Source author record

Hazem M. Soliman

Hazem M. Soliman appears in the imported research catalog. Authorship, coauthor and topic links are available while profile ownership is still unclaimed.

ResearcherUnclaimed source record

Catalog footprint

What is connected

2works
3topics
4close collaborators

Actions

Connect this record

Log in to claim

Research graph

See the researcher in context

Open full explorer

Inspect adjacent papers, topics, institutions and collaborators without losing the researcher page.

Building this map preview

BZPEER is loading the nearby papers, people, topics and institutions for this page.

Published work

2 published item(s)

preprint2021arXiv

RANK: AI-assisted End-to-End Architecture for Detecting Persistent Attacks in Enterprise Networks

Advanced Persistent Threats (APTs) are sophisticated multi-step attacks, planned and executed by skilled adversaries targeting modern government and enterprise networks. Intrusion Detection Systems (IDSs) and User and Entity Behavior Analytics (UEBA) are commonly employed to aid a security analyst in the detection of APTs. The prolonged nature of APTs, combined with the granular focus of UEBA and IDS, results in overwhelming the analyst with an increasingly impractical number of alerts. Consequent to this abundance of data, and together with the crucial importance of the problem as well as the high cost of the skilled personnel involved, the problem of APT detection becomes a perfect candidate for automation through Artificial Intelligence (AI). In this paper, we provide, up to our knowledge, the first study and implementation of an end-to-end AI-assisted architecture for detecting APTs -- RANK. The goal of the system is not to replace the analyst, rather, it is to automate the complete pipeline from data sources to a final set of incidents for analyst review. The architecture is composed of four consecutive steps: 1) alert templating and merging, 2) alert graph construction, 3) alert graph partitioning into incidents, and 4) incident scoring and ordering. We evaluate our architecture against the 2000 DARPA Intrusion Detection dataset, as well as a read-world private dataset from a medium-scale enterprise. Extensive results are provided showing a three order of magnitude reduction in the amount of data to be reviewed by the analyst, innovative extraction of incidents and security-wise scoring of extracted incidents.

preprint2011arXiv

Fair Allocation of Backhaul Resources in Multi-Cell MIMO Co-operative Networks

In this paper the problem of allocating the limited backhaul bandwidth among users in Multi-cell MIMO cooperative networks is considered. We approach the problem from both the sum-rate and fairness perspectives. First, we show that there are many allocations that can provide near maximum sumrate while varying significantly in fairness, which is assessed through the mean versus variance criteria. Second, Two novel schemes that achieve near maximum sum-rate while offering fair allocation of the backhaul bandwidth among users are proposed: the Equal Signal-to-Interference ratio (SIR) and the Equal Interference schemes. Simulation results show that, for the same mean rate among users, the proposed schemes can achieve more fairness when compared to the conventional scheme, which gives all users the same share of bandwidth. Moreover, we show that the Equal SIR scheme can achieve zero variance among users in a wide range of backhaul bandwidths while keeping very close to maximum sum rate. This is the most fair solution that can be used in Multi-cell MIMO in that range of backhaul bandwidths.