Ryma Abassi

dblp:87/2508 · DBLP profile ↗
← Back
29ranked-venue papers
5as first author
14since 2021 · last 2025
0000-0003-2148-7965ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 15 · 4 first-author · 2 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Computer networks · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author
YearPublicationVenuePosition
2025 Collusion Attacks in the Internet of Drones: A Fog Computing Approach for Detection and Prevention
Amine Hedfi, Aida Ben Chehida Douss, Ryma Abassi, Mohamed Aymen Chalouf, Omessaad Hamdi
AINA (8)3
2025 Exploring Experimental Approaches for Enhancing Alzheimer's Disease Prediction with MRI Data and Deep Learning
abstract
Alzheimer's disease (AD) is a debilitating neurodegenerative disorder that requires an accurate diagnosis for effective treatment and management. During the past two decades, substantial research has focused on developing artificial intelligence (AI) models to automate AD prediction using datasets such as the Alzheimer's Disease Neuroimaging Initiative (ADNI). Since its launch in 2004 [1], ADNI has contributed to more than 6,000 scientific publications. Despite this progress, challenges such as data heterogeneity, limited annotations, class imbalance, and the absence of standardized resources continue to hinder reproducibility and scalability. In this study, we address these limitations by demonstrating that harmonized preprocessing of ADNI magnetic resonance images significantly improves the prediction and prognosis of AD. Our pipeline includes: (1) standardized data acquisition and preprocessing to generate three subdatasets based on MRI views: AXIAL, CORONAL, and SAGITTAL; (2) classification of these subsets using deep learning models; and (3) refinement of the most promising dataset (CORONAL) through hippocampus masking to enhance diagnostic performance. We compared several models including pre-trained transfer learning architectures: ResNet50 [2], DenseNet121 [3], InceptionV3 [4] and a newly proposed hybrid model [5] that combines InceptionV3 and DenseNet121. These were evaluated across the three anatomical views to identify the most informative MRI orientation. Using the hippocampus-masked CORONAL dataset, our hybrid model achieved a classification accuracy of 99 %, outperforming individual models. These findings show that targeted preprocessing, anatomical region focus, and hybrid deep learning models can significantly enhance AD detection and classification from MRI data.
Hadil Belanes, Mohamed Hamroun 0001, Benoît Crespin, Ryma Abassi
ICTAI4
2025 Enhancing Privacy and Performance in V2P Systems through Decentralized Federated Learning
abstract
In spite of the substantial development that faced Intelligent Transportation Systems (ITS) and, particularly, Vehicle-to-Pedestrian (V2P) communication systems, they still confront several challenges. These challenges are not only related to performance optimization, but also to privacy preservation. In fact, traditional centralized machine learning approaches for V2P exacerbate this privacy risk (1) by exposing the pedestrian data to privacy risks such as unauthorized tracking and data misuse, and (2) by intermingling with Noisy Background Information (NBI) real data.This paper presents RingFL-V2P, a decentralized Federated Learning framework that protects pedestrian data during model training. Instead of relying on a central server, RingFL-V2P uses a ring structure. Each device trains the model locally and then passes the updated model to the next device. This method keeps personal information safe while allowing devices to learn together.A comparative evaluation was carried on NuScenes-KITTI datasets in order to scrutinize the effectiveness of the proposed approach in the context of V2P communication systems. Results highlight that RingFL-V2P maintains competitive performance while ensuring privacy preservation.
Rihab Hmaied, Takoua Kefi-Fatteh, Ryma Abassi
IWCMC3
2025 RAFID: A Hybrid ResNet50-ViT Framework for Arabic Sign Language Recognition in Healthcare
abstract
Sign language, is a visual communication system that uses hand shapes, facial expressions, and body gestures. These languages are region specific. For instance, Arabic Sign Language (ArSL) differs significantly from English Sign Language. This project aims to develop an Arabic Sign Language Recognition (ArSLR) system tailored for healthcare, addressing communication challenges arising from the shortage of sign-fluent professionals and the limited availability of regionally adaptive technologies. Previous research utilizing Convolutional Neural Networks (CNNs) for sign recognition encountered challenges in capturing dynamic hand movements and facial cues. To overcome these limitations, we introduce a novel framework called RAFID, which is based on a cutting-edge architecture ResNet50ViT. This hybrid model combines ResNet50's capability for local feature extraction with Vision Transformer’s (ViT) global attention mechanism to deliver superior recognition performance. The system was trained on a multimodal medical dataset containing 92 dynamic signs. Performance was further enhanced through preprocessing and optimization techniques. RAFID achieved an impressive test accuracy of 99.86%, demonstrating the effectiveness of combining CNN-based feature extraction with transformer-based context modeling to capture both localized gestures and global patterns.This innovative system is anticipated to significantly enhance inclusivity and accessibility in medical care for the deaf community.
Ibtihel Mansour, Mohamed Hamroun 0001, Sonia Lajmi, Ryma Abassi
IWCMC4
2025 Securing Localization on the Internet of Drones: A Trust Based Intrusion Prevention System
abstract
The Internet of Drones (IoD) has recently gained popularity in several areas, such as military operations, smart agriculture, traffic analysis and Search And Rescue (SAR). In a SAR mission, drones' localization is a key element of IoD. It is a fundamental process in Cyber-Physical Systems (CPS), where environmental and location data are intimately linked. However, the protection of the drone's localization from security attacks and threats like injection of false locations and data by malicious drones, remains a major concern. In this paper, we present a novel approach for securing drone's localization during SAR mission using Intrusion Prevention System (IPS). Our main objective is to detect any trajectory deviation using the anomaly behavior based on node's reputation and to isolate malicious drones when an alert is triggered. Our model consists of a Master Drone (MD), selected based on its high performance compared to other drones, and a Ground Control Station (GCS) that configures the drones with the necessary parameters for the mission. The MD is synchronized with GCS to analyze the behavior of other drones using our IPS and a reputation value to determine if there is a significant deviation, indicating that the planned trajectory has been modified or altered. The proposed system model is based on IPS and trust management in order to detect the deviation of drones from their already configured trajectory planning. A case study of the proposed framework is provided in this paper.
Amine Hedfi, Aida Ben Chehida Douss, Ryma Abassi, Mohamed Aymen Chalouf, Omessaad Hamdi
WCNC3
2025 Secure V2P Risk Prediction: A Decentralized Federated Deep Learning Approach
abstract
Federated Learning (FL) is increasingly adopted to tackle privacy concerns in Intelligent Transportation Systems (ITS), particularly within Vehicle-to-Pedestrian (V2P) communication frameworks. Extending our previous research on decentralized federated learning frameworks using classical machine learning algorithms, this study investigates the efficacy of advanced Convolutional Neural Networks (CNNs), specifically ResNet18, ResNet34, MobileNetV2, and EfficientNetB0, within a decentralized FL context. We comparatively evaluate these models using performance metrics such as accuracy, loss, training time, and communication delay. Our experimental results demonstrate that ResNet34 achieves superior overall performance, offering the best trade-off between accuracy, convergence efficiency, and reduced communication overhead. This research confirms the applicability and advantages of CNN-based decentralized federated learning as a robust solution for secure and efficient V2P communication.
Rihab Hmaied, Takoua Kefi-Fatteh, Ryma Abassi
WiMob3
2024 A Novel Lightweight Authentication Mechanism for UAVs based on SDDN architecture
abstract
Unmanned Aerial Vehicles (UAVs) are versatile, used for tasks such as surveillance, mapping and delivery, offering cost-effective and efficient solutions in various industries. Hence, the rapid advancements of UAVs technologies increase their confrontation to substantial challenges like their constrained capacities: endurance, range, data process, etc. In addition, security and privacy of UAVs are a primary issue since attacks on UAV systems can cause loss of life and property. Ensuring drones authentication has become imperative to limit several kinds of attacks. UAVs networks management is also a challenging condition to ensure flexibility and scalability. Therefore, in this paper, we aim to ensure a secure UAV network by proposing a lightweight authentication mechanism based on Elliptic Curve Cryptographic (ECC) based on Software Defined Drone Network (SDDN). Through the proposed SDDN architecture, a secure efficient management of network resources is provided. Using this proposed authentication process, attacks such as Man-In- The-Middle, ID spoofing, replay, injection, modification, etc. are detected. To prove the effectiveness of our proposition, we validate it using two methods: A case study that illustrate the different attacks prevented and detected by our protocol. A formal security analysis using the Automated Validation of Internet Security Protocols and Applications (AVISPA) tool in order to confirm the safety of the proposal.
Nadia Kammoun, Aida Ben Chehida Douss, Ryma Abassi
WiMob3
2024 Towards Secure and Privacy Preserving Data Processing in E-Health
abstract
E-health guarantees the continuity of medical care and facilitates communication between the patient and healthcare organizations. For this reason, medical data must be accessible at all times and exchanged between stakeholders. Given the highly sensitive nature of this data and the increasing frequency of data breaches, it is crucial to implement strict privacy and security measures. Since patient is considered the owner of his medical data under laws as the Health Insurance Portability and Accountability Act HIPAA and the General Data Protection Regulation GDPR, he/she must have the right to privacy and to make decisions about sharing sensitive data. On the other hand, the stakeholders with whom the patient will share its information are not similar; each one requires specific data for different purposes. That's why the data transfer should not be performed in the same manner. In this article, we propose a framework to ensure the security and privacy of data processing in E-health systems. This framework is based on smart contracts to manage patient consent and traceability of data transfer, as well as mechanisms to classify data and apply the most suitable data masking technique to protect efficiently sensitive information.
Naoures Khairallah, Aida Ben Chehida Douss, Ryma Abassi, Mohamed Aymen Chalouf, Omessaad Hamdi
WiMob3
2022 Ensuring Data Integrity Using Digital Signature in an IoT Environment
Nadia Kammoun, Aida Ben Chehida Douss, Ryma Abassi, Sihem Guemara El Fatmi
AINA (3)3
2021 Formal Validation of a Security Mechanism against the RSU Compromise Attack
Ons Chikhaoui, Ryma Abassi, Aida Ben Chehida Douss, Sihem Guemara El Fatmi
ARES2
2021 Formal Validation of Credibility and Accuracy Assessment of Safety Messages in VANETs
abstract
In Vehicular Ad hoc NETworks (VANETs), vehicles exchange safety messages containing valuable information about traffic environment to increase roads’ safety. The critical nature of these messages entails securing them before considering them. In this context, the credibility and the accuracy assessment of these included safety information arises as a necessity since the consumption of false or imprecise ones by vehicles may cause hazardous consequences. To treat this requirement, we proposed the scheme [1] enabling vehicles to evaluate the credibility and the accuracy of the contents of the safety messages exchanged in VANETs. That scheme is based on three modules: a reputation module, a time and location closeness estimation module, and a majority module. A vehicle can use these modules in a separated or joint way according to the circumstances. Since that scheme is error prone, we conducted in [2], a formal validation, using inference system, to prove the soundness and the completeness of these three modules and their combination. In this paper, we complete that formal validation of [1] by handling the junctions of the three basic modules two by two. To do this, we first completed the inference system in [2] so that the junctions of the three modules two by two become incorporated. A formal verification using this holistic inference system was proposed in a second step to prove the soundness and the completeness of these junctions. This verification's obtained results confirmed the validity of the said junctions for being sound and complete.
Ons Chikhaoui, Aida Ben Chehida Douss, Ryma Abassi, Sihem Guemara El Fatmi
ARES3
2021 A Lightweight Authentication Scheme for SDN-Based Architecture in IoT
Nadia Kammoun, Ryma Abassi, Sihem Guemara El Fatmi, Mohamed Mosbah 0001
AINA (3)2
2021 Towards the Performance Evaluation of a Trust Based Routing Protocol for VANET
Amira Kchaou, Ryma Abassi, Sihem Guemara El Fatmi
AINA (1)2
2021 A Distributed Resource Management for VANET using Smart Contract
abstract
Recently, the Vehicular Ad-hoc network (VANET) has progressively gained attention from both industry and research with the rapid development of wireless communication technology and intelligent vehicles. The vehicles exchange messages with other entities but cannot share the resources between them. Therefore, security is required in some scenarios including integrity, traceability, confidentiality, notarization of exchanged information as well as access control. In order to provide a secure vehicle communication and access control, we propose an ABAC access control model using smart contract on the blockchain. The use of the blockchain facilitates the sharing of secure messages among vehicles. Moreover, vehicles are able to share the resources with each other exploiting the access control policy on the XACML standard. Then, we evaluate the access response time and the storage overhead of the proposal.
Amira Kchaou, Ryma Abassi, Samiha Ayed, Sihem Guemara El Fatmi
IWCMC2
2020 Towards the performance evaluation of a clustering and trust based security mechanism for VANET
abstract
Vehicular Ad-hoc Networks (VANETs) establish communication between vehicles in order to share safety information about road accidents or traffic jams, or non-safety information through messages. Besides, VANETs have a dynamic topology since the vehicles have a high mobility and therefore, the exchanged messages could be dropped or modified. However, falsified messages can be transmitted, the network performance can be affected. In a previous work, we have proposed a Clustering Mechanism for VANET (CMV) as well as a Trust management based on CMV (TCMV) to secure clustering mechanism for message exchange in the VANET. The CMV is based on two steps: (1) the clusters formation step where clusters are formed and the Cluster Heads are elected, and (2) the clusters maintenance step where the organization of clusters is kept in the presence of velocity when the topology changes in VANET, mainly at the arrival of a new vehicle or the displacement or the failure of a vehicle. Besides, the TCMV is used the reputation values of vehicles to compute the credibility of exchanged message. In this paper, we evaluate the performance of the CMV and TCMV. Hence, several simulations were realized with different number of vehicles, velocities and transmission range for the number of formed clusters, the cluster stability status, the Packet Data Ratio (PDR), the reputation of honest and dishonest vehicle, and cases of Trust Message.
Amira Kchaou, Ryma Abassi, Sihem Guemara El Fatmi
ARES2
2019 Towards a New Clustering Algorithm based on Trust Management and Edge Computing for IoT
abstract
Today Internet of things (IoT) is omnipresent bringing to us tracking and identification technologies, enhanced communication protocols and distributed intelligence in smart objects. Unfortunately, IoT is not far from security risks since it is an heterogeneous network comprising different nodes status. Malicious nodes impact harmfully on IoT network stability. In addition, IoT objects have limited capacities in processing, storage and batteries. To improve their batteries lifetime, objects workload should be bend down. Taking into consideration these IoT issues, we propose in this paper a clustering mechanism based on trust management and edge computing for IoT. The security intervention is based on excluding malicious nodes from an IoT network as well as by disseminating reliability between worthy nodes in favour of trust management. In order to minimize energy consumption, we established a one hop clustering mechanism based on density of nodes in an IoT network, trust and energy levels of nodes. All clusters are supervised by base stations in the edge of the network. We also integrate edge computing to migrate data processing and storage to base stations.
Nadia Kammoun, Ryma Abassi, Sihem Guemara El Fatmi
IWCMC2
2018 Towards a Privacy Preserving and Flexible Scheme for Assessing the Credibility and the Accuracy of Safety Messages Exchanged in VANETs
abstract
In Vehicular Ad hoc NETworks (VANETs), vehicles exchange safety related messages in order to improve the driving experience. However, it is not realistic to presume the absence of attackers intending to subvert the proper operation of the network. While message authentication enables the receiver to make sure of the received message's integrity and to verify its originator, it does not permit the verification of the message's credibility and accuracy. The main contribution of this paper is then the proposition of a scheme to assess the credibility and the accuracy of safety related messages exchanged in VANETs. Three modules constitute our proposal: a reputation module to evaluate the respective reputations of vehicles, a time and location closeness estimation module to judge the accuracy of a reported event and a majority module to decide the trueness of a received traffic information. These modules can be used in a separated or a combined way enabling a more flexibility in front of different circumstances confronted in VANETs. An in-depth security analysis is performed to demonstrate the efficiency of our proposal. Case studies that illustrate the different modules are also presented.
Ons Chikhaoui, Aida Ben Chehida Douss, Ryma Abassi, Sihem Guemara El Fatmi
ARES3
2018 Toward a Distributed Trust Management scheme for VANET
abstract
A Vehicular Ad hoc NETwork (VANET) is a self-organized network, formed by vehicles and some fixed equipment on roads called Roads Side Units (RSUs). Vehicular communications are expected to share different kinds of information between vehicles and infrastructure. Because of these specifications, securing VANET constitutes a difficult and challenging task that has attracted the interest of many researchers. In a previous work, we proposed a Clustering Mechanism for VANET (CMV) and its inherit Trust management scheme (TCMV) to ensure security of communication among vehicles. CMV organizes vehicles into clusters and elected Cluster Heads (CHs), and allows the clusters maintenance while dealing with velocity. On the other side, TCMV computes the credibility of the message by CH using the reputation of vehicles. However, we found that the value of credibility of the message by CH is not enough to verify if an exchanged message is correct or no. In order to provide a secured vehicle communication and to build reliance communication among vehicles, we propose a distributive trust management scheme for VANET to verify the correctness of the message based on the controlling of the vehicle'behavior by a miner and the credibility of message by a CH.
Amira Kchaou, Ryma Abassi, Sihem Guemara El Fatmi
ARES2
2018 Dealing with Collusion Attack in a Trust-Based MANET
abstract
Trust allows collaborating entities to cope with their uncertainty especially when these collaborations are the bedrock of the network existence such as in Mobile Ad hoc NETworks (MANET). The trustworthiness of collaborators can be evaluated using reputations. Reputation is an appreciation of the node credibility created through past actions. It can be calculated using direct observations and/or using other nodes appreciations exchanged through recommendations. Unfortunately, some nodes may be attempted to disturb the network by sending faked recommendations in order to decrease the reputation of a benevolent node or to increase the one of an attacker. That’s collusion attack. The main contribution of this paper concerns then, the proposition of collusion prevention and detection process in a trust based MANET.
Ryma Abassi
Cybern. Syst.1
2015 Trust Negotiation Based Approach to Enforce MANET Routing Security
abstract
MANETs (Mobile Ad hoc Networks) are described assets of mobile nodes connected with wireless links. To be efficient, routing protocols in MANETs should, in fact, manage mobility, handle nodes energy dissipation and ensure security. We argue in this paper that trust negotiation is appropriate in such context to enhance the network performances. Trust concept is of concern to communication and network protocol designers. Thus, building trust relationships among participating nodes is critical to enabling collaborative optimization of system metrics. The main contribution of this paper is an extension of our previous proposition DTMCA (Delegation Trust Mobility-based Clustering Approach) which defines a new clustering approach, a trust management process and a delegation process. This environment allows the localization and the isolation of malicious nodes in MANETs. The extension proposed in this paper extends the trust management process by adding a trust negotiation module used in order to minimize the risk that malicious nodes join the MANETs.
Aida Ben Chehida Douss, Samiha Ayed, Ryma Abassi, Nora Cuppens, Sihem Guemara El Fatmi
ARES3
2015 A Model for Specification and Validation of a Trust Management Based Security Scheme in a MANET Environment
abstract
Recently, we proposed a reputation based trust management scheme built upon a Mobility-based Clustering Approach (MCA) organizing Mobile Ad hoc Network MANET and detecting and isolating malicious behaviors. The whole scheme was called TMCA (Trust based MCA) and was extended in a second time with a delegation process resulting a proposition baptized DTMCA (Delegation TMCA based process). However, deploying such scheme is error prone and it appears necessary to validate it before its real implementation. In fact, scheme specification and validation constitute two fundamental challenges in the development of secure communication systems ensuring that the scheme is correctly enforced and complete. Hence, the main contribution of this paper concerns a validation framework for DTMCA scheme. The first step towards validation process is its formal specification. This is our first concern in this paper: a formal specification language called SCMSL (Secured Clustered MANET Specification Language) defined through a syntax based on authorization and obligation rules and a clear semantics. The second part of this paper proves the two major characteristics that must be guaranteed in such case: consistency and completeness. Consistency is proved by showing that there is no conflict in our scheme whereas completeness is proved by assessing that all potential situations are handled. The proof of consistency and completeness is made using automated systems through the definition of adequate algorithms.
Aida Ben Chehida Douss, Ryma Abassi, Sihem Guemara El Fatmi
ARES2
2015 A Formal Environment for MANET Organization and Security
Aida Ben Chehida Douss, Ryma Abassi, Nihel Ben Youssef, Sihem Guemara El Fatmi
CANS2
2015 Toward Securing MANET Against the Energy Depletion Attack
Aida Ben Chehida Douss, Ryma Abassi, Sihem Guemara El Fatmi
CRiSIS2
2014 A Trust Management Based Security Mechanism against Collusion Attacks in a MANET Environment
abstract
MANETs (Mobile Ad hoc Networks) are self organized networks with mobile and collaborating nodes without any pre-established infrastructure. Because of these characteristics, securing MANETs constitute a hard and challenging task. Consequently, new mechanisms may be of interest to secure such networks. To this end, we have found that trust management can be a support for MANET security. In fact, the reputation concept and the establishment of trustful relation between collaborating nodes can be meaningful to express security aspects in such environment. From there, we proposed in previous works a Mobility-based Clustering Algorithm (MCA) and a Trust management scheme for MCA (TMCA) to secure routing behaviors. MCA organizes nodes into clusters managed by a cluster-head (CH) and TMCA detects malicious routing behavior based on CHs direct observations and exchanged alerts. A delegation based process was also defined on TMCA and was called DTMCA. Although DTMCA meets security objectives, it may unfortunately be faced with various threats from malicious nodes: Several nodes can in fact collude in order to increase or decrease other reputation values to damage the QoS and even the MANET functioning. Our objective in this paper is then to secure DTMCA against collusion attacks. The mechanism proposed here is based on colluding nodes detection through cluster members behavior monitoring and by comparing this behavior with the received reputation value in the alert message. Detected colluder nodes are then discarded from further communication.
Aida Ben Chehida Douss, Ryma Abassi, Sihem Guemara El Fatmi
ARES2
2013 A Reputation-Based Clustering Mechanism for MANET Routing Security
abstract
A Mobile Ad hoc NETwork (MANET) is a collection of mobile nodes having no fixed topology and cooperating with each other. Due to these particularities, classical routing protocols cannot be used and some specific ones have been proposed. Because routing process is fundamental in a MANET deployment, it constitutes a privileged target of attackers. In this paper we propose a novel reputation-based clustering mechanism to locate malicious nodes and isolate them. In order to reduce network overhead and to handle network topology dynamicity, the proposed mechanism is based on a specific clustering environment. The clustering maintenance complexity is for its part reduced by the use of a reputation based delegation process allowing the cluster-head to delegate its privileges to a chosen cluster member in case of displacement or lack of energy. Moreover, node's reputation handling allows the detection and isolation of malicious nodes. Five modules constitute this mechanism: a monitoring module to detect malicious nodes, a reputation module to update reputation values, an isolation module to discard malicious nodes, an identity recognition module to assess alerts sources and a delegation module to allow clusterhead privileges delegation.
Aida Ben Chehida Douss, Ryma Abassi, Sihem Guemara El Fatmi
ARES2
2012 Trust-based delegation for Ad Hoc QoS enhancing
abstract
The importance of resources and services availability in Ad Hoc networks has already been proved several times in the past. It concerns, essentially, node availability as well as routing and forwarding actions accessibility. Unfortunately, nodes' lifetimes may be reduced or even depleted which leads to route failure, packets loss, QoS deterioration, etc. This is mainly due to a battery problem that can be caused by a legitimate consumption or by an attacker. To mitigate this problem and in order to allow nodes perpetuity and to face up any unavailability or flinching, a sharing of nodes' permissions can be used. Delegation is a common practice that is used to simplify and to manage this kind of sharing. Our proposition is then, to use a delegation process in order to enhance the QoS of Ad hoc networks by allowing the perpetuity of routes without stopping the packets transfer nor the re-calculation of a novel route. In view of the importance of the issue, we propose to base delegation on trust relations. Trust is a security concept generally used to provide collaborating network entities with a mean to counter their uncertainty. The main contribution in this paper is then, the proposition of a trust based delegation model for Ad Hoc networks in order to enhance QoS and specially routes availability.
Ryma Abassi, Sihem Guemara El Fatmi
CRiSIS1
2008 A Model for Specification and Validation of Security Policies in Communication Networks: The Firewall Case
abstract
A security policy constitutes one of the major actors in the protection of communication networks. For this, and in order to manage the access grants in accordance with the security constraints, a security policy has to be validated before its deployment. Unfortunately, in the literature, there is no well established validation mechanisms ensuring the well founded of such security policies. This paper proposes a validation framework for security policies where: (1) executable specifications are used to build an 'Executable Security Policy', (2) a validation model is proposed to support the validation activity, and (3) a validation of the executable security policy is performed. The main contributions provided by this paper concerns the adaptation of some concepts and mechanisms traditionally used in software engineering for validation aims, such as specification, executable specification or reachability graph. All the definitions made in this paper have been proposed in accordance with the firewall case.
Ryma Abassi, Sihem Guemara El Fatmi
ARES1
2008 An Automated Validation Method for Security Policies: The Firewall Case
abstract
Research in computer security issues has recently addressed the development of security policy specification languages. It has however omitted the need of formal validation. In this paper we try to remedy to this drawback by the proposition of an automated tool for security policies. Because we have found several similarities between security policies and software engineering, our approach is strongly inspired from the reasoning followed in the software engineering. First, it brings out a model inspired by Promela to enable the validation task. Secondly, it proposes a 3-step validation process that deals with consistency, completeness and preservation of safety and liveness properties.
Ryma Abassi, Sihem Guemara El Fatmi
IAS1
2008 Towards an automated firewall security policies validation process
abstract
A security policy constitutes one of the major actors in the protection of communication networks. However, it can be one of their weaknesses if it is inadequate according to the network security requirements. For this, a security policy has to be validated before its deployment. Unfortunately, in the literature, there is no well established validation mechanisms ensuring the well founded of such security policies. This paper proposes a validation framework for security policies based on the concept of executable specifications and applied to the firewall case. The main contributions provided by this paper concerns the adaptation of some concepts and mechanisms traditionally used in software engineering for validation aims, such as specification, executable specification or reachability graph.
Ryma Abassi, Sihem Guemara El Fatmi
CRiSIS1