EDBT 2026 Demo / reviewers in the wild / expert
Ehab Al-Shaer
dblp:a/EhabAlShaer · also Ehab S. Al-Shaer
· DBLP profile ↗
121ranked-venue papers
20as first author
10since 2021 · last 2025
0000-0002-7665-8293ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 48 · 10 first-author · 1 since 2021Security and privacy · 45 · 4 first-author · 6 since 2021Systems, architecture and hardware · 9 · 1 first-authorArtificial intelligence and machine learning · 3 · 2 since 2021Databases, data management, data science and information retrieval · 3 · 2 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 1 first-author · 1 since 2021Software engineering, systems software and programming languages · 2 · 1 first-authorTheory of computation · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Hallucination Detection in Large Language Models Using Diversion Decoding
Basel Abdeen, S. M. Tahmid Siddiqui, Meah Tahmeed Ahmed, Anoop Singhal, Latifur Khan, Punya Parag Modi, Ehab Al-Shaer |
DBSec | 7 |
| 2025 | Dynamic Real-time Learning of Electromagnetic Interference Parameters for Drone Crashing AttackabstractDrones are increasingly used in mission-critical environments such as border surveillance, military logistics, and infrastructure inspection. However, their flexibility also introduces cybersecurity risks, as adversaries can exploit them for malicious purposes. A promising defense technique involves using electromagnetic interference to selectively neutralize rogue drones—provided their communication parameters can be precisely identified.In this work, we propose a reinforcement learning agent based on Proximal Policy Optimization (PPO) to autonomously identify the frequency–power pair susceptible to interference for an unknown drone-controller system. The agent operates in a large search space, guided by an environment modeled with dynamic hot zones. It is designed to minimize probing steps and energy consumption, making it suitable for time- and resource-constrained defensive scenarios. Experimental results in a simulated environment show that the agent achieves 90% accuracy in identifying effective jamming parameters, demonstrating its potential as a real-time, adaptive cybersecurity countermeasure for drone-based threats. Yasser El-Alfy, Ehab Al-Shaer, Uthman A. Baroudi, Umar Johar |
PIMRC | 2 |
| 2025 | Security Control Grid for Optimized Cyber Defense PlanningabstractCybersecurity controls are essential for ensuring information confidentiality, integrity, and availability. However, selecting the most effective controls to maximize return on investment (RoI) in cyber defense is a complex task involving numerous factors such as vulnerabilities, threat prioritization, and budget constraints. This paper introduces an innovative model and optimization techniques to select cybersecurity controls (CSC) for optimal risk mitigation, balancing residual risk, budget, and resiliency requirements. Our approach features the Security Control Grid (SCG) model, which automatically determines the necessary controls based on their security functions (Identify, Protect, Detect, Respond, and Recover), strategic placement within the cyber environment, and effectiveness at different stages of the attack kill chain. We formulate cybersecurity control decision-making as a multidimensional optimization problem, solving it using Satisfiability Modulo Theories (SMT). Additionally, we integrate a domain-specific language model that links CSCs with Common Vulnerabilities and Exposures (CVEs). This approach is implemented in the SCG solver tool, which generates scalable and robust CSC deployment plans that optimize cybersecurity RoI and maintain acceptable residual risk for large-scale enterprises. Ashutosh Dutta, Ehab Al-Shaer, Ehsan Aghaei, Qi Duan, Hasan Yasar |
IEEE Trans. Netw. Serv. Manag. | 2 |
| 2024 | Prompting LLM to Enforce and Validate CIS Critical Security ControlabstractProper security control enforcement reduces the attack surface and protects the organizations against attacks. Organizations like NIST and CIS (Center for Internet Security) provide critical security controls (CSCs) as a guideline to enforce cyber security. Automated enforcement and measurability mechanisms for these CSCs still need to be developed. Analyzing the implementations of security products to validate security control enforcement is non-trivial. Moreover, manually analyzing and developing measures and metrics to monitor, and implementing those monitoring mechanisms are resource-intensive tasks and massively dependent on the security analyst's expertise and knowledge. To tackle those problems, we use large language models (LLMs) as a knowledge base and reasoner to extract measures, metrics, and monitoring mechanism implementation steps from security control descriptions to reduce the dependency on security analysts. Our approach used few-shot learning with chain-of-thought (CoT) prompting to generate measures and metrics and generated knowledge prompting for metrics implementation. Our evaluation shows that prompt engineering to extract measures, metrics, and monitoring implementation mechanisms can reduce dependency on humans and semi-automate the extraction process. We also demonstrate metric implementation steps using generated knowledge prompting with LLMs. Jinpeng Wei, Ehab Al-Shaer |
SACMAT | 3 |
| 2023 | SMET: Semantic Mapping of CVE to ATT&CK and Its Application to Cybersecurity
Basel Abdeen, Ehab Al-Shaer, Anoop Singhal, Latifur Khan, Kevin W. Hamlen |
DBSec | 2 |
| 2023 | symbSODA: Configurable and Verifiable Orchestration Automation for Active Malware DeceptionabstractMalware is commonly used by adversaries to compromise and infiltrate cyber systems in order to steal sensitive information or destroy critical assets. Active Cyber Deception (ACD) has emerged as an effective proactive cyber defense against malware to enable misleading adversaries by presenting fake data and engaging them to learn novel attack techniques. However, real-time malware deception is a complex and challenging task because (1) it requires a comprehensive understanding of the malware behaviors at technical and tactical levels in order to create the appropriate deception ploys and resources that can leverage this behavior and mislead malware, and (2) it requires a configurable yet provably valid deception planning to guarantee effective and safe real-time deception orchestration. This article presents symbSODA, a highly configurable and verifiable cyber deception system that analyzes real-world malware using multipath execution to discover API patterns that represent attack techniques/tactics critical for deception, enables users to create their own customized deception ploys based on the malware type and objectives, allows for constructing conflict-free Deception Playbooks , and finally automates the deception orchestration to execute the malware inside a deceptive environment. symbSODA extracts Malicious Sub-graphs (MSGs) consisting of WinAPIs from real-world malware and maps them to tactics and techniques using the ATT&CK framework to facilitate the construction of meaningful user-defined deception playbooks. We conducted a comprehensive evaluation study on symbSODA using 255 recent malware samples. We demonstrated that the accuracy of the end-to-end malware deception is 95% on average, with negligible overhead using various deception goals and strategies. Furthermore, our approach successfully extracted MSGs with a 97% recall, and our MSG-to-MITRE mapping achieved a top-1 accuracy of 88.75%. Our study suggests that symbSODA can serve as a general-purpose Malware Deception Factory to automatically produce customized deception playbooks against arbitrary malware behavior. Md Sajidul Islam Sajid, Jinpeng Wei, Ehab Al-Shaer, Qi Duan, Basel Abdeen, Latifur Khan |
ACM Trans. Priv. Secur. | 3 |
| 2022 | VWC-BERT: Scaling Vulnerability-Weakness-Exploit Mapping on Modern AI AcceleratorsabstractDefending cybersystems needs accurate mapping of software and hardware vulnerabilities to generalized descriptions of weaknesses, and weaknesses to exploits. These mappings enable cyber defenders to build plans for effective defense and assessment of potential risks to a cybersystem. With close to 200k vulnerabilities, manual mapping is not a feasible option. However, automated mapping is challenging due to limited training data, computational intractability, and limitations in computational natural language processing. Tools based on breakthroughs in Transformer-based language models have been demonstrated to classify vulnerabilities with high accuracy. We make three key contributions in this paper: (1) We present a new framework, VWC-BERT, that augments the Transformer-based hierarchical multi-class classification framework of Das et al. (V2W-BERT) with the ability to map weaknesses to exploits. (2) We implement VWC-BERT on modern AI accelerator platforms using two data parallel techniques for the pre-training phase and demonstrate nearly linear speedups across NVIDIA accelerator platforms. We observe nearly linear speedups for up to 16 V100 and 8 A100 GPUs, and about 3.4× speedup for A100 relative to V100 GPUs. Enabled by scaling, we also demonstrate higher accuracy using a larger language model, RoBERTa-Large. We show up to 87% accuracy for strict and up to 98% accuracy for relaxed classification. (3) We develop a novel parallel link manager for the link prediction phase and demonstrate up to 21× speedup with 16 V100 GPUs relative to one V100 GPU, and thus reducing the runtime from 2.5 hours to 10 minutes. We believe that generalizability and scalability of VWC-BERT will benefit both the theoretical development and practical deployment of novel cyberdefense solutions and vulnerability classification. Siddhartha Shankar Das, Mahantesh Halappanavar, Antonino Tumeo, Edoardo Serra, Alex Pothen, Ehab Al-Shaer |
IEEE Big Data | 6 |
| 2022 | SecureBERT: A Domain-Specific Language Model for Cybersecurity
Ehsan Aghaei, Xi Niu, Waseem G. Shadid, Ehab Al-Shaer |
SecureComm | 4 |
| 2021 | SODA: A System for Cyber Deception Orchestration and AutomationabstractActive Cyber Deception (ACD) has emerged as an effective proactive cyber defense technique that can mislead adversaries by presenting falsified data and allow opportunities for engaging with them to learn novel attack techniques. Adversaries often implement their attack techniques within malware and use it as the medium to steal valuable information. Comprehensive malware analysis is required to understand the malware behaviors at technical and tactical levels to create the honey resources and appropriate ploys that can leverage this behavior and mislead malware and APT adversaries. This paper presents SODA, a cyber deception orchestration system that analyzes real-world malware, discovers attack techniques, creates Deception Playbooks, a set of deception actions, and finally orchestrates the environment to deceive malware. SODA extracts Malicious Sub-graphs (MSGs) consisting of WinAPIs from real-world malware and maps them to MITRE ATT&CK techniques. This MSG-to-MITRE mapping describes how ATT&CK techniques are implemented in malware and, as a result, guides the construction of appropriate deception actions. We conducted comprehensive evaluations on SODA with 255 recent malware samples to demonstrate end-to-end deception effectiveness. We observed an average accuracy of 95% in deceiving the malware with negligible overhead for specified deception goals and strategies. Furthermore, our approach successfully extracted MSGs with a 97% recall and our MSG-to-MITRE mapping achieved a top-1 accuracy of 88.75%. More importantly, SODA can serve as a general purpose malware deception factory to automatically produce customized deception playbooks against arbitrary malware. Md Sajidul Islam Sajid, Jinpeng Wei, Basel Abdeen, Ehab Al-Shaer, Md. Mazharul Islam 0001, Walter Diong, Latifur Khan |
ACSAC | 4 |
| 2021 | V2W-BERT: A Framework for Effective Hierarchical Multiclass Classification of Software VulnerabilitiesabstractWe consider the problem of automating the mapping of observed vulnerabilities in software listed in Common Vulnerabilities and Exposures (CVE) reports to weaknesses listed in Common Weakness Enumerations (CWE) reports, a hierarchically designed dictionary of software weaknesses. Mapping of CVEs to CWEs provides a means to understand how they might be exploited for malicious purposes, and to mitigate their impact. Since manual mapping of CVEs to CWEs is not a viable approach due to their ever-increasing sizes, automated approaches need to be devised but obtaining highly accurate mapping is a challenging problem. We present a novel Transformer-based learning framework (V2W-BERT) in this paper to solve this problem by bringing together ideas from natural language processing, link prediction and transfer learning. Our method outperforms previous approaches not only for CWE instances with abundant data to train, but also for rare CWE classes with little or no data. Using vulnerability and weakness reports from MITRE and the National Vulnerability Database, we achieve up to 97% prediction accuracy for randomly partitioned data and up to 94% prediction accuracy in temporally partitioned data. We demonstrate significant improvements in using historical data to predict weaknesses for future instances of CVEs. We believe that our work will would influence the design of better automated mapping approaches, and also that this technology could be deployed for more effective cybersecurity. Siddhartha Shankar Das, Edoardo Serra, Mahantesh Halappanavar, Alex Pothen, Ehab Al-Shaer |
DSAA | 5 |
| 2020 | A Formal Analysis of Moving Target DefenseabstractStatic system configuration provides a significant advantage for the adversaries to discover the assets and launch attacks. Configuration-based moving target defense (MTD) reverses the cyber warfare asymmetry by mutating certain configuration parameters to disrupt the attack planning or increase the attack cost significantly. In this research, we present a methodology for the formal verification of MTD techniques. We formally modeled MTD techniques and verified them against constraints. We use Random Host Mutation (RHM) as a case study for MTD formal verification. The RHM transparently mutates the IP addresses of end-hosts and turns into untraceable moving targets. We apply the formal methodology to verify the correctness, safety, mutation, mutation quality, and deadlock-freeness of RHM using the model checking tool. An adversary is also modeled to validate the effectiveness of the MTD technique. Our experimentation validates the scalability and feasibility of the formal verification methodology. Muhammad Abdul Basit Ur Rahim, Qi Duan, Ehab Al-Shaer |
COMPSAC | 3 |
| 2020 | From Word Embedding to Cyber-Phrase Embedding: Comparison of Processing Cybersecurity TextsabstractMuch of the vital information about emerging threats and the corresponding defensive measures are contained in large volumes of natural language texts online. Capturing such actionable intelligence in real-time is critical to prevent large scale attacks automatically. The ATT&CK framework is a widely recognized standard to catalog technical details of cyber threats and deploy mitigating measures. A technique in ATT&CK specifies a set of adversary actions to achieve a particular goal, such as Exfiltration over Command and Control channel. Details of the technique include encrypted traffic and encoded data. A key challenge in identifying such cyber intelligence from natural language texts is that for a given action, such as encrypted traffic, many alternative expressions are possible (e.g., send using a self-signed certificate, send using HTTPS requests). It is not practical to manually provide an exhaustive list of all such variants. We demonstrate that using cyber-phrase embedding on a cybersecurity text corpus is a promising approach to overcome such difficulties. Our evaluation demonstrates that our model outperforms existing models. We have created an open-source project to make our tools and data available for the cybersecurity research community. Moumita Das Purba, Bill Chu, Ehab Al-Shaer |
ISI | 3 |
| 2020 | ThreatZoom: Hierarchical Neural Network for CVEs to CWEs Classification
Ehsan Aghaei, Waseem G. Shadid, Ehab Al-Shaer |
SecureComm (1) | 3 |
| 2020 | Email Address Mutation for Proactive Deterrence Against Lateral Spear-Phishing Attacks
Md. Mazharul Islam 0001, Ehab Al-Shaer, Muhammad Abdul Basit Ur Rahim |
SecureComm (1) | 2 |
| 2020 | A Formal Verification of Configuration-Based Mutation Techniques for Moving Target Defense
Muhammad Abdul Basit Ur Rahim, Ehab Al-Shaer, Qi Duan |
SecureComm (1) | 2 |
| 2020 | A game-theoretic analysis to defend against remote operating system fingerprinting
Mohammad Ashiqur Rahman, Md. Golam Moula Mehedi Hasan, Mohammad Hossein Manshaei, Ehab Al-Shaer |
J. Inf. Secur. Appl. | 4 |
| 2019 | IoTC2: A Formal Method Approach for Detecting Conflicts in Large Scale IoT Systems
Abdullah Al Farooq, Ehab Al-Shaer, Thomas Moyer, Krishna Kant 0001 |
IM | 2 |
| 2019 | Security design against stealthy attacks on power system state estimation: A formal approach
Mohammad Ashiqur Rahman, Amarjit Datta, Ehab Al-Shaer |
Comput. Secur. | 3 |
| 2018 | Using Entropy and Mutual Information to Extract Threat Actions from Cyber Threat IntelligenceabstractWith the rapid growth of the cyber attacks, cyber threat intelligence (CTI) sharing becomes essential for providing advance threat notice and enabling timely response to cyber attacks. Our goal in this paper is to develop an approach to extract low-level cyber threat actions from publicly available CTI sources in an automated manner to enable timely defense decision making. Specifically, we innovatively and successfully used the metrics of entropy and mutual information from Information Theory to analyze the text in the cybersecurity domain. Combined with some basic NLP techniques, our framework, called ActionMiner has achieved higher precision and recall than the state-of-the-art Stanford typed dependency parser, which usually works well in general English but not cybersecurity texts. Ghaith Husari, Xi Niu, Bill Chu, Ehab Al-Shaer |
ISI | 4 |
| 2018 | PhishMon: A Machine Learning Framework for Detecting Phishing WebpagesabstractDespite numerous research efforts, phishing attacks remain prevalent and highly effective in luring unsuspecting users to reveal sensitive information, including account credentials and social security numbers. In this paper, we propose PhishMon, a new feature-rich machine learning framework to detect phishing webpages. It relies on a set of fifteen novel features that can be efficiently computed from a webpage without requiring third-party services, such as search engines, or WHOIS servers. These features capture various characteristics of legitimate web applications as well as their underlying web infrastructures. Emulation of these features is costly for phishers as it demands to spend significantly more time and effort on their underlying infrastructures and web applications; in addition to the efforts required for replicating the appearance of target websites. Through extensive evaluation on a dataset consisting of 4,800 distinct phishing and 17,500 distinct benign webpages, we show that PhishMon can distinguish unseen phishing from legitimate webpages with a very high degree of accuracy. In our experiments, PhishMon achieved 95.4% accuracy with 1.3% false positive rate on a dataset containing unique phishing instances. Amirreza Niakanlahiji, Bei-tseng Chu, Ehab Al-Shaer |
ISI | 3 |
| 2017 | TTPDrill: Automatic and Accurate Extraction of Threat Actions from Unstructured Text of CTI SourcesabstractWith the rapid growth of the cyber attacks, sharing of cyber threat intelligence (CTI) becomes essential to identify and respond to cyber attack in timely and cost-effective manner. However, with the lack of standard languages and automated analytics of cyber threat information, analyzing complex and unstructured text of CTI reports is extremely time- and labor-consuming. Without addressing this challenge, CTI sharing will be highly impractical, and attack uncertainty and time-to-defend will continue to increase. Ghaith Husari, Ehab Al-Shaer, Bill Chu, Xi Niu |
ACSAC | 2 |
| 2017 | Prioritized active learning for malicious URL detection using weighted text-based featuresabstractData analytics is being increasingly used in cyber-security problems, and found to be useful in cases where data volumes and heterogeneity make it cumbersome for manual assessment by security experts. In practical cyber-security scenarios involving data-driven analytics, obtaining data with annotations (i.e. ground-truth labels) is a challenging and known limiting factor for many supervised security analytics task. Significant portions of the large datasets typically remain unlabelled, as the task of annotation is extensively manual and requires a huge amount of expert intervention. In this paper, we propose an effective active learning approach that can efficiently address this limitation in a practical cyber-security problem of Phishing categorization, whereby we use a human-machine collaborative approach to design a semi-supervised solution. An initial classifier is learnt on a small amount of the annotated data which in an iterative manner, is then gradually updated by shortlisting only relevant samples from the large pool of unlabelled data that are most likely to influence the classifier performance fast. Prioritized Active Learning shows a significant promise to achieve faster convergence in terms of the classification performance in a batch learning framework, and thus requiring even lesser effort for human annotation. An useful feature weight update technique combined with active learning shows promising classification performance for categorizing Phishing/malicious URLs without requiring a large amount of annotated training samples to be available during training. In experiments with several collections of PhishMonger's Targeted Brand dataset, the proposed method shows significant improvement over the baseline by as much as 12%. Sreyasee Das Bhattacharjee, Ashit Talukder, Ehab Al-Shaer, Pratik Doshi |
ISI | 3 |
| 2017 | IoTChecker: A data-driven framework for security analytics of Internet of Things configurations
Mujahid Mohsin, Zahid Anwar, Farhat Zaman, Ehab Al-Shaer |
Comput. Secur. | 4 |
| 2017 | Data-driven analytics for cyber-threat intelligence and information sharing
Sara Qamar, Zahid Anwar, Mohammad Ashiqur Rahman, Ehab Al-Shaer, Bei-tseng Chu |
Comput. Secur. | 4 |
| 2017 | A Novel Class of Robust Covert Channels Using Out-of-Order PacketsabstractCovert channels are usually used to circumvent security policies and allow information leakage without being observed. In this paper, we propose a novel covert channel technique using the packet reordering phenomenon as a host for carrying secret communications. Packet reordering is a common phenomenon on the Internet. Moreover, it is handled transparently from the user and application-level processes. This makes it an attractive medium to exploit for sending hidden signals to receivers by dynamically manipulating packet order in a network flow. In our approach, specific permutations of successive packets are selected to enhance the reliability of the channel, while the frequency distribution of their usage is tuned to increase stealthiness by imitating real Internet traffic. It is very expensive for the adversary to discover the covert channel due to the tremendous overhead to buffer and sort the packets among huge amount of background traffic. A simple tool is implemented to demonstrate this new channel. We studied extensively the robustness and capabilities of our proposed channel using both simulation and experimentation over large varieties of traffic characteristics. The reliability and capacity of this technique have shown promising results. We also investigated a practical mechanism for distorting and potentially preventing similar novel channels. Adel El-Atawy, Qi Duan, Ehab Al-Shaer |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2017 | Secure and Private Data Aggregation for Energy Consumption Scheduling in Smart GridsabstractThe recent proposed solutions for demand side energy management leverage the two-way communication infrastructure provided by modern smart-meters and sharing the usage information with the other users. In this paper, we first highlight the privacy and security issues involved in the distributed demand management protocols. We propose a novel protocol to share required information among users providing privacy, confidentiality, and integrity. We also propose a new clustering-based, distributed multi-party computation (MPC) protocol. Through simulation experiments we demonstrate the efficiency of our proposed solution. The existing solutions typically usually thwart selfish and malicious behavior of consumers by deploying billing mechanisms based on total consumption during a few time slots. However, the billing is typically based on the total usage in each time slot in smart grids. In the second part of this paper, we formally prove that under the per-slot based charging policy, users have incentive to deviate from the proposed protocols. We also propose a protocol to identify untruthful users in these networks. Finally, considering a repeated interaction among honest and dishonest users, we derive the conditions under which the smart grid can enforce cooperation among users and prevents dishonest declaration of consumption. Mohammad Ashiqur Rahman, Mohammad Hossein Manshaei, Ehab Al-Shaer, Mohamed Shehab |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2017 | Automated Synthesis of Distributed Network Access Controls: A Formal Framework with RefinementabstractDue to the extensive use of network services and emerging security threats, enterprise networks deploy varieties of security devices for controlling resource access based on organizational security requirements. These requirements need fine-grained access control rules based on heterogeneous isolation patterns like access denial, trusted communication, and payload inspection. Organizations are also seeking for usable and optimal security configurations that can harden the network security within enterprise budget constraints. In order to design a security architecture, i.e., the distribution of security devices along with their security policies, that satisfies the organizational security requirements as well as the business constraints, it is required to analyze various alternative security architectures considering placements of network security devices in the network and the corresponding access controls. In this paper, we present an automated formal framework for synthesizing network security configurations. The main design alternatives include different kinds of isolation patterns for network traffic flows. The framework takes security requirements and business constraints along with the network topology as inputs. Then, it synthesizes cost-effective security configurations satisfying the constraints and provides placements of different security devices, optimally distributed in the network, according to the given network topology. In addition, we provide a hypothesis testing-based security architecture refinement mechanism that explores various security design alternatives using ConfigSynth and improves the security architecture by systematically increasing the security requirements. We demonstrate the execution of ConfigSynth and the refinement mechanism using case studies. Finally, we evaluate their scalability using simulated experiments. Mohammad Ashiqur Rahman, Ehab Al-Shaer |
IEEE Trans. Parallel Distributed Syst. | 2 |
| 2016 | Optimizing the RoI of cyber risk mitigationabstractIn this paper, we present a security analytics framework that augments host compliance reports with network configuration to assess the risk globally and devise cost-effective mitigation plans. We define metrics to measure the global enterprise risk based on network assets' vulnerabilities, their inter-dependencies, and network configurations. Our framework takes the decision burden away from administrators by automatically recommending cost-effective mitigation actions that achieve the expected return on investment (RoI). We use XCCDF, a language defined as part of the Security Content Automation Protocol (SCAP), to communicate the compliance benchmarking and scoring reports. In addition, we utilize the basic metrics defined in the standard vulnerability scoring systems, such as CVSS, to accurately assess the global risk. We formalize our proposed mitigation planning solution as a constraints satisfaction problem and we solve it using the Z3 SMT solver. Mohammed Noraden Alsaleh, Ghaith Husari, Ehab Al-Shaer |
CNSM | 3 |
| 2016 | Formal Analysis for Dependable Supervisory Control and Data Acquisition in Smart GridsabstractSmart grids provide innovative and efficient energy management services that offer operational reliability. The Supervisory Control and Data Acquisition (SCADA) system is a core component of a smart grid. Unlike the traditional cyber networks, these components consist of heterogeneous devices, such as intelligent electronic devices, programmable logic controllers, remote terminal units, control servers, routing and security devices, etc. SCADA devices communicate with one another under various communication protocols, physical media, and security properties. Failures or attacks on such networks have the potential of data unavailability and false data injection causing incorrect system estimations and control decisions leading to critical damages including power outages and destruction of equipment. In this work, we develop an automated security and resiliency analysis framework for SCADA in smart grids. This framework takes smart grid configurations and organizational security and resiliency requirements as inputs, formally models configurations and various security constraints, and verifies the dependability of the system under potential contingencies. We demonstrate the execution of this framework on an example problem. We also evaluate the scalability of the framework on synthetic SCADA systems. Mohammad Ashiqur Rahman, A. H. M. Jakaria, Ehab Al-Shaer |
DSN | 3 |
| 2016 | Strategic Cyber Threat Intelligence Sharing: A Case Study of IDS LogsabstractCyber threat intelligence sharing is emerging as an important tool for network security as it can identify evolving threat patterns and prevent attackers from replicating their early success across the Internet. However the types of information sharing being practiced today are at the tactical level focusing on specific attacks, e.g. characteristics of a piece of malware, and black listed IP addresses and domains. In this paper we argue sharing cyber intelligence at a more strategic level is needed. By strategic information we mean information about salient common features of groups of attacks and attackers. Strategic information allows us to take actions that are much closer to the source of the attacks. For example instead of block an IP address as opposed to shutting down the botnet. We propose at set of strategic cyber threat indicators and show how they can be derived using an IDS log from a large commercial enterprise. Spike E. Dog, Alex Tweed, LeRoy Rouse, Bill Chu, Duan Qi, Yueqi Hu, Ehab Al-Shaer |
ICCCN | 8 |
| 2016 | Economic metric to improve spam detectors
Fida Gillani, Ehab Al-Shaer, Basil AsSadhan |
J. Netw. Comput. Appl. | 2 |
| 2015 | SafeConfig 2015: Workshop on Automated Decision Making for Active Cyber DefenseabstractThe 8th SafeConfig Workshop is held in Denver, Colorado USA on October 12, 2015 and being run with the conjunction of the 22nd ACM Conference on Computer and Communications Security (CCS). The title of this year's SafeConfig is "Automated Decision Making for Cyber Security". Today, the use of cyber technology is evolving rapidly. The computing and networking is everywhere, public to private organizations, large enterprises to individuals, and data centers to smart phones and Internet-of-Things. The highly growing use of the Internet also leads to newly evolving security threats. The automated decision making should be able to determine the security and resiliency of networked information systems and services. The integration of security requirements, capabilities, and deployment constraints in a unified framework will enable intelligent response, automated defense, and network resiliency. Ehab Al-Shaer, Christopher S. Oehmen, Mohammad Ashiqur Rahman |
CCS | 1 |
| 2015 | Agile virtualized infrastructure to proactively defend against cyber attacksabstractDDoS attacks have been a persistent threat to network availability for many years. Most of the existing mitigation techniques attempt to protect against DDoS by filtering out attack traffic. However, as critical network resources are usually static, adversaries are able to bypass filtering by sending stealthy low traffic from large number of bots that mimic benign traffic behavior. Sophisticated stealthy attacks on critical links can cause a devastating effect such as partitioning domains and networks. In this paper, we propose to defend against DDoS attacks by proactively changing the footprint of critical resources in an unpredictable fashion to invalidate an adversary's knowledge and plan of attack against critical network resources. Our present approach employs virtual networks (VNs) to dynamically reallocate network resources using VN placement and offers constant VN migration to new resources. Our approach has two components: (1) a correct-by-construction VN migration planning that significantly increases the uncertainty about critical links of multiple VNs while preserving the VN placement properties, and (2) an efficient VN migration mechanism that identifies the appropriate configuration sequence to enable node migration while maintaining the network integrity (e.g., avoiding session disconnection). We formulate and implement this framework using SMT logic. We also demonstrate the effectiveness of our implemented framework on both PlanetLab and Mininet-based experimentations. Fida Gillani, Ehab Al-Shaer, Samantha Lo, Qi Duan, Mostafa H. Ammar, Ellen Zegura |
INFOCOM | 2 |
| 2015 | Adversary-aware IP address randomization for proactive agility against sophisticated attackersabstractNetwork reconnaissance of IP addresses and ports is prerequisite to many host and network attacks. Meanwhile, static configurations of networks and hosts simplify this adversarial reconnaissance. In this paper, we present a novel proactive-adaptive defense technique that turns end-hosts into untraceable moving targets, and establishes dynamics into static systems by monitoring the adversarial behavior and reconfiguring the addresses of network hosts adaptively. This adaptability is achieved by discovering hazardous network ranges and addresses and evacuating network hosts from them quickly. Our approach maximizes adaptability by (1) using fast and accurate hypothesis testing for characterization of adversarial behavior, and (2) achieving a very fast IP randomization (i.e., update) rate through separating randomization from end-hosts and managing it via network appliances. The architecture and protocols of our approach can be transparently deployed on legacy networks, as well as software-defined networks. Our extensive analysis and evaluation show that by adaptive distortion of adversarial reconnaissance, our approach slows down the attack and increases its detectability, thus significantly raising the bar against stealthy scanning, major classes of evasive scanning and worm propagation, as well as targeted (hacking) attacks. Jafar Haadi Jafarian, Ehab Al-Shaer, Qi Duan |
INFOCOM | 2 |
| 2015 | PoliCon: a policy conciliation framework for heterogeneous mobile ad hoc networksabstractAbstract It is increasingly important to implement a conflict‐free access control policies for co‐allied networks where different organizations are involve for a common goal. Mobile ad hoc networks are widely used for mission critical situations where teams from different organizational networks cooperate to form a single network to implement their respective operations. These teams (or quads) have different sets of local policies enforced for their own security resulting heterogeneity in access control. Each team wants to preserve its access control policies at a maximum level. Moreover, a set of allied policies govern the cooperation and interaction between the different teams, which may conflict with their local policies. The policy conflicts arise from the transitivity of policy rules, mobility of the nodes, cooperative behaviors, and so on. In addition, the policy rules may be temporal or static. To achieve the successful completion of the mission, it may be required to compromise with the stringency of the enforcement of the conflicting rules for the quads. In this paper, we propose an automated and formal framework to find the optimal conciliation of the policy rules to preserve the mission and thus ensure minimal compromise with the enforcement of policy for each quad. The efficacy of the work lies on optimizing the enforcement of access control policies to achieve the coalition instead of negating the policy. Copyright © 2014 John Wiley & Sons, Ltd. Soumya Maity, Soumya K. Ghosh 0001, Ehab Al-Shaer |
Secur. Commun. Networks | 3 |
| 2015 | An Effective Address Mutation Approach for Disrupting Reconnaissance AttacksabstractNetwork reconnaissance of addresses and ports is prerequisite to a vast majority of cyber attacks. Meanwhile, the static address configuration of networks and hosts simplifies adversarial reconnaissance for target discovery. Although the randomization of host addresses has been suggested as a proactive disruption mechanism against such reconnaissance, the proposed approaches do not exploit the full potentials of address randomization in provision of unpredictability and attack adaptability. Moreover, these approaches do not provide thorough analysis on effectiveness and limitations of address randomization against relevant threat models, including stealthy scanning and worms. In this paper, we present an effective address randomization technique, called random host address mutation (RHM), that turns end-hosts into untraceable moving targets. This technique achieves maximum efficacy by allowing address randomization to be highly unpredictable and fast, and adaptive to adversarial behavior, while incurring low operational and reconfiguration overhead. Our approach achieves the following objectives: (1) it achieves high uncertainty in adversary scanning by modeling address mutation randomization as a multi-level satisfiability problem; (2) it adapts the mutation scheme by fast characterization of adversarial reconnaissance patterns; (3) it achieves high mutation rate by separating mutation from end-hosts and managing it via network appliances; and (4) it preserves network integrity, manageability and performance by bounding the size of routing tables, preserving end-to-end reachability, and efficient handling of reconfiguration updates. Our extensive analyses and simulation show that the RHM distorts adversarial reconnaissance, slows down (deters) the attack, and increases its detectability. Consequently, the RHM is effective in countering a significant number of sophisticated threat models, including reconnaissance, stealthy/evasive scanning methods, and targeted attacks. We also address limitations of our approach in terms of effectiveness and applicability. Jafar Haadi Jafarian, Ehab Al-Shaer, Qi Duan |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2015 | Randomization-Based Intrusion Detection System for Advanced Metering InfrastructureabstractSmart grid deployment initiatives have been witnessed in recent years. Smart grids provide bidirectional communication between meters and head-end systems through Advanced Metering Infrastructure (AMI). Recent studies highlight the threats targeting AMI. Despite the need for tailored Intrusion Detection Systems (IDSs) for smart grids, very limited progress has been made in this area. Unlike traditional networks, smart grids have their own unique challenges, such as limited computational power devices and potentially high deployment cost, that restrict the deployment options of intrusion detectors. We show that smart grids exhibit deterministic and predictable behavior that can be accurately modeled to detect intrusion. However, it can also be leveraged by the attackers to launch evasion attacks. To this end, in this article, we present a robust mutation-based intrusion detection system that makes the behavior unpredictable for the attacker while keeping it deterministic for the system. We model the AMI behavior using event logs collected at smart collectors, which in turn can be verified using the invariant specifications generated from the AMI behavior and mutable configuration. Event logs are modeled using fourth-order Markov chain and specifications are written in Linear Temporal Logic (LTL). To counter evasion and mimicry attacks, we propose a configuration randomization module. The approach provides robustness against evasion and mimicry attacks; however, we discuss that it still can be evaded to a certain extent. We validate our approach on a real-world dataset of thousands of meters collected at the AMI of a leading utility provider. Muhammad Qasim Ali, Ehab Al-Shaer |
ACM Trans. Inf. Syst. Secur. | 2 |
| 2014 | Summary Abstract for the 7th ACM International Workshop on Cyber Security Analytics, Intelligence and AutomationabstractThe 7th ACM International Workshop on Cyber Security Analytics, Intelligence and Automation (SafeConfig) is held as part of ACM Computer and Communications Security CCS 2014. SafeConfig 14, following many successful preceding workshops, is concerned with developing new security techniques and approaches that offer proactive, intelligent and a holistic security analytics based on analyzing the system artifacts including system traces, configurations, logs, incident reports, alarms and network traffic. Scalable analytics techniques are essential to handle large volumes of data and to normalize, model, integrate, analyze and respond to threats in real time. Ehab Al-Shaer, Krishna Kant 0001 |
CCS | 1 |
| 2014 | Security Threat Analytics and Countermeasure Synthesis for Power System State EstimationabstractState estimation plays a critically important role in ensuring the secure and reliable operation of the power grid. However, recent works have shown that the widely used weighted least squares (WLS) estimator, which uses several system wide measurements, is vulnerable to cyber attacks wherein an adversary can alter certain measurements to corrupt the estimator's solution, but evade the estimator's existing bad data detection algorithms and thus remain invisible to the system operator. Realistically, such a stealthy attack in its most general form has several constraints, particularly in terms of an adversary's knowledge and resources for achieving a desired attack outcome. In this light, we present a formal framework to systematically investigate the feasibility of stealthy attacks considering constraints of the adversary. In addition, unlike prior works, our approach allows the modeling of attacks on topology mappings, where an adversary can drastically strengthen stealthy attacks by intentionally introducing topology errors. Moreover, we show that this framework allows an operator to synthesize cost-effective countermeasures based on given resource constraints and security requirements in order to resist stealthy attacks. The proposed approach is illustrated on standard IEEE test cases. Mohammad Ashiqur Rahman, Ehab Al-Shaer, Rajesh G. Kavasseri |
DSN | 2 |
| 2014 | Impact Analysis of Topology Poisoning Attacks on Economic Operation of the Smart Power GridabstractThe Optimal Power Flow (OPF) routine used in energy control centers allocates individual generator outputs by minimizing the overall cost of generation subject to system level operating constraints. The OPF relies on the outputs of two other modules, namely topology processor and state estimator. The topology processor maps the grid topology based on statuses received from the switches and circuit breakers across the system. The state estimator computes the system state, i.e., voltage magnitudes with phase angles, transmission line flows, and system loads based on real-time meter measurements. However, topology statuses and meter measurements are vulnerable to false data injection attacks. Recent research has shown that such cyber attacks can be launched against state estimation where adversaries can corrupt the states but still remain undetected. In this paper, we show how the stealthy topology poisoning attacks can compromise the integrity of OPF, and thus undermine economic operation. We describe a formal verification based framework to systematically analyze the impact of such attacks on OPF. The proposed framework is illustrated with an example. We also evaluate the scalability of the framework with respect to time and memory requirements. Mohammad Ashiqur Rahman, Ehab Al-Shaer, Rajesh G. Kavasseri |
ICDCS | 2 |
| 2014 | Information theoretic feature space slicing for statistical anomaly detection
Ayesha Binte Ashfaq, Sajjad Rizvi, Mobin Javed, Syed Ali Khayam, Muhammad Qasim Ali, Ehab Al-Shaer |
J. Netw. Comput. Appl. | 6 |
| 2014 | Firewall Policy Reconnaissance: Techniques and AnalysisabstractIn the past decade, scanning has been widely used as a reconnaissance technique to gather critical network information to launch a follow up attack. To combat, numerous intrusion detectors have been proposed. However, scanning methodologies have shifted to the next-generation paradigm to be evasive. The next-generation reconnaissance techniques are intelligent and stealthy. These techniques use a low volume packet sequence and intelligent calculation for the victim selection to be more evasive. Previously, we proposed models for firewall policy reconnaissance that are used to set bound for learning accuracy as well as to put minimum requirements on the number of probes. We presented techniques for reconstructing the firewall policy by intelligently choosing the probing packets based on the responses of previous probes. In this paper, we show the statistical analysis of these techniques and discuss their evasiveness along with the improvement. First, we present the previously proposed two techniques followed by the statistical analysis and their evasiveness to current detectors. Based on the statistical analysis, we show that these techniques still exhibit a pattern and thus can be detected. We then develop a hybrid approach to maximize the benefit by combining the two heuristics. Muhammad Qasim Ali, Ehab Al-Shaer, Taghrid Samak |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2014 | Problem Localization and Quantification Using Formal Evidential Reasoning for Virtual NetworksabstractOverlay (virtual) networks are mainly used to improve Internet reliability and facilitate a rapid deployment of new services. However, in order for overlay services to adapt to dynamic network conditions in a timely manner, efficient diagnosis of performance problems is required. Existing overlay diagnosis approaches assume extensive knowledge about the network and require invasive monitoring sensors or active measurements. In this paper, we propose a novel diagnosis technique to localize performance anomalies and determine the packet loss in each network component. Our approach is purely based on packet loss observations at the end-points to reason about the loss location and severity in the network without any active probing or sensor deployment. We formulate the problem as a constraint-satisfaction problem using network loss properties and end-user observations. Our diagnosis is robust against insufficient observations or malicious end-user participation. We evaluate our approach extensively using simulation and experimentation and demonstrate the accuracy, effectiveness, and scalability of our approach under various network sizes, participation ratio, and malicious observation ratio. Fida Gillani, Mehmet Demirci, Ehab Al-Shaer, Mostafa H. Ammar |
IEEE Trans. Netw. Serv. Manag. | 3 |
| 2013 | Configuration-based IDS for advanced metering infrastructureabstractSmart grid deployment initiatives have been witnessed in the past recent years. Smart grids provide bi-directional communication between meters and headend system through Advanced Metering Infrastructure (AMI). Recent studies highlight the threats targeting AMI. Despite the need of tailored Intrusion Detection Systems (IDS) for the smart grid, very limited progress has been made in this area. Unlike traditional networks, smart grid has its own unique challenges, such as limited computational power devices and potentially high deployment cost, that restrict the deployment options of intrusion detectors. We show that smart grid exhibits deterministic and predictable behavior that can be accurately modeled to develop intrusion detection system. In this paper, we show that AMI behavior can be modeled using event logs collected at smart collectors, which in turn can be verified using the specifications invariant generated from the configurations of the AMI devices. Event logs are modeled using fourth order Markov Chain and specifications are written in Linear Temporal Logic (LTL). The approach provides robustness against evasion and mimicry attacks, however, we discuss that it still can be evaded to a certain extent. We validate our approach on a real-world dataset of thousands of meters collected at the AMI of a leading utility provider. Muhammad Qasim Ali, Ehab Al-Shaer |
CCS | 2 |
| 2013 | Revisiting anomaly detection system design philosophyabstractThe inherent design of anomaly detection systems (ADSs) make them highly susceptible to evasion attacks and hence their wide-spread commercial deployment has not been witnessed. There are two main reasons for this: 1) ADSs incur high false positives; 2) Are highly susceptible to evasion attacks (false negatives). While efforts have been made to minimize false positives, evasion is still an open problem. We argue that ADSs design is inherently flawed since it relies on the ADS's detection logic and feature space which is trivial to estimate. In information security e.g. cryptographic algorithms (such as DES), security is inherently dependent upon the key and not the algorithm, which makes these systems very robust by rendering evasion computationally infeasible. We believe there is a need to redesign the anomaly detection systems similar to cryptographic systems. We propose to randomize the feature space of an ADS such that it acts as a cryptographic key for the ADS and hence this randomized feature space is used by the ADS logic for detection of anomalies. This would make the evasion of the ADS computationally infeasible for the attacker. Ayesha Binte Ashfaq, Muhammad Qasim Ali, Ehab Al-Shaer, Syed Ali Khayam |
CCS | 3 |
| 2013 | A formal approach for virtual machine migration planningabstractCloud computing is an emerging paradigm in information technology. Virtualization is the corner stone for this paradigm in which resources are utilized by running multiple virtual machines (VMs) on a physical host. During the VM's life cycle, the cloud provider may migrate the VM from one host to another host. During the live migration process, some security, capacity, and dependency requirements are subject to violations due to the temporal relationship between migration steps. In this paper, we present a formal approach to plan VM migration; that is to find a sequence of migration steps such that all security, dependency, and performance requirements are met. The migration planning problem is modeled as a Constraints Satisfaction Problem and it is solved using Satisfiability Modulo Theory (SMT) solvers. We provide VMM-Planner, a formal framework that provides a VM migration plan to formally verify the given requirements in all intermediate migration steps. Saeed Al-Haj, Ehab Al-Shaer |
CNSM | 2 |
| 2013 | Formal Approach for Route Agility against Persistent Attackers
Jafar Haadi Jafarian, Ehab Al-Shaer, Qi Duan |
ESORICS | 2 |
| 2013 | Overlay network placement for diagnosabilityabstractOverlay networks have become an effective method to help overcome the limitations of the Internet in the last decade. Overlays must be monitored for various kinds of problems so that efficient performance can be sustained. An overlay's topology and placement on the substrate have a considerable effect on the level of difficulty in monitoring it. In this paper, we study the problem of placing overlay networks onto the substrate in a way that makes it easier to detect and localize faults, in other words, improves their diagnosability. Overlay network fault diagnosis is especially challenging because of their construction as virtual networks on top of a network substrate. We give a practical definition of diagnosability, and develop an overlay assignment algorithm that aims to optimize overlay placement for the ease and quickness of fault diagnosis. We evaluate the efficiency of this algorithm using an existing passive fault diagnosis scheme, and show that we are able to improve diagnosability without placing a significant strain on the network. We also analyze diagnosability in situations where traffic is sufficient for passive measurements on a percentage of paths rather than the whole network, and study how to augment passive diagnosis with selective active probing in order to raise diagnosability to a desired level. Mehmet Demirci, Fida Gillani, Mostafa H. Ammar, Ehab Al-Shaer |
GLOBECOM | 4 |
| 2013 | A Formal Framework for Network Security Design SynthesisabstractDue to the extensive use of Internet services and emerging security threats, most enterprise networks deploy varieties of security devices for controlling resource access based on organizational security requirements. These requirements are becoming more fine-grained, where access control depends on heterogeneous isolation patterns like access deny, trusted communication, and payload inspection. However, organizations are looking to design usable and optimal security configurations that can harden the network security within enterprise budget constraints. This requires analyzing various alternative security architectures in order to find a security design that satisfies the organizational security requirements as well as the business constraints. In this paper, we present ConfigSynth, an automated framework for synthesizing network security configurations by exploring various security design alternatives to provide an optimal solution. The main design alternatives include different kinds of isolation patterns for traffic flows in different segments of the network. ConfigSynth takes security requirements and business constraints along with the network topology as inputs. Then it synthesizes optimal and cost-effective security configurations satisfying the constraints. ConfigSynth also provides optimal placements of different security devices in the network according to the given network topology. ConfigSynth uses Satisfiability Modulo Theories (SMT) for modeling this synthesis problem. We demonstrate the scalability of the tool using simulated experiments. Mohammad Ashiqur Rahman, Ehab Al-Shaer |
ICDCS | 2 |
| 2013 | A formal approach for network security management based on qualitative risk analysis
Mohammad Ashiqur Rahman, Ehab Al-Shaer |
IM | 2 |
| 2013 | Metrics for Automated Network Security Design
Mohammad Ashiqur Rahman, Ehab Al-Shaer |
NDSS | 2 |
| 2013 | Adaptive Information Coding for Secure and Reliable Wireless Telesurgery Communications
M. Engin Tozal, Yongge Wang 0001, Ehab Al-Shaer, Kamil Saraç, Bhavani Thuraisingham, Bei-tseng Chu |
Mob. Networks Appl. | 3 |
| 2013 | Automated Anomaly Detector Adaptation using Adaptive Threshold TuningabstractReal-time network- and host-based Anomaly Detection Systems (ADSs) transform a continuous stream of input data into meaningful and quantifiable anomaly scores. These scores are subsequently compared to a fixed detection threshold and classified as either benign or malicious. We argue that a real-time ADS’ input changes considerably over time and a fixed threshold value cannot guarantee good anomaly detection accuracy for such a time-varying input. In this article, we propose a simple and generic technique to adaptively tune the detection threshold of any ADS that works on threshold method. To this end, we first perform statistical and information-theoretic analysis of network- and host-based ADSs’ anomaly scores to reveal a consistent time correlation structure during benign activity periods. We model the observed correlation structure using Markov chains, which are in turn used in a stochastic target tracking framework to adapt an ADS’ detection threshold in accordance with real-time measurements. We also use statistical techniques to make the proposed algorithm resilient to sporadic changes and evasion attacks. In order to evaluate the proposed approach, we incorporate the proposed adaptive thresholding module into multiple ADSs and evaluate those ADSs over comprehensive and independently collected network and host attack datasets. We show that, while reducing the need of human threshold configuration, the proposed technique provides considerable and consistent accuracy improvements for all evaluated ADSs. Muhammad Qasim Ali, Ehab Al-Shaer, Syed Ali Khayam |
ACM Trans. Inf. Syst. Secur. | 2 |
| 2012 | Monetizing spambot activity and understanding its relation with spambot traffic featuresabstractA myriad of studies are reporting an exponential increase in the number and size of worldwide botnets [1, 2, 15, 17, 20, 21]. For instance, it has been reported that the Storm botnet increased by a factor of three during the second quarter of 2008. The reason of such exponential growth is the financial gain that these spam botnets can generate [1, 2, 3]. Absent grounded empirical data, it is challenging to reconcile "revenue estimates" that can range from $2M/day for one spam botnet [4]. Paxson et. al [1] have documented 82,000 and 37,00 monthly orders for seven counterfeit pharmacies and counterfeit software stores, respectively. The spammers running all these spams generally purchase time from a bot master to launch a spam campaign with a single objective to increase their respective profit margins from such spam campaigns. Fida Gillani, Ehab Al-Shaer, Sardar Ali, Syed Ali Khayam |
AsiaCCS | 2 |
| 2012 | Provable configuration planning for wireless sensor networks
Qi Duan, Saeed Al-Haj, Ehab Al-Shaer |
CNSM | 3 |
| 2012 | Fine-grain diagnosis of overlay performance anomalies using end-point network experiences
Fida Gillani, Ehab Al-Shaer, Mostafa H. Ammar, Mehmet Demirci |
CNSM | 2 |
| 2012 | Anomaly Discovery and Resolution in MySQL Access Control Policies
Mohamed Shehab, Saeed Al-Haj, Salil Bhagurkar, Ehab Al-Shaer |
DEXA (2) | 4 |
| 2012 | SmartAnalyzer: A noninvasive security threat analyzer for AMI smart gridabstractThe Advanced Metering Infrastructure (AMI) is the core component in smart grid that exhibits highly complex network configurations comprising of heterogeneous cyber-physical components. These components are interconnected through different communication media, protocols, and secure tunnels, and they are operated using different data delivery modes and security policies. The inherent complexity and heterogeneity in AMI significantly increase the potential of security threats due to misconfiguration or absence of defense, which may cause devastating damage to AMI. Therefore, there is a need of creating a formal model that can represent the global behavior of AMI configuration in order to verify the potential threats. In this paper, we present SmartAnalyzer, a formal security analysis tool, which offers manifold contributions: (i) formal modeling of AMI configuration including device configurations, topology, communication properties, interactions between the devices, data flows, and security properties; (ii) formal modeling of AMI invariant and user-driven constraints based on the interdependencies between AMI device configurations, security properties, and security control guidelines; (iii) verifying the AMI configuration's compliances with security constraints using Satisfiability Modulo Theory (SMT) solver; (iv) generating a comprehensive security threat report with possible remediation plan based on the verification results. The accuracy, scalability, and usability of the tool are evaluated on real smart grid environment and synthetic test networks. Mohammad Ashiqur Rahman, Padmalochan Bera, Ehab Al-Shaer |
INFOCOM | 3 |
| 2012 | On stochastic risk ordering of network services for proactive security managementabstractContemporary network services don't have any statistical ranking mechanism for proactive security management. Since the emerging threats are actively exploiting the vulnerabilities in network services to compromise the system, not much attention has been paid to rank these services based on their vulnerability history. We argue in this paper that a reliable mechanism could be used to rank these services based on their vulnerability history. Such ranking will be significantly helpful for proactive network security management to partition services and deploy security countermeasures. We propose a framework using stochastic order alternatives to statistically rank network services based on time intervals between exploits as reported by National Vulnerability Database (NVD). We show that Statistical techniques can be used to rank these services by modeling the related metrics. We validated our technique using products of known ranking, and presented some case studies to confirm our result on real network services. Mohamed Amezziane, Ehab Al-Shaer, Muhammad Qasim Ali |
NOMS | 2 |
| 2012 | An evasive attack on SNORT flowbitsabstractThe support of stateful signatures is an important feature of signature-based Network Intrusion Detection Systems (NIDSs) which permits the detection of multi-stage attacks. However, due to the difficulty to completely simulate every application protocol, several NIDS evasion techniques exploit this Achilles' heel, making the NIDS and its protected system see and explain a packet sequence differently. In this paper, we propose an evasion technique to the Snort NIDS which exploits its flowbits feature. We specify the flowbit evasion attack and provide practical algorithms to solve it with controllable false positives and formally prove their correctness and completeness. We implemented a tool called SFET which can automatically parse a Snort rule set, generate all possible sequences that can evade it, as well as produce a patch to guard the rule set against those evasions. Although Snort was used for illustration, both the evasion attack and the solution to it are applicable to any stateful signature-based NIDS. Tung Tran 0002, Issam Aib, Ehab Al-Shaer, Raouf Boutaba |
NOMS | 3 |
| 2012 | Random Host Mutation for Moving Target Defense
Ehab Al-Shaer, Qi Duan, Jafar Haadi Jafarian |
SecureComm | 1 |
| 2012 | Secure Distributed Solution for Optimal Energy Consumption Scheduling in Smart GridabstractThe demand-side energy management is crucial to optimize the energy usage with its production cost, so that the price paid by the users is minimized, while it also satisfies the demand. The recent proposed solutions leverage the two- way communication infrastructure provided by modern smart- meters. The demand management problem assumes that users can shift their energy usage from peak hours to off-peak hours with the goal of balancing the energy usage. The scheduling of the energy consumption is often formulated as a game- theoretic problem, where the players are the users and their strategies are the load schedules of their household appliances. The Nash equilibrium of the formulated game provides the global optimal performance (i.e., the minimum energy costs). To provide a distributed solution the users require to share their usage information with the other users to converge to the Nash equilibrium. Hence, this open sharing among users introduces potential privacy and security issues. In addition, the existing solutions assume that all the users are rational and truthful. In this paper, we first highlight the privacy and security issues involved in the distributed demand management protocols. Secondly, we propose an efficient clustering based multi-party computation (MPC) distributed protocol that enables users to share their usage schedules and at the same time preserve their privacy and confidentiality. To identify untruthful users, we propose a mechanism based on a third party verifier. Through simulation experiments we have demonstrated the scalability and efficiency of our proposed solution. Mohammad Ashiqur Rahman, Libin Bai, Mohamed Shehab, Ehab Al-Shaer |
TrustCom | 4 |
| 2012 | Fuzzy Conflict Analysis for QoS Policy Parameters in DiffServ NetworksabstractPolicy-based network management is a necessity for managing large-scale environments. It provides the means for separating high-level system requirements from the actual implementation. As the network size increases, the need for automated tools to perform management becomes more apparent. But configuring routers and network devices to achieve QoS goals is a challenging task. Using Differentiated Services to dynamically perform this configuration involves defining policies on different network nodes in multiple domains. Policy aggregation across domains requires a unified policy model that can overcome the challenge of conflict detection and resolution. In this work, we propose a unified model to represent and encode QoS policies. This model enables efficient and flexible conflict analysis. The representation utilizes a bottom-up approach, from the base policy parameters to the aggregation of policies across domains with respect to traffic classes. We also present a classification of these conflicts and a measure of conflicts to assess the severity of any misconfiguration. The model and the conflict measure are evaluated with large networks and different topologies. Taghrid Samak, Ehab Al-Shaer |
IEEE Trans. Netw. Serv. Manag. | 2 |
| 2012 | Reasoning under Uncertainty for Overlay Fault DiagnosisabstractThe performance and reliability of overlay services rely on the underlying overlay network's ability to effectively diagnose and recover from faults such as link failures and overlay node outages. However, overlay networks bring to fault diagnosis new challenges such as large-scale deployment, inaccessible underlay network information, dynamic symptom-fault causality relationship, and multi-layer complexity. In this paper, we develop an evidential overlay fault diagnosis framework called DigOver to tackle these challenges. Firstly, DigOver identifies a set of potential faulty components based on shared end-user observed negative symptoms. Then, each potential faulty component is evaluated to quantify its fault likelihood and the corresponding evaluation uncertainty. Finally, DigOver dynamically constructs a plausible fault graph to locate the root causes of end-user observed negative symptoms. Both simulation and Internet experiments demonstrate that DigOver can effectively and accurately diagnose overlay faults based on end-user observed negative symptoms. Yongning Tang, Ehab Al-Shaer, Kaustubh R. Joshi |
IEEE Trans. Netw. Serv. Manag. | 2 |
| 2011 | On synthesizing distributed firewall configurations considering risk, usability and cost constraints
Bin Zhang 0007, Ehab Al-Shaer |
CNSM | 2 |
| 2011 | A declarative approach for global network security configuration verification and evaluationabstractWith the increasing number of security devices and rules in the network, the complexity of detecting and tracing network security configuration errors become a very challenging task. This in turn increases the potential of security breaches due to rule conflicts, requirement violations or lack of security hardening. Most of the existing tools are either limited in scope as they do not offer a global analysis of different network devices or hard to comprehensively use because these tools are not declarative. Declarative logic programming can readily express network configurations and security requirements for verification analysis. In this paper, we use Prolog to model the entire network security configurations including topology, routing, firewall and IPSec. This is implemented in a tool called ConfigAnalyzer, which was also evaluated with large network and policy sizes. The tool allows for verifying reachability and security properties in flexible and expressive manner. It also allows for evaluating security configurations in terms of accessibilities credentials and rules. Mohammad Ashiqur Rahman, Ehab Al-Shaer |
Integrated Network Management | 2 |
| 2011 | QoS policy verification for DiffServ networksabstractConfiguring routers and network devices to achieve quality of service (QoS) goals is a challenging task. In a DiffServ environment, traffic flows are assigned specific classes of service, and service level agreements (SLA) are enforced at routers within the domain. We present a model for QoS policy con figurations that facilitates efficient property-based verification. Network configuration is given as a set of policies governing each device. The model efficiently checks the SLA against the current configuration using computation tree logic model checking. By following possible decision paths for a specific flow from source to destination, properties can be checked at each hop, and assessments can be made on how well configurations adhere to the specified agreement. The model also covers configuration debugging given a specific QoS violation. Taghrid Samak, Adel El-Atawy, Ehab Al-Shaer |
IWQoS | 3 |
| 2011 | Build and Test Your Own Network Configuration
Saeed Al-Haj, Padmalochan Bera, Ehab Al-Shaer |
SecureComm | 3 |
| 2011 | A potential low-rate DoS attack against network firewallsabstractAbstract In this paper we identify a potential Denial of Service (DoS) attack that targets the last‐matching rules of the security policy of a firewall. The last‐matching rules are those rules that are located at the bottom of the ruleset of a firewall's security policy, and would require the most processing time by the firewall. If these rules are discovered, an attacker can potentially launch an effective low‐rate DoS attack to trigger worst‐case or near worst‐case processing, thereby overwhelming the firewall and bringing it to its knees. In this paper, we present a probing technique to remotely discover the last‐matching rules of a firewall. We study experimentally the effectiveness of this probing technique taking into account important factors such as the firewall's motherboard architecture and load conditions at network links and hosts. In addition we examine the impact of launching a low‐rate DoS attack on a firewall's performance. The performance is studied in terms of the firewall's CPU utilization and throughput, packet loss, and latency. Copyright © 2009 John Wiley & Sons, Ltd. Khaled Salah 0001, Karim Sattar, Mohammed H. Sqalli, Ehab Al-Shaer |
Secur. Commun. Networks | 4 |
| 2010 | Towards Automatic Creation of Usable Security ConfigurationabstractThe objective of this work is to create usable security architecture that will minimize network risk while considering usability and budget. We propose and formulate a novel framework for automatic creation of network security architecture including configuration rules and device placements in order to minimize risk while satisfying the business requirements, service usability and budget constraints. Our framework also automates the creation of external and internal Demilitarized Zones (DMZ) to improve security by increasing isolation. We formalize this as an optimization problem and show that it is NP-hard. We then provide heuristic approximation algorithms. The implemented systems, called SecBuilder, were evaluated under different network sizes, topologies and security requirements. Our evaluation study shows that the results obtained by SecBuilder are close to the theoretical lower bound and the performance is scalable with the network size. Bin Zhang 0007, Ehab Al-Shaer |
INFOCOM | 2 |
| 2010 | Automated management of network access control from design to enforcementabstractRecent studies show that more than 65% of the network vulnerabilities are due to misconfigured network access control. Arbor Networks in their ISP survey shows that managing access control is the top challenge in ISP networks today, which creates major reachability and security violations such as unauthorized access/traffic, backdoors and increasing attack surface [1]. Access control exists in network devices such as routers, firewall and IPSec gateways and application-level such RBAC systems and authorization servers. The wide distribution of large number of access control configurations that usually exhibit different syntactic and semantic behavior in highly dynamic network environments creates real challenges for verifying, evaluating and enforcing access control policies. Thus, there is a pressing need for models and tools that allow for global end-toend analysis of access control by integrating network and application-level access control in a single framework from design, verification and optimization to evaluation and deployment. These frameworks should also provide quantitative means to design and evaluate access control automatically and objectively [2, 3]. In addition, as security risk is dynamically changing in networks due to new threats or users' behavior, enabling proactive access control will play an important role in future network defense. In this talk, I will present the state-of-the-art and discuss future challenges of designing, verification and evaluation of access control policies. Ehab Al-Shaer |
SACMAT | 1 |
| 2009 | TimeVM: a framework for online intrusion mitigation and fast recovery using multi-time-lag traffic replayabstractNetwork intrusions become a signification threat to network servers and its availability. A simple intrusion can suspend the organization's network services and can lead to a financial disaster. In this paper, we propose a framework called TimeVM to mitigate, or even eliminate, the infection of a network intrusion on-line as fast as possible. The framework is based on the virtual machine technology and traffic-replay-based recovery. TimeVM gives the illusion of "time machine". TimeVM logs only the network traffic to a server and replays the logged traffic to multiple "shadow" virtual machines (Shadow VM) after different time delays (time lags). Consequently, each Shadow VM will represent the server at different time in history. When attack/infection is detected, TimeVM enables navigating through the traffic history (logs), picking uninfected Shadow VM, removing the attack traffic, and then fast-replaying the entire traffic history to this Shadow VM. As a result, a typical up-to-date uninfected version of the original system can be constructed. Khalid Elbadawi, Ehab Al-Shaer |
AsiaCCS | 2 |
| 2009 | Sharing end-user negative symptoms for improving overlay network dependabilityabstractThe dependability of overlay services rely on the overlay network's capabilities to effectively diagnose and recover faults (e.g., link failures, overlay node outages). However, overlay applications bring to overlay fault diagnosis new challenges, which include large-scale deployment, inaccessible underlying network information, dynamic symptom-fault causality relationship, and multi-layer complexity. In this paper, we develop an evidential overlay fault diagnosis framework (called DigOver) to tackle these challenges. Firstly, the DigOver identifies a set of potential faulty components based on shared end-user observed negative symptoms. Then, each potential faulty component is evaluated to quantify its fault likelihood and the corresponding evaluation uncertainty. Finally, the DigOver dynamically constructs a plausible fault graph to locate the root causes of end-user observed negative symptoms. Yongning Tang, Ehab Al-Shaer |
DSN | 2 |
| 2009 | Information Theoretic Approach for Characterizing Spam Botnets Based on Traffic PropertiesabstractIn this paper, we present several novel identifying characteristics of spam-sending bots (or spambots) based on traffic statistics. We use the entropy to measure the distribution skewness for a number of traffic features including packet inter-departure time, email per recipients, rate of change in recipient list and destination domains, and inconsistency in email header information of the outgoing email traffic. We also show how we can measure the deviation in these features from benign emails traffic to decisively detect spambots. Our tool is developed to sit anonymously behind the mail server in a network, capturing SMTP data packets and analyzing the traffic while keeping all of the personal email data private and unrecoverable. Unlike content filtering, our technique is hard to evade and used to detect spam email close to the source. In addition, our technique uses online light weight calculations and can be efficiently deployed in the end-user or ISP devices as well. We evaluated our technique using about 6 million email records of real spambot traffic collected during June 2007 - June 2008. Our evaluation results show that our tool can detect spambots accurately and efficiently even with high traffic volume. Kyle Smith, Ehab Al-Shaer, Khalid Elbadawi |
ICC | 2 |
| 2009 | Network Configuration in A Box: Towards End-to-End Verification of Network Reachability and SecurityabstractRecent studies show that configurations of network access control is one of the most complex and error prone network management tasks. For this reason, network misconfiguration becomes the main source for network unreachablility and vulnerability problems. In this paper, we present a novel approach that models the global end-to-end behavior of access control configurations of the entire network including routers, IPSec, firewalls, and NAT for unicast and multicast packets. Our model represents the network as a state machine where the packet header and location determines the state. The transitions in this model are determined by packet header information, packet location, and policy semantics for the devices being modeled. We encode the semantics of access control policies with Boolean functions using binary decision diagrams (BDDs). We then use computation tree logic (CTL) and symbolic model checking to investigate all future and past states of this packet in the network and verify network reachability and security requirements. Thus, our contributions in this work is the global encoding for network configurations that allows for general reachability and security property-based verification using CTL model checking. We have implemented our approach in a tool called ConfigChecker. While evaluating ConfigChecker, we modeled and verified network configurations with thousands of devices and millions of configuration rules, thus demonstrating the scalability of this approach. Ehab Al-Shaer, Wilfredo Marrero, Adel El-Atawy, Khalid Elbadawi |
ICNP | 1 |
| 2009 | Optimizing correlation structure of event services considering time and capacity constraintsabstractConstructing optimal event correlation architecture is crucial to large-scale event services. It plays an instrumental role in detecting composite events requested by different subscribers in scalable and timely manner. However, events generated from different sources might have different time and priority requirements. In addition, the network links and correlation servers might have different bandwidth and processing constraints respectively. In this work, we address the problem of optimizing distributed event correlation to maximize the correlation profit (benefit minus shipping and processing cost) of detecting composite events, while at the same time satisfying the network bandwidth, node capacity, and correlation tasks time constrains. We show that this problem is NP-hard and provide a heuristic approximation algorithm. We evaluate our heuristic approach with different network sizes, topologies under different event delivery and detection requirements. Our simulation study shows that the results obtained by our heuristic are close to the upper bound. Bin Zhang 0007, Ehab Al-Shaer |
Integrated Network Management | 2 |
| 2009 | Building Covert Channels over the Packet Reordering PhenomenonabstractNew modes of communication have shown themselves to be needed for more secure and private types of data. Steganography or data-hiding through covert channels can be highly motivated by today’s security requirements and various needs of applications. Moreover, the amount of information in the Internet traffic is not bounded by what is contained in packets payload; there is considerable hidden capacity within packets and flows characteristics to build robust and stealthy covert channels. In this paper, we propose using the packet reordering phenomenon as the media to carry a hidden channel. As a naturally occurring behavior of packets traveling the Internet, it can as well be induced to send a signal to the receiving end. Specific permutations are selected to enhance the reliability of the channel, while their distribution was selected to imitate real traffic and increase stealthiness. The robustness of such channel is analyzed, and its bandwidth is calculated. A simple tool is implemented to communicate over the natural phenomenon of packet reordering. Reliability and capacity of the techniques are evaluated and promising results show the potential of the proposed approach. Adel El-Atawy, Ehab Al-Shaer |
INFOCOM | 2 |
| 2009 | Adaptive Early Packet Filtering for Defending Firewalls Against DoS AttacksabstractA major threat to data networks is based on the fact that some traffic can be expensive to classify and filter as it will undergo a longer than average list of filtering rules before being rejected by the default deny rule. An attacker with some information about the access-control list (ACL) deployed at a firewall or an intrusion detection and prevention system (IDS/IPS) can craft packets that will have maximum cost. In this paper, we present a technique that is light weight, traffic-adaptive and can be deployed on top of any filtering mechanism to pre-filter unwanted expensive traffic. The technique utilizes Internet traffic characteristics coupled with a special carefully tuned representation of the policy to generate early defense policies. We use Boolean expressions built as binary decision diagrams (BDD) to represent relaxed versions of the policy that are faster to evaluate. Moreover, it is guaranteed that the technique will not add an overhead that will not be compensated by the gain in filtering time in the underlying filtering method. Evaluation has shown considerable savings to the overall filtering process, thus saving the firewall processing power and increasing overall throughput. Also, the overhead changes according to the traffic behavior, and can be tuned to guarantee its worst case time cost. Adel El-Atawy, Ehab Al-Shaer, Tung Tran 0002, Raouf Boutaba |
INFOCOM | 2 |
| 2009 | Overlay Fault Diagnosis Based on Evidential ReasoningabstractThe attractive characteristics of overlay networks bring to overlay fault diagnosis new challenges, which include inaccessible underlying network information, incomplete and inaccurate network status observations, dynamic symptom-fault causality relationship, and multi-layer complexity. To address these challenges, we propose a novel evidential reasoning based overlay fault diagnosis technique called ERD. Firstly, by analyzing end-user observed network symptoms, ERD narrows down suspicious components, and investigates their status (i.e., good or bad) with likelihood measurement and uncertainty evaluation using a novel evidence-driven belief function. Next, ERD adapts to the changes in highly dynamic overlay networks by dynamically constructing plausible fault diagnosis graph based on belief evaluation. Finally, ERD conducts plausible fault reasoning to locate the root causes of observed network symptoms. Yongning Tang, Ehab Al-Shaer |
INFOCOM | 2 |
| 2009 | Community-base Fault Diagnosis Using Incremental Belief RevisionabstractOverlay networks have emerged as a powerful and flexible platform for developing new disruptive network applications. The attractive characteristics of overlay networks such as planetary-scale distributions, user-level flexibility (e.g., overlay routing) and manageability bring to overlay fault diagnosis new challenges, which include inaccessible underlying network information, incomplete and inaccurate network status observations; dynamic symptom-fault causality relationships, and multi-layer complexity. To address these challenges, we propose a distributed user-level Belief Revision based overlay fault diagnosis technique called EUDiag. EUDiag can passively use observed overlay symptoms as reported by overlay monitoring agents to correlate and diagnose faults, and select the least-costly appropriate probing actions whenever necessary to enhance the passive fault reasoning results. EUDiag adapts to the changes in highly dynamic overlay networks by incrementally revising user beliefs based on new observed overlay symptoms. EUDiag can diagnose faults without relying on underlying network fault probabilistic quantifications (e.g. prior fault probability).Simulations and experimental studies show that EUDiag can efficiently (e.g. low latency) and accurately localize root causes of overlay faults/problems, even when the observed symptoms are incomplete. Yongning Tang, Guang Cheng 0001, Zhiwei Xu 0001, Ehab Al-Shaer |
NAS | 4 |
| 2009 | Automated pseudo-live testing of firewall configuration enforcementabstractNetwork security devices such as firewalls and intrusion detection systems are constantly updated in their implementation to accommodate new features, performance standards and to utilize new hardware optimization. Reliable, yet practical, testing techniques for validating the configuration enforcement after every new software and firmware update become necessary to assure correct configuration realization. Generating random traffic to test the firewall configuration enforcement is not only inaccurate but also impractical as it requires an infeasible number of test cases for a reasonable testing coverage. In addition, in most cases the policies used during testing are manually generated or have limited configuration profiles. We present a framework for automatic testing of the firewall configuration enforcement using efficient and flexible policy and traffic generation. In a typical test session, a large set of different policies are generated based on the access-control list (ACL) grammar and according to custom profiles. Test packets are generated to particularly consider critical segments of the tested policies and to achieve high coverage of the testing space. We also describe our implementation of a fully-automated framework, which includes ACL grammar modeling, the policy generation, test cases generation, capturing and analyzing firewall output, and creating detailed test reports. Our evaluation results show that our security configuration testing is not only achievable but it also offers high coverage with significant degree of confidence. Ehab Al-Shaer, Adel El-Atawy, Taghrid Samak |
IEEE J. Sel. Areas Commun. | 1 |
| 2008 | A Novel Quantitative Approach For Measuring Network SecurityabstractEvaluation of network security is an essential step in securing any network. This evaluation can help security professionals in making optimal decisions about how to design security countermeasures, to choose between alternative security architectures, and to systematically modify security configurations in order to improve security. However, the security of a network depends on a number of dynamically changing factors such as emergence of new vulnerabilities and threats, policy structure and network traffic. Identifying, quantifying and validating these factors using security metrics is a major challenge in this area. In this paper, we propose a novel security metric framework that identifies and quantifies objectively the most significant security risk factors, which include existing vulnerabilities, historical trend of vulnerability of the remotely accessible services, prediction of potential vulnerabilities for any general network service and their estimated severity and finally policy resistance to attack propagation within the network. We then describe our rigorous validation experiments using real- life vulnerability data of the past 6 years from National Vulnerability Database (NVD) [10] to show the high accuracy and confidence of the proposed metrics. Some previous works have considered vulnerabilities using code analysis. However, as far as we know, this is the first work to study and analyze these metrics for network security evaluation using publicly available vulnerability information and security policy configuration. Mohammad Salim Ahmed, Ehab Al-Shaer, Latifur Khan |
INFOCOM | 2 |
| 2008 | Towards Collaborative User-Level Overlay Fault DiagnosisabstractOverlay networks have emerged as a powerful and flexible platform for developing new disruptive network applications. The attractive characteristics of overlay networks such as planetary-scale distributions, user-level flexibility (e.g. overlay routing) and manageability bring to overlay fault diagnosis new challenges, which include inaccessible underlying network information, incomplete and inaccurate network status observations; dynamic symptom-fault causality relationships, and multi-layer complexity. To address these challenges, we propose a collaborative overlayUserObservationbased fault diagnosis technique called OUD. OUD can passively use observed overlay symptoms as reported by overlay monitoring agents to correlate multiple users' observations to diagnose faults. OUD can diagnose faults without relying on underlying network fault probabilistic quantifications (e.g. prior fault probability). Simulations and experimental studies show that OUD can efficiently (e.g. low latency) and accurately localize root causes of overlay faults/problems, even when the observed symptoms are incomplete. Yongning Tang, Ehab Al-Shaer |
INFOCOM | 2 |
| 2008 | Towards autonomic risk-aware security configurationabstractSecurity of a network depends on a number of dynamically changing factors. These include emergence of new vulnerabilities and threats, policy structure and network traffic. Due to the dynamic nature of these factors, identifying security metrics that measure objectively the quality of security configuration pose a major challenge. Moreover, this evaluation must be done dynamically to handle real time changes in the threat toward the network. In this paper, we extend our security metric framework [2] that identifies and quantifies objectively the most significant security risk factors, which include existing vulnerabilities, historical trend of vulnerabilities of remotely accessible services, prediction of potential vulnerabilities for any general network service and their estimated severity and finally propagation of an attack within the network. We have implemented this framework as a user-friendly tool called Risk based prOactive seCurity cOnfiguration maNAger (ROCONA) and showed how this tool simplifies security configuration management using risk measurement and mitigation. Mohammad Salim Ahmed, Ehab Al-Shaer, Mohamed Mahmoud Taibah, Muhammad Arshad Ul Abedin, Latifur Khan |
NOMS | 2 |
| 2008 | Designing, optimizing, and evaluating network security configuration
Ehab Al-Shaer |
NOMS | 1 |
| 2008 | Alert prioritization in Intrusion Detection SystemsabstractIntrusion Detection Systems (IDSs) are designed to monitor user and/or network activity and generate alerts whenever abnormal activities are detected. The number of these alerts can be very large; making the task of security analysts difficult to manage. Furthermore, IDS alert management techniques, such as clustering and correlation, suffer from involving unrelated alerts in their processes and consequently provide imprecise results. In this paper, we propose a fuzzy-logic based technique for scoring and prioritizing alerts generated by an IDS(1). In addition, we present an alert rescoring technique that leads to a further reduction of the number of alerts. The approach is validated using the 2000 DARPA intrusion detection scenario specific datasets and comparative results between the Snort IDS alert scoring and our scoring and prioritization scheme are presented. Khalid Alsubhi, Ehab Al-Shaer, Raouf Boutaba |
NOMS | 2 |
| 2008 | Autonomic QoS optimization of real-time internet audio using loss prediction and stochastic controlabstractQuality of Internet audio is highly sensitive to packet loss caused by congestion in the links. Packet loss for audio is normally rectified by adding redundancy using forward error correction (FEC). Alternatively, path diversity mechanisms are used to improve reliability and thus session quality. To achieve optimized receiver audio quality for transmissions using single or multiple paths, we propose a self-adaptive joint error and rate control framework based on packet loss prediction and on-line quality assessment. The error control chooses proactive FEC to preserve quality with optimal bandwidth, using a Markov decision process (MDP) and a stochastic inventory control, a new approach for multimedia error recovery. The rate control uses a quality optimization model to determine the optimal dispersion over single or multiple paths. We present results using simulation and Internet experiments to show the superiority of our mechanism over other similar techniques. Lopamudra Roychoudhuri, Ehab Al-Shaer |
NOMS | 2 |
| 2008 | Correlation-based load balancing for network intrusion detection and prevention systemsabstractIn large-scale enterprise networks, multiple network intrusion detection and prevention systems are used to provide high quality protections. In this context, keeping load evenly distributed among the systems is crucial. This is because even load distributions provide protection to the networks and improve the networks' quality of service.A challenging problem, however, is to maintain the load balancing of the systems while minimizing the loss of correlation information due to distributing traffic. Since anomaly- based detection and prevention of some intrusions, such as distributed denial of service (DDoS) attacks and port scans, require a single system to analyze correlated flows of the attacks, this loss of correlation information might severely affect the accuracy of the detections and preventions.In this paper, we address this challenging problem by first formalizing the load balancing problem as an optimization problem, considering both the systems' load variance and the correlation information loss. We then present our Benefit-based Load Balancing (BLB) algorithm as a solution to the optimization problem.We have implemented a prototype load-balancer which uses the BLB algorithm. We evaluated the load-balancer against various port scans and DDoS attacks. The evaluation results show that our load-balancer significantly improves the detection accuracy of these attacks while keeping the systems' load close within a desired bound. Raouf Boutaba, Ehab Al-Shaer |
SecureComm | 3 |
| 2008 | Efficient fault diagnosis using incremental alarm correlation and active investigation for internet and overlay networksabstractFault localization is the core element in fault management. Symptom-fault map is commonly used to describe the symptom-fault causality in fault reasoning. For Internet service networks, a well-designed monitoring system can effectively correlate the observable symptoms (i.e., alarms) with the critical network faults (e.g., link failure). However, the lost and spurious symptoms can significantly degrade the performance and accuracy of a passive fault localization system. For overlay networks, due to limited underlying network accessibility, as well as the overlay scalability and dynamics, it is impractical to build a static overlay symptom-fault map. In this paper, we firstly propose a novel active integrated fault reasoning (AIR) framework to incrementally incorporate active investigation actions into the passive fault reasoning process based on an extended symptom-fault-action (SFA) model. Secondly, we propose an overlay network profile (ONP) to facilitate the dynamic creation of an overlay symptom-fault-action (called O-SFA) model, such that the AIR framework can be applied seamlessly to overlay networks (called O-AIR). As a result, the corresponding fault reasoning and action selection algorithms are elaborated. Extensive simulations and Internet experiments show that AIR and O-AIR can significantly improve both accuracy and performance in the fault reasoning for Internet and overlay service networks, especially when the ratio of the lost and spurious symptoms is high. Yongning Tang, Ehab Al-Shaer, Raouf Boutaba |
IEEE Trans. Netw. Serv. Manag. | 2 |
| 2007 | FireCracker: A Framework for Inferring Firewall Policies using Smart ProbingabstractA firewall policy that is correct and complete is crucial to the safety of a computer network. An adversary will benefit a lot from knowing the policy or its semantics. In this paper, we propose a framework that could be used to blindly discover a firewall policy remotely as a black box and without prior knowledge about the network configuration. We show how an attacker can reconstruct a firewall's policy by probing the firewall with tailored packets into a network and forming an idea of what the policy looks like. The proposed methodology shows how to discover a policy that is semantically equivalent to the original one used in the deployed firewall. Three techniques are proposed for reconstructing the policy as well as to intelligently choose the probing packets adaptively based on the firewall response. We show the possibility of obtaining the deployed policy in a feasible time with acceptable accuracy. Taghrid Samak, Adel El-Atawy, Ehab Al-Shaer |
ICNP | 3 |
| 2007 | Toward Globally Optimal Event Monitoring & Aggregation For Large-scale Overlay NetworksabstractOverlay networks have emerged as a powerful and flexible platform for developing new disruptive network applications. The performance and reliability of overlay applications depend on the capability of overlay networks to dynamically adapt to various factors such as link/node failures, overlay link quality, and overlay node characteristics. In order to achieve this, the overlay applications require scalable and open overlay monitoring services to monitor, aggregate globally distributed events and take appropriate control actions. In this paper, we propose the techniques and algorithms to create an optimal event monitoring and aggregation infrastructure (called MOON) that minimizes the monitoring latency (i.e., event retrival/detection time) and event aggregation cost (i.e., intrusiveness) considering the large-scale geographical and network distribution of overlay nodes. The proposed monitoring infrastructure, MOON, clusters and organizes overlay nodes efficiently such that overlay applications can globally monitor and query correlated events in an overlay network with minimum latency and monitoring cost. Our simulations and experimental studies show the evaluation of MOON under many various topological structures, network sizes, and event aggregation volumes. Yongning Tang, Ehab Al-Shaer, Bin Zhang 0007 |
Integrated Network Management | 2 |
| 2007 | Using Online Traffic Statistical Matching for Optimizing Packet Filtering PerformanceabstractPacket classification plays a critical role in many of the current networking technologies, and efficient yet lightweight packet classification techniques are highly crucial for their successful deployment. Most of the current packet classification techniques exploit the characteristics of classification policies, without considering the traffic behavior in optimizing their search data structures. In this paper, we present novel techniques that utilize traffic characteristics coupled with careful analysis of the policy to obtain adaptive methods that can accommodate varying traffic statistics while maintaining a high throughput. The first technique uses segmentation of the traffic space to achieve disjoint subsets of traffic properties and build bounded depth Huffman trees using the statistics collected for these segments. The second technique simplifies the structure maintenance by keeping the segments ordered in a most-recently-used (MRU) list instead of a tree. The techniques are evaluated and their performance are compared. Moreover, attacks targeting the firewall performance are discussed and corresponding protection schemes are presented. Adel El-Atawy, Taghrid Samak, Ehab Al-Shaer |
INFOCOM | 3 |
| 2007 | Ranking-Based Optimal Resource Allocation in Peer-to-Peer NetworksabstractThis paper presents a theoretic framework of optimal resource allocation and admission control for peer-to-peer networks. Peer's behavioral rankings are incorporated into the resource allocation and admission control to provide differentiated services and even to block peers with bad rankings. These peers may be free-riders or suspicious attackers. A peer improves her ranking by contributing resources to the P2P system or deteriorates her ranking by consuming services. Therefore, the ranking-based resource allocation provides necessary incentives for peers to contribute their resources to the P2P systems. We define a utility function which captures the best wish for the source peer to serve competing peers, who request services from the source peer. Although the utility function is convex, Harsanyi-type social welfare functions are devised to obtain a unique optimal resource allocation that achieves max-min fairness. The parameters used in our model can be derived from the nature of the services or chosen by the source peer. No private information is required to reveal from individual peers. This prevents selfish peers to play the system strategically and cheat the resource allocation mechanism for their own benefits. The resource allocation and admission control are fully distributed and linearly scalable. Yonghe Yan, Adel El-Atawy, Ehab Al-Shaer |
INFOCOM | 3 |
| 2007 | PolicyVis: Firewall Security Policy Visualization and Inspection
Tung Tran 0002, Ehab Al-Shaer, Raouf Boutaba |
LISA | 2 |
| 2007 | Specifications of a high-level conflict-free firewall policy language for multi-domain networksabstractMultiple firewalls typically cooperate to provide security properties for a network, despite the fact that these firewalls are often spatially distributed and configured in isolation. Without a global view of the network configuration, such a system is ripe for misconfiguration, causing conflicts and major security vulnerabilities. Bin Zhang 0007, Ehab Al-Shaer, Radha Jagadeesan, James Riely, Corin Pitcher |
SACMAT | 2 |
| 2006 | Dynamic rule-ordering optimization for high-speed firewall filteringabstractPacket filtering plays a critical role in many of the current high speed network technologies such as firewalls and IPSec devices. The optimization of firewall policies is critically important to provide high performance packet filtering particularly for high speed network security. Current packet filtering techniques exploit the characteristics of the filtering policies, but they do not consider the traffic behavior in optimizing their search data structures. This results in impractically high space complexity, which undermines the performance gain offered by these techniques. Also, these techniques offer upper bounds for the worst case search times; nevertheless, average case scenarios are not necessarily optimized. Moreover, the types of packet filtering fields used in most of these techniques are limited to IP header fields and cannot be generalized to cover transport and application layer filtering.In this paper, we present a novel technique that utilizes Internet traffic characteristics to optimize firewall filtering policies. The proposed technique timely adapts to the traffic conditions using actively calculated statistics to dynamically optimize the ordering of packet filtering rules. The rule importance in traffic matching as well as its dependency on other rules are both considered in our optimization algorithm. Through extensive evaluation experiments using simulated and real Internet traffic traces, the proposed mechanism is shown to be efficient and easy to deploy in practical firewall implementations. Hazem H. Hamed, Ehab Al-Shaer |
AsiaCCS | 2 |
| 2006 | Adaptive Statistical Optimization Techniques for Firewall Packet FilteringabstractAbstract — Packet filtering plays a critical role in the performance of many network devices such as firewalls, IPSec gateways, DiffServ and QoS routers. A tremendous amount of research was proposed to optimize packet filters. However, most of the related works use deterministic techniques and do not exploit the traffic characteristics in their optimization schemes. In addition, most packet classifiers give no specific consideration for optimizing packet rejection, which is important for many filtering devices like firewalls. Our contribution in this paper is twofold. First, we present a novel algorithm for maximizing early rejection of unwanted flows without impacting other flows significantly. Second, we present a new packet filtering optimization technique that uses adaptive statistical search trees to utilizes important traffic characteristics and minimize the average packet matching time. The proposed techniques timely adapt to changes in the traffic conditions by performing simple calculations for optimizing the search data structure. Our techniques are practically attractive because they exhibit simple-to-implement and easy-to-deploy algorithms. Our extensive evaluation study using Internet traces shows that the proposed techniques can significantly minimize the packet filtering time with reasonable memory space requirements. I. Hazem H. Hamed, Adel El-Atawy, Ehab Al-Shaer |
INFOCOM | 3 |
| 2006 | Email Worm Detection Using Naïve Bayes and Support Vector Machine
Mohammad M. Masud 0001, Latifur Khan, Ehab Al-Shaer |
ISI | 3 |
| 2006 | Analysis of Firewall Policy Rules Using Data Mining TechniquesabstractFirewall is the de facto core technology of today's network security and defense. However, the management of firewall rules has been proven to be complex, error-prone, costly and inefficient for many large-networked organizations. These firewall rules are mostly custom-designed and hand-written thus in constant need for tuning and validation, due to the dynamic nature of the traffic characteristics, ever-changing network environment and its market demands. One of the main problems that we address in this paper is that how much the firewall rules are useful, up-to-dated, well-organized or efficient to reflect the current characteristics of network traffics. In this paper, we present a set of techniques and algorithms to analysis and manage firewall policy rules: (1) Data Mining technique to deduce efficient firewall policy rules by mining its network traffic log based on its frequency, (2) Filtering-Rule Generalization (FRG) to reduce the number of policy rules by generalization, and (3) a technique to identify any decaying rule and a set of few dominant rules, to generate a new set of efficient firewall policy rules. The anomaly detection based on the mining exposes many hidden but not detectable by analyzing only the firewall policy rules, resulting in two new types of the anomalies. As a result of these mechanisms, network security administrators can automatically review and update the rules. We have developed a prototype system and demonstrated usefulness of our approaches. Korosh Golnabi, Richard K. Min, Latifur Khan, Ehab Al-Shaer |
NOMS | 4 |
| 2006 | Fair Bandwidth Allocation under User Capacity ConstraintsabstractIn this paper, we present a theoretical framework and a distributed mechanism for fair bandwidth allocation on a network with various bottleneck links. In our model, a user is guaranteed a minimum bandwidth and charged a price for a bandwidth capacity request. We defined a utility function that reflects user's bandwidth demand when the user requests the bandwidth capacity. We then present a non-cooperative game with social welfare function to resolve users' conflicting bandwidth capacity requests at bottleneck links. We also show that our proposed game-theoretic solution guarantees fair bandwidth allocation as defined in our residual capacity fairness. In order to guarantee the minimum bandwidth requirement, we integrate an admission control in our solution. However, global optimal admission conditions are not easy to implement for large networks. We therefore propose a distributed admission scheme. As a result, the paper presents fair and practical distributed algorithms for bandwidth allocation and admission control in enterprise networks. Our simulation and evaluation study show that the distributed approach is sufficiently close to the global optimal solution. Yonghe Yan, Adel El-Atawy, Ehab Al-Shaer |
NOMS | 3 |
| 2006 | Special issue: monitoring and measurements of IP networks
Raouf Boutaba, Ehab Al-Shaer, Kevin C. Almeroth |
Comput. Commun. | 2 |
| 2006 | On the impact of loss and delay variation on Internet packet audio transmission
Lopamudra Roychoudhuri, Ehab Al-Shaer, Gregory B. Brewster |
Comput. Commun. | 2 |
| 2006 | On Dynamic Optimization of Packet Matching in High-Speed FirewallsabstractPacket matching plays a critical role in the performance of many network devices and a tremendous amount of research has already been invested to come up with better optimized packet filters. However, most of the related works use deterministic techniques and do not exploit the traffic characteristics in their optimization schemes. In addition, most packet classifiers give no specific consideration for optimizing packet rejection, which is important for many filtering devices like firewalls. Our contribution in this paper is twofold. First, we present a novel algorithm for maximizing early rejection of unwanted flows with minimal impact on other flows. Second, we present a new packet filtering dynamic optimization technique that uses statistical search trees to utilize traffic characteristics and minimize the average packet matching time. The proposed techniques timely adapt to changes in the traffic conditions by performing simple calculations for optimizing the search data structure. Our techniques are practically attractive because they exhibit simple-to-implement and easy-to-deploy algorithms. Our extensive evaluation study using Internet traces shows that the proposed techniques can significantly minimize the packet filtering time with reasonable memory space requirements Hazem H. Hamed, Adel El-Atawy, Ehab Al-Shaer |
IEEE J. Sel. Areas Commun. | 3 |
| 2005 | Modeling and Verification of IPSec and VPN Security PoliciesabstractIPSec has become the defacto standard protocol for secure Internet communications, providing traffic integrity, confidentiality and authentication. Although IPSec supports a rich set of protection modes and operations, its policy configuration remains a complex and error-prone task. The complex semantics of IP Sec policies that allow for triggering multiple rule actions with different security modes/operations coordinated between different IPSec gateways in the network increases significantly the potential of policy misconfiguration and thereby insecure transmission. Successful deployment of IPSec requires thorough and automated analysis of the policy configuration consistency for IPSec devices across the entire network. In this paper, we present a generic model that captures various filtering policy semantics using Boolean expressions. We use this model to derive a canonical representation for IPSec policies using ordered binary decision diagrams. Based on this representation, we develop a comprehensive framework to classify and identify conflicts that could exist in a single IPSec device (intra-policy conflicts) or between different IPSec devices (inter-policy conflicts) in enterprise networks. Our testing and evaluation study on different network environments demonstrates the effectiveness and efficiency of our approach. Hazem H. Hamed, Ehab Al-Shaer, Will Marrero |
ICNP | 2 |
| 2005 | Active integrated fault localization in communication networksabstractFault localization is a core element in fault management. Many fault reasoning techniques use deterministic or probabilistic symptom-fault causality model for fault diagnoses and localization. Symptom-fault map is commonly used to describe symptom-fault causality in fault reasoning. However, due to lost and spurious symptoms in fault reasoning systems that passively collect symptoms, the performance and accuracy of the fault localization can be significantly degraded. In this paper, we propose an extended symptom-fault-action model to incorporate actions into fault reasoning process to tackle the above problem. This technique is called active integrated fault reasoning (AIR), which contains three modules: fault reasoning, fidelity evaluation and action selection. Corresponding fault reasoning and action selection algorithms are elaborated. Simulation study shows both performance and accuracy of fault reasoning can be greatly improved by taking actions, especially when the rate of spurious and lost symptoms is high. Yongning Tang, Ehab Al-Shaer, Raouf Boutaba |
Integrated Network Management | 2 |
| 2005 | Conflict classification and analysis of distributed firewall policiesabstractFirewalls are core elements in network security. However, managing firewall rules, particularly, in multifirewall enterprise networks, has become a complex and error-prone task. Firewall filtering rules have to be written, ordered, and distributed carefully in order to avoid firewall policy anomalies that might cause network vulnerability. Therefore, inserting or modifying filtering rules in any firewall requires thorough intrafirewall and interfirewall analysis to determine the proper rule placement and ordering in the firewalls. In this paper, we identify all anomalies that could exist in a single- or multifirewall environment. We also present a set of techniques and algorithms to automatically discover policy anomalies in centralized and distributed firewalls. These techniques are implemented in a software tool called the "Firewall Policy Advisor" that simplifies the management of filtering rules and maintains the security of next-generation firewalls. Ehab Al-Shaer, Hazem H. Hamed, Raouf Boutaba, Masum Hasan |
IEEE J. Sel. Areas Commun. | 1 |
| 2005 | Real-time packet loss prediction based on end-to-end delay variationabstractThe effect of packet loss on the quality of real-time audio is significant. Nevertheless, Internet measurement experiments continue to show a considerable variation of packet loss, which makes audio error recovery and concealment challenging. We propose a novel framework to predict packet loss and congestion, based on measurements of end-to-end delay variation and trend, enabling proactive error recovery and congestion avoidance. Our preliminary simulation and experimentation results with various sites on the Internet show the effectiveness and the accuracy of the Loss Predictor technique. Lopamudra Roychoudhuri, Ehab Al-Shaer |
IEEE Trans. Netw. Serv. Manag. | 2 |
| 2004 | Adaptive rate control for real-time packet audio based on loss predictionabstractThe paper presents an adaptive rate control framework, which performs proactive rate control based on packet loss prediction and on-line audio quality assessment for real-time packet audio. The proposed framework determines the optimal combination of various audio codecs for transmission, utilizing a thorough analysis of audio quality based on individual codec characteristics, as opposed to the ad-hoc codec redundancy used by other approaches. As a main component of this framework, a preliminary formulation of the packet loss predictor is shown; it determines the likelihood of packet loss in terms of available bandwidth, delay variation trend, and network history. We present simulation and experimental results to show the accuracy and efficiency of this technique. Lopamudra Roychoudhuri, Ehab Al-Shaer |
GLOBECOM | 2 |
| 2004 | Discovery of Policy Anomalies in Distributed FirewallsabstractFirewalls are core elements in network security. However, managing firewall rules, particularly in multi-firewall enterprise networks, has become a complex and error-prone task. Firewall filtering rules have to be written, ordered and distributed carefully in order to avoid firewall policy anomalies that might cause network vulnerability. Therefore, inserting or modifying filtering rules in any firewall requires thorough intra- and inter-firewall analysis to determine the proper rule placement and ordering in the firewalls. We identify all anomalies that could exist in a single- or multi-firewall environment. We also present a set of techniques and algorithms to automatically discover policy anomalies in centralized and distributed legacy firewalls. These techniques are implemented in a software tool called the "Firewall Policy Advisor" that simplifies the management of filtering rules and maintains the security of next-generation firewalls. Ehab Al-Shaer, Hazem H. Hamed |
INFOCOM | 1 |
| 2004 | Managing firewall and network-edge security policiesabstractSummary form only given. Firewalls are core elements in network security. However, managing firewall rules, particularly in multi-firewall enterprise networks, has become a complex and error-prone task. Firewall filtering rules have to be written, ordered and distributed carefully in order to avoid firewall policy conflicts (or anomalies) and network vulnerability. Therefore, in order to produce anomaly-free firewall policies when adding or modifying rules in any firewall, a thorough intra- and inter-firewall analysis is required to determine the rule location (which firewall) and position (what order in the firewall policy) in the network. We comprehensibly identify all types of anomaly that could exist in single- or multi-firewall environments. We then present a set of techniques/tools that automatically discover and rectify policy anomalies in centralized and distributed legacy firewalls. Ehab Al-Shaer |
NOMS (1) | 1 |
| 2004 | MRMON: remote multicast monitoringabstractAlthough IP multicasting has been deployed for more than a decade, management of multicast networks and services is still a challenging problem. The fact that IP multicast is a receiver-oriented and stateless protocol makes end-to-end multicast monitoring an intractable task. Important multicast information such as join/leave status, group membership, tree information, path/traffic characteristics, and session status is either unrevealed or distributed in various locations on the network. In this paper, we present a new remote passive multicast monitoring infrastructure, called MRMON, to capture, analyze and present multicast session, traffic and membership information in real time. The MRMON probes inhabit a well-organized multicast information structure (MIB) that provides a comprehensive view of multicast network activities in remote subnets. We show how information can be collected from different MRMON probes and then correlated to diagnose multicast session problems. MRMON is a crucial step toward effective multicast management, and our goal is to promote MRMON as a standard MIB in multicast management. Ehab Al-Shaer, Yongning Tang |
NOMS (1) | 1 |
| 2004 | Modeling and Management of Firewall PoliciesabstractFirewalls are core elements in network security. However, managing firewall rules, especially for enterprise networks, has become complex and error-prone. Firewall filtering rules have to be carefully written and organized in order to correctly implement the security policy. In addition, inserting or modifying a filtering rule requires thorough analysis of the relationship between this rule and other rules in order to determine the proper order of this rule and commit the updates. In this paper we present a set of techniques and algorithms that provide automatic discovery of firewall policy anomalies to reveal rule conflicts and potential problems in legacy firewalls, and anomaly-free policy editing for rule insertion, removal, and modification. This is implemented in a user-friendly tool called "Firewall Policy Advisor." The Firewall Policy Advisor significantly simplifies the management of any generic firewall policy written as filtering rules, while minimizing network vulnerability due to firewall rule misconfiguration. Ehab Al-Shaer, Hazem H. Hamed |
IEEE Trans. Netw. Serv. Manag. | 1 |
| 2003 | Management and translation of filtering security policiesabstractFirewalls are essential elements of security policy enforcement in modern networks. However, managing a filtering security policy, especially for enterprise networks, has become complex and error-prone. Filtering rules have to be carefully written and organized in order to correctly implement the security policy and avoid policy anomalies. In this paper, we present a set of techniques and algorithms that provide (1) automatic anomaly discovery for rule conflicts and potential problems in legacy firewalls, (2) anomaly-free policy editing for rule insertion, modification and removal, and (3) concise translation of filtering rules to high-level textual description for user visualization and verification. These techniques significantly simplify the management of any generic firewall policy written as filtering rules, while minimizing network vulnerability due to filtering policy misconfiguration. Ehab Al-Shaer, Hazem H. Hamed |
ICC | 1 |
| 2003 | Audio transmission over the Internet: experiments and observationsabstractThe performance of IP telephony systems is highly dependent on the audio codecs and their reaction to packet loss and instantaneous delays. Understanding the interaction between audio encoding and the dynamic behavior of the Internet is significant for designing adaptive audio transport mechanisms. For this purpose, we conducted a large-scale audio transmission experiment over the Internet in a 12-month period using various Internet sites. As a result of this experiment, we have made a number of new observations to assess the audio quality of G.711 and G.728 codes under different loss and delay conditions. The paper also states a number of recommendations for implementing efficient adaptive FEC and playout mechanisms. Lopamudra Roychoudhuri, Ehab Al-Shaer, Hazem H. Hamed, Gregory B. Brewster |
ICC | 2 |
| 2003 | Firewall Policy Advisor for Anomaly Discovery and Rule Editing
Ehab Al-Shaer, Hazem H. Hamed |
Integrated Network Management | 1 |
| 2002 | SMRM: SNMP-based multicast reachability monitoringabstractOne of the main challenges of deploying multicast services in the Internet is the lack of active monitoring tools that can detect and isolate multicast reachability problems in real-time. Existing multicast monitoring tools are either not scalable or use proprietary protocols which limit their deployment in enterprise networks. This paper presents SNMP-based multicast reachability monitoring (SMRM), a framework for monitoring the health and the quality of multicast delivery paths (or forwarding tree) in real-time. SMRM addresses these limitations by using SNMP as a core component, which significantly facilitates the wide deployment of SMRM in existing networks. The SMRM framework combines distributed monitoring and centralized control, which offers a scalable, easy-to-use and easy-to-deploy multicast monitoring service. Ehab Al-Shaer, Yongning Tang |
NOMS | 1 |
| 2001 | A Dynamic Group Management Framework for Large-scale Distributed Event MonitoringabstractDistributed event monitoring is an important service for fault, performance and security management. Next generation event monitoring services are highly distributed and involve a large number of monitoring agents. In order to support scalable event monitoring, the monitoring agents use IP multicasting for disseminating events and control information. However, due to the dynamic nature of event detection and correlation in distributed monitoring, devising an efficient group management for agents organization and coordination becomes a challenging issue. This paper presents an adaptive group management framework that dynamically re-configures the group structures and membership assignments at run-time according to the event correlation requirements and allows for optimal delivery of multicast messages between the management entities. This framework provides techniques for solving agents' state synchronization, collision-free group allocation and agents bootstrap problems in distributed event monitoring. The presented framework has been implemented within a HiFi system which is a distributed hierarchical monitoring system. Ehab Al-Shaer |
Integrated Network Management | 1 |
| 2001 | Toward integrating IP multicasting in internet network management protocols
Ehab Al-Shaer, Yongning Tang |
Comput. Commun. | 1 |
| 1999 | HiFi: A New Monitoring Architecture for Distributed Systems ManagementabstractWith the increasing complexity of large scale distributed (LSD) systems, an efficient monitoring mechanism has become an essential service for improving the performance and reliability of such complex applications. The paper presents a scalable, dynamic, flexible and nonintrusive monitoring architecture for managing large scale distributed (LSD) systems. This architecture, which is referred to as the HiFi monitoring system, detects and classifies interesting primitive and composite events and performs either a corrective or steering action. When appropriate, information is also disseminated to management applications, such as reactive control tools. The outlined solution offers improvements over related works by supporting new monitoring techniques such as hierarchical filtering based monitoring and filter incarnation that improve the monitoring scalability and dynamism which are required for managing large scale distributed systems. The HiFi monitoring system has been implemented and used at the Old Dominion University for monitoring and steering Interactive Remote Instruction (IRI) which is a large scale distributed multimedia system for distance learning. Ehab Al-Shaer, Hussein M. Abdel-Wahab, Kurt Maly |
ICDCS | 1 |
| 1997 | Event Filtering Framework: Key Criteria and Design Trade-offsabstractEvent filtering is an essential service to classify and disseminate events in a distributed systems environment. This paper describes the key design criteria and challenges of developing high-performance event filtering for dynamic distributed applications such as automated monitoring in distributed systems. We also classify existing event filtering mechanisms according to the key criteria. In addition, we discuss the trade-offs of designing efficient and flexible event filtering mechanisms. Ehab Al-Shaer |
COMPSAC | 1 |
| 1997 | Application-Layer Group Communication Server for Extending Reliable Multicast Protocols ServicesabstractReliable multicast protocols are becoming an essential element in distributed applications such as interactive distance learning applications. However, the existing implementations of reliable multicast protocols are not sufficient to satisfy the group communications requirements of some distributed applications. Our experience of using number of multicast protocols in IRI distance learning applications shows the necessity of providing an application-layer reliable multicast server (RMS) to extend the primitive group communication services provided by such multicast protocols. Examples of such services include handling heterogeneous environments (such as LAN vs. WAN networks and different reliable multicast protocols), automatic fault recovery and simple application interface. In this paper, we motivate and describe the design and the implementation of RMS architecture which has been used in IRI learning sessions for two semesters. We also show how RMS improves the reliability, performance and flexibility of IRI sessions via supporting extended group communication services. Ehab Al-Shaer, Hussein M. Abdel-Wahab, Kurt Maly |
ICNP | 1 |