Ali Chehab

dblp:88/5173 · DBLP profile ↗
← Back
108ranked-venue papers
1as first author
25since 2021 · last 2026
0000-0002-1939-2740ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 36 · 8 since 2021Security and privacy · 14 · 5 since 2021Graphics, computer vision, multimedia, augmented reality and games · 11 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 10Systems, architecture and hardware · 9 · 1 first-author · 3 since 2021Databases, data management, data science and information retrieval · 4 · 2 since 2021Human-computer interaction and ubiquitous computing · 1
YearPublicationVenuePosition
2026 Efficient and Lightweight Object Detection via Multi-Round Response-Based Knowledge Distillation
Ahmed Hamdi, Hassan N. Noura, Ali Chehab
IWCMC3
2026 A Knowledge Distillation-Reinforcement Learning-Based Neural Architecture Search Framework
Ahmed Hamdi, Hassan N. Noura, Ali Chehab, Guy Pujolle
IWCMC3
2026 Toward accurate and cost-effective LLM agents via information flow optimization: Insights from a phishing detection case study
Fouad Trad, Ali Chehab
Inf. Process. Manag.2
2025 Leveraging Large Language Models for Reducing False Positives and Prioritizing Alerts in Intrusion Detection Systems
Ali Mustafa, Fouad Trad, Ali Chehab
AINA (4)3
2025 OCSVM-Siamese Framework for Detecting Adversarial Attacks for Autonomous Driving Cars
abstract
In this paper, we propose a robust adversarial detection framework to secure AI models against adversarial threats specifically in autonomous driving cars. The proposed framework combines two levels of security. The first level is based on the anomaly detection capability of the One-Class Support Vector Machine (OCSVM) for detecting adversarial inputs with large perturbations. The second level leverages the Siamese network’s ability to extract the embedding feature vector of the input. The embedding vector is used to identify the input belonging to a certain category based on the cosine similarity index. The proposed method is adversarial training-agnostic and model-agnostic. To evaluate the proposed method, we compare its performance with the state-of-the-art detection method, Feature Squeezing. The experimental results show the effectiveness and robustness of the proposed method in detecting various adversarial perturbations with a remarkable detection accuracy of 100% as opposed to 88.5% for Feature Squeezing under eleven adversarial attacks on the speed limit signs of the GTSRB dataset.
Ahmad Fakhr Aldeen Sattout, Ali Chehab
IWCMC2
2025 Evaluating the Efficacy of Prompt-Engineered Large Multimodal Models versus Fine-Tuned Vision Transformers in Image-Based Security Applications
abstract
The success of Large Language Models (LLMs) has spurred the rise of Large Multimodal Models (LMMs), which integrate multiple modalities, such as text and images, to address complex data analysis tasks. As these black-box models gain popularity due to their ease of use and adaptability, there is growing interest in understanding their potential to replace or complement task-specific models in domain-specific applications. This article evaluates the applicability and effectiveness of prompt-engineered LMMs, specifically LLaVA, BakLLaVA, Moondream, Gemini 1.5 Flash, and GPT-4o, compared to fine-tuned Vision Transformer (ViT) models in addressing cybersecurity challenges of varying complexity. Our study examines three distinct tasks: (1) detecting visual triggers indicative of potential backdoors in two scenarios (digit recognition and traffic sign classification), (2) identifying phishing attempts from Web site screenshots, and (3) classifying malware based on visual representations. The results reveal that prompt-engineered LMMs perform competitively on tasks with visually evident or moderately complex features, such as trigger detection and phishing classification, with GPT-4o and Gemini 1.5 Flash demonstrating superior performance among LMMs. However, for the highly specialized task of malware classification, LMMs exhibit notable limitations when relying solely on prompting. Fine-tuning GPT-4o significantly improves its performance, yet it still lags behind fine-tuned ViT models, which consistently achieve higher accuracy across all tasks. While ViTs deliver superior precision and robustness, they require substantial resources for training, fine-tuning, and maintenance. In contrast, LMMs provide flexibility and ease of deployment, making them an appealing alternative for scenarios where resource constraints or rapid implementation are critical. This study highlights the tradeoffs between these approaches, emphasizing that while ViTs are indispensable for high precision, specialized applications, LMMs offer a scalable and versatile solution for less complex or resource-limited tasks.
Fouad Trad, Ali Chehab
ACM Trans. Intell. Syst. Technol.2
2024 SERS: Secure & Efficient Random and Symbol Linear Network Coding Schemes
abstract
Recently, several security schemes for Random Linear Network Coding (RLNC) have been proposed to increase the immunity of the RLNC technology against security attacks. One of the presented security schemes aims at securing the Global Encoding Vectors (GEV) that use other vectors to maintain the proper encoding process of RLNC at intermediate nodes. However, this approach introduces overhead in terms of computational complexity (block cipher with multiple rounds and operations) and communication (2xn elements for each packet instead of n). To that end, this paper proposes a new scheme, $S E R S$, that overcomes the disadvantages and limitations of the existing security schemes by relying on a single GEV instead of two, which is the case of the original RLNC. The proposed scheme reduces the required computational complexity by eliminating AES encryption and by keeping the source RLNC encoding step as a secret. SERS is based on a dynamic key structure, and the introduced modifications result in a modern lightweight, and secure RLNC while achieving higher efficiency and minimizing the space of vulnerabilities. SERS exhibits minimal computational complexity and communication overhead, and it ensures message confidentiality and availability, in addition to source authentication when a homomorphic keyed hash function is employed. A second variant of the proposed scheme is also presented. The main advantages of the proposed scheme are that 1) it operates at the sub-generation level, 2) it can be implemented in parallel, and 3) it increases the security level by using different RLNC encoding matrices instead of just one.
Ola Salman, Hassan N. Noura, Ali Chehab
IWCMC3
2024 Efficient and secure message authentication algorithm at the physical layer
Hassan N. Noura, Reem Melki, Ali Chehab, Javier Hernandez Fernandez
Wirel. Networks3
2024 Lightweight and secure cipher scheme for multi-homed systems
Hassan N. Noura, Reem Melki, Mohammad M. Mansour, Ali Chehab
Wirel. Networks4
2023 High-Density FeFET-based CAM Cell Design Via Multi-Dimensional Encoding
abstract
Content addressable memory is one of the most frequently used technologies in Data-centric applications due to its exceptional search parallelism capability. SRAM cells were initially used to implement CAM designs. Recent innovations proposed using compact nonvolatile memories instead. FeFETs emerged as a multi-level NVM device with promising potential and 2T FeFET CAM designs were studied. In this paper, a new potential is discussed for increasing the density efficiency of FeFET CAM architectures by adapting higher-dimensional encoding using 3T and 4T CAM designs. We propose a scalable greedy search algorithm for maximizing encoding capabilities. We compare the density, latency, accuracy, and energy consumption of our designs to standard 2T architecture demonstrating a 4x and 8x decrease in fail probability with up to 16% and 26.5% increase in memory density (bits/unit-area) in the 3T and 4T designs respectively.
Hadi Noureddine, Omar Bekdache, Mohamad Al Tawil, Rouwaida Kanj, Ali Chehab, Mohamed E. Fouda, Ahmed M. Eltawil
ACM Great Lakes Symposium on VLSI5
2023 LESCA: LightwEight Stream Cipher Algorithm for emerging systems
Hassan N. Noura, Ola Salman, Raphaël Couturier, Ali Chehab
Ad Hoc Networks4
2023 Machine learning-based anti-jamming technique at the physical layer
abstract
Abstract The reliance on wireless services to exchange critical data is associated with various threats and attacks, which must be mitigated to ensure integrity and security of those wireless services. Posing a serious challenge to wireless systems, jamming is among these attacks. In order to mitigate jamming, directive antennas are used to minimize the signals that are received from the jammer, while maximizing the received legitimate signal from the authorized transmitter. In this paper, we propose a machine learning‐based anti‐jamming framework to provide a spatially dynamic and instantaneous anti‐jamming performance that is achieved at the physical layer. The proposed framework incorporates a dataset that can be deployed in the hardware of a receiver with a massive Multiple‐Inputs Multiple‐Outputs–(MIMO) antenna. Our extensive performance evaluation results demonstrate the effective performance of the proposed framework in preserving integrity of a massive–MIMO communication system despite the presence of a hostile jammer. Particularly, due to the tabular nature of the generated dataset, tree‐based random forest models achieved the best performance with a signal‐to‐interference‐plus‐noise ratio accuracy of and fast anti‐jamming response in around 1.66 s under sever jamming conditions.
Mahdi Chehimi, Mohamad Khattar Awad, Mohammed Al-Husseini, Ali Chehab
Concurr. Comput. Pract. Exp.4
2023 Conception of efficient key-dependent binary diffusion matrix structures for dynamic cryptographic algorithms
Hassan N. Noura, Ola Salman, Ali Chehab
J. Inf. Secur. Appl.3
2022 Efficient and secure selective cipher scheme for MIoT compressed images
Hassan N. Noura, Ola Salman, Raphaël Couturier, Ali Chehab
Ad Hoc Networks4
2022 Towards efficient real-time traffic classifier: A confidence measure with ensemble Deep Learning
Ola Salman, Imad H. Elhajj, Ali Chehab, Ayman I. Kayssi
Comput. Networks3
2022 A Single-Pass and One-Round Message Authentication Encryption for Limited IoT Devices
abstract
In this work, we propose three efficient variants of a message authentication encryption (MAE) algorithm, which is based on the dynamic key-dependent concept and dynamic operation mode to reach a high level of security. These variants consist of a single pass and a single round, in addition to the use of common operations for the encryption and authentication processes to reduce the required execution time and resources. Accordingly, the proposed scheme outperforms the existing solutions that are based on the static approach with multiple rounds. Furthermore, to reduce the overhead associated with the regeneration of the dynamic key and the corresponding cryptographic primitives, we propose a simple, yet effective update process. In such a scheme, even when the same plaintext is processed, it will be encrypted and authenticated using different cryptographic primitives (substitution and permutation tables in addition to round keys), which guards against the existing cryptanalysis techniques. The experimental results show that the proposed MAE variants are more efficient than the counter with cipher block chaining message authentication code (CCM), Galois message authentication code (GMAC), offset codebook mode (OCB), and the Chacha20-poly1305. The best performance is achieved with the third MAE variant that presents a high throughput with an enhancement of at least 373% compared to CCM, 90% compared to GCM, 23% compared to OCB, and 22% compared to Chacha20-poly1305.
Hassan N. Noura, Ola Salman, Raphaël Couturier, Ali Chehab
IEEE Internet Things J.4
2022 Efficient binary diffusion matrix structures for dynamic key-dependent cryptographic algorithms
Hassan N. Noura, Ali Chehab
J. Inf. Secur. Appl.2
2022 Network coding and MPTCP: Enhancing security and performance in an SDN environment
Hassan N. Noura, Reem Melki, Ali Chehab
J. Inf. Secur. Appl.3
2022 Group LARS-Based Iterative Reweighted Least Squares Methodology for Efficient Statistical Modeling of Memory Designs
abstract
Regularized logistic regression is a popular classification tool that can be employed to accurately model the binary nature of the memory cell fail mechanisms for purposes of the yield analysis of memory designs. The iterative reweighted least squares (IRLS) method has been employed along with the least angle regression (LARS) to efficiently solve the$L_{1}$regularized logistic regression problem. In this brief, we propose an efficient$L_{1}$regularized logistic regression methodology. At the core lies a Group LARS-based approach that benefits from Group LARS inherent ability to handle groups of variables and exploits the natural evolution of the solution to speed up the search for the critical features of the classifier. Thus, it tracks Newton’s step direction from one round of the solution to the next and employs weighted directions to efficiently solve for the underlying$L_{1}$constrained iterative least squares problem. We apply the methodology in the context of an importance sampling-based yield analysis framework targeting rare fail probability estimation. We study the yield of 14-nm FinFET SRAM designs with programmable and resonant boosting. Our results demonstrate up to$14\times $–$20\times $speedup for the Group LARS compared to the pure LARS-based approach, and we report 98.7% accuracy and 0.12$\sigma $average error compared to pure circuit-simulations approach for the resulting classifier.
Lama Shaer, Rouwaida Kanj, Rajiv V. Joshi, Ali Chehab
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst.4
2021 Efficient and Robust Keyed Hash Function Based on Artificial Neural Networks
abstract
In this paper, we propose a new dynamic key and message-dependent hash function based on Artificial Neural Networks (ANN) that satisfies the necessary security requirements with low computational complexity. It requires only two rounds of confusion and diffusion operations. Moreover, a dynamic non-invertible construction technique of a synaptic weight matrix is defined in order to ensure the one-way property. The proposed message authentication algorithm is evaluated in terms of desirable cryptographic properties. The results show that the proposed solution is robust due to the dynamic cryptographic primitives approach, which also results in reduced latency and required resources. The initial weight matrix is changed at regular time intervals depending on the application requirements. Recent enhancement in ANN hardware implementations enables the practical application of the proposed solution within wireless and mobile networks.
Hassan N. Noura, Ali Chehab
ISNCC2
2021 Efficient and robust data availability solution for hybrid PLC/RF systems
Hassan N. Noura, Reem Melki, Ali Chehab, Javier Hernandez Fernandez
Comput. Networks3
2021 Efficient data confidentiality scheme for 5G wireless NOMA communications
Hassan N. Noura, Reem Melki, Ali Chehab
J. Inf. Secur. Appl.3
2021 Data representation for CNN based internet traffic classification: a comparative study
Ola Salman, Imad H. Elhajj, Ayman I. Kayssi, Ali Chehab
Multim. Tools Appl.4
2021 Optimal Packet Camouflage Against Traffic Analysis
abstract
Research has proved that supposedly secure encrypted network traffic is actually threatened by privacy and security violations from many aspects. This is mainly due to flow features leaking evidence about user activity and data content. Currently, adversaries can use statistical traffic analysis to create classifiers for network applications and infer users’ sensitive data. In this article, we propose a system that optimally prevents traffic feature leaks. In our first algorithm, we model the packet length probability distribution of the source app to be protected and that of the target app that the source app will resemble. We define a model that mutates the packet lengths of a source app to those lengths from the target app having similar bin probability. This would confuse a classifier by identifying a mutated source app as the target app. In our second obfuscation algorithm, we present an optimized scheme resulting in a trade-off between privacy and complexity overhead. For this reason, we propose a mathematical model for network obfuscation. We formulate analytically the problem of selecting the target app and the length from the target app to mutate to. Then, we propose an algorithm to solve it dynamically. Extensive evaluation of the proposed models, on real app traffic traces, shows significant obfuscation efficiency with relatively acceptable overhead. We were able to reduce a classification accuracy from 91.1% to 0.22% using the first algorithm, with 11.86% padding overhead. The same classification accuracy was reduced to 1.76% with only 0.73% overhead using the second algorithm.
Louma Chaddad, Ali Chehab, Imad H. Elhajj, Ayman I. Kayssi
ACM Trans. Priv. Secur.2
2021 Secure MIMO D2D communication based on a lightweight and robust PLS cipher scheme
Hassan N. Noura, Reem Melki, Rouwaida Kanj, Ali Chehab
Wirel. Networks4
2020 Towards Securing LoRaWAN ABP Communication System
Hassan N. Noura, Ola Salman, Tarif Hatoum, Mohammad Malli, Ali Chehab
CLOSER5
2020 Efficient and Secure Keyed Hash Function Scheme Based on RC4 Stream Cipher
abstract
High number of rounds is needed for the existing message authentication algorithms, such as keyed hash functions like Hash-based Message Authentication Code (HMAC) or block cipher based functions like Cipher-based Message Authentication Code (CMAC) and Galois Message Authentication Code (GMAC). Moreover, the employed compression functions consist of several operations to achieve two main properties: confusion and diffusion. This large number of rounds introduces high overhead for resource-limited systems like Internet of Things (IoT) or delay-sensitive systems that have real-time requirements like Intelligent Transparent Systems. In this paper, a new lightweight message authentication algorithm is proposed to reduce the number of rounds to one. The proposed compression function is based on the RC4 stream cipher to reduce the required overhead in terms of latency and resources. Finally, the security and performance analysis shows that the proposed keyed hash function is resistant towards existing security attacks with low resources overhead.
Hassan N. Noura, Ola Salman, Ali Chehab, Raphaël Couturier
ISCC3
2020 Physical Layer Anti-jamming Technique Using Massive Planar Antenna Arrays
abstract
Wirelessly connected devices play a vital role in people's daily life, especially with the significant rise in the number of devices connected to the Internet and the huge data being generated everyday. However, the open nature of the wireless channels makes them vulnerable to several threats. One of these major threats is jamming attacks which try to disrupt the reception of the useful signal by a receiver. In this paper, we propose a physical layer security anti-jamming method using massive planar antenna arrays. A receiver is assumed to perform anti-jamming against a single jammer trying to degrade the communication link between two parties. A large database of possible antenna array configurations with different radiation patterns is generated. Two methods are proposed for searching through the database. In the first, searching through the database gives the configuration with the deepest null towards the jammer, while in the second, we identify the configuration with the largest maximum to null ratio. The signal-to-interference-plus-noise-ratio is the chosen metric of performance for evaluating the chosen array configurations by both methods. Supporting simulation results validate the effectiveness of the proposed anti-jamming strategy.
Mahdi Chehimi, Elias Yaacoub, Ali Chehab, Mohammed Al-Husseini
IWCMC3
2020 DistLog: A distributed logging scheme for IoT forensics
Hassan N. Noura, Ola Salman, Ali Chehab, Raphaël Couturier
Ad Hoc Networks3
2020 Performance analysis of SDN vs OSPF in diverse network environments
abstract
Summary Network convergence is an important aspect in networks because it can limit the damage resulting from network failures and changes. Consequently, a lot of research considered comparing the performance of different routing protocols, whether in IP or SDN, to assess their convergence speed and reaction to failures. We previously modeled OSPF vs SDN networks in general network deployments and studied their comparative convergence delays for different network conditions. However, the type of network and the architecture choices also affect performance. Consequently in this paper, we model network convergence for two network architectures, datacenters and WANs, to discern the difference in SDN and IP convergence processes and speeds when the network type and characteristics change.
Sarah Abdallah, Ayman I. Kayssi, Imad H. Elhajj, Ali Chehab
Concurr. Comput. Pract. Exp.4
2020 Securing internet of medical things systems: Limitations, issues and recommendations
Jean-Paul A. Yaacoub, Mohamad Noura, Hassan N. Noura, Ola Salman, Elias Yaacoub, Raphaël Couturier, Ali Chehab
Future Gener. Comput. Syst.7
2020 ESSENCE: GPU-based and dynamic key-dependent efficient stream cipher for multimedia contents
Raphaël Couturier, Hassan N. Noura, Ali Chehab
Multim. Tools Appl.3
2020 Efficient & secure image availability and content protection
Hassan N. Noura, Mohamad Noura, Ola Salman, Raphaël Couturier, Ali Chehab
Multim. Tools Appl.5
2020 Physical layer security schemes for MIMO systems: an overview
Reem Melki, Hassan N. Noura, Mohammad M. Mansour, Ali Chehab
Wirel. Networks4
2019 Joint Security and Energy Efficiency in IoT Networks Through Clustering and Bit Flipping
abstract
Channel-aware encryption is investigated as a physical layer security technique in internet of things (IoT) scenarios. Clustering algorithms for grouping sensor nodes into cooperative clusters are proposed, with the purpose of decreasing energy consumption and reducing the transmission time of sensor data. Bit flipping is implemented with the clustering method in order to "encrypt" the transmitted data based on channel state information. The simulation results validate the performance of the proposed approach in terms of reducing energy consumption, reducing transmission time, and of confusing the eavesdropper from guessing the correct transmissions of sensor nodes.
Elias Yaacoub, Ali Chehab, Mohammed Al-Husseini, Khalid Abualsaud, Tamer Khattab, Mohsen Guizani
IWCMC2
2019 Efficient & Secure Physical Layer Cipher Scheme for VLC Systems
abstract
Visible Light Communication (VLC) is a wireless technology that exploits Light Emitting Diodes (LEDs) for both, illumination and data communication. A major challenge is that this system is vulnerable to passive attacks due to the broadcast nature of wireless networks. In this paper, an efficient and lightweight cipher scheme for VLC systems is proposed at the physical layer. Unlike previous schemes in the literature, the proposed one-round scheme utilizes simple substitution and phase shuffling operations to secure the underlying Orthogonal Frequency Division Multiplexing (OFDM) symbols. A dynamic key derivation scheme that benefits from the dynamic properties of VLC channels is also proposed. Experimental simulations and cryptanalysis show that the proposed solution strikes a good balance between performance and security robustness.
Reem Melki, Hassan N. Noura, Ali Chehab
VTC Fall3
2019 Lightweight and Secure D2D Authentication & Key Management Based on PLS
abstract
Device-to-Device (D2D) communication is one of the key components of 4G/5G mobile networks since it enhances network capacity and enables support for public applications. On the other hand, device authentication in D2D is an inherent problem since devices connect and leave the network frequently and freely. Recently, "3rd Generation Partnership Project (3GPP)" has adopted the Authentication Key Agreement (AKA) protocol for 5G New Radio (NR) networks, where the Home Network (HN) first authenticates the User Equipment (UE) and then produces sessions keys. However, in D2D communication, data is directly conveyed between communicating entities (independently from the HN), which makes the AKA protocol not very suited for this technology. In this paper, we propose a new framework based on Physical Layer Security (PLS) that targets device authentication and key establishment in D2D/5G communication systems. The proposed protocol uses common channel characteristics and asymmetric cryptography to ensure legitimate authentication, without relying on the core network. Finally, security and performance analysis are presented to prove the proposed scheme's efficiency and immunity against different types of authentication attacks.
Reem Melki, Hassan N. Noura, Ali Chehab
VTC Fall3
2019 Secure and Lightweight Mutual Multi-Factor Authentication for IoT Communication Systems
abstract
Authentication is critical for any digital system as it represents the first step towards accessing data and resources. Authentication of entities, especially devices in the Internet-of-Things (IoT) system, is one of the most important security challenges that needs to be addressed; otherwise, it will hinder the deployment of IoT applications. The most widely used authentication mechanisms in IoT are based on one-factor cryptographic techniques. These techniques are often not sufficient in the context of IoT due to the limited computational power of IoT devices and the severity of security concerns, especially that these devices are physically not well protected. Consequently, any weakness in the identification/authentication schemes would allow a compromised entity to perform dangerous attacks. To overcome the above-mentioned limitations and achieve high authentication accuracy, we propose an efficient two-factor lightweight mutual authentication scheme for IoT entities, which can be deployed at various levels; device, control, aggregation node, gateway, and server. The first factor is based on a cryptographic protocol which employs a configurable Physically Unclonable Function (PUF) along with a nonce extracted from the physical channel. The second factor is an entity-based fingerprint that uses specific information (i.e., features that can be extracted from various layers of the communication protocol) to construct a unique fingerprint for each entity. The proposed scheme is designed to require the minimum possible overhead in terms of computation and communication overhead, and ensure maximum security resilience against authentication attacks.
Hassan N. Noura, Reem Melki, Ali Chehab
VTC Fall3
2019 An Efficient and Secure Variant of RC4 Stream Cipher Scheme for Emerging Networks
abstract
Data Confidentiality (DC) is considered one of the most important security services. Currently, a set of existing cipher algorithms is being used to ensure DC. However still, designing and implementing a more efficient cipher scheme is always being sought. Moreover, various vulnerabilities are constantly being targeted by new kinds of attacks such as the physical ones. In addition, some cipher algorithms exhibit limitations in terms of latency and required resources, and hence cannot be preferred to constrained devices. This leads to a trade-off between system performance and security level. Towards solving these challenges, we propose a lightweight cipher scheme that ensures a high level of security with minimal latency and resource requirements compared to existing standards such as AES. Specifically, the proposed cipher scheme is based on the original RC4 but adapted and extended by introducing two different round functions that consist of substitutions, addition, and non-invertible diffusion operations to achieve the aforementioned goals. Experimental results indicate that the proposed cipher is a strong and promising stream cipher candidate that has high key sensitivity, high randomness degree, as well as periodicity properties.
Hassan N. Noura, Ali Chehab
WCNC2
2019 Lightweight Dynamic Key-Dependent and Flexible Cipher Scheme for IoT Devices
abstract
Security attacks against Internet of Things (IoT) are on the rise and they lead to drastic consequences. Data confidentiality is typically based on a strong symmetric-key algorithm to guard against confidentiality attacks. However, there is a need to design an efficient lightweight cipher scheme for a number of applications for IoT systems. Recently, a set of lightweight cryptographic algorithms have been presented and they are based on the dynamic key approach, requiring a small number of rounds to minimize the computation and resource overhead, without degrading the security level. This paper follows this logic and provides a new flexible lightweight cipher, with or without chaining operation mode, with a simple round function and a dynamic key for each input message. Consequently, the proposed cipher scheme can be utilized for real-time applications and/or devices with limited resources such as Multimedia Internet of Things (MIoT) systems. The importance of the proposed solution is that it produces dynamic cryptographic primitives and it performs the mixing of selected blocks in a dynamic pseudo-random manner. Accordingly, different plaintext messages are encrypted differently, and the avalanche effect is also preserved. Finally, security and performance analysis are presented to validate the efficiency and robustness of the proposed cipher variants.
Hassan N. Noura, Ali Chehab, Raphaël Couturier
WCNC2
2019 Lightweight Stream Cipher Scheme for Resource-Constrained IoT Devices
abstract
The Internet of Things (IoT) systems are vulnerable to many security threats that may have drastic impacts. Existing cryptographic solutions do not cater for the limitations of resource-constrained IoT devices, nor for real-time requirements of some IoT applications. Therefore, it is essential to design new efficient cipher schemes with low overhead in terms of delay and resource requirements. In this paper, we propose a lightweight stream cipher scheme, which is based, on one hand, on the dynamic key-dependent approach to achieve a high security level, and on the other hand, the scheme involves few simple operations to minimize the overhead. In our approach, cryptographic primitives change in a dynamic lightweight manner for each input block. Security and performance study as well as experimentation are performed to validate that the proposed cipher achieves a high level of efficiency and robustness, making it suitable for resource-constrained IoT devices.
Hassan N. Noura, Raphaël Couturier, CongDuc Pham, Ali Chehab
WiMob4
2019 Preserving data security in distributed fog computing
Hassan N. Noura, Ola Salman, Ali Chehab, Raphaël Couturier
Ad Hoc Networks3
2019 Design and realization of efficient & secure multi-homed systems based on random linear network coding
Hassan N. Noura, Reem Melki, Mohammad M. Mansour, Ali Chehab
Comput. Networks4
2019 Crowdsourcing for click fraud detection
abstract
Mobile ads are plagued with fraudulent clicks which is a major challenge for the advertising community. Although popular ad networks use many techniques to detect click fraud, they do not protect the client from possible collusion between publishers and ad networks. In addition, ad networks are not able to monitor the user’s activity for click fraud detection once they are redirected to the advertising site after clicking the ad. We propose a new crowdsource-based system called Click Fraud Crowdsourcing (CFC) that collaborates with both advertisers and ad networks in order to protect both parties from any possible click fraudulent acts. The system benefits from both a global view, where it gathers multiple ad requests corresponding to different ad network-publisher-advertiser combinations, and a local view, where it is able to track the users’ engagement in each advertising website. The results demonstrated that our approach offers a lower false positive rate (0.1) when detecting click fraud as opposed to proposed solutions in the literature, while maintaining a high true positive rate (0.9). Furthermore, we propose a new mobile ad charging model that benefits from our system to charge advertisers based on the duration spent in the advertiser’s website.
Riwa Mouawi, Imad H. Elhajj, Ali Chehab, Ayman I. Kayssi
EURASIP J. Inf. Secur.3
2019 An Efficient OFDM-Based Encryption Scheme Using a Dynamic Key Approach
abstract
Physical layer (PHY) security has emerged as a promising methodology for securing current and future networks that employ orthogonal frequency-division multiplexing (OFDM) technology. OFDM is the basic building block for multicarrier modulation in most contemporary networks such as vehicular ad hoc networks, Internet of Things (IoT), as well as 4G/5G systems. Most existing OFDM-based security solutions lack the notion of secrecy and dynamicity when combining a secret key with random information extracted from the physical channel. Yet, some solutions perform encryption preinverse fast Fourier transform and some postinverse fast Fourier transform, without clear guidelines concerning the impact on performance and security. In this paper, OFDM-based encryption schemes at the PHY are investigated, analyzed, and weaknesses are identified. It is shown that encryption in the frequency domain slightly mitigates the effects of channel fading and improves the bit error-rate performance. On the other hand, time-domain encryption is shown to be more secure. Furthermore, a dynamic secret key approach that enhances the security level of OFDM-based encryption schemes, in addition to a new technique for updating cipher primitives for input OFDM symbols or frames, are proposed. These schemes are shown to strike a good balance between performance and security robustness as demonstrated through experimental simulations.
Reem Melki, Hassan N. Noura, Mohammad M. Mansour, Ali Chehab
IEEE Internet Things J.4
2019 A Physical Encryption Scheme for Low-Power Wireless M2M Devices: a Dynamic Key Approach
Hassan N. Noura, Reem Melki, Ali Chehab, Mohammad M. Mansour
Mob. Networks Appl.3
2019 Lightweight, dynamic and efficient image encryption scheme
Hassan N. Noura, Ali Chehab, Mohamad Noura, Raphaël Couturier, Mohammad M. Mansour
Multim. Tools Appl.2
2019 Efficient and secure cipher scheme for multimedia contents
Hassan N. Noura, Mohamad Noura, Ali Chehab, Mohammad M. Mansour, Raphaël Couturier
Multim. Tools Appl.3
2019 Efficient & secure cipher scheme with dynamic key-dependent mode of operation
Hassan N. Noura, Ali Chehab, Raphaël Couturier
Signal Process. Image Commun.2
2018 Adaptive Optimization for Hybrid Network Control Planes
abstract
Hybrid Networks, defined as networks that include both SDN and IP nodes, were considered as a natural consequence of the incremental deployment of SDN in the current all-IP world. However, under some circumstances, the centralized control plane of SDN offers advantages over the traditional distributed one. This drove our work as we design a hybrid network in which each node adaptively switches its control state between centralized and distributed given the prevailing network conditions. The proposed optimization problem delivered the expected network behavior; the network was fully centralized when conditions were favorable for full centralization, and it was fully distributed when conditions favored full distributivity. For random conditions, we were able to capture the behavior of network nodes with time and with different decision thresholds.
Sarah Abdallah, Ayman I. Kayssi, Imad H. Elhajj, Ali Chehab
AICCSA4
2018 Channel-Punctured Large MIMO Detection
abstract
Low-complexity data detectors targeted for large multiple-input multiple-output (MIMO) systems are considered. By systematically puncturing the channel matrix to have a specific structure, the complexity of standard non-linear detectors can be significantly reduced. The performance of these detectors is characterized and analyzed mathematically, and bounds on the achievable diversity gain and probability of bit error are derived. It is shown that puncturing does not negatively impact the receive diversity gain in hard-output detectors. Moreover, in soft-output detection, significant performance gains are attainable by ordering the layer of interest to be at the root when puncturing the channel. The proposed schemes scale up efficiently both in the number of antennas and constellation size.
Hadi Sarieddeen, Mohammad M. Mansour, Ali Chehab
ISIT3
2018 Efficient and Secure Physical Encryption Scheme for Low-Power Wireless M2M Devices
abstract
Recently, physical layer security has emerged as a promising security scheme for wireless networks, in contrast to traditional solutions that mainly rely on upper network layers. As such, several physical layer encryption algorithms that benefit from the random characteristics of physical channels have appeared in the literature. However, the majority of these schemes lack the notion of secrecy and dynamicity. In this paper, we focus on enhancing the physical layer encryption for wireless machine-to-machine devices, which share the same channel, with the aim of striking a good balance between performance and security robustness. The main idea is to perform encryption at the physical layer after symbol modulation. The cipher scheme is based on one round and one operation that reduces the encryption overhead in terms of latency and required resources. Furthermore, we propose a dynamic key approach that combines a pre-shared/stored secret key with a dynamic nonce extracted from the channel information to generate a dynamic key. The main advantage of the dynamic key approach is that it achieves a high-security level with minimal overhead. The dynamic key can be changed frequently upon any change in channel parameters or upon starting a new session. In addition to data encryption, a preamble encryption scheme is also proposed to prevent unauthorized synchronization or channel estimation by illegitimate users. Finally, security and performance analyses are performed to demonstrate the validity, efficiency and robustness of the proposed approach.
Hassan N. Noura, Reem Melki, Ali Chehab, Mohammad M. Mansour, Steven Martin 0001
IWCMC3
2018 Joint channel allocation and power control for D2D communications using stochastic geometry
abstract
Device-to-Device (D2D) communication is a viable network technology that can potentially enhance the spectral and energy efficiency of cellular networks. To exploit this benefit in D2D-underlaid cellular networks, the co-channel interference between D2D and cellular users should be properly managed. In this paper, we propose a joint channel allocation (CA) and power control (PC) scheme to mitigate interference in a D2D underlaid cellular system modeled as a random network using stochastic geometry. The novel aspect of the proposed CA scheme is that it enables D2D links to share resources with multiple cellular users as opposed to one as previously considered in the literature. The PC scheme compensates for large-scale path-loss effects by employing distance-dependent path-loss parameters with an estimation error margin. Closed-form expressions for the coverage probability of cellular links, D2D links, and the sum rate of the D2D links are derived in terms of the allocated power, density of the D2D links, and the path-loss exponent. Simulation results demonstrate an enhancement of 10%-40% for the cellular and D2D coverage probabilities, and 35% for spectral efficiency.
Asmaa Abdallah, Mohammad M. Mansour, Ali Chehab
WCNC3
2018 A fairness-based congestion control algorithm for multipath TCP
abstract
Multipath TCP (MP-TCP) has been introduced as an extension to the legacy TCP transport protocol to support communication through multiple paths under a single connection session. The target is to improve both resource utilization and connection robustness. Several congestion control algorithms (CCAs) have emerged in the literature to adapt subflow rates to congestion conditions on the various paths without negatively impacting competing single-path TCP sources. The challenge is to provide a trade-off among three factors, namely, fairness, responsiveness, and window oscillation. In this paper, we propose a new fairness-based CCA (FCCA) based on the fluid model that improves fairness without degrading the other two metrics. The FCCA tracks the performance on each route and dynamically adapts the respective congestion windows, enhancing the overall performance. The proposed algorithm is implemented in a Linux kernel. Simulation results demonstrate that FCCA is capable of achieving almost maximal fairness (98%) while maintaining responsiveness, unlike existing CCAs.
Reem Melki, Mohammad M. Mansour, Ali Chehab
WCNC3
2018 IoT survey: An SDN and fog computing perspective
Ola Salman, Imad H. Elhajj, Ali Chehab, Ayman I. Kayssi
Comput. Networks3
2018 Mobile Apps identification based on network flows
Georgi A. Ajaeiya, Imad H. Elhajj, Ali Chehab, Ayman I. Kayssi, Marc Kneppers
Knowl. Inf. Syst.3
2018 One round cipher algorithm for multimedia IoT devices
Hassan N. Noura, Ali Chehab, Lama Sleem, Mohamad Noura, Raphaël Couturier, Mohammad M. Mansour
Multim. Tools Appl.2
2018 A dynamic approach for a lightweight and secure cipher for medical images
Mohamad Noura, Hassan N. Noura, Ali Chehab, Mohammad M. Mansour, Lama Sleem, Raphaël Couturier
Multim. Tools Appl.3
2018 A new efficient lightweight and secure image cipher scheme
Hassan N. Noura, Lama Sleem, Mohamad Noura, Mohammad M. Mansour, Ali Chehab, Raphaël Couturier
Multim. Tools Appl.5
2018 Network Programming and Probabilistic Sketching for Securing the Data Plane
abstract
This paper presents VISKA, a cloud security service for dynamically detecting malicious switching elements in software defined networking (SDN) infrastructures. The main contributions of VISKA lie in (1) utilizing network programming and secure probabilistic sketching in SDN environments to dynamically detect and isolate parts of the data plane that experience malicious behavior, (2) applying a set of focused packet probing and sketching mechanisms on isolated network partitions/views rather than focusing the security mechanisms on the whole physical network, (3) efficiently analyzing the network behavior of the resulting views by recursively partitioning them in a divide-and-conquer fashion to logarithmically reduce the problem size in order to localize abnormal/malicious switching units, and (4) providing an attack categorization module that analyzes live ingress/egress traffic of the maliciously detected switch(es) solely to identify the specific type of attack, rather than inspecting the whole network traffic as is done in traditional intrusion detection systems. This significantly enhances the performance of attack detection and reduces the load on the controller. A testbed prototype implementation is realized on the Mininet network emulator. The experimental analysis corroborated the algorithms’ convergence property using the linear and FatTree topologies with network sizes of up to 250 switches. Moreover, an implementation of the attack categorization module is realized and achieved an accuracy rate of over 90% for the different attack types supported.
Maha Shamseddine, Wassim Itani, Ali Chehab, Ayman I. Kayssi
Secur. Commun. Networks3
2018 Power Control and Channel Allocation for D2D Underlaid Cellular Networks
abstract
Device-to-Device (D2D) communications underlaying cellular networks is a viable network technology that can potentially increase spectral utilization and improve power efficiency for proximity-based wireless applications and services. However, a major challenge in such deployment scenarios is the interference caused by D2D links when sharing the same resources with cellular users. In this paper, we propose a channel allocation (CA) scheme together with a set of three power control (PC) schemes to mitigate interference in a D2D underlaid cellular system modeled as a random network using the mathematical tool of stochastic geometry. The novel aspect of the proposed CA scheme is that it enables D2D links to share resources with multiple cellular users as opposed to one as previously considered in the literature. Moreover, the accompanying distributed PC schemes further manage interference during link establishment and maintenance. The first two PC schemes compensate for large-scale path-loss effects and maximize the D2D sum rate by employing distance-dependent path-loss parameters of the D2D link and the base station, including an error estimation margin. The third scheme is an adaptive PC scheme based on a variable target signal-to-interference-plus-noise ratio, which limits the interference caused by D2D users and provides sufficient coverage probability for cellular users. Closed-form expressions for the coverage probability of cellular links, D2D links, and sum rate of D2D links are derived in terms of the allocated power, density of D2D links, and path-loss exponent. The impact of these key system parameters on network performance is analyzed and compared with previous work. Simulation results demonstrate an enhancement in cellular and D2D coverage probabilities, and an increase in spectral and power efficiency.
Asmaa Abdallah, Mohammad M. Mansour, Ali Chehab
IEEE Trans. Commun.3
2018 Large MIMO Detection Schemes Based on Channel Puncturing: Performance and Complexity Analysis
abstract
A family of low-complexity detection schemes based on channel matrix puncturing targeted for large multiple-input multiple-output (MIMO) systems is proposed. It is well known that the computational cost of MIMO detection based on QR decomposition is directly proportional to the number of nonzero entries involved in back-substitution and slicing operations in the triangularized channel matrix, which can be too high for low-latency applications involving large MIMO dimensions. By systematically puncturing the channel to have a specific structure, it is demonstrated that the detection process can be accelerated by employing standard schemes, such as chase detection, list detection, nulling-and-cancellation detection, and sub-space detection on the transformed matrix. The performance of these schemes is characterized and analyzed mathematically, and bounds on the achievable diversity gain and probability of bit error are derived. Surprisingly, it is shown that puncturing does not negatively impact the receive diversity gain in hard-output detectors. The analysis is extended to soft-output detection when computing per-layer bit log-likelihood ratios; it is shown that significant performance gains are attainable by ordering the layer of interest to be at the root when puncturing the channel. Simulations of coded and uncoded scenarios certify that the proposed schemes scale up efficiently both in the number of antennas and constellation size, as well as in the presence of correlated channels. In particular, soft-output per-layer sub-space detection is shown to achieve a 2.5 dB signal-to-noise ratio gain at 10-4bit error rate in 256-quadratic-amplitude modulation 16 × 16 MIMO, while saving 77% of nulling-and-cancellation computations.
Hadi Sarieddeen, Mohammad M. Mansour, Ali Chehab
IEEE Trans. Commun.3
2017 SDN for MPTCP: An enhanced architecture for large data transfers in datacenters
abstract
Multi-Path TCP (MPTCP) boosts network performance of applications by aggregating bandwidth over multiple paths using sub-flows of the same TCP connection. However, MPTCP suffers from three limitations: (1) it is an end-to-end protocol with no control over the network routes, and sub-flows might end up traversing the same links, (2) it has no dynamic control over choosing the optimal number of sub-flows to achieve maximum throughput, (3) its performance may degrade due to the large number of out-of-order caused by the heterogeneous paths traversed. Software Defined Networking (SDN), being centralized by nature, provides a global view of the network. When integrated with MPTCP, SDN improves resource utilization as we show in this paper. We propose an SDN-enhanced MPTCP that achieves higher data rates while transferring big-data in large-scale L2 networks such as those found in datacenters. Test results show a 20% to 30% increase in the throughput over regular MPTCP.
Ali Hussein, Imad H. Elhajj, Ali Chehab, Ayman I. Kayssi
ICC3
2017 Virtualized network views for localizing misbehaving sources in SDN data planes
abstract
In this paper, we present VISKA, a Cloud security service for detecting malicious switching elements in software defined networking (SDN) environments. VISKA leverages network virtualization and secure probabilistic sketching to isolate misbehaving switches in the underlying SDN network data plane. The main contribution lies in utilizing network virtualization in SDN environments to dynamically isolate parts of the data plane and check their forwarding behavior. This is achieved by applying a set of focused packet probing and sketching mechanisms on virtualized network views mapped to these data plane partitions instead of focusing the security mechanisms on the whole physical network. VISKA flexibly analyzes the network behavior of the granular virtual views and recursively partitions these views to reduce the problem size in order to localize abnormal/malicious network switching units. A test bed prototype implementation is realized on the OpenVirtex SDN network virtualization platform. The experimental analysis corroborated the algorithm's convergence property using the linear and FatTree topologies with SDN network sizes of up to 250 switching units.
Maha Shamseddine, Wassim Itani, Ayman I. Kayssi, Ali Chehab
ICC4
2017 Flow-based Intrusion Detection System for SDN
abstract
Software-defined networks (SDN) are vulnerable to most of the attacks that traditional networks are vulnerable to. In addition, SDN has introduced new vulnerabilities through its unique architecture such as those related to the southbound and northbound controller interfaces. In this paper, we introduce a lightweight flow-based Intrusion Detection System (IDS) that periodically gathers statistical information about flows from SDN OpenFlow switches, and analyzes traffic information by extracting and aggregating a set of features. The proposed IDS system proved to be accurate with a high detection rate at 0.98 measured by the F1 score of the classification model and a relatively low false alarm rate.
Georgi A. Ajaeiya, Nareg Adalian, Imad H. Elhajj, Ayman I. Kayssi, Ali Chehab
ISCC5
2017 Hard-output chase detectors for large MIMO: BER performance and complexity analysis
abstract
In this paper, a family of cost-efficient hard-output detection algorithms for large multiple-input multiple-output (MIMO) systems is proposed. The schemes employ punctured QR decomposition (QRD) instead of regular QRD to reduce complexity. The bit error rate performance is studied analytically, where it is shown that channel matrix puncturing does not affect the diversity gain of the detectors. Through empirical simulations, the proposed schemes are shown to achieve significant reductions in computational complexity with graceful performance degradation. In particular, at an SNR cost of 4dB, 77% of complex multiplications in nulling and cancellation are saved in 16 × 16 MIMO, while 30% of multiplications are saved at a 2dB cost in 4×4 MIMO. The savings can reach 94% in 64×64 MIMO.
Hadi Sarieddeen, Mohammad M. Mansour, Ali Chehab
PIMRC3
2017 A Distance-Based Power Control Scheme for D2D Communications Using Stochastic Geometry
abstract
Device-to-Device (D2D) communication is a promising technology that can potentially enhance the spectral and energy efficiency of cellular networks. To exploit this benefit in D2D-underlaid cellular networks, the co-channel interference between D2D and cellular users should be properly managed. In this paper, we propose a distributed power control scheme to mitigate interference in a D2D underlaid cellular system modeled as a random network using the mathematical tool of stochastic geometry. The proposed PC scheme compensates for large-scale path-loss effects by employing distance-dependent path-loss parameters of the D2D link and the base station, including an estimation error margin. Closed-form expressions for the coverage probability of cellular links, D2D links, and the sum rate of D2D links are derived in terms of the allocated power, density of D2D links, and path-loss exponent. The coverage performance of both cellular and D2D users is analyzed, and the analytical results are validated through simulations. Experimental results demonstrate the efficacy and advantages of our proposed scheme over other schemes by an enhancement of 20%-30% for the cellular and D2D coverage probabilities, and an increase in spectral efficiency by 60%.
Asmaa Abdallah, Mohammad M. Mansour, Ali Chehab
VTC Fall3
2017 A privacy-enhanced computationally-efficient and comprehensive LTE-AKA
Khodor Hamandi, Jacques Bou Abdo, Imad H. Elhajj, Ayman I. Kayssi, Ali Chehab
Comput. Commun.5
2016 Interlaced Column-Row Message-Passing Schedule for Decoding LDPC Codes
abstract
This paper investigates efficient decoding algorithms for LDPC codes. Alternating column-row message-passing (ACRMP) and Interlaced column-row message-passing (I-CRMP) schedules for decoding of LDPC codes are proposed and investigated in this work. Existing serial scheduling schemes for LDPC decoding are based either on column message-passing (MP) or row MP, and roughly converge twice as fast as Gallager's flooding-based MP schedule at high signal-to-noise ratio (SNR). To further accelerate the convergence speed of serial decoders, hybrid column-row MP schedules that perform multiple message passes between check and variable nodes within or between iterations are proposed. Our proposed I-CRMP schedule converges in less than half the number of iterations compared to the best existing serial decoding schedules. Compared to column MP, the added complexity of this scheme is proportional only to check-node-degree times more additions at variable nodes. This increase in complexity is moderate compared to the convergence acceleration factor that the scheme achieves. Superior performance of the proposed I-CRMP scheme is confirmed by decoding randomly generated as well as IEEE 802.11n/ac LDPC codes.
Saleh Usman, Mohammad M. Mansour, Ali Chehab
GLOBECOM3
2016 Efficient subspace detection for high-order MIMO systems
abstract
In this paper, low-complexity multiple-input multiple-output (MIMO) subspace detection schemes are studied, which decompose a channel into multiple decoupled streams to be detected disjointly. Existing schemes require a number of matrix decomposition operations equal to the number of detected streams, which is computationally complex, especially in high-order MIMO systems. We propose two computationally efficient detection algorithms, based on a preprocessing stage that consists of special layer ordering, followed by permutation-robust QR decomposition (QRD) and elementary matrix operations. The algorithms are illustrated in the context of a 4-layer MIMO system, and their complexity is studied. Simulations demonstrate that using the proposed scheme, the QRD overhead is reduced by almost 50% for very high order MIMO, without incurring any performance degradation.
Hadi Sarieddeen, Mohammad M. Mansour, Ali Chehab
ICASSP3
2016 Efficient near optimal joint modulation classification and detection for MU-MIMO systems
abstract
Optimum data detection schemes for dual layer multi-user multiple-input multiple-output (MU-MIMO) systems are studied. A joint maximum likelihood (ML) modulation classification (MC) of the co-scheduled user and data detection receiver is developed. By expanding the max-log-maximum-a-posteriori MC approach to include distances of counter ML hypothesis symbols, the decision metric for MC is shown to be an accumulation over a set of tones of Euclidean distance computations also used by the ML detector for bit log-likelihood ratio soft decision generation. With a small complexity overhead, the proposed approach achieves near-optimal performance. An efficient hardware architecture is presented for the proposed approach.
Hadi Sarieddeen, Mohammad M. Mansour, Louay M. A. Jalloul, Ali Chehab
ICASSP4
2016 SDN verification plane for consistency establishment
abstract
Software Defined Networking (SDN) is the new promise towards an easily configured and centrally controlled network. Based on this centralized control, SDN technology has proved its positive impact in the world of network communications from different aspects. Consistency in SDN, as in any rule-based network, is an essential feature that every communication system should possess. In this paper, we propose an SDN verification layer based on formal techniques to establish flow consistency between SDN switches before the flow insertion process takes place. We show how such an approach can be used to prevent loopbacks, deadlocks, security domain breaches, and to verify the time delay for a controller to update a switch versus the switch to forward a packet. This last point ensures that the update process is synchronized and no packet would be checked against old rules during this update process. The solution lies in introducing a verification plane enabling our verification module to interact with a third party verification tool (UPPAAL) translating the controller's view of the network to a state machine and verifying each flow before being installed. The verification tool checks each flow against a predefined set of rules by applying the new flow to the scheme and testing if a packet can pass from point A to B without violating these rules. Our evaluation shows the capability of the proposed system to enforce different levels of consistency verification in case of flow update and topology change in a SDN network.
Ali Hussein, Imad H. Elhajj, Ali Chehab, Ayman I. Kayssi
ISCC3
2016 Identity-based authentication scheme for the Internet of Things
abstract
Security and privacy are among the most pressing concerns that have evolved with the Internet. As networks expanded and became more open, security practices shifted to ensure protection of the ever growing Internet, its users, and data. Today, the Internet of Things (IoT) is emerging as a new type of network that connects everything to everyone, everywhere. Consequently, the margin of tolerance for security and privacy becomes narrower because a breach may lead to large-scale irreversible damage. One feature that helps alleviate the security concerns is authentication. While different authentication schemes are used in vertical network silos, a common identity and authentication scheme is needed to address the heterogeneity in IoT and to integrate the different protocols present in IoT. We propose in this paper an identity-based authentication scheme for heterogeneous IoT. The correctness of the proposed scheme is tested with the AVISPA tool and results showed that our scheme is immune to masquerade, man-in-the-middle, and replay attacks.
Ola Salman, Sarah Abdallah, Imad H. Elhajj, Ali Chehab, Ayman I. Kayssi
ISCC4
2016 Efficient near-optimal 8×8 MIMO detector
abstract
In this paper, a low-complexity near-optimal detector for 8-layer MIMO systems is proposed. The detector employs subspace detection schemes, which decompose a spacially multiplexed MIMO channel into multiple decoupled streams to be detected separately. Several existing subspace detection algorithms are studied, all of which require a significant overhead for channel matrix decomposition. We propose computationally efficient schemes based on special layer ordering, followed by permutation-robust QR Decomposition (PR-QRD) using the modified Gram-Schmidt orthogonalization procedure, and elementary matrix operations. A hardware architecture is proposed, which allows building an 8-layer detector from 4-layer and 2-layer constituent detector blocks. Simulations demonstrate that using the proposed scheme, the QRD overhead is reduced by 30%, without incurring any performance degradation.
Hadi Sarieddeen, Mohammad M. Mansour, Ali Chehab
WCNC3
2016 Low-complexity joint modulation classification and detection in MU-MIMO
abstract
In this paper, dual-layer multi-user multiple-input multiple-output systems are studied. Building on the low-complexity layered orthogonal lattice detector (LC-LORD), an efficient sub-optimal joint modulation classification (MC) of the co-scheduled user and data detection receiver is developed. By adjusting the Max-Log-Maximum-a-Posteriori MC approach to the limitations of LC-LORD, and expanding it to include distances of counter maximum likelihood hypothesis symbols, the decision metric for MC is shown to be an accumulation over a set of tones of Euclidean distance computations also used by the LC-LORD detector for bit log-likelihood ratio soft decision generation. Simulations demonstrate that with a small complexity overhead, the proposed approaches achieve near interference-aware performance. An efficient hardware implementation scheme is presented.
Hadi Sarieddeen, Mohammad M. Mansour, Louay M. A. Jalloul, Ali Chehab
WCNC4
2015 An architecture for the Internet of Things with decentralized data and centralized control
abstract
Internet of Things (IoT) is considered to be the Internet of the future. Thus, a lot of effort is being invested in finding the best design for a global IoT architecture. Recently, Software-Defined Networking (SDN) surfaced as a new networking paradigm that aims to centralize the network control and to separate the control and the data planes. Thus, one can benefit from SDN to abstract the major management complexities residing in this ubiquitous network of networks. Therefore, dealing with the huge amount of generated data in such network will be a major challenge; so, adopting advanced data technologies (cloud and fog computing) will be essential for the new architecture. In this paper, we review work done concerning the application of SDN to the IoT. Also, we propose and analyze a new SDN-based IoT architecture characterized by the centralization of the network control and the decentralization of the data management.
Ola Salman, Imad H. Elhajj, Ayman I. Kayssi, Ali Chehab
AICCSA4
2015 Comparison of in-app ads traffic in different ad networks
abstract
Mobile advertising using in-app ads has increased in popularity along with the substantial number of current free mobile applications and games in the app stores. This relatively new type of advertising has raised several concerns during the past few years, such as the battery consumption that it entails and the network traffic overhead that it consumes to download the ads. While several efforts revealed key observations regarding ads-related energy and bandwidth consumption, they did not compare these two types of consumptions among different ad networks. Unlike some previous work that just mentioned the ad networks associated with the tested apps, our work evaluates bandwidth and energy consumption and compares them among several popular ad networks that support ads for Android applications. The experimental procedure followed in this study demonstrated that resource consumption varies significantly among networks based on our statistical tests. In addition, this study highlights a common behavior when fetching ads, where ads are fetched at the beginning of app runtime and displayed throughout the application session.
Riwa Mouawi, Imad H. Elhajj, Ali Chehab, Ayman I. Kayssi
WiMob3
2014 3G to Wi-Fi offloading on Android
abstract
In this paper, we propose a 3G to Wi-Fi offloading Android-based application. Due to growing demand for a high-speed mobile data connection around the clock, 3G networks begin to face high congestion levels rendering the mobile service providers unable to meet customer expectations. Despite the existence of various solutions, offloading to Wi-Fi proves to be an optimal one as it takes advantage of the resources that Wi-Fi offers in terms of availability and bandwidth. The proposed application measures the download speed of an online page on both Wi-Fi and 3G networks simultaneously. After comparing the results, the device gets switched to the best network. This enables operators to manage their networks more adequately and to improve users experience.
Khaled Bakhit, Chantal Chalouhi, Sabine Francis, Sara Mourad, Imad H. Elhajj, Ayman I. Kayssi, Ali Chehab
AICCSA7
2014 DAGGER: Distributed architecture for granular mitigation of mobile based attacks
abstract
In this paper, we present DAGGER, a distributed architecture for collaborating mobile hosts and telecom operators for the granular mitigation of mobile-based attacks. Due to the growing usage of network resources by mobile handsets and the increasing spread of malicious applications among those handsets, it has become vital for mobile operators to join the fight against mobile-based attacks in order to protect their resources and infrastructure. Several security solutions are available in the market for telecom operators to detect anomalies. DAGGER extends those solutions and enables the operators to not only detect the subscriber(s) that generated anomalies, but also to granularly identify the malicious applications behind those abnormalities, allowing the operators to terminate the malwares themselves rather than shutdown the network connection for the mobile subscriber(s). We present an Android host-based component and define the distributed host-network communication procedure in order to identify malicious applications causing network anomalies and thus to terminate such applications.
Khaled Bakhit, Imad H. Elhajj, Ali Chehab, Ayman I. Kayssi
AICCSA3
2014 Smartphone sensors as random bit generators
abstract
Finding good entropy sources, designing deterministic (pseudo) random number generators, or simply finding suitable non-deterministic random number generators are major challenges. The goal of this paper is to evaluate the use of three motion sensors present in smartphones as potential nondeterministic, true random bit generators (TRNG). This paper focuses in particular on sensors present in Samsung Galaxy S3 and S4 devices. Data from the sensors was collected and submitted to the NIST STS v-2.1.1 test suite and the resulting bits were found fit enough to be used as the output of a TRNG. In addition, 4 SHA versions were used to whiten the data (as per NIST recommendation). Their conditioning performance was compared to each other, and found to be very close.
Joseph Loutfi, Ali Chehab, Imad H. Elhajj, Ayman I. Kayssi
AICCSA2
2014 CrowdApp: Crowdsourcing for application rating
abstract
One of the main concerns for application developers is user satisfaction. Before installing any application from an app market, users first look at the app rating and the number of times it was downloaded. However, ratings are not made by experts, are subjective, and require user involvement; therefore, a large number of reviews are needed before the ratings become statistically reliable. One way to obtain user input transparently is to collect data from devices through crowdsourcing. In this work, we present CrowdApp, a crowdsourcing-based application that continuously runs in the background and collects data from the device without any active user participation (transparent crowdsourcing). Then it computes a score for every app installed on the device. The application was tested on Android. Our results show that there is a high correlation (> 0.8) between CrowdApp scores and Google Play scores. More importantly, CrowdApp scores also agreed with subjective ratings by the users themselves at the end of the experiment period.
Farah Saab, Imad H. Elhajj, Ali Chehab, Ayman I. Kayssi
AICCSA3
2014 Mobile malware exposed
abstract
In this paper, we propose a new method to detect malicious activities on mobile devices by examining an application's runtime behavior. To this end, we use the Xposed framework to build a monitoring module that generates behavior profiles for applications. The module integrates with our intrusion detection system which then analyzes and reports on the profiles. We use this tool to detect malicious behavior patterns using both a custom-written malware and a real one. We also detect behavior patterns for some popular applications from the Google Play Store to expose their functionality. The results show that standard techniques that are used to evade static analysis are not effective against our monitoring approach. This approach can also be generalized to detect unknown malware or expose exact application behavior to the user.
Alaa Salman, Imad H. Elhajj, Ali Chehab, Ayman I. Kayssi
AICCSA3
2014 Application-Aware Fast Dormancy in LTE
abstract
Two Radio Resource Control states have been proposed in LTE and implemented to ensure low UE power consumption and high network resource availability. Transiting between these two states optimizes network performance if tuned properly. Currently, a UE switches from the LTE_ACTIVE state to the LTE_IDLE state after a pre-configured static inactivity duration. This paper seeks to demonstrate that no static timeout is optimal for all users at all times. In addition, a user-level dynamic decision algorithm is proposed to have fine-grain user level optimization. Since achieving better efficiency is related to context awareness, we present a solution that allows the UE to auto-learn its traffic behavior. The dynamic algorithm was applied to five different user load scenarios of combined application and legacy traffic, and the results showed that we are able to attain power savings of up to 30% when compared to the fixed timeout case.
Jacques Bou Abdo, Imad Sarji, Imad H. Elhajj, Ali Chehab, Ayman I. Kayssi
AINA4
2014 IP Spoofing Detection Using Modified Hop Count
abstract
With the global widespread usage of the Internet, more and more cyber-attacks are being performed. Many of these attacks utilize IP address spoofing. This paper describes IP spoofing attacks and the proposed methods currently available to detect or prevent them. In addition, it presents a statistical analysis of the Hop Count parameter used in our proposed IP spoofing detection algorithm. We propose an algorithm, inspired by the Hop Count Filtering (HCF) technique, that changes the learning phase of HCF to include all the possible available Hop Count values. Compared to the original HCF method and its variants, our proposed method increases the true positive rate by at least 9% and consequently increases the overall accuracy of an intrusion detection system by at least 9%. Our proposed method performs in general better than HCF method and its variants.
Ayman Mukaddam, Imad H. Elhajj, Ayman I. Kayssi, Ali Chehab
AINA4
2014 ALPS: The Accountable Cloud Protocol Stack
Wassim Itani, Ayman I. Kayssi, Ali Chehab
CLOSER3
2014 Fast dynamic internet mapping
Mehiar Dabbagh, Naoum Sayegh, Ayman I. Kayssi, Imad H. Elhajj, Ali Chehab
Future Gener. Comput. Syst.5
2014 ServBGP: BGP-inspired autonomic service routing for multi-provider collaborative architectures in the cloud
Wassim Itani, Cesar Ghali, Ramzi Bassil, Ayman I. Kayssi, Ali Chehab
Future Gener. Comput. Syst.5
2013 Perception-aware packet-loss resilient compression for networked haptic systems
Jalal Awed, Imad H. Elhajj, Ali Chehab, Ayman I. Kayssi
Comput. Commun.3
2012 CENTER: A Centralized Trust-Based Efficient Routing protocol for wireless sensor networks
abstract
In this paper, we present CENTER, a CENtralized Trust-based Efficient Routing protocol for wireless sensor networks (WSN). CENTER is a secure and efficient routing protocol that utilizes the powerful sink base station (BS) to identify and ban different types of misbehaving nodes that may interrupt or abuse the functionality of the WSN. In CENTER, the BS periodically accumulates simple local observations of every node and deduces a detailed global view of the network. The BS calculates different quality metrics - namely the maliciousness, cooperation, and compatibility, approximates the battery life, and evaluates the Data Trust and Forwarding Trust values of each node. The BS then uses an effective technique to isolate all “bad” nodes, whether misbehaving or malicious, based on their history. Finally, the BS uses an efficient method to disseminate updated routing information, indicating the uplinks and the next hop downlink for every node. Through its centralized approach, CENTER provides more efficient and secure routing while accounting for the energy-constrained sensor nodes. We present simulation results of CENTER performed using TOSSIM to verify its correctness, security, and reliability.
Ayman Tajeddine, Ayman I. Kayssi, Ali Chehab
PST3
2011 Accountable Reputation Ranking Schemes for Service Providers in Cloud Computing
Wassim Itani, Cesar Ghali, Ayman I. Kayssi, Ali Chehab
CLOSER4
2011 A novel technique to measure data retention voltage of large SRAM arrays
abstract
This paper presents a new technique to accurately measure the data retention voltage (DRV) of large SRAM arrays in the presence of process variations. The proposed technique relies on a built-in-self-test (BIST) unit along with a DC-DC converter. The BIST unit implements a modified version of the March C-test that accounts for data retention faults. Whereas, the DC-DC converter is used to scale down the supply voltage of the array as is done when the array is in data retention mode. The proposed technique can accurately measure the DRV to ensure the SRAM operates at its minimum energy point. The circuit was developed in 90nm technology and simulated using HSPICE. Monte-Carlo simulation of 100k samples determined the DRV as 150mV whereas the proposed technique showed that the DRV of the SRAM under test could be lowered to 80mV which would result in significant power savings.
Farah B. Yahya, Mohammad M. Mansour, Ali Chehab
ISCAS3
2011 A design methodology for energy aware neural networks
abstract
The increasing demand for mobile devices and high performance computing has made energy consumption a main issue in computer technology. Mobile devices require extended battery life, but the available technology still puts limits on the need for recharging the devices. High performance computing has a high price tag on energy for compute-intensive applications such as data mining. As a result, optimizations at various layers of the computer platform are becoming necessary to minimize energy usage or extend the time before a battery needs to be recharged. This paper focuses on back-propagation neural network algorithm, one of the popular compute-intensive data mining algorithms. The goal is to present a design methodology for developing an energy aware algorithm. The key idea revolves around identifying operations called kernels, which are frequently used in the algorithm, and that can be implemented in hardware. Optimizing these kernels for performance or energy would then lead to a major impact in these areas. These kernels are analyzed for their impact on the overall application energy using energy-based asymptotic analysis. The methodology then considers additional optimizations not related to kernels, but are specific to the back-propagation algorithm. Suggestions are provided to improve the performance and reduce energy consumption. Experiments show that there are significant potentials in energy reduction through the use of alternative lower energy kernels or through custom optimizations with tradeoffs in the accuracy of the results.
Mehiar Dabbagh, Hazem M. Hajj, Ali Chehab, Wassim El-Hajj, Ayman I. Kayssi, Mohammad M. Mansour
IWCMC3
2011 TRACE: A centralized Trust And Competence-based Energy-efficient routing scheme for wireless sensor networks
abstract
We present TRACE as a centralized TRust And Competence-based Energy-efficient routing scheme to protect wireless sensor networks from various attacks and misbehaving nodes. TRACE identifies different types of “bad” nodes that can affect the correct routing operation and the reliability of the message delivery to the sink base station (BS). TRACE aids the routing protocol functionality and makes it more efficient and secure by using a centralized approach, where the more powerful and knowledgeable sink BS processes and validates the information received from the sensor nodes and calculates the maliciousness, competence, and cooperation levels of each node. The sink BS calculates two trust values for each node - namely Data Trust and Forwarding Trust and broadcasts a list of suspicious nodes in a Trust Report. TRACE accounts for the energy requirements of the severely-constrained network nodes by detecting and isolating the problematic nodes while eliminating the power-consuming reputation inquiries and computations required by each node in a distributed approach. We present energy calculations and simulations of TRACE and show its low energy consumption, correctness, and reliability.
Ayman Tajeddine, Ayman I. Kayssi, Ali Chehab
IWCMC3
2011 Policy-based Security Channels for Protecting Network Communication in Mobile Cloud Computing
Wassim Itani, Ayman I. Kayssi, Ali Chehab
SECRYPT3
2011 E2VoIP2: Energy efficient voice over IP privacy
Elias Abou Charanek, Hoseb Dermanilian, Imad H. Elhajj, Ayman I. Kayssi, Ali Chehab
Comput. Secur.5
2010 SinPack: A Security Protocol for Preventing Pollution Attacks in Network-Coded Content Distribution Networks
abstract
We present SinPack, a security protocol for preventing packet pollution attacks in network-coded content distribution networks. SinPack employs a homomorphically-addressable Bloom filter data structure to enforce the integrity of network-coded packets all the way from source to destination. Using a Bloom filter "amortizes" the functionality of traditional cryptographic integrity verification constructs (Message Authentication Codes, hash trees, digital signatures, etc) in a relatively small-sized data structure. This aids in reducing network traffic and, more significantly, allows the incremental integrity verification of out of order network packets. The novel homomorphic Bloom filter construction permits intermediate routers and destination end systems to verify the integrity of source packets even after being network-coded by routers. This methodology avoids the need to establish expensive and intricate trust relationships among the different network routers and ensures the authenticity of the integrity structures using a single source public-key operation. Moreover, SinPack not only allows the content downloader to immediately verify the integrity of coded packets, but also provides this capability to any intermediate router on the path to the destination. This helps in eliminating polluted packets in the network upstream closest to the source of attack and as a result contributes to a great reduction in bogus network traffic and hence sizeable energy savings.
Wassim Itani, Cesar Ghali, Ahmad M. El-Hajj, Ayman I. Kayssi, Ali Chehab
GLOBECOM5
2009 Privacy as a Service: Privacy-Aware Data Storage and Processing in Cloud Computing Architectures
abstract
In this paper we present PasS (privacy as a service); a set of security protocols for ensuring the privacy and legal compliance of customer data in cloud computing architectures. PasS allows for the secure storage and processing of users' confidential data by leveraging the tamper-proof capabilities of cryptographic coprocessors. Using tamper-proof facilities provides a secure execution domain in the computing cloud that is physically and logically protected from unauthorized access. PasS central design goal is to maximize users' control in managing the various aspects related to the privacy of sensitive data. This is achieved by implementing user-configurable software protection and data privacy mechanisms. Moreover, PasS provides a privacy feedback process which informs users of the different privacy operations applied on their data and makes them aware of any potential risks that may jeopardize the confidentiality of their sensitive information. To the best of our knowledge, PasS is the first practical cloud computing privacy solution that utilizes previous research on cryptographic coprocessors to solve the problem of securely processing sensitive data in cloud computing infrastructures.
Wassim Itani, Ayman I. Kayssi, Ali Chehab
DASC3
2009 Smart encryption channels for securing virtual machine-based networked applications
abstract
Abstract We present PARAGON, a novel security protocol for efficiently securing the network communications of web‐deployed enterprise applications. PARAGON relies on an application tag set, which is a collection of metadata entries that specify the backend servers with which the client application is expected to communicate during its lifetime. The application tag set controls the quality of the security mechanisms established on each backend server connection, and allows the security protocol to utilize the trust relationship present between the deployed application and its source server to create a set of public‐key security associations between the source server and the enterprise backend servers on behalf of the client. PARAGON is a multi‐phase security protocol that matures with time. Incrementally, PARAGON approaches a fully symmetric‐key encryption system. The performance advantage becomes evident when the client application communicates with a relatively large set of remote servers. Examples of such clients include web browsers, email clients, file torrent clients, stock exchange applications, etc. A prototype implementing PARAGON's specifications and showing its performance advantages is shown for SUN's J2SE 1.6/J2EE 1.5 platforms. Copyright © 2008 John Wiley & Sons, Ltd.
Wassim Itani, Ayman I. Kayssi, Ali Chehab
Secur. Commun. Networks3
2008 Ring of Masters (ROM): A new ring structure for Bluetooth scatternets with dynamic routing and adaptive scheduling schemes
Tarek Hassan, Ayman I. Kayssi, Ali Chehab
Pervasive Mob. Comput.3
2007 SmartSSL: Efficient Policy-Based Web Security
abstract
In this paper we present SmartSSL as a policy-based solution for assuring the security of Web servers and that employs SSL in an efficient way. SmartSSL is content-based and applies SSL dynamically on parts of the Web traffic, as configured by a security policy. SmartSSL does not require any modifications on the client and is designed in a platform-independent manner. SmartSSL can be seamlessly integrated into existing server platforms. Implementation results show substantial performance improvement for SmartSSL as compared to bulk SSL.
Camille Gaspard, Batoul Haidar, Ayman I. Kayssi, Ali Chehab
AICCSA4
2007 Personalized Web Page Ranking Using Trust and Similarity
abstract
Search engines, like Google, use link structure to rank web pages. Although this approach provides an objective global estimate of the web page importance, it is not targeted to the specific user preferences. This paper presents a novel approach for the personalization of the results of a search engine based on the user's taste and preferences. The concepts of trust and similarity, captured from explicit user input and implicit user behavioral patterns, are used to compute personalized page rankings.
Lara Srour, Ayman I. Kayssi, Ali Chehab
AICCSA3
2007 XPRIDE: Policy-Driven Web Services Security Based on XML Content
abstract
In this paper we present XPRIDE as an efficient security architecture for assuring the confidentiality and integrity of the XML-based SOAP messages in Web Services. The policy-based approach employed in XPRIDE can be easily configured and modified to provide security according to the content and sensitivity of the data. Implementation shows that XPRIDE has considerable performance gains over existing bulk encryption protocols such as SSL and over existing policy-based solutions such as WS-Security. XPRIDE is designed as a platform-independent architecture and can be seamlessly integrated into existing application servers.
Zein Radwan, Camille Gaspard, Ayman I. Kayssi, Ali Chehab
GLOBECOM4
2006 PATROL-F - A Comprehensive Reputation-Based Trust Model with Fuzzy Subsystems
Ayman Tajeddine, Ayman I. Kayssi, Ali Chehab, Hassan Artail
ATC3
2006 PRIDE: Policy-Driven Web Security for Handheld Wireless Devices
abstract
In this paper we present PRIDE (Policy-driven web secuRity for handheld wireless DEvices) as an efficient security architecture for assuring the confidentiality and integrity of web traffic between wireless handheld devices and enterprise application servers. PRIDE is a scalable, policy-based solution capable of evolving and adapting to suit the security requirements of a wide range of wireless devices with various capabilities and resources. The customizable policy-based architecture in PRIDE can be configured to provide the security services according to the content and sensitivity of the network data in a web transaction. This gives PRIDE considerable performance gains over existing bulk encryption protocols such as SSI. PRIDE is designed as a platform- independent architecture and can be seamlessly integrated into existing application servers and wireless mobile client devices.
Wassim Itani, Camille Gaspard, Ayman I. Kayssi, Ali Chehab
GLOBECOM4
2006 Cylindrical Antenna Arrays for WCDMA Downlink Capacity Enhancement
abstract
Advanced antenna arrays at the base stations are one of the key techniques to improve the downlink capacity of WCDMA cellular systems. Traditionally, linear and circular arrays are used to form the beams. In this paper, cylindrical antenna arrays with various types of input excitations are proposed, and the beam steering adaptive antenna technique is considered. The user capacity per cell among the linear, circular, and cylindrical arrays is presented and compared in a simulation environment supporting various types of adaptive antennas, soft/softer handover, and multiple services. A notable superiority of the proposed cylindrical antenna arrays was demonstrated by the simulation results.
Elias Yaacoub, Karim Y. Kabalan, Ali El-Hajj, Ali Chehab
ICC4
2006 An enterprise policy-based security protocol for protecting relational database network objects
abstract
In this paper we present ESCORT, an Enterprise, policy-baSed seCurity prOtocol for protecting relational daTabase network objects. ESCORT is an efficient end-to-end security architecture that ensures the confidentiality and integrity of database objects flowing over network links between the Enterprise Information System (EIS) layer represented mainly in relational database servers and the client layer represented by a large variety of devices with diverse capabilities and resources. ESCORT is designed to provide the suitable security strength for a wide range of enterprise application configurations without compromising the application's efficiency and performance. It secures data based on content and sensitivity and highly surpasses the performance of bulk encryption protocols such as the SSL protocol and the TLS protocol by utilizing a customizable policy-based security architecture. This policy-based architecture makes use of the relational structure of database objects to provide flexible, multi-level, and fine-grained encryption and hashing methodologies that target the field level in the database result object. Moreover, ESCORT's security policy can be configured to hit the byte- level granularity in securing individual database fields. This makes ESCORT a very efficient choice for operation in wireless enterprise environments characterized by low-bandwidth wireless networks and supporting limited-resource wireless devices with low memory and processing power. ESCORT neither deals with the security of static data in the database store nor requires the encryption of database objects at the storage level. Results show a performance gain by a factor of three for ESCORT as compared to bulk encryption.
Wassim Itani, Ayman I. Kayssi, Ali Chehab
IWCMC3
2006 Scaling of iDDT Test Methods for Random Logic Circuits
Ali Chehab, Saurabh Patel, Rafic Z. Makki
J. Electron. Test.1
2005 Short Paper: PATRIOT- a Policy-Based, Multi-level Security Protocol for Safekeeping Audit Logs on Wireless Devices
abstract
This paper presents PATRIOT (Policy-bAsed, mulTi-level secuRIty prOTocol), an optimized, policy-driven security architecture for protecting the confidentiality and integrity of audit log files on wireless devices. PATRIOT is based on a set of well-known cryptographic protocols and is designed to suit the limited nature of wireless devices. It offers a policy-driven, customizable security model and specifies a flexible, multilevel, and fine-grained encryption methodology that provides the suitable security strength without compromising performance. PATRIOT is designed in a platform-neutral manner and it can be deployed on a wide range of wireless devices and operating systems.
Wassim Itani, Ayman I. Kayssi, Ali Chehab
SecureComm3