVs trajectories while minimizing the energy consumption and response time. We assume that each UAV is equipped with a global positioning system (GPS) sensor to identify its position. Moreover, we take into account the margin error of the GPS to provide the position of a given UAV. The location of each UAV is gathered by a cluster head, which is the UAV that has either the highest autonomy or the greatest computational capacity. The cluster head runs the EDC-UAV algorithm to control the rest of the UAVs, thus guaranteeing a collision free mission and minimizing the energy consumption to achieve different purposes. The proper operation of our solution is validated through simulations. The obtained results demonstrate the efficiency of EDC-UAV in achieving its design goals. Sihem Ouahouah, Jonathan Prados-Garzon, Tarik Taleb, Chafika Benzaid |
GLOBECOM | 4 |
| 2017 | Efficient offloading mechanism for UAVs-based value added servicesabstractUnmanned Aerial Vehicles (UAVs) are expected to be used everywhere to provision different services and applications, impacting different aspects of our daily lives. Basically, UAVs are characterized by their high mobility. Some may remain motionless for a specific time to perform pre-programmed missions. Whilst UAVs would be used for specific applications, they could additionally offer numerous IoT (Internet of Things) value-added services (VAS) when they are equipped with suitable IoT devices. Many IoT VAS applications require high amount of resources and/or diverse IoT devices that cannot be offered by a single UAV. In order to overcome this limitation, this paper aims to explore, i) the diversity of IoT devices on-board UAVs, and ii) the mobility of UAVs for offering UAVs-based IoT VAS. Two solutions are proposed for carrying out different IoT VAS. Both solutions are modeled using linear integer programming. While the first solution aims to reduce the energy consumption, the second one aims to shorten the response time. The simulation results demonstrate the efficiency of both solutions in achieving their design goals. Sihem Ouahouah, Tarik Taleb, Jaeseung Song, Chafika Benzaid |
ICC | 4 |
| 2017 | Efficient clock synchronization for clustered wireless sensor networks
Chafika Benzaid, Miloud Bagaa, Mohamed F. Younis |
Ad Hoc Networks | 1 |
| 2017 | Energy-efficient coverage protocol based on stable and predictive scheduling in wireless sensor networks
Manel Chenait, Bahia Zebbane, Chafika Benzaid, Nadjib Badache |
Comput. Networks | 3 |
| 2016 | CMTS: Consensus-based Multi-hop Time Synchronization protocol in wireless sensor networksabstractThe Consensus Time Synchronization (CTS) overcomes the shortcoming of centralized time synchronization in terms of scalability and robustness to node failure. However, CTS leads to slow convergence rate, high communication traffic and the inability to provide synchronization to an external time source. This paper proposes a novel distributed time synchronization protocol for WSNs, the Consensus-based Multi-hop Time Synchronization (CMTS) protocol. CMTS combines the benefits of consensus-based scheme, multi-level topology, synchronization by overhearing, master node synchronization, and MAC-layer timestamping. Simulations are performed to validate the effectiveness of CMTS. The results show that CMTS achieves high accuracy and improves the convergence time compared to competing schemes in the literature. Amin Saiah, Chafika Benzaid, Nadjib Badache |
NCA | 2 |
| 2016 | Fast authentication in wireless sensor networks
Chafika Benzaid, Karim Lounis, Ameer Al-Nemrat, Nadjib Badache, Mamoun Alazab |
Future Gener. Comput. Syst. | 1 |
| 2014 | An efficient clock synchronization protocol for wireless sensor networksabstractIn wireless sensor networks (WSNs), it may be necessary to have a unified time reference for all network nodes. Such a necessity may be imposed by the management strategy in the network, e.g., using time based medium access arbitration, or simply due to the dynamic nature of the application, e.g. target tracking. Since each node more or less operates autonomously, the clocks of the individual nodes have to be synchronized. Contemporary clock synchronization protocols introduce significant messaging overhead and thus do not suit the resource-constrained WSNs. In the paper, we propose a novel solution called Synchronization through Piggybacked Reference Timestamps (SPiRT). SRiRT exploits the popularity of two-tier network architectures in WSN, where nodes are grouped into disjoint clusters and each cluster is lead by a cluster-head that aggregates the data from its members. Each cluster-head synchronizes its clock to that of a reference node in the network through message exchange. Since cluster members can overhear the cluster-head transmissions, SPiRT takes advantages of such synchronization traffic to adjust the clock of the cluster members. SPiRT calls for appending the reference timestamps in the cluster-head messages so that a cluster member can estimate their clock adjustment. This cuts on energy consumption and increases the synchronization efficiency of SPiRT. SPiRT is validated through simulation and implementation on a Micaz based testbed. The validation results confirm the effectiveness of SPiRT and show that it outperforms competing schemes in the literature. Chafika Benzaid, Miloud Bagaa, Mohamed F. Younis |
IWCMC | 1 |
| 2014 | An Enhanced Secure Pairwise Broadcast Time Synchronization Protocol in Wireless Sensor NetworksabstractThis paper proposes an Enhanced Secure Pairwise Broadcast Time Synchronization (E-SPBS) protocol that allows authenticated MAC-layer timestamping on high-data rate radio interfaces. E-SPBS ensures the security of the Receiver-Only synchronization approach using a Public-Key-based Cryptography authentication scheme. The robustness and accuracy of E-SPBS were evaluated through simulations and experiments on a MICAz platform. Both simulation and experimental results demonstrate that E-SPBS achieves high robustness to external and internal attacks with low energy consumption. However, while the simulation results indicate that E-SPBS can achieve an average accuracy of less than 1μ s, the experimental results show that the synchronization error is higher and not stable. This comparison gives us a good indication on how much confidence can be put into simulation results. Chafika Benzaid, Amin Saiah, Nadjib Badache |
PDP | 1 |
| 2008 | A causal multicast protocol for dynamic groups in cellular networksabstractGroup communication is an abstraction which deals with multicasting a message from a source process to a group of processes. In Group Communication Systems (GCS), causal message ordering is an essential tool to ensure interaction among group members in a consistent way. In this paper, we propose a simple and optimal causal multicast protocol which copes with the dynamically changing groups in mobile environments. The protocol presents an optimal communication overhead without causing inhibition effect in the delivery of messages. The group membership management depends on a simple, yet powerful idea. This original idea consists in considering the join and leave requests as data messages, and then will be ordered with other messages. This makes no need to a coordination phase in the installation of a new view. Our protocol requires minimal resources on mobile hosts and wireless links and scales well with large groups. Chafika Benzaid, Nadjib Badache |
EATIS | 1 |
| 2008 | An Optimal Causal Broadcast Protocol in Mobile Dynamic GroupsabstractIn Group Communication Systems (GCS), causal message ordering is an essential tool to ensure interaction among group members in a consistent way. In several group-based applications, the exchanged information is often diffused to all members. Using a multicast protocol to ensure this broadcast should make the definition of data structures not optimal for this kind of applications. In this paper, we propose a simple and optimal causal broadcast protocol which copes with the dynamically changing groups in mobile environments. The protocol depends on two simple, yet powerful ideas. The first depends on the use of the immediate dependency relationship in the construction of control information, resulting in O(1) message overhead. When the second original idea depends on considering the join and leave requests as data messages. This ensures a consistent perception of the communication done in the group and makes no need to a coordination phase in the installation of a new view. Chafika Benzaid, Nadjib Badache |
ISPA | 1 |
| 2008 | BMobi_Causal: a causal broadcast protocol in mobile dynamic groupsabstractIn this paper, we propose a simple and optimal causal broadcast protocol which copes with the dynamically changing groups in mobile environments. The protocol depends on two simples, yet powerful ideas. The first consists in the use of the immediate dependency relationship (IDR) in the construction of control information (CI), resulting in O(1) message overhead. When the second original idea consists in considering the join/leave requests as data messages. This ensures a consistent perception within a group and makes no need to a coordination phase in the installation of a view. Chafika Benzaid, Nadjib Badache |
PODC | 1 |