EDBT 2026 Demo / reviewers in the wild / expert
Qusay H. Mahmoud
dblp:m/QusayHMahmoud
· DBLP profile ↗
87ranked-venue papers
15as first author
9since 2021 · last 2026
0000-0003-0472-5757ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Applied, interdisciplinary, general and emerging computing · 23 · 3 since 2021Human-computer interaction and ubiquitous computing · 22 · 7 first-author · 1 since 2021Computer networks · 13 · 2 first-authorDatabases, data management, data science and information retrieval · 9 · 1 since 2021Artificial intelligence and machine learning · 6 · 1 since 2021Software engineering, systems software and programming languages · 6 · 2 first-authorSystems, architecture and hardware · 4Security and privacy · 2 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 first-author
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Software engineering, system software, and programming languages
4 papers |
Operating systems · 60% Services computing and microservices · 40% | |
| Network and information security
1 paper |
Systems and software security · 100% |
Topics — the 3 heaviest of 6, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Services computing and microservices › service discovery
web service discovery |
0.2 | 3 | 2008 | Investigating web services on the world wide web · WWW 2008 Discovering the best web service · WWW 2007 Crawling multiple UDDI business registries · WWW 2007 |
Services computing and microservices › web services
web service crawling |
0.2 | 2 | 2008 | Investigating web services on the world wide web · WWW 2008 Crawling multiple UDDI business registries · WWW 2007 |
Information retrieval
web search |
0.0 | 1 | 2008 | Investigating web services on the world wide web · WWW 2008 |
Methods — techniques the papers use, named apart from their topics
probabilistic model · 1.1model checking · 1.1autoencoder · 1.1web crawling · 0.3experimental validation · 0.2statistical analysis · 0.2relevancy function · 0.1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Accelerated Reinforcement Learning for Real-Time Task Scheduling in Edge Computing Environments
Amin Avan, Akramul Azim, Qusay H. Mahmoud |
ISORC | 3 |
| 2025 | Privacy in Generative AI: Understanding User Concerns, Trust, and AwarenessabstractGenerative Artificial Intelligence (GenAI) has transformed various domains, offering advanced capabilities in content generation, automation, and decision-making. However, privacy concerns remain a significant challenge, particularly regarding data security, user trust, and transparency. This paper examines user perceptions of AI privacy through a survey of 290 respondents, analyzing their familiarity with privacy risks, trust levels, and engagement with privacy policies. The results indicate a clear gap between AI adoption and privacy awareness, with many users uncertain about data handling practices. To address these concerns, AI developers must enhance transparency, integrate privacy-preserving techniques, and strengthen regulatory compliance. By prioritizing user education and ethical AI governance, a more secure and trustworthy AI ecosystem can be achieved. Hamda Al Breiki, Qusay H. Mahmoud, Thani Al-Riyami, Khaled Aljneibi Aljneibi |
AICCSA | 2 |
| 2024 | Evaluating the Efficacy of Large Language Models in Automating Academic Peer ReviewsabstractThis paper explores the application of large language models (LLMs) in automating the peer review process for academic papers, a critical area for enhancing the efficiency and consistency of scholarly publication. We utilized GPT-4-0125 to automatically generate reviews for 20 papers sourced from openreview.net and analyzed the AI-generated peer reviews for quality and effectiveness. The analysis includes a detailed assessment of the text properties of the reviews, such as sentiment, revealing that LLM-generated reviews tend to be more uniformly positive than their human-written counterparts. In addition, we conducted a user survey in which participants attempted to distinguish between AI-generated and human-written reviews. The survey results indicated a low correct identification rate, suggesting that participants often could not discern the origin of the review, thereby highlighting the potential of LLMs to mimic human-like review qualities. However, the study also identifies limitations in LLM's performance, particularly concerning the variability in review quality, which appears to correlate with the model's vocabulary usage of the generated content. Weimin Zhao, Qusay H. Mahmoud |
ICMLA | 2 |
| 2023 | Design and Development of Policy Enforcement for the Privacy by Design FrameworkabstractPrivacy by Design (PbD) is a set of guiding principles for providing stronger guarantees of privacy protection in systems that handle sensitive information. In this paper, we present the design and development of PbD constructs with a proof of concept prototype in Python, where data variables are tagged with information describing their privacy requirements while common methods are augmented with privacy requirement checking code. With these additions, we demonstrate how the task of writing Privacy by Design compliant code is greatly simplified. Michael Lescisin, Qusay H. Mahmoud |
AICCSA | 2 |
| 2023 | A Robust Scheduling Algorithm for Overload-Tolerant Real-Time SystemsabstractA real-time system is overloaded when all the tasks in a workload cannot meet their deadlines, and hence a robust algorithm is essential to maximize the number of tasks that meet their deadlines with the minimum number of miss rates and context switching. Although the Rate Monotonic (RM), Earliest Deadline First (EDF), and Least Laxity First (LLF) algorithms optimally perform and schedule tasks on a non-overloaded system, they have deficient performance when the system is overloaded. Therefore, we propose a new scheduling algorithm for uniprocessor and partitioned multiprocessor systems to address the overload situation. Since the proposed scheduling algorithm operates like EDF non-overloaded conditions, the proposed algorithm is optimal for non-overloaded systems. In addition, the proposed algorithm is robust against overloading situations as it executes the maximum possible tasks in the overload situation instead of missing deadlines of many tasks or burdening context switching to the system. The proposed algorithm allocates a processor to tasks based on the possibility of executing the task. The experimental results demonstrate that the proposed scheduling algorithm maximizes the number of tasks that meet their deadlines in overload conditions without a domino effect and context switching. In addition, the proposed algorithm achieves the lowest miss rate without context switching and the highest efficiency and processor utilization in the overloaded system compared with RM, EDF, and LLF. Amin Avan, Akramul Azim, Qusay H. Mahmoud |
ISORC | 3 |
| 2023 | Building Trust in Deep Learning Models via a Self- Interpretable Visual ArchitectureabstractDeep learning models are being utilized and further developed in many application domains, but challenges still exist regarding their interpretability and consistency. Interpretability is important to provide users with transparent information that enhances the trust between the user and the learning model. It also gives developers feedback to improve the consistency of their deep learning models. In this paper, we present a novel architectural design to embed interpretation into the architecture of the deep learning model. We apply dynamic pixel-wised weights to input images and produce a highly correlated feature map for classification. This feature map is useful for providing interpretation and transparent information about the decision-making of the deep learning model while keeping full context about the relevant feature information compared to previous interpretation algorithms. The proposed model achieved 92% accuracy for CIFAR 10 classifications without finetuning the hyperparameters. Furthermore, it achieved a 20% accuracy under 8/255 PGD adversarial attack for 100 iterations without any defense method, indicating extra natural robustness compared to other Convolutional Neural Network (CNN) models. The results demonstrate the feasibility of the proposed architecture. Weimin Zhao, Qusay H. Mahmoud, Sanaa A. Alwidian |
PST | 2 |
| 2022 | An Anomaly Detection Model for IoT Networks based on Flow and Flag Features using a Feed-Forward Neural NetworkabstractThe security of IoT networks is becoming increasingly challenging, and anomaly detection for IoT network traffic is a critical technique for addressing this issue. However, extracting precise and effective network traffic features for anomaly detection is challenging. To address this issue, the current research analyzes various types of network flow features. In this paper, we present the design and development of an anomalous activity detection system for IoT networks based on flow and control flags features using a feed-forward neural network. The model has been evaluated using BoT-IoT, IoT network intrusion, MQTT-IoT-IDS2020, MQTTset, IoT-23, and IoT-DS2 datasets for binary and multiclass classification. Our proposed binary and multiclass classification model attained high accuracy, precision, recall, and F1 score compared to existing deep learning implementations. Imtiaz Ullah, Qusay H. Mahmoud |
CCNC | 2 |
| 2022 | A Machine Learning Based Approach to Detect Fault Injection Attacks in IoT Software SystemsabstractWith the rapid growth of Internet of Things (IoT) applications, the security of these systems has become critical. Fault injection attacks are a type of physical attack on the hardware components of an IoT system. These attacks cause the IoT system software to behave abnormally, which the adversaries exploit. Typically, these attacks have been detected through the use of a separate hardware detection mechanism, which is expensive and itself vulnerable to attack. The purpose of this paper is to propose a machine learning based approach to detect the attacks by monitoring specific run-time software parameters in the live environment of an IoT system. The proposed approach generates a labelled dataset by injecting instruction-level faults into the software executable, which is then used to train a machine learning model that can predict whether the IoT software system is currently being affected by a fault injection attack. Using a software fault injection tool to create a labelled dataset enables the use of supervised machine learning techniques, which produce more accurate prediction results than unsupervised techniques. The machine learning model can be used in the live environment of an IoT software system to monitor specific run-time software properties in order to detect the effects of a fault injection attack on the software. Additionally, the model classifies the type of fault introduced into the software as a result of the attack, which can be used to determine the necessary corrective action. Aakash Gangolli, Qusay H. Mahmoud, Akramul Azim |
SMC | 2 |
| 2022 | A Framework for Anomaly Detection in Time-Driven and Event-Driven Processes Using Kernel TracesabstractModel-checking and verification using Kripke structures and computational tree logic* (CTL*) use abstractions from the model/process/application to create the state-transition graphs that verify the model behavior. This scheme of profiling the performance of a process imports that the depth of the process operation correlates with the level abstraction. However, because of state explosion problems, these abstractions tend to restrict the scope to create manageable execution states. Therefore, for context modeling, this procedure does not generate a fine-grained behavioral model as generated states limit the ability of the abstraction to capture the execution time interactions amongst the processes, the hardware, and the kernel. Hence, in this paper, we present an end-to-end framework that comprises auto-encoders and probabilistic models to understand the behavior of system processes and detect deviant behaviors. We test this framework with a publicly available dataset generated from an autonomous aerial vehicle (UAV) application and the results show that by creating a fine-grained model that exploits previously unharnessed properties of the system calls, we can create a dynamic anomaly detection framework that evolves as the threats change. Mellitus Ezeme, Qusay H. Mahmoud, Akramul Azim |
IEEE Trans. Knowl. Data Eng. | 2 |
| 2020 | Design and Implementation of a Blockchain-Based E-Health Consent Management FrameworkabstractTransformation of data into knowledge is the hallmark of modern medicine. As an evolving field of medicine, e-Health involves the electronic processing of a patient's personal, medical and other health-related data to improve healthcare delivery. Data captured from clinical interactions between patients and their care providers, as well as health data collected through medical sensors, provide a rich source of data, known as patient medical records (PMRs), which can be processed in various ways to enhance the delivery of healthcare services. However, indiscriminate processing of PMRs could potentially result in the violation of the security or privacy of patients. To ensure that PMRs are not processed in ways that could be harmful to the security or privacy of the patients, modern data protection regulations, such as the European General Data Protection Regulation (GDPR), requires healthcare service provides to obtain the consent of a patient for any processing operation on their PMRs. The mechanism by which a patient exercises their right to control who can process their PMRs, when and for what purpose, is referred to as consent management in e-Health. Existing health information technology systems do not provide adequate support for consent management; there is a lack of transparency and auditability in the existing systems to monitor and ensure that healthcare service providers comply to the relevant data protection regulations in processing PMRs. The emerging blockchain technology offers an opportunity to design an e-Health consent management system that is compliant with modern data protection regulations such as GDPR. In this paper, we present the design and implementation of an e-Health consent management framework, based on the state-of-the-art blockchain technologies, for processing PMRs. Our analysis confirms that our system satisfies the requirements for consent management in e-Health. Cornelius Chidubem Agbo, Qusay H. Mahmoud |
SMC | 2 |
| 2020 | An Intelligent Risk-Based Authentication Approach for Smartphone ApplicationsabstractAuthentication on smartphones is performed at the initial entry, mostly utilizing knowledge-based authentication methods which are fast and convenient. Device-based authentication does not guarantee that the user will utilize effective authentication credentials as many users choose less robust and easy to remember credentials. To reduce the explicit intervention from users and to increase user adoption, implicit authentication should be present. This approach authenticates users based on temporal access patterns to mobile devices, such as modeling the access behavior to applications. This paper presents an intelligent risk-based authentication method based on temporal access behavior to general applications on mobile devices. The risk score is calculated from the modeled pattern on the mobile device and the approach minimizes the required credentials based on the quality of this pattern. The evaluation of the presented method is achieved on real datasets and the results show the effectiveness of the approach. Importantly, the approach requires only a short period of application usage to build the model in addition to adapting to new app usage. Ultimately, the results show that the approach provides a low false acceptance rate and false rejection rate, which enhances its usability. Yosef Ashibani, Qusay H. Mahmoud |
SMC | 2 |
| 2020 | Human-in-the-Loop Error Precursor Detection using Language Translation Modeling of HMI StatesabstractSituational Awareness (SA) is paramount to ensuring operational safety in Nuclear Power Plant (NPP) and Commercial aviation industry. An increase in Human-in-the-loop (HITL) error rate may be indicative of reduced operator SA while undermining safety. In this paper, natural language processing (NLP) is applied for modelling industrial Human Machine Interface (HMI) state transitions as a means to detect operator HITL error precursors in real-time. A custom seq2seq encode-decoder deep-learning model design is implemented and evaluated using real-plant scenario dataset obtained from a NPP Operator training simulator. Results support NLP HMI state model may be employed to detect HITL error precursor within the desired N time-steps prior to an accident event. Harsh V. P. Singh, Qusay H. Mahmoud |
SMC | 2 |
| 2020 | A Technique for Generating a Botnet Dataset for Anomalous Activity Detection in IoT NetworksabstractIn recent times, the number of Internet of Things (IoT) devices and the applications developed for these devices has increased; as a result, these IoT devices are targeted by many malicious activities that cause potential damage in many smart infrastructures. A technique is required to appropriately classify anomalous activities to minimize the impact of these activities. The IoT networks are difficult to analyze and test because of the lack of sufficient well-structured IoT datasets for anomaly-based intrusion detection. In this paper, we present a technique we have used to generate a new Botnet dataset, from an existing one, for anomalous activity detection in IoT networks. The new IoT botnet dataset has a wider network and flow-based features. A flow-based Intrusion Detection System (IDS) can be analyzed and tested using flow-based features. Finally, we use different machine learning methods to test the accuracy of our proposed dataset. We also test the accuracy of our proposed dataset through various feature correlation and the methodology for recursive feature elimination. Our proposed IoT botnet dataset provides a ground to analyze and evaluate anomalous activity detection model for IoT networks. We have shared the newly generated Botnet dataset publicly, and a link is provided in this paper. Imtiaz Ullah, Qusay H. Mahmoud |
SMC | 2 |
| 2020 | Remote Method Delegation: a Platform for Grid Computing
Bradley Wood, Brock Watling, Zachary Winn, Daniel Messiha, Qusay H. Mahmoud, Akramul Azim |
J. Grid Comput. | 5 |
| 2019 | M2MHub: A Blockchain-Based Approach for Tracking M2M Message ProvenanceabstractThe Internet of Things (IoT) is a fast growing and popular subset of technology. One of the main features of IoT is device autonomy, the ability for the machines embedded in the devices to function without human intervention. This includes communications with other devices through Machine-to-Machine (M2M) communication. Unfortunately, M2M communications are only stored with what behaviours they have observed, without the causal relationship as to how or why they observed those behaviours. Since M2M messages can trigger more M2M messages, the provenance of issues inside an IoT system can be hidden behind a long chain of messages, so finding the root source of any problem, such as malicious or defective devices, is almost impossible to detect. To solve this problem, in this paper we introduce M2MHub, a centralized auditing system which collects M2M messages in an IoT system and stores them in a blockchain. Devices in the system can tell the hub if they wish to open, continue, or end transactions, allowing the hub to keep track of who is the provenance of the transaction and how their transaction affects other devices. A proof-of-concept simulation has been constructed, demonstrating how M2MHub may function in a real-world implementation. The current implementation is not scalable enough to be deployed to actual IoT networks, so several ideas for future work are offered. Darren Saguil, Qiao Xue, Qusay H. Mahmoud |
AICCSA | 3 |
| 2019 | A Two-Level Hybrid Model for Anomalous Activity Detection in IoT NetworksabstractIn this paper we propose a two-level hybrid anomalous activity detection model for intrusion detection in IoT networks. The level-1 model uses flow-based anomaly detection, which is capable of classifying the network traffic as normal or anomalous. The flow-based features are extracted from the CICIDS2017 and UNSW-15 datasets. If an anomaly activity is detected then the flow is forwarded to the level-2 model to find the category of the anomaly by deeply examining the contents of the packet. The level-2 model uses Recursive Feature Elimination (RFE) to select significant features and Synthetic Minority Over-Sampling Technique (SMOTE) for oversampling and Edited Nearest Neighbors (ENN) for cleaning the CICIDS2017 and UNSW-15 datasets. Our proposed model precision, recall and F score for level-1 were measured 100% for the CICIDS2017 dataset and 99% for the UNSW-15 dataset, while the level-2 model precision, recall, and F score were measured at 100 % for the CICIDS2017 dataset and 97 % for the UNSW-15 dataset. The predictor we introduce in this paper provides a solid framework for the development of malicious activity detection in IoT networks. Imtiaz Ullah, Qusay H. Mahmoud |
CCNC | 2 |
| 2019 | User Authentication for Smart Home Networks Based on Mobile Apps UsageabstractEnd-user devices, such as mobile phones and tablets, have become essential tools for accessing smart homes. Consequently, user authentication, one of the most important security factors, needs to be considered to prevent unauthorized access to home devices. Although mobile phones are equipped with different means of authentication such as fingerprint readers, these methods are only employed at the time of access; hence, countermeasures should be developed to overcome potential threats. This paper presents a continuous user authentication model based on apps access usage on mobile devices. To validate the presented model, two public real-world datasets collected from real users over a long period, are used. The model is evaluated for its ability to differentiate between users utilizing shared apps at the same daily intervals. Moreover, various classification approaches regarding legitimate user classification in compliance with the history of apps usage are evaluated. The results demonstrate the capacity of the presented method to authenticate users with high true positive and true negative rates. Yosef Ashibani, Qusay H. Mahmoud |
ICCCN | 2 |
| 2019 | Classification and Feature Extraction for User Identification for Smart Home Networks Based on Apps Access HistoryabstractAdvancements in smartphones has led to increasing dependency on them as an essential part of IoT smart home networks. Although this increase provides convenience to users, many challenges, including user identification and authentication, need to be considered. Many related works consider smartphone user authentication that assumes that the same user will be using the device throughout the access session. However, after the login stage, the device could be used by others, either in the home environment or outside, leading to undesired access to home appliances. In this paper, we present a continuous user identification approach that uses implicit features that can be integrated as a second layer of identification beyond the login step, based on user behavior on smartphones. The proposed method is mainly based on user interaction on the smartphone, which thus reflects the user's pattern that in turn provides the impetus to employ user identification as a complementary approach beyond the user login stage. Yosef Ashibani, Qusay H. Mahmoud |
ICMLA | 2 |
| 2019 | A Deep Learning Approach to Distributed Anomaly Detection for Edge ComputingabstractOne of the multiplier effects of the boom in mobile technologies ranging from cell phones to computers and wearables like smart watches is that every public and private common spaces are now dotted with Wi-Fi hotspots. These hotspots provide the convenience of accessing the internet on-the-go for either play or work. Also, with the increased automation of our daily routines by our mobile devices via a multitude of applications, our vulnerability to cyber fraud or attacks becomes higher too. Hence, the need for heightened security that is capable of detecting anomalies on-the-fly. However, these edge devices connected to the local area network come with diverse capabilities with varying degrees of limitations in compute and energy resources. Therefore, running a process-based anomaly detector is not given a high priority in these devices because; a) the primary functions of the applications running on the devices is not security; therefore, the device allocates much of its resources into satisfying the primary duty of the applications. b) the volume and velocity of the data are high. Therefore, in this paper, we introduce a multi-node (nodes and devices are used interchangeably in the paper) ad-hoc network that uses a novel offloading scheme to bring an online anomaly detection capability on the kernel events to the nodes in the network. We test the framework in a Wi-Fi-based ad-hoc network made up of several devices, and the results confirm our hypothesis that the scheme can reduce latency and increase the throughput of the anomaly detector, thereby making online anomaly detection in the edge possible without sacrificing the accuracy of the deep recurrent neural network. Mellitus Ezeme, Qusay H. Mahmoud, Akramul Azim |
ICMLA | 2 |
| 2019 | Ad-hoc messaging infrastructure for peer-to-peer communication
Michael Lescisin, Qusay H. Mahmoud |
Peer-to-Peer Netw. Appl. | 2 |
| 2018 | A Behavior Profiling Model for User Authentication in IoT Networks based on App Usage PatternsabstractAccess to Internet of Things (IoT) devices is, in most cases, achieved remotely through end-user devices such as smartphones. However, these devices are susceptible to theft or loss, and their use by unauthorized users could lead to unauthorized access to IoT networks, consequently allowing access to user information. Due to the inherent weaknesses in many authentication approaches, such as knowledge-based authentication, as well as the complications involved in employing them for continuous and implicit authentication, focus has turned to a consideration of behavioral-based authentication. As most access to IoT devices is achieved through end-user devices, a variety of information can be extracted and utilized for continuous authentication without requiring further user intervention. As an example, the ability to continuously retrieve application usage profiles and sensor data on such devices strengthens the argument for employing behavioral-based mechanisms for continuous user authentication. Behavioral techniques that are user-friendly and non-intrusive can be utilized in the background to continuously and transparently verify users. This paper discusses behavioral-based authentication mechanisms with regard to security and usability. It then presents an authentication model that verifies users with an average F-measure of 96.5%. Overall, the preliminary results are promising and show the effectiveness and usability of the proposed model. Yosef Ashibani, Qusay H. Mahmoud |
IECON | 2 |
| 2018 | Failure Analysis and Characterization of Scheduling Jobs in Google Cluster TraceabstractMost public and private cloud providers have experienced failure in one of their services that may affect numerous applications and websites. Thus, in order to understand the causes of different types of failures and remediate the issue, failure analysis is one of the most critical steps. Failure analysis has been developed based on monitoring the most significant metrics of the system in order to study the behavior and frequency changes in the systems. Then, the monitored data will be stored in log files to be utilized for analysis and prediction tasks. In this paper, we primarily focus on analyzing and interpreting the characteristic behavior of finished/failed jobs in association with physically available resources using a publicly available dataset, Google cluster trace. The primary objective of our work is to enhance the understanding of job failure in cloud computing environments. Our results show a clear correlation between failed jobs and requested resources including memory, CPU, and disk space. Based on our results, we find that many techniques can be applied to increase the reliability and availability of cloud applications, such as developing scheduling algorithms, predicting job failure, limiting task resubmission or changing the priority policies. Mohammad S. Jassas, Qusay H. Mahmoud |
IECON | 2 |
| 2018 | Dataset for Web Traffic Security AnalysisabstractPatterns of network activity can reveal an abundance of information on the behaviour of an application. Research has shown that despite the widespread use of network encryption protocols such as TLS or SSH, network application confidentiality can often times be violated through network traffic pattern analysis. Achieving sound mitigation of these information leaks while maintaining network usage efficiency is still an ongoing research topic. The goal of the research conducted in this paper is to provide network security researchers with a dataset of captured network traffic from a popular SSL/TLS protected website, which we have chosen to be reddit.com, for the purpose of evaluating algorithms for attacking and defending against network based side-channel information leaks. Our dataset is represented as a graph describing a crawl through the website. Every path from the center of the graph to any other connected point represents a sequence of user interactions with the website. By following a directed path through the graph, researchers can obtain probable sequences of user interactions with a website and the associated patterns of network traffic which these interactions generate. Michael Lescisin, Qusay H. Mahmoud |
IECON | 2 |
| 2018 | Hierarchical Attention-Based Anomaly Detection Model for Embedded Operating SystemsabstractReal-time embedded system applications have become pervasive, and with the increasing reliance on automated systems for both critical and non-critical tasks, the trend is set to continue. This growing reliance on real-time embedded systems, as well as the rise in the complexity of these systems, demands an efficient monitoring tool that takes the complex interactions in the system into consideration. These systems are well-specified, and there exists standard error or fault detection mechanism to detect when an anomaly occurs in the applications controlling the operation. Nonetheless, these anomaly detection mechanisms gather information about the behavior of the software against its intended goals through the use of plausibility checks which rely on a priori knowledge of the application behavior. This kind of test raises two issues: (1) there should be a complete characterization of the software to derive the redundant information needed for plausibility checks, (2) this test focuses mainly on detecting errors/faults/anomalies in a single application with no regard to other entities in the integrated system. On the other hand, an embedded real-time system (fitted with an operating system) usually has the operating system and the integrated application statically linked to produce a single executable image. This bespoke nature of the embedded real-time system design means that the kernel traces reflect the behavior of the application and the associated hardware components at every point in time. Consequently, detecting deviations in the kernel trace invariably imply system-wide anomaly detection in the associated application and hardware. Thus, this paper targets anomaly not just in the application layer, but also in other layers that make up the real-time embedded system. Therefore, we introduce a hierarchical attention-based anomaly detection (HAbAD) model based on stacked Long Short-Term Memory (LSTM) Networks with Attention. It is a closed-world prediction-classification model which uses the reconstruction error from a non-parametric kernel density estimator to detect when an anomaly has occurred. We show the effectiveness of this approach using publicly available dataset, and the results confirm that this is a robust means of detecting anomalies in real-time embedded systems. Mellitus Ezeme, Qusay H. Mahmoud, Akramul Azim |
RTCSA | 2 |
| 2017 | An Imputation-based Augmented Anomaly Detection from Large Traces of Operating System EventsabstractSoftware debugging, audit, and compliance testing are some of the tasks we perform using execution traces of an operating system. However, these actions gather information about the behavior of the software vis-a-vis its design aims. In this work, our analysis of the execution traces of an embedded real-time operating system (RTOS) is rather to model the behavior of the physical system being managed by the software application via the embedded operating system. Hence, for an event-triggered embedded RTOS that controls the behavior of a bespoke system like an unmanned aerial vehicle (UAV), the events in the execution traces of the embedded RTOS is directly linked to the operation of the controlled physical system. Therefore, we hypothesize that the frequency of events (method/function calls) per observation is a useful feature for modeling the behavior of the physical system controlled by the operating system. Mellitus Ezeme, Akramul Azim, Qusay H. Mahmoud |
BDCAT | 3 |
| 2017 | A filter-based feature selection model for anomaly-based intrusion detection systemsabstractFeature selection is an important factor in modeling anomaly-based intrusion detection systems. An irrelevant feature can result in overfitting and affect the modeling power of classification algorithms. The objective of feature selection is to remove irrelevant and redundant attributes from the dataset to improve the predictive power of a classification algorithm. In this paper, we introduce a filter-based feature selection model for anomaly-based intrusion detection systems. The proposed model evaluates the features based on information gain by considering consistency, dependency, information, and distance of each feature. The experimental results show that our proposed model has a key effect in reducing computational and time complexity. The accuracy of the proposed model was measured as 99.70 % and 99.90% for the ISCX and NSL-KDD datasets respectively. Imtiaz Ullah, Qusay H. Mahmoud |
IEEE BigData | 2 |
| 2017 | A hybrid model for anomaly-based intrusion detection in SCADA networksabstractSupervisory Control and Data Acquisition (SCADA) systems complexity and interconnectivity increase in recent years have exposed the SCADA networks to numerous potential vulnerabilities. Several studies have shown that anomaly-based Intrusion Detection Systems (IDS) achieves improved performance to identify unknown or zero-day attacks. In this paper, we propose a hybrid model for anomaly-based intrusion detection in SCADA networks using machine learning approach. In the first part, we present a robust hybrid model for anomaly-based intrusion detection in SCADA networks. Finally, we present a feature selection model for anomaly-based intrusion detection in SCADA networks by removing redundant and irrelevant features. Irrelevant features in the dataset can affect modeling power and reduce predictive accuracy. These models were evaluated using an industrial control system dataset developed at the Distributed Analytics and Security Institute Mississippi State University Starkville, MS, USA. The experimental results show that our proposed model has a key effect in reducing the time and computational complexity and achieved improved accuracy and detection rate. The accuracy of our proposed model was measured as 99.5 % for specific-attack-labeled. Imtiaz Ullah, Qusay H. Mahmoud |
IEEE BigData | 2 |
| 2017 | A context-aware authentication service for smart homesabstractThe rapid increase of Internet of Things (IoT) devices will have a significant impact on people's daily life, providing a wide range of services, such as smart lights, door locks, and cameras remotely controlled by smartphones. Remote access within the same environment or via the Internet requires effective authentication and authorization mechanisms beyond those provided by static authentication methods. We believe a dynamic authentication mechanism for mobile users is needed to protect against unauthorized access. This paper proposes a context-aware authentication service for mobile users in Smart Home environments. The service we have designed and implemented provides secure and flexible access to local as well as remote users, as demonstrated by the evaluation results. Yosef Ashibani, Dylan Kauling, Qusay H. Mahmoud |
CCNC | 3 |
| 2017 | Sensorian Hub: An IFTTT-based platform for collecting and processing sensor dataabstractThe Sensorian Hub is a software platform designed and developed for using the Raspberry Pi Single Board Computer (SBC) as a sensor node, whether independently or in a larger network of sensors. The intention of the platform is to provide an easy to use and highly customizable system for collecting and processing sensor data in a variety of environments and applications. In this paper, the design and implementation of the system through the use of a Python client, a PHP and Flask Web Server/API, a Relational Database Management System (RDBMS) MySQL and external connections to services such as If This Then That (IFTTT) are discussed in detail. Some sample applications and a prototype implementation with the Sensorian Shield are presented as well to demonstrate the current capabilities as well as the opportunities for future work. Dylan Kauling, Qusay H. Mahmoud |
CCNC | 2 |
| 2017 | Hidden android permissions: Remote code execution and shell access using a live wallpaperabstractGiven Android's popularity, it is likely that Android devices will be targeted with increasing frequency by malware designers, in particular by programs which are designed to steal some of the sensitive personal or financial information. This threat puts an obligation on security professionals and software developers to work to ensure that the Android platform is as secure as possible. Users of mobile devices should also be aware that the trust they grant to mobile applications they download from app stores can be exploited. In this demo paper, we present a live wallpaper app to demonstrate how trust can be exploited to gain shell access even on unrooted Android devices. Qusay H. Mahmoud, Dylan Kauling, Shaun Zanin |
CCNC | 1 |
| 2017 | Claimsware: A Claims-Based Middleware for Securing IoT ServicesabstractThe Internet of Things (IoT) is the ever-growing network of physical devices with IP addresses for Internet connectivity. Due to its ubiquitous nature and distributed architecture which includes devices, applications and humans, it presents a complex structure for security. Also, the incorporation of thousands of heterogeneous IoT devices with different characteristics into a single network creates the risk of security threats and privacy. This is where a middleware becomes significant. Middleware provides the platform services for various devices with different protocols to communicate with ease and provides all the functions intended for a particular task. Hosting these tasks as Microservices simplifies the job of an application developer. In this paper, we introduce Claimsware - a claims-based middleware for securing IoT services that are implemented as Microservices. The implemented prototype is evaluated in a local area network and in the cloud to test the feasibility of the framework. Performance results show the overhead of claims in local network and cloud. Vathalloor Merin George, Qusay H. Mahmoud |
COMPSAC (1) | 2 |
| 2017 | An efficient and secure scheme for smart home communication using identity-based signcryptionabstractSecuring communication between users and devices is an important aspect of Internet of Things applications. Although a number of cryptographic schemes have been proposed for securing communication among IoT devices, the ability to handle such schemes, especially with devices that have constrained computing resources, is difficult. Thus, there is a need for a secure and efficient scheme that will protect connections between devices with limited capabilities. For overcoming such constraints, many symmetric and asymmetric cryptographic techniques have been proposed. However, not all of the available cryptographic mechanisms can satisfy all of the security goals. Fortunately, there is a single mechanism that can provide combined security goals with low cost in terms of computation and communication overhead in addition to memory requirement. This technique, known as signcryption, can more efficiently satisfy authentication, integrity and confidentiality than combining encryption and signature schemes. This paper presents an identity-based signcryption scheme for smart home communication. Analysis and evaluation show that, in addition to efficiently providing authentication, the proposed scheme provides integrity and confidentiality as well as the ability to protect communication between devices against possible attacks. Yosef Ashibani, Qusay H. Mahmoud |
IPCCC | 2 |
| 2017 | ViDAQ: A Framework for Monitoring Human Machine InterfacesabstractA novel case for visual data acquisition (ViDAQ) as an non-intrusive, scalable and reliable means of monitoring Human Machine Interfaces (HMIs) is envisioned. ViDAQ is a step towards achieving real-time cross-validation of human operator commands with respect to HMI states in large scale industrial control room environments. HMIs are integral in allowing human operators to safely command and monitor various critical processes, such as in nuclear power plants, commercial aviation, public transit vehicles, etc. However, HMI related perceptual dynamics presents a challenge to the designed safeguards against human-in-the-loop errors, which, ultimately is dependent on operator situational awareness. We envision, an expert supervisory framework for HMIs (EYE-on-HMI) utilizing ViDAQ, that is scalable and extensible to various industrial applications with prospective safety improvement to next generation commercial automation especially those with "driverless" operational modes. To this end, we present the design, implementation and evaluation of the ViDAQ to visually read rotary multi-dial meters herein. Harsh V. P. Singh, Qusay H. Mahmoud |
ISORC | 2 |
| 2017 | HMI-guard: A platform for detecting errors in human-machine interfacesabstractThe HMI-Guard platform opens up a non-intrusive means of guarding against human errors that are introduced by Human-in-the-loop (HITL) interaction via the Human Machine Interfaces (HMIs). Motivation for this framework is partly in response to prevalence of legacy HMI devices (E.g. meters, rotary dials, gauges, alarm indicators, etc.) in industrial control room environments such as in nuclear power plants, aviation and automotive industry that must be manually monitored by trained operators. Alternatively, real-time monitoring of legacy HMI devices requires digital data acquisition which, may require expensive retrofits, design changes and cause production downtime. Moreover, severity of accidents caused due to operator error in manually reading these devices can be reduced if HITL errors are promptly discovered, trended and intervened upon. Harsh V. P. Singh, Qusay H. Mahmoud |
SMC | 2 |
| 2017 | Cyber physical systems security: Analysis, challenges and solutions
Yosef Ashibani, Qusay H. Mahmoud |
Comput. Secur. | 2 |
| 2016 | Fair and Delay Adaptive Scheduler (FDAS) preliminary modeling and optimizationabstractFair and Delay Adaptive Scheduler (FDAS) is a scheduling mechanism that dynamically adapts to the incoming traffic flows' requirements in term of bandwidth allocation, delay bounds and packet loss restrictions. It performs this utilizing both virtual finish time fluid scheduling along with schedulability and delay sensitive scheduling. The former ensures that the flows receive a fair share of the available output throughput while the later ensures that time critical flows that are about to expire will receive preferential treatment when needed to avoid getting garbled and dropped when possible. FDAS tries to maximize the satisfaction as perceived by incoming traffic flows through balancing between bandwidth fairness and delay bound accommodation. FDAS acts as a hybrid scheduler that tries to overcome fairness allocation problems due to preferential treatment for the soon-to-expire packets which happens in Earliest Deadline First (EDF) schedulers. Meanwhile, it tries to minimize the number of packets that violate their deadlines for transmission and get garbled accordingly that happens on Weighted Fair Queuing (WFQ) and its derivatives. In this paper, we try to answer the question of how many of the flows and how much of their traffic can be accommodated in terms of delay bound and throughput requirements given the incoming mixture of traffic with diverse QoS requirements. FDAS preliminary modeling and optimization is discussed in this paper to answer the above question in a manner that maximizes the overall performance satisfaction as perceived by incoming flows taking into consideration traffic priorities, if any. Abdelwahab M. Elnaka, Qusay H. Mahmoud, Xining Li |
CCNC | 2 |
| 2016 | Simulation based comparative performance analysis of QoS traffic scheduling using fair and delay adaptive scheduler (FDAS) versus WFQ and EDFabstractSeveral objectives are aimed when scheduling traffic for transmission on heterogeneous networks. Traffic flows might belong and required to satisfy different set of requirements for a diverse set of applications, end users and networks. Schedulers have several goals to achieve in order to meet the needs of all stakeholders involved. Some schedulers are built to ensure fairness in bandwidth allocation, others try to prioritize certain flows and increase their share in the network resources, typically available bandwidth, and last but not least some are built to meet the stringent and time critical delay constraint of certain flows. Weighted fair queuing (WFQ) is a very well known scheduling algorithm that fairly allocates bandwidth between a set of flows contending for available output bandwidth while taking their weights into its scheduling calculation. Earliest deadline first (EDF), on the other hand, is a scheduling mechanism that favors flow packets that are about to expire and gives them preferential treatment and priority to be transmitted first. Neither WFQ nor EDF achieves both fairness and deadline goals simultaneously. For this reason, we introduced our fair and delay adaptive scheduler (FDAS) to bridge the gap and balance between fairness and delay requirements of incoming traffic flows. In this paper, we present a detailed simulation comparative study to manifest the difference between our proposed scheduler and the two popular schedulers and how it outperforms both to relatively achieve both bandwidth allocation fairness and traffic delay bound objectives simultaneously. Abdelwahab M. Elnaka, Qusay H. Mahmoud, Xining Li |
CCNC | 2 |
| 2016 | The Sensorian IoT platformabstractThe Sensorian platform is an add-on sensor shield that transforms the Raspberry Pi into an IoT platform. It is compatible with all of the existing models of the Raspberry Pi (A/B, B+, version 1 and 2), and the firmware has been tested with the Raspbian operating system, and a custom image is available for download from [1]. A Kickstarter campaign has been successfully completed and 400 shields have been shipped. The Sensorian IoT platform can be used for tinkering and for teaching, learning and research. Qusay H. Mahmoud, Dhimiter Qendri |
CCNC | 1 |
| 2016 | The Sensorian Shield: Transforming the Raspberry Pi into an IoT PlatformabstractSensorian is an add-on sensor shield that transforms the Raspberry Pi into an IoT platform. This academic project has been successfully funded through a Kickstarter campaign. The product has been developed and 400 boards have already been shipped. The objective of this demo is not to sell the shield at SIGCSE 2016, but rather to tell the story of the Sensorian shield and demo how students can build on this open source project and learn to tinker with software and hardware technologies. It can be used for a variety of courses, from introducing programming IoT applications in CS1 to Linux and embedded systems. More information about the Sensorian shield can be found at www.sensorian.io. Qusay H. Mahmoud, Dhimiter Qendri, Michael Lescisin |
SIGCSE | 1 |
| 2015 | Range-free localization approach for M2M communication system using mobile anchor nodes
Lutful Karim, Nidal Nasser, Qusay H. Mahmoud, Alagan Anpalagan, Tarek El Salti |
J. Netw. Comput. Appl. | 3 |
| 2015 | An evaluation framework for cross-platform mobile application development toolsabstractSummary The mobile application market is becoming increasingly fragmented with the availability of multiple mobile platforms that differ in development procedures. Developers are forced to choose to support only some platforms and specific devices because of limited development resources. To address these challenges, numerous tools have been created to aid developers in building cross‐platform applications; however, there is no metric to evaluate the quality of these tools or the applications produced by them. This paper introduces a framework for evaluating the features, performance, and development experience of existing and future cross‐platform development tools. The framework is implemented by benchmarking several tools, and the results identify a disparity in the features and performance of applications built using different development tools. Copyright © 2014 John Wiley & Sons, Ltd. Sunny Dhillon, Qusay H. Mahmoud |
Softw. Pract. Exp. | 2 |
| 2014 | Evaluation of a platform for the provisioning of community-contributed web servicesabstractDespite research spanning more than a decade in the area of Web services, the industry has not yet seen a consensus regarding an effective method for the provisioning of Web services. In recent years, a new paradigm for implementing Web services based on Representational State Transfer, the successful architectural foundation of the Web, has seen greater interest in the industry. We had previously proposed a framework for the implementation of platforms for provisioning community-contributed Web services using the REpresentational State Transfer (REST) paradigm. We had also presented a proof-of-concept prototype implementation of the framework for use as a reference. In this paper, we elaborate more on the prototype by presenting its architecture and then present the results of evaluating the performance of this prototype in order to explore the feasibility of our proposed framework. Daniel Vijayakumar, Qusay H. Mahmoud |
IPCCC | 2 |
| 2014 | An integrated framework for wireless sensor network managementabstractWireless Sensor Networks (WSNs) have significant potential in many application domains, and are poised for growth in many markets ranging from agriculture and animal welfare to home and office automation. Although sensor network deployments have only begun to appear, the industry still awaits the maturing of this technology to realize its full benefits. The main constraints to large scale commercial adoption\nof sensor networks are the lack of available network management and control tools for determining the degree of data aggregation prior to transforming it into useful information, localizing the sensors accurately so that timely emergency actions can be taken at exact location, and scheduling data packets so that data are sent based\non their priority and fairness. Moreover, due to the limited communication range of sensors, a large geographical area cannot be covered, which limits sensors application domain. Thus, we investigate a scalable and flexible WSN architecture that relies on multi-modal nodes equipped with IEEE 802.15.4 and IEEE 802.11 in order to use a Wi-Fi overlay as a seamless gateway to the Internet through WiMAX networks. We focus on network management approaches such as sensors localization, data scheduling, routing, and data aggregation for the WSN plane of this large scale multimodal network architecture and find that most existing approaches are not scalable, energy efficient, and fault tolerant. Thus, we introduce an efficient approach for each of localization, data scheduling, routing, and data aggregation; and compare the performance of proposed approaches with existing ones in terms of network energy consumptions, localization error, end-to-end data transmission delay and packet delivery ratio. Simulation results, theoretical and statistical analysis show that each of these approaches outperforms the existing approaches. To the best of our knowledge, no integrated network management solution comprising efficient localization, data scheduling, routing, and data aggregation approaches exists in the literature for a large scale WSN. Hence, we e±ciently integrate all network management components so that it can be used as a single network management solution for a large scale WSN, perform experimentations to evaluate the performance of the proposed framework, and validate the results through statistical analysis. Experimental results show that our proposed framework outperforms existing approaches in terms of localization energy consumptions, localization accuracy, network energy consumptions and end-to-end data transmission delay. Lutful Karim, Qusay H. Mahmoud, Nidal Nasser, Nargis Khan |
Wirel. Commun. Mob. Comput. | 2 |
| 2013 | A hybrid mobility model based on social, cultural and language diversityabstractHuman Mobility Models (HMMs) have become increasingly relevant in different application domains including networks designed for data dissemination protocols. Most existing HMMs consider the temporal and spatial features of human mobility. In addition, many recent HMMs based on social networks have b Lutful Karim, Qusay H. Mahmoud |
CollaborateCom | 2 |
| 2012 | A collaborative Bluetooth-based approach to localization of mobile devicesabstractIn this paper we present a collaborative Bluetooth localization method, which aggregates the location information about Bluetooth devices that is provided by multiple mobile devices. The method aims to take advantage of an enhanced version of the KNN algorithm in which the location of a mobile devic Nicholas Mair, Qusay H. Mahmoud |
CollaborateCom | 2 |
| 2012 | LRSA: A multi-component Wireless Sensor Network management frameworkabstractAlthough Wireless Sensor Networks (WSNs) have significant applications in monitoring, security and other areas, they still lack network management solutions to enable large scale adoption. Such solutions would help in determining the degree of data aggregation prior to transforming it into useful information, localizing the sensors accurately, scheduling and routing data by reducing end-to-end delay, and energy consumptions. Moreover, to the best of our knowledge, no integrated network management framework consisting of efficient localization, data scheduling, routing, and data aggregation approaches exists in the literature for a large scale WSN. Thus, we introduce an integrated management framework comprising sensors Localization, Routing, data Scheduling, and Aggregation (LRSA) for a large scale WSN. Simulation results show that LRSA outperforms other approaches in terms of localization energy consumptions and error, end-to-end delay, and network energy consumptions. Lutful Karim, Qusay H. Mahmoud, Nidal Nasser, Nargis Khan |
GLOBECOM | 2 |
| 2012 | Hands-on labs for a mini-course on mobile application development (abstract only)abstractIn this poster we present a set of hands-on labs for a mini-course on mobile application development that can be used as a lab component of any Computing course. The labs revolve around a single theme whereby students experiment with designing and developing the user interface, interaction model, and inter-connectivity of a mobile application for Google Scholar; the developed application can be deployed on a variety of mobile platforms, including BlackBerry, Android, and iPhone devices (smartphones and tablets). Students learn about mobile programming models and cross-platform development and appreciate the unique opportunities such devices offer, but also become aware of the development challenges they present. For more information, please visit: http://cmer.uoguelph.ca. Qusay H. Mahmoud, Nicholas Mair, Sunny Dhillon |
SIGCSE | 1 |
| 2011 | Workshop - Introducing and teaching smartphone application developmentabstractThe diversity of mobile hardware and software platforms is one of the major challenges in developing applications for mobile devices such as smartphones. Mobile applications are developed on platform like MS Windows or Linux, and deployed on a totally different platform such as a BlackBerry smartphone. Integrating mobile devices into computing education can raise the level of excitement for students, and satisfaction with the curriculum [1]. This workshop will help participants understand the different echnologies that can be used for mobile application development, and the opportunities and challenges in integrating mobile devices into the computing curricula. The workshop is of particular interest to Computer Science, Information Technology, and Engineering faculty interested in integrating smartphones and mobile application development into their courses. Qusay H. Mahmoud |
FIE | 1 |
| 2011 | Best practices in teaching mobile application developmentabstractThis paper presents best practices for teaching mobile application development across the Computing curricula. While the focus is on the BlackBerry smartphone, the best practices can be used when teaching application development for other mobile platforms. The best practices are supported by the freely available CMER Academic Kit for integrating mobile devices into the Computer Science Curriculum. Qusay H. Mahmoud |
ITiCSE | 1 |
| 2011 | A mobile web-based approach to introductory programmingabstractIn this paper an approach for teaching introductory programming courses using mobile web-based technologies is introduced. This approach focuses on using standard Web technologies, such as HTML, JavaScript, and Cascading Style Sheets to make teaching computer programming fun, especially for users of mobile devices. This approach is supported by the CMER Academic Kit for integrating mobile devices into the Computer Science Curriculum. Qusay H. Mahmoud |
ITiCSE | 1 |
| 2010 | MobiEureka: an approach for enhancing the discovery of mobile web services
Eyhab Al-Masri, Qusay H. Mahmoud |
Pers. Ubiquitous Comput. | 2 |
| 2010 | WSB: a broker-centric framework for quality-driven web service discoveryabstractAbstract Web service interfaces can be discovered through several means, including service registries, search engines, service portals, and peer‐to‐peer networks. But discovering Web services in such heterogeneous environments is becoming a challenging task and raises several concerns, such as performance, reliability, and robustness. In this paper, we introduce the Web Service Broker (WSB) framework that provides a universal access point for discovering Web services. WSB uses a crawler to collect the plurality of Web services disseminated throughout the Web, continuously monitor the behavior of Web services in delivering the expected functionality, and enable clients to articulate service queries tailored to their needs. The framework features ranking algorithms we have developed which are capable of ranking services according to Quality of Web Service parameters. WSB can be seamlessly integrated into the existing service‐oriented architectures. Copyright © 2010 John Wiley & Sons, Ltd. Eyhab Al-Masri, Qusay H. Mahmoud |
Softw. Pract. Exp. | 2 |
| 2009 | A service broker and business model for saas applicationsabstractEnterprise software is being transformed from an installed product to a hosted service whereby customers pay a subscription fee to access functionality using a Web browser or other clients. The service-oriented architecture (SOA) and Web services will play a key role in driving the vision of software as a service (SaaS). As the number of services and users grow, there is a need for a trusted service broker to manage services offered by service providers and subscribed customers. In this paper we propose a trusted service broker for SaaS applications. In addition to a business model, one of the novel features of this broker is an environment for an Internet desktop that allows users to login and use the applications at anytime from anywhere as long as they have a computer and an Internet connection. This model has a very close resemblance to the old thin client model and the old mainframe setups where the terminals really didn't need to have any special CPU power or mass storage capacity. A proof of concept implementation is discussed; it enables users to have an integrated set of applications that closely reflect their business process or the tasks they are trying to accomplish. Qusay H. Mahmoud |
AICCSA | 2 |
| 2009 | Device-Aware Discovery and Ranking of Mobile ServicesabstractWhile several service discovery protocols and standards have been proposed for supporting service discovery from mobile devices, this remains a challenging problem. In many cases, mobile clients may discover services which they consider relevant but soon realize that such services are not completely usable on their mobile devices due to compatibility and interoperability issues. Without integrating device capabilities into the discovery process, or a device-aware mobile service discovery, it becomes extremely difficult to determine whether discovered services may or may not function properly within the device's constraints. This paper introduces a solution to this problem and proposes MobiEureka, a mobile device- aware system for enhancing the discovery of mobile services using mobile devices. This paper presents experimental validation, results, and analysis of the presented ideas. Eyhab Al-Masri, Qusay H. Mahmoud |
CCNC | 2 |
| 2009 | Privacy-Aware Web Services in Smart Homes
Zakaria Maamar, Qusay H. Mahmoud, Nabil Sahli, Khouloud Boukadi |
ICOST | 2 |
| 2009 | An academic kit for integrating mobile devices into the CS curriculumabstractIn this paper we present our freely available academic kit to help universities in integrating mobile devices into the Computer Science (CS) curriculum. The kit was designed and developed at the Centre for Mobile Education and Research at the University of Guelph, and includes instructors' resources for introducing and teaching mobile application development. The first release of the kit includes the teaching material for a full introductory course on mobile application development, and concrete teaching modules for integrating mobile devices into courses on software engineering, game design and development, web services, information security, and operating systems. Qusay H. Mahmoud, Thanh Ngo, Razieh Niazi, Pawel Popowicz, Robert Sydoryshyn, Matthew Wilks, Dave Dietz |
ITiCSE | 1 |
| 2009 | Understanding Web Service Discovery GoalsabstractArticulating proper services search queries has been a challenging task for clients when searching for relevant Web services. Service discovery search results will not be improved unless we determine ways for correctly understanding client discovery goals. In this paper, we introduce a solution to this problem and perform a key study for understanding service discovery goals. We introduce the concept of Quality of Web Service (QWS) for our quality-driven ranking mechanism. Based on our study, we determine that service discovery goals can be defined as exploratory or informational. We further use these findings to demonstrate how the knowledge of service discovery goals are beneficial in improving the way clients perform service search queries. Results from our experiments are intriguing and show that the performance of informational service queries in terms of precision improves the querying process by 36.26% and 40.39% when compared to Google's PageRank and Yahoo, respectively. We further use our findings to provide insights on improving the service retrieval process. Eyhab Al-Masri, Qusay H. Mahmoud |
SMC | 2 |
| 2009 | Discovering the Best Web Service: A Neural Network-based SolutionabstractDifferentiating between Web services that share similar functionalities is becoming a major challenge into the discovery of Web services. In this paper we propose a framework for enabling the efficient discovery of Web services using Artificial Neural Networks (ANN) best known for their generalization capabilities. The core of this framework is applying a novel neural network model to Web services to determine suitable Web services based on the notion of the Quality of Web Service (QWS). The main concept of QWS is to assess a Web service's behaviour and ability to deliver the requested functionality. Through the aggregation of QWS for Web services, the neural network is capable of identifying those services that belong to a variety of class objects. The overall performance of the proposed method shows a 95% success rate for discovering Web services of interest. To test the robustness and effectiveness of the neural network algorithm, some of the QWS features were excluded from the training set and results showed a significant impact in the overall performance of the system. Hence, discovering Web services through a wide selection of quality attributes can considerably be influenced with the selection of QWS features used to provide an overall assessment of Web services. Eyhab Al-Masri, Qusay H. Mahmoud |
SMC | 2 |
| 2008 | Investigating web services on the world wide webabstractSearching for Web service access points is no longer attached to service registries as Web search engines have become a new major source for discovering Web services. In this work, we conduct a thorough analytical investigation on the plurality of Web service interfaces that exist on the Web today. Using our Web Service Crawler Engine (WSCE), we collect metadata service information on retrieved interfaces through accessible UBRs, service portals and search engines. We use this data to determine Web service statistics and distribution based on object sizes, types of technologies employed, and the number of functioning services. This statistical data can be used to help determine the current status of Web services. We determine an intriguing result that 63% of the available Web services on the Web are considered to be active. We further use our findings to provide insights on improving the service retrieval process. Eyhab Al-Masri, Qusay H. Mahmoud |
WWW | 2 |
| 2008 | Monte Carlo simulation-based algorithms for estimating the reliability of mobile agent-based systems
Mosaab Daoud, Qusay H. Mahmoud |
J. Netw. Comput. Appl. | 2 |
| 2008 | Guest editorial: Service-oriented computingabstracteditorial Free Access Share on Guest editorial: Service-oriented computing Authors: Qusay H. Mahmoud University of Guelph, Canada University of Guelph, CanadaView Profile , Peter Langendoerfer IHP, Germany IHP, GermanyView Profile Authors Info & Claims ACM Transactions on Internet TechnologyVolume 8Issue 3May 2008 Article No.: 11pp 1–3https://doi.org/10.1145/1361186.1361187Published:28 May 2008Publication History 0citation526DownloadsMetricsTotal Citations0Total Downloads526Last 12 Months1Last 6 weeks1 Get Citation AlertsNew Citation Alert added!This alert has been successfully added and will be sent to:You will be notified whenever a record that you have chosen has been cited.To manage your alert preferences, click on the button below.Manage my Alerts New Citation Alert!Please log in to your account Save to BinderSave to BinderCreate a New BinderNameCancelCreateExport CitationPublisher SiteeReaderPDF Qusay H. Mahmoud, Peter Langendörfer |
ACM Trans. Internet Techn. | 1 |
| 2008 | Toward Behavioral Web Services Using PoliciesabstractMaking Web services context-aware is a challenge. This is like making Web service expose appropriate behaviors in response to changes detected in the environment. Context awareness requires a review and extension of the current execution model of Web services. This paper discusses the seamless combination of context and policy to manage behaviors that Web services expose during composition and in response to changes in the environment. For this purpose, a four-layer approach is devised. These layers are denoted by policy, user, Web service, and resource. In this approach, behavior management and binding are subject to executing policies of types permission, obligation, restriction, and dispensation. A prototype that illustrates how context and policy are woven into Web services composition scenarios is presented as well. Zakaria Maamar, Djamal Benslimane, Ghita Kouadri Mostéfaoui, Sattanathan Subramanian, Qusay H. Mahmoud |
IEEE Trans. Syst. Man Cybern. Part A | 5 |
| 2007 | A Framework for Efficient Discovery of Web Services Across Heterogeneous RegistriesabstractGrowth and propagation of the Internet has been a contributing factor for information overload which acts as a deterrent for quick and easy discovery of information. As Web services proliferate, the same dilemma perceived in the discovery of Web pages will become tangible. Currently, the automatic discovery of Web services, an important capability of service- oriented architecture (SOA), is mainly achieved by performing inquiries to business registries such as the UDDI or ebXML. The ability to discover Web services across multiple heterogeneous registries is becoming a challenging task and raises several issues such as performance, reliability, and robustness. In this paper, we introduce the Web Service Repository Builder (WRSB) that serves as an integrated SOA registry and repository for managing the proliferation of Web services and system artifacts. Specifically, the proposed framework actively captures and navigates among multiple service registries and provides a unified environment for the discovery of Web services. The WSRB framework is compatible with, and can be integrated seamlessly into, the existing infrastructure without any modifications to the existing environments. Eyhab Al-Masri, Qusay H. Mahmoud |
CCNC | 2 |
| 2007 | QoS-based Discovery and Ranking of Web ServicesabstractDiscovering Web services using keyword-based search techniques offered by existing UDDI APIs (i.e. Inquiry API) may not yield results that are tailored to clients' needs. When discovering Web services, clients look for those that meet their requirements, primarily the overall functionality and Quality of Service (QoS). Standards such as UDDI, WSDL, and SOAP have the potential of providing QoS-aware discovery, however, there are technical challenges associated with existing standards such as the client's ability to control and manage discovery of Web services across accessible service registries. This paper proposes a solution to this problem and introduces the Web Service Relevancy Function (WsRF) used for measuring the relevancy ranking of a particular Web service based on client's preferences, and QoS metrics. We present experimental validation, results, and analysis of the presented ideas. Eyhab Al-Masri, Qusay H. Mahmoud |
ICCCN | 2 |
| 2007 | WSCE: A Crawler Engine for Large-Scale Discovery of Web ServicesabstractThis paper addresses issues relating to the efficient access and discovery of Web services across multiple UDDI Business Registries (UBRs). The ability to explore Web services across multiple UBRs is becoming a challenge particularly as size and magnitude of these registries increase. As Web services proliferate, finding an appropriate Web service across one or more service registries using existing registry APIs (i.e. UDDI APIs) raises a number of concerns such as performance, efficiency, end-to-end reliability, and most importantly quality of returned results. Clients do not have to endlessly search accessible UBRs for finding appropriate Web services particularly when operating via mobile devices. Finding relevant Web services should be time effective and highly productive. In an attempt to enhance the efficiency of searching for businesses and Web services across multiple UBRs, we propose a novel exploration engine, the Web Service Crawler Engine (WSCE). WSCE is capable of crawling multiple UBRs, and enables for the establishment of a centralized Web services' repository which can be used for large-scale discovery of Web services. The paper presents experimental validation, results, and analysis of the presented ideas. Eyhab Al-Masri, Qusay H. Mahmoud |
ICWS | 2 |
| 2007 | Relevancy Ranking of Web ServicesabstractIn order for Web services to truly become a standard approach for just-in-time application integration, we need to enhance the discovery mechanism by assisting clients to select relevant Web services of interest. In recent years, there have been several standards that regulate how services can be published, discovered, or used (i.e. UDDI, WSDL, SOAP). Many of these standards have the potential of enhancing the discovery process, however, there are major technical challenges associated with these standards. One of these challenges is the client’s ability to control and mange the discovery process for finding Web services of interest. Clients should be able to find relevant services much more efficiently. To address this issue, we propose a Web Service Ranking (WSR) algorithm for measuring the relevancy of Web services to particular clients’ requirements. This paper presents experimental validation, results and analysis of the presented ideas. Eyhab Al-Masri, Qusay H. Mahmoud |
SMC | 2 |
| 2007 | A fuzzy approach to reliability estimation of mobile agent-based systemsabstractIn this paper we explore the reliability of mobile agent-based systems under the assumption of uncertainty regarding the system's environment (network). The lack of information about the failure rates of processors and communications links make it hard to estimate the required reliability using the conventional approach. To solve this problem, a fuzzy approach is suggested and experiments are conducted through Monte Carlo simulation. The results show the robustness of the proposed approach. Mosaab Daoud, Qusay H. Mahmoud |
SMC | 2 |
| 2007 | Crawling multiple UDDI business registriesabstractAs Web services proliferate, size and magnitude of UDDI Business Registries (UBRs) are likely to increase. The ability to discover Web services of interest then across multiple UBRs becomes a major challenge specially when using primitive search methods provided by existing UDDI APIs. Clients do not have the time to endlessly search accessible UBRs for finding appropriate services particularly when operating via mobile devices. Finding services of interest should be time effective and highly productive. This paper addresses issues relating to the efficient access and discovery of Web services across multiple UBRs and introduces a novel exploration engine, the Web Service Crawler Engine (WSCE). WSCE is capable of crawling multiple UBRs, and enables for the establishment of a centralized Web services repository that can be used for discovering Web services much more efficiently. The paper presents experimental validation, results, and analysis of the proposed ideas. Eyhab Al-Masri, Qusay H. Mahmoud |
WWW | 2 |
| 2007 | Discovering the best web serviceabstractMajor research challenges in discovering Web services include, provisioning of services across multiple or heterogeneous registries, differentiating between services that share similar functionalities, improving end-to-end Quality of Service (QoS), and enabling clients to customize the discovery process. Proliferation and interoperability of this multitude of Web services have lead to the emergence of new standards on how services can be published, discovered, or used (i.e. UDDI, WSDL, SOAP). Such standards can potentially provide many of these features and much more, however, there are technical challenges associated with existing standards. One of these challenges is the client.s ability to control the discovery process across accessible service registries for finding services of interest. This work proposes a solution to this problem and introduces the Web Service Relevancy Function (WsRF) used for measuring the relevancy ranking of a particular Web service based on QoS metrics and client preferences. We present experimental validation, results, and analysis of the presented ideas. Eyhab Al-Masri, Qusay H. Mahmoud |
WWW | 2 |
| 2007 | Dynamic management of UDDI registries in a wireless environment of web services: Concepts, architecture, operation, and deployment
Zakaria Maamar, Hamdi Yahyaoui, Qusay H. Mahmoud |
J. Intell. Inf. Syst. | 3 |
| 2007 | Design and implementation of a smart system for personalization and accurate selection of mobile services
Qusay H. Mahmoud, Eyhab Al-Masri, Zhixin Wang |
Requir. Eng. | 1 |
| 2006 | A context-aware mobile service discovery and selection mechanism using artificial neural networksabstractIn this paper we present SmartCon, a context-aware system for the discovery and selection of mobile services using Artificial Neural Networks (ANNs). The solution we have developed is a mobile agent-enabled system that adaptively and iteratively learns to select the best available mobile service derived from the extraction of a series of features utilizing contextual information such as the Composite Capabilities/Preferences Profile (CC/PP), service-specific, and non-uniform user-specific features which are supplied to a backpropagation neural network. Based on the features provided, the neural network classifies the most relevant mobile service. In the present work, the system is also capable through iterative learning to generalize and gather information using cognitive feedback based on user's decisions and interactivity with a mobile device. SmartCon is evaluated using a series of preliminary empirical data and results show an 87% success rate in the discovery and selection of the best or most relevant mobile service. Eyhab Al-Masri, Qusay H. Mahmoud |
ICEC | 2 |
| 2006 | On Promoting Ad-Hoc Collaboration Among MessengersabstractThe explosion growth in the market place for handheld wireless devices has enabled new opportunities for wireless applications. Currently, handheld devices are restricted to being clients that make requests to servers and receive responses over the network. But as mobile ad-hoc networks become the trend, such devices will need to become active participants that serve requests from other devices and convey data to other devices as well. In this paper we present our vision of the future role that handheld devices will play in a mobile ad-hoc network configuration. We present this vision as part of the MESSENGER, project that develops data management mechanisms for UDDI registries of Web services using mobile users and their software agents, and then describe its extension for exchanging descriptions of Web services during ad-hoc collaboration sessions. User agents are in charge of interacting with peer users over an ad-hoc network, and collaborating on feeding UDDI registries with recent content Zakaria Maamar, Qusay H. Mahmoud, Abdelouahid Derhab |
AINA (1) | 2 |
| 2006 | Customizing and delivering mobile services using software agents and CC/PPabstractA downside brought about by the explosive growth of online information and the shear amount of data traffic moving through our networks is the modern day headaches of information overload. The growth of handheld wireless devices can only mean that the end-users will continually be bombarded by emails and real-time information feeds, but now, even as they are on the go. Software agents provide mechanisms that have good potentials to lower the amount of information that an end- user has to deal with. Agent-enabled applications allow the end- user to personalize the way online resources are presented and can also filter out irrelevant or unwanted information. In this paper, we present our experience in using software agents and the Composite Capabilities/Preference Profiles (CC/PP) for customizing and delivering mobile services for Java 2 Micro Edition (J2ME) enabled and Wireless Application Protocol (WAP) enabled devices. We use software agents because such autonomous software entities have characteristics that can benefit mobile devices and the wireless environment, and the CC/PP is a standard for defining profiles for user preferences and device capabilities. Qusay H. Mahmoud, Zhixin Wang |
CCNC | 1 |
| 2006 | Provisioning Context-Aware Advertisements to Wireless Mobile UsersabstractMobile advertising, which is an area of mobile commerce, is a form of advertising that targets users of handheld wireless devices such as mobile phones and personal digital assistants (PDAs). Given the constraints of such devices, mobile advertisements should be context-aware in the sense that the behaviour of such value-added services is mostly driven by information based on user's location, time, user preferences, and the task at hand. This paper presents the design and prototyping of a system for provisioning context-aware advertisements to wireless mobile users. We use mobile agents because such autonomous entities have characteristics that can benefit mobile devices and the wireless environment. We have constructed a proof of concept implementation using Java technologies with support for WAP-enabled and J2ME-enabled devices Qusay H. Mahmoud |
ICME | 1 |
| 2006 | Ad-Hoc Collaboration Between Messengers: Operations and IncentivesabstractThis paper discusses how ad-hoc collaboration boosts the operation of a set of messengers. This discussion continues the research we earlier initiated in theMESSENGER project, which develops data management mechanisms for UDDI registries of Web services using mobile users and software agents. In the current operation mode of messengers, descriptions of Web services are first, collected from UDDI registries and later on, distributed to other UDDI registries. This distribution mode of Web services descriptions does not foster the tremendous opportunities that both wireless technologies and mobile devices offer. When mobile devices are in the vicinity of each other, they can form a mobile ad-hoc network, which enables the exchange of data between these devices without any preexisting communication infrastructure. By authorizing messengers to engage in collaboration, collecting additional descriptions of Web services from other messengers can happen, too. Zakaria Maamar, Qusay H. Mahmoud, Abdelouahid Derhab, Wathiq Mansoor |
MDM | 2 |
| 2005 | Reliability Estimation of Mobile Agent Systems Using the Monte Carlo ApproachabstractIn this paper two algorithms are proposed for estimating the reliability of mobile agent systems, which are based on the conditions of the underlying computer network. A third algorithm is proposed for generating a random static planning strategy for mobile agents. The complexity of the mobile agent system network makes it hard to obtain the reliability of the system theoretically; instead we estimate it using the Monte Carlo simulation approach. In this paper, we assume that the system consists of a number of independent mobile agents operating simultaneously. The results we have achieved demonstrate the robustness of the proposed algorithms. Mosaab Daoud, Qusay H. Mahmoud |
AINA | 2 |
| 2005 | A Framework for Automatic and Dynamic Composition of Personalized Web ServicesabstractThis paper presents a framework that enables automatic and dynamic composition of Web services, and allows them to be displayed on virtually any mobile device. The framework proposes new context-aware techniques that make this possible. The design and implementation of a new service registry is discussed; this registry is more efficient that current techniques that involve semantics with UDDI. The CC/PP is used to aid in the compatibility of devices that need to use our system based on our personalized service finder (PSF) framework. We propose the use of output dependencies to customize the discovery process of services, and to help ensure the quality of the results. Wassam Zahreddine, Qusay H. Mahmoud |
AINA | 2 |
| 2005 | An Agent-Based Approach to Composite Mobile Web ServicesabstractThe ability to access Web services over mobile devices would allow users to expand the capabilities of their appliance. Accessing several services to complete one goal can be cumbersome because now the user has to sift through several service providers and examine responses from each. This is inconvenient given the low bandwidth and high latency of wireless connections. This paper proposes an agent-based approach for composite mobile Web services over mobile devices. Three methods for composition are discussed and compared. Wassam Zahreddine, Qusay H. Mahmoud |
AINA | 2 |
| 2005 | Maximizing the route reliability of mobile agents in unreliable environmentsabstractAutonomous mobility of an agent is the most important feature of mobile agent-based systems. In this paper, we study the reliability of mobility (movement) of an agent in a faulty network environment with invariant (constant) latencies between its nodes. To achieve a reliable agent, we used the integer linear programming model to maximize the route reliability to complete a given task. The suggested criteria could be used as part of the planning module in the planning system of mobile agents. Moreover, we propose a bi-objective planning strategy when the network latencies are highly varied. This leads to a new concept which we call it a mixed planning strategy; it is locally static within each subnetwork but globally dynamic over all connected subnetworks. Mosaab Daoud, Qusay H. Mahmoud |
ISADS | 2 |
| 2005 | Blending Web services and agents for mobile usersabstractThis paper investigates Web services and mobile agents as two individually powerful technologies and when combined together, provides ease of use and reliability for any user. Web services have their shortfalls but with the help of mobile agents these weaknesses can be overcome. A single Web service may not be enough to satisfy a user's requirements. It might be necessary to combine multiple Web services together (a composite service) to satisfy a requirement; that is where agents can be used to compose Web services on behalf of their users. On the other hand, when agents move around to perform a task on behalf of a user, they will need to execute a service and such a service might be a Web service itself. In this paper, we discuss why agents and Web services should not be viewed as competing technologies and we present methods for integrating them together to deliver reliable services to the end user. Wassam Zahreddine, Qusay H. Mahmoud |
ISADS | 2 |
| 2005 | Estimating the Task Route Reliability of Mobile Agent-Based Systems Using Monte Carlo SimulationabstractIn this paper we propose two algorithms for estimating the task route reliability of mobile agent-based systems (MABS), which are based on the conditions of the underlying computer network. In addition, we propose a third algorithm for generating a random static planning strategy for mobile agents. The complexity of mobile agent network systems makes it hard to obtain the task route reliability of the MABS theoretically; instead we estimate it using Monte Carlo simulation. In this paper, we assume that the MABS consists of a number of independent mobile agents operating simultaneously. The results we have achieved demonstrate the robustness of the proposed algorithms. Mosaab Daoud, Qusay H. Mahmoud |
ISCC | 2 |
| 2005 | Guest Editors' Introduction
Qusay H. Mahmoud, Upkar Varshney |
Mob. Networks Appl. | 1 |
| 2005 | A Comprehensive Service Discovery Solution for Mobile Ad Hoc Networks
Jerry Tyan, Qusay H. Mahmoud |
Mob. Networks Appl. | 2 |
| 2004 | Messengers for the Dynamic Management of Distributed UDDI RegistriesabstractThis work presents an approach for the dynamic management of the content of several Universal Description, Discovery, and Integration (UDDI) registries. By content, it is meant the announcements of Web services that providers post on various distributed UDDI registries. Unlike other initiatives in the field of Web services, our concerns are the following: availability of several UDDI registries, no predefined communication infrastructure between the UDDI registries, and no centralized component to coordinate the UDDI registries. The solution presented in this paper integrates users and software agents into what we call messengers. When a user is in the vicinity of an UDDI registry, his software agent, which resides in his mobile device, interacts with that registry. The objective is to submit the details on Web services that are stored in the mobile device. Zakaria Maamar, Hamdi Yahyaoui, Qusay H. Mahmoud, Soraya Kouadri Mostéfaoui, Wathiq Mansoor |
MobiQuitous | 3 |
| 2004 | Redesigning introductory computer programming with HTML, JavaScript, and JavaabstractIn this paper we describe our experience in the design and teaching of a new evolutionary introductory programming course in a new Distributed Computing and Communications Systems Technology program at the University of Guelph-Humber. This course is evolutionary and innovative because it integrates the use of HTML, JavaScript, and Java in a one-semester introductory computer programming course. This is a marked departure from the use of a single conventional, general purpose, programming language such as Java or C++. The course is designed with two goals in mind: to improve the students experience in their first computer programming; and to achieve retention in the new program. Qusay H. Mahmoud, Wlodzimierz Dobosiewicz, David A. Swayne |
SIGCSE | 1 |
| 2004 | Practice and experience with Java in educationabstractPractice and experience with Java in educationThe Java programming language has been a phenomenal success.By removing some of the syntactic absurdities of C++, Java has become the dominant language for undergraduate programming courses.Its simple object-oriented model and libraries for networking and graphical user interfaces have made it better suited to conveying object-oriented concepts and advanced computing topics such as threads and distributed objects.In addition, its platform-independent architecture has made it the language of choice for developing applications that run anywhere, from the smallest devices to the most scalable servers.No language is perfect, however, and Java is no exception.The main method signature, public static void main(String argv[]), for example, contains several constructs that are not easy to explain to first year computing students with no previous computing background.In addition, the large number of libraries may offer an intimidating feeling for students who want to master Java.The aim of this issue is to report on experiences with Java in education and provide a snapshot of its continuing evolution.The papers included in this issue, which address the challenges discussed above, reflect the broad spectrum of the Java programming language.To this end, Kenneth J. Goldman presents "An interactive environment for beginning Java programmers", that discusses JPie-an integrated development environment that supports live construction of Java programs by direct manipulation of graphical representations of class definitions.Using JPie, students can learn the Java programming language while avoiding many of the common pitfalls and distractions of textual programming.In "Educational and technical design of a Web-based interactive tutorial on programming in Java", Claudia Bieg and Stephan Diehl present JOSH-online, an interactive interpreter that allows students to learn by trial and error.They believe that this approach encourages students to consolidate and extend their newly acquired knowledge by means of experimental verification.In "A Java-based system for building animated presentations over the Web", Vincenzo Bonifaci, Benedetto A. Colombo, Camil Demetrescu, Irene Finocchi, and Luigi Laura describe Leonardo Web, which is a collection of tools for building animated presentations for teaching and e-learning.Leonardo allows such presentations to be posted and viewed over the Web using an applet.In "A Java-based approach for teaching principles of adaptive and evolvable software", Jeff Gray describes his experiences in teaching a special-topics software engineering Qusay H. Mahmoud |
Sci. Comput. Program. | 1 |