VLDB 2026 Research / reviewers in the wild / expert
Rémi Badonnel
dblp:04/5407 · also Remi Badonnel
· DBLP profile ↗
48ranked-venue papers
10as first author
11since 2021 · last 2026
0000-0001-9213-4695ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 19 · 8 first-author · 5 since 2021Security and privacy · 3 · 2 since 2021Software engineering, systems software and programming languages · 3 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Vulnerability-Aware Secure Service Deployment in Cloud-Edge ContinuumabstractSoftware weaknesses and vulnerabilities are continuously discovered and rapidly evolving. Their direct and indirect interference with the business process workflow execution is neither fully understood nor addressed by the current literature. The strict control of the vulnerability footprint of the landing platform before cloud/web service workflow execution is nowadays largely used as a prevention measure in order to improve execution trustworthiness. The vulnerability footprint governance is exacerbated by the cloud, where a common execution platform hosting (vulnerable) services is shared between different tenants. The paper proposes a service workflow deployment solution tailored for Edge-Cloud Continuum, made of different landing platforms showing different peculiarities. The proposed solution is capable of finding a suitable deployment recipe for a given workflow by i) evaluating the vulnerability footprint of each platform, ii) computing the set of candidate deployment platforms, iii) finding the optimal deployment solution, and iv) migrating already deployed workflows in case the vulnerability requirement is no longer satisfied. Each workflow can be associated with a set of requirements to be satisfied by our deployment solution, like the maximum level of vulnerability footprint accepted. Each workflow deployment contributes to the vulnerability footprint of the landing platform involved. Ruslan Bondaruc, Nicolas Schnepf, Rémi Badonnel, Claudio A. Ardagna, Marco Anisetti |
IEEE Trans. Netw. Serv. Manag. | 3 |
| 2025 | Enhancing Artificial Intelligence with Verification Techniques to Support Automated Moving Target Defense in Cloud Composite ServicesabstractAdvancements in softwarization and service composition have contributed to the deployment of large-scale distributed cloud services across diverse infrastructures. The growing complexity of these services, combined with the continuous emergence of new vulnerabilities, constitutes a significant challenge in terms of security management. Moving target defense strategies, leveraged by artificial intelligence, offer new opportunities to protect them. At the meantime, the changes that are operated by these strategies may lead these services into vulnerable configurations. We propose in this paper a moving target defense strategy which bridges the gap between artificial intelligence and configuration verification techniques. The objective is to select the movements to be applied on the cloud composite service, in order to reduce the predictability of configuration changes, while minimizing the risk of critical vulnerable configurations. We formalize and design a framework exploiting reinforcement learning and SMT solving, to support this strategy. We also perform large series of experiments to evaluate the feasibility and performance of our solution based on OVAL vulnerability descriptions. Mohamed Oulaaffart, Rémi Badonnel, Nicolas Schnepf, Christophe Bianco |
NetSoft | 2 |
| 2025 | Eagle: Vulnerability and Congestion Aware Software Update Synthesis in Softwarized Networks with a 5G Network Case StudyabstractEffective scheduling of software updates is a significant challenge in network operations and management, particularly when considering specific performance and security requirements. This paper focuses on the synthesis of such software updates in the context of emerging virtualized and softwarized networks, such as 5G network infrastructures, with the objective of ensuring vulnerability avoidance and congestion freedom at any time during the updates. We formalize the update synthesis problem and propose an algorithmic solution, called Eagle, that exploits formal methods and mixed integer linear programming, to achieve optimal solutions. We then complement it with a greedy algorithm to support faster computation. We exemplify our framework considering an implementation of a 5G architecture, as the one described in the ETSI 5123 standard, and which relies on kubernetes. Finally, we evaluate our approach through a large range of realistic ISP topologies from the Topology Zoo dataset, and we also perform extensive experiments on our kubernetes cluster, where we execute the software update sequences generated by our tool. This allows us to discuss the scalability of our approach along with its practical applicability. Nicolas Schnepf, Rémi Badonnel, Damien Saucez, Stefan Schmid 0001, Jirí Srba |
NOMS | 2 |
| 2022 | Job Adverts Analyzer for Cybersecurity Skills Needs EvaluationabstractThis article presents a new free web-based application, the Cybersecurity Job Ads Analyzer, which has been created to collect and analyse job adverts using a machine learning algorithm. This algorithm enables the detection of the skills required in advertised cybersecurity work positions. The application is both interactive and dynamic allowing for automated analyses and for the underlying database of job adverts to be easily updated. Through the Cybersecurity Job Ads Analyzer, it is possible to explore the skills required over time, and thereby enable academia and other training providers to better understand and address the needs of the industry. We will describe in detail the user interface and technical background of the application, as well as highlight the preliminary statistical results we have obtained from analysing the current database of job adverts. Sara Ricci, Marek Sikora, Simon Parker, Imre Lendak, Yianna Danidou, Argyro Chatzopoulou, Rémi Badonnel, Donatas Alksnys |
ARES | 7 |
| 2022 | An Automated SMT-based Security Framework for Supporting Migrations in Cloud Composite ServicesabstractThe growing maturity of orchestration languages is contributing to the elaboration of cloud composite services, whose resources may be deployed over different distributed infrastructures. These composite services are subject to changes over time, that are typically required to support cloud properties, such as scalability and rapid elasticity. In particular, the migration of their elementary resources may be triggered by performance constraints. However, changes induced by this migration may introduce vulnerabilities that may compromise the resources, or even the whole cloud service. In that context, we propose an automated SMT1-based security framework for supporting the migration of resources in cloud composite services, and preventing the occurrence of new configuration vulnerabilities. We formalize the underlying security automation based on SMT solving, in order to assess the migrated resources and select adequate counter-measures, considering both endogenous and exogenous security mechanisms. We then evaluate its benefits and limits through large series of experiments based on a proof-of-concept prototype implemented over the CVC4 commonly-used open-source solver. These experiments show a minimal overhead with regular operating systems deployed in cloud environments. Mohamed Oulaaffart, Rémi Badonnel, Christophe Bianco |
NOMS | 2 |
| 2022 | Guest Editors Introduction: Special Section on Recent Advances in Network Security ManagementabstractAs the backbone of communications amongst objects, humans, companies, and administrations, the Internet has become a great integration platform capable of efficiently interconnecting billions of entities, from RFID chips to data centers. This platform provides access to multiple hardware and virtualized resources (servers, networking, storage, applications, connected objects) coming from cloud computing and Internet-of-Things (IoT) infrastructures. From these resources that may be hosted and distributed amongst different providers and tenants, the building and operation of complex and value-added networked systems is enabled. Rémi Badonnel, Carol J. Fung, Sandra Scott-Hayward, Qi Li 0002, Fulvio Valenza, Cristian Hesselman |
IEEE Trans. Netw. Serv. Manag. | 1 |
| 2021 | PESTLE Analysis of Cybersecurity EducationabstractCybersecurity is a vital part of digital economies and digital governing but the discipline is suffering from a pronounced skills shortage. Nevertheless, the reasons for the inability of academia to produce enough graduates with the skills that reflect the needs of the cybersecurity industry are not well understood. Sara Ricci, Vladimir Janout, Simon Parker, Jan Jerabek, Jan Hajny, Argyro Chatzopoulou, Rémi Badonnel |
ARES | 7 |
| 2021 | An Ensemble Learning-Based Architecture for Security Detection in IoT InfrastructuresabstractThe Internet of Things has known an important development. However, security management is still a key challenge in particular for deploying complex IoT systems that provide sophisticated services. In this paper, we design an ensemble learning-based architecture to support early security detection in the context of multi-step attacks, by leveraging the performance of different detection techniques. The architecture relies on a total of five major methods, including process mining, elliptic envelope, one class support vector machine, local outlier factor and isolation forest. We describe the main components of this architecture and their interactions, from the data preprocessing to the generation of alerts, through the calculation of scores. The different detection methods are executed in parallel, and their results are combined by an ensemble learning strategy in order to improve the overall detection performance. We develop a proof-of-concept prototype and perform a large set of experiments to quantify the benefits and limits of this approach based on industrial datasets. Adrien Hemmer, Mohamed Abderrahim 0002, Rémi Badonnel, Isabelle Chrisment |
CNSM | 3 |
| 2021 | Towards Automating Security Enhancement for Cloud Services
Mohamed Oulaaffart, Rémi Badonnel, Olivier Festor |
IM | 2 |
| 2021 | Guest Editors' Introduction: Special Issue on Latest Developments for Security Management of Networks and ServicesabstractAs the backbone of communications amongst objects, humans, companies, and administrations, the Internet has become a great integration platform capable of efficiently interconnecting billions of entities, from RFID chips to data centers. This platform provides access to multiple hardware and virtualized resources (servers, networking, storage, applications, connected objects) coming from cloud computing and Internet-of-Things (IoT) infrastructures. From these resources that may be hosted and distributed amongst different providers and tenants, the building and operation of complex and value-added networked systems is enabled. Rémi Badonnel, Carol J. Fung, Sandra Scott-Hayward, Qi Li 0002, Jie Zhang 0002, Cristian Hesselman |
IEEE Trans. Netw. Serv. Manag. | 1 |
| 2021 | Comparative Assessment of Process Mining for Supporting IoT Predictive SecurityabstractThe growth of the Internet-of-Things (IoT) has been characterized by the large-scale deployment of sensors and connected objects. These ones are integrated with other Internet resources in order to elaborate more complex systems and applications. Security management is a major challenge for these systems due to their complexity, their heterogeneity and the limited resources of their devices. In this article we evaluate the exploitability and performance of a process mining approach for detecting misbehaviors in such systems. We describe the considered architecture and detail its operation, from the generation of behavioral models to the detection of potential attacks. We formalize several alternative commonly-used detection methods, including elliptic envelope, support-vector machine, local outlier factor, and isolation forest techniques. After presenting a proof-of-concept prototype, we quantify comparatively the benefits and limits of our process mining solution combined with data pre-processing, through extensive experiments based on different industrial datasets. Adrien Hemmer, Mohamed Abderrahim 0002, Rémi Badonnel, Jérôme François, Isabelle Chrisment |
IEEE Trans. Netw. Serv. Manag. | 3 |
| 2020 | A Process Mining Approach for Supporting IoT Predictive SecurityabstractThe growing interest for the Internet-of-Things (IoT) is supported by the large-scale deployment of sensors and connected objects. These ones are integrated with other Internet resources in order to elaborate more complex and value-added systems and applications. While important efforts have been done for their protection, security management is a major challenge for these systems, due to their complexity, their heterogeneity and the limited resources of their devices. In this paper we introduce a process mining approach for detecting misbehaviors in such systems. It permits to characterize the behavioral models of IoT-based systems and to detect potential attacks, even in the case of heterogenous protocols and platforms. We then describe and formalize its underlying architecture and components, and detail a proof-of-concept prototype. Finally, we evaluate the performance of this solution through extensive experiments based on real industrial datasets. Adrien Hemmer, Rémi Badonnel, Isabelle Chrisment |
NOMS | 2 |
| 2020 | A Process Mining Tool for Supporting IoT SecurityabstractThe development of the Internet has been characterized by a growing interest for the Internet-of-Things (IoT). In particular, connected devices are integrated to other Internet resources (such as cloud resources) to elaboratevalue-added services. However, they pose important challenges with respect to security management due to their heterogeneity, their distribution, and their limited resources. In this demonstration, we present a process mining toool for supporting IoT security. This tool is capable to automate the detection of misbehaviours and attacks in large and heterogeneous IoT infrastructures, based on process mining techniques combined with normalization and clustering data pre-processing. We detail the different building blocks of this tool provided into a docker container, and illustrate its operations with different scenarios. Adrien Hemmer, Rémi Badonnel, Jérôme François, Isabelle Chrisment |
NOMS | 2 |
| 2020 | From virtualization security issues to cloud protection opportunities: An in-depth analysis of system virtualization models
Maxime Compastié, Rémi Badonnel, Olivier Festor, Ruan He |
Comput. Secur. | 2 |
| 2020 | Guest Editorial: Special Section on Cybersecurity Techniques for Managing Networked SystemsabstractAs the backbone of communications amongst objects, humans, companies, and administrations, the Internet has become a great integration platform capable of efficiently interconnecting billions of entities, from RFID chips to data centers. This platform provides access to multiple hardware and virtualized resources (servers, networking, storage, applications, connected objects) coming from cloud computing and Internet-of-Things (IoT) infrastructures. From these resources that may be hosted and distributed amongst different providers and tenants, the building and operation of complex and value-added networked systems is enabled. Rémi Badonnel, Carol J. Fung, Qi Li 0002, Sandra Scott-Hayward |
IEEE Trans. Netw. Serv. Manag. | 1 |
| 2019 | Automated Factorization of Security Chains in Software-Defined Networks
Nicolas Schnepf, Rémi Badonnel, Abdelkader Lahmadi, Stephan Merz |
IM | 2 |
| 2019 | A Tool Suite for the Automated Synthesis of Security Function Chains
Nicolas Schnepf, Rémi Badonnel, Abdelkader Lahmadi, Stephan Merz |
IM | 2 |
| 2019 | A TOSCA-Oriented Software-Defined Security Approach for Unikernel-Based Protected CloudsabstractCloud infrastructures provide new facilities to build elaborated added-value services by composing and configuring a large variety of computing resources, from virtualized hardware devices to software products. In the meantime, they are further exposed to security attacks than traditional environments. The complexity of security management tasks has been increased by the multi-tenancy, heterogeneity and geographical distribution of these resources. They introduce critical issues for cloud service providers and their customers, with respect to security programmability and scenarios of adaptation to contextual changes. In this paper, we propose a software-defined security approach based on the TOSCA language, to enable unikernel-based protected clouds. We first introduce extensions of this language to describe unikernels and specify security constraints for their orchestrations. We then describe an architecture exploiting this extended version of TOSCA for automatically generating, deploying and adjusting cloud resources in the form of protected unikernels with a low attack surface. We finally detail a proof-of-concept prototype, and evaluate the proposed solution through extensive series of experiments. Maxime Compastié, Rémi Badonnel, Olivier Festor, Ruan He |
NetSoft | 2 |
| 2018 | Demo: On-the-fly generation of unikernels for software-defined security in cloud infrastructuresabstractThe programmability of security mechanisms through software-defined security permits the outsourcing of security management to a dedicated plan. Unikernels offer new perspectives for supporting this programmability, and addressing the challenges with respect to the heterogeneity and the dynamics of cloud resources. In this demo, we demonstrate how unikernel properties may enable an adequate security enforcement at the resource level. We present a framework for integrating security mechanisms into unikernel virtual machines, and align them to a given security policy, through the on-the-fly unikernel VM generation. We showcase an implementation prototype and confront it to cloud exploitation scenarios. Maxime Compastié, Rémi Badonnel, Olivier Festor, Ruan He |
NOMS | 2 |
| 2018 | Unikernel-based approach for software-defined security in cloud infrastructuresabstractThe heterogeneity of cloud resources implies substantial overhead to deploy and configure adequate security mechanisms. In that context, we propose a software-defined security strategy based on unikernels to support the protection of cloud infrastructures. This approach permits to address management issues by uncoupling security policy from their enforcement through programmable security interfaces. It also takes benefits from unikernel virtualization properties to support this enforcement and provide resources with low attack surface. These resources correspond to highly constrained configurations with the strict minimum for a given period. We describe the management framework supporting this software-defined security strategy, formalizing the generation of unikernel images that are dynamically built to comply with security requirements over time. Through an implementation based on MirageOS, and extensive experiments, we show that the cost induced by our security integration mechanisms is small while the gains in limiting the security exposure are high. Maxime Compastié, Rémi Badonnel, Olivier Festor, Ruan He, Mohamed Kassi-Lahlou |
NOMS | 2 |
| 2018 | Synaptic: A formal checker for SDN-based security policiesabstractSoftware-defined networking offers new opportunities for protecting end users by designing dynamic security policies. In particular, security chains can be built by combining security functions, such as firewalls, intrusion detection systems and services for preventing data leakage. The configuration of these security functions and their associated policies is based on behavioural models of end-user applications when accessing the network. In this demo, we present our tool Synaptic, a SDN-based framework intended for the formal verification of security policies as well as for automatically generating such policies based on automata learning methods applied on NetFlow records of end-user applications collected at the device level. Nicolas Schnepf, Rémi Badonnel, Abdelkader Lahmadi, Stephan Merz |
NOMS | 2 |
| 2018 | Generation of SDN policies for protecting android environments based on automata learningabstractSoftware-defined networking offers new opportu-nities for protecting end users and their applications. In that context, dedicated chains can be built to combine different security functions, such as firewalls, intrusion detection systems and services for preventing data leakage. To configure these security chains, it is important to have an adequate model of the patterns that end user applications exhibit when accessing the network. We propose an automated strategy for learning the networking behavior of end applications using algorithms for generating finite state models. These models can be exploited for inferring SDN policies ensuring that applications respect the observed behavior: such policies can be formally verified and deployed on SDN infrastructures in a dynamic and flexible manner. Our solution is prototypically implemented as a collection of Python scripts that extend our Synaptic verification package. The performance of our strategy is evaluated through extensive experimentations and is compared to the Synoptic and Invarimint automata learning algorithms. Nicolas Schnepf, Rémi Badonnel, Abdelkader Lahmadi, Stephan Merz |
NOMS | 2 |
| 2017 | Automated verification of security chains in software-defined networks with synapticabstractSoftware-defined networks provide new facilities for deploying security mechanisms dynamically. In particular, it is possible to build and adjust security chains to protect the infrastructures, by combining different security functions, such as firewalls, intrusion detection systems and services for preventing data leakage. It is important to ensure that these security chains, in view of their complexity and dynamics, are consistent and do not include security violations. We propose in this paper an automated strategy for supporting the verification of security chains in software-defined networks. It relies on an architecture integrating formal verification methods for checking both the control and data planes of these chains, before their deployment. We describe algorithms for translating specifications of security chains into formal models that can then be verified by SMT1solving or model checking. Our solution is prototyped as a package, named Synaptic, built as an extension of the Frenetic family of SDN programming languages. The performances of our approach are evaluated through extensive experimentations based on the CVC4, veriT, and nuXmv checkers. Nicolas Schnepf, Rémi Badonnel, Abdelkader Lahmadi, Stephan Merz |
NetSoft | 2 |
| 2017 | A Distributed Monitoring Strategy for Detecting Version Number Attacks in RPL-Based NetworksabstractThe Internet of Things is characterized by the large-scale deployment of low power and lossy networks (LLN), interconnecting pervasive objects. The routing protocol for LLN (RPL) protocol has been standardized by IETF to enable a lightweight and robust routing in these constrained networks. A versioning mechanism is incorporated into RPL in order to maintain an optimized topology. However, an attacker can exploit this mechanism to significantly damage the network and reduce its lifetime. After analyzing and comparing existing work, we propose in this paper a monitoring strategy with dedicated algorithms for detecting such attacks and identifying the involved malicious nodes. The performance of this solution is evaluated through extensive experiments, and its scalability is quantified with the support of a monitoring node placement optimization method. Anthéa Mayzaud, Rémi Badonnel, Isabelle Chrisment |
IEEE Trans. Netw. Serv. Manag. | 2 |
| 2016 | A Software-Defined Security Strategy for Supporting Autonomic Security Enforcement in Distributed CloudabstractWe propose in this paper a software-defined security framework, for supporting the enforcement of security policies in distributed cloud environments. These ones require security mechanisms able to cape with their multi-tenancy and multi-cloud properties. This framework relies on the autonomic paradigm to dynamically configure and adjust these mechanisms to distributed cloud constraints, and exploit the software-defined logic to express and propagate security policies to the considered cloud resources. The proposed framework is evaluated through a set of validation scenarios corresponding to a realistic use cases including cloud resource allocation/deallocation, cloud resource state change, and dynamic access control. Maxime Compastié, Rémi Badonnel, Olivier Festor, Ruan He, Mohamed Kassi-Lahlou |
CloudCom | 2 |
| 2016 | Detecting version number attacks in RPL-based networks using a distributed monitoring architectureabstractThe concept of Internet of Things involves the deployment of Low power and Lossy Networks (LLN) allowing communications among pervasive devices such as embedded sensors. The IETF designed the Routing Protocol for Low power and Lossy Networks (RPL) for supporting these constrained networks. Keeping in mind the different requirements of such networks, the protocol supports multiple routing topologies, called DODAGs, built using different objective functions, so as to optimize routing based on several metrics. A DODAG versioning system is incorporated into RPL in order to ensure an optimized topology. However, an attacker can exploit this mechanism to damage the network and reduce its lifetime. In this paper we propose a detection strategy based on a distributed monitoring architecture with dedicated algorithms that is able to identify malicious nodes performing such attacks in RPL-based environments. The performance of this solution is evaluated through extensive experiments and its scalability is quantified considering a monitoring node placement method. Anthéa Mayzaud, Rémi Badonnel, Isabelle Chrisment |
CNSM | 2 |
| 2016 | Using the RPL protocol for supporting passive monitoring in the Internet of ThingsabstractMost devices deployed in the Internet of Things (IoT) are expected to suffer from resource constraints. Using specialized tools on such devices for monitoring IoT networks would take away precious resources that could otherwise be dedicated towards their primary task. In many IoT applications such as Advanced Metering Infrastructure (AMI) networks, higher order devices are expected to form the backbone infrastructure, to which the constrained nodes would connect. It would, as such, make sense to exploit the capabilities of these higher order devices to perform network monitoring tasks. We propose in this paper a distributed monitoring architecture that takes benefits from specificities of the IoT routing protocol RPL to passively monitor events and network flows without having impact upon the resource constrained nodes. We describe the underlying mechanisms of this architecture, quantify its performances through a set of experiments using the Cooja environment. We also evaluate its benefits and limits through a use case scenario dedicated to anomaly detection. Anthéa Mayzaud, Anuj Sehgal, Rémi Badonnel, Isabelle Chrisment, Jürgen Schönwälder |
NOMS | 3 |
| 2015 | Behavioral and dynamic security functions chaining for Android devicesabstractWe present an approach for dynamically outsourcing and composing security functions for mobile devices, according to the network behavior of their running applications. Applications are characterized from a network point of view using data mining and clustering techniques with the aim to select their appropriate security functions. Software-defined networking mechanisms are employed to chain the selected functions and to redirect mobile apps traffic through the resulting security compositions. Those ones can be fully outsourced or split between in-cloud and on-device. Both a prototype and extensive simulations demonstrate the feasibility of the approach and assess its benefits. Gaetan Hurel, Rémi Badonnel, Abdelkader Lahmadi, Olivier Festor |
CNSM | 2 |
| 2015 | Towards cloud-based compositions of security functions for mobile devicesabstractIn order to prevent attacks against smartphones and tablets, dedicated security applications are usually deployed on the mobile devices themselves. However, these applications may have a significant impact on the device resources, and users may be tempted to uninstall or disable them. In this paper, we propose a new approach to outsource mobile security functions and build transparent in-path security compositions for mobile devices. The functions are dynamically activated, configured and composed using software-defined networking and virtualization capabilities. We present a mathematical formalization to model the security compositions, and describe the functional architecture. We provide an implementation prototype and evaluate the solution through an extensive set of experiments. Gaetan Hurel, Rémi Badonnel, Abdelkader Lahmadi, Olivier Festor |
IM | 2 |
| 2014 | A SAT-based autonomous strategy for security vulnerability managementabstractComputer and network systems are consistently exposed to security threats, making their management even more complex. The management of known vulnerabilities plays a crucial role for ensuring their safe configurations and preventing security attacks. However, this activity should not generate new vulnerable states. In this paper we present a novel approach for autonomously assessing and remediating vulnerabilities. We describe a detailed mathematical model that supports this activity and we formalize the remediation decision process as a SAT problem. We present a framework that is able to assess OVAL vulnerability descriptions and perform corrective actions by using XCCDF-based descriptions of future machine states and the NETCONF protocol. We also provide details of our implementation and evaluate its feasibility through a comprehensive set of experiments. Martín Barrère, Rémi Badonnel, Olivier Festor |
NOMS | 2 |
| 2013 | A probabilistic cost-efficient approach for mobile security assessmentabstractThe development of mobile technologies and services has contributed to the large-scale deployment of smartphones and tablets. These environments are exposed to a wide range of security attacks and may contain critical information about users such as contact directories and phone calls. Assessing configuration vulnerabilities is a key challenge for maintaining their security, but this activity should be performed in a lightweight manner in order to minimize the impact on their scarce resources. In this paper we present a novel approach for assessing configuration vulnerabilities in mobile devices by using a probabilistic cost-efficient security framework. We put forward a probabilistic assessment strategy supported by a mathematical model and detail our assessment framework based on OVAL vulnerability descriptions. We also describe an implementation prototype and evaluate its feasibility through a comprehensive set of experiments. Martín Barrère, Gaetan Hurel, Rémi Badonnel, Olivier Festor |
CNSM | 3 |
| 2013 | Improving present security through the detection of past hidden vulnerable states
Martín Barrère, Rémi Badonnel, Olivier Festor |
IM | 2 |
| 2013 | Ovaldroid: An OVAL-based vulnerability assessment framework for Android
Martín Barrère, Gaetan Hurel, Rémi Badonnel, Olivier Festor |
IM | 3 |
| 2012 | Collaborative remediation of configuration vulnerabilities in autonomic networks and systems
Martín Barrère, Rémi Badonnel, Olivier Festor |
CNSM | 2 |
| 2012 | A trust-based strategy for addressing residual attacks in the RELOAD architectureabstractTelephony over IP has undergone a large-scale deployment thanks to the development of high-speed broadband access and the standardization of signalling protocols. A particular attention is currently given to P2PSIP networks which are exposed to many security threats. The RELOAD protocol defines a peer-to-peer signalling overlay designed to support these networks. It introduces a security framework based on certification mechanisms, but P2PSIP networks are still exposed to residual attacks, such as refusals of service. We propose in this work to address these residual attacks by integrating into the RELOAD architecture a dedicated trust model coupled with prevention countermeasures. We mathematically defines this trust-based strategy, and describe the considered prevention mechanisms implemented by safeguards and watchmen. We quantify the benefits and limits of our solution through an extensive set of experiments. Oussema Dabbebi, Rémi Badonnel, Olivier Festor |
ICC | 2 |
| 2012 | Towards the assessment of distributed vulnerabilities in autonomic networks and systemsabstractVulnerability management constitutes a crucial activity within autonomic networks and systems. Distributed vulnerabilities must be assessed over a consolidated view of the network in order to detect vulnerable states that may simultaneously involve two or more devices. In this work, we present a novel approach for describing and assessing distributed vulnerabilities in such self-governed environments. We put forward a mathematical construction for defining distributed vulnerabilities as well as an extension of the OVAL language called DOVAL for describing them. We then define a framework for assessing distributed vulnerabilities in autonomic environments that exploits the knowledge provided by such descriptions. We finally show the feasibility of our solution by analyzing the behavior of the proposed algorithms and strategies through a comprehensive set of experiments. Martín Barrère, Rémi Badonnel, Olivier Festor |
NOMS | 2 |
| 2012 | Dynamic exposure control in P2PSIP networksabstractVoice over IP services have undergone a large-scale deployment thanks to the development of high-speed broadband access and the standardization of dedicated signaling protocols. They offer new opportunities, in particular in the context of peer-to-peer networks. However they are exposed to multiple security attacks due to a lower confinement in comparison to traditional networks. Protection mechanisms are available, but may significantly impact the service performance. We propose in this paper a risk management strategy for dynamically adapting the exposure of P2PSIP networks. We describe the underlying mechanisms for mitigating risks based on a portfolio of countermeasures. We also detail the mathematical modeling which supports our solution based on the analysis of a case study. Finally we quantify the benefits and limits of this approach through an extensive set of experiments performed with the OMNET++ simulator. Oussema Dabbebi, Rémi Badonnel, Olivier Festor |
NOMS | 2 |
| 2011 | Supporting vulnerability awareness in autonomic networks and systems with OVAL
Martín Barrère, Rémi Badonnel, Olivier Festor |
CNSM | 2 |
| 2011 | A broad-spectrum strategy for runtime risk management in VoIP enterprise architecturesabstractTelephony over IP (ToIP) has known a large scale deployment and is supported by the standardization of dedicated signalling protocols. This service is less confined than traditional telephony and is exposed to multiple security attacks. In the meantime, protection mechanisms may seriously impact on its performance. Risk management provides new opportunities for dynamically controlling the service exposure while maintaining low security costs. We propose in this paper a broad-spectrum strategy for runtime risk management in VoIP networks and services. We first analyse and model VoIP attacks based on their observability properties. We then generalize a runtime risk model capable of automatically assessing and treating risks based on dynamic safeguards. In particular, we quantify the potentiality of VoIP attacks and the induced risks with respect to their observability. We evaluate the benefits as well as the limits of our solution through an implementation prototype and an extensive set of simulations. Oussema Dabbebi, Rémi Badonnel, Olivier Festor |
Integrated Network Management | 2 |
| 2010 | Risk management in VoIP infrastructures using support vector machinesabstractTelephony over IP is exposed to multiple security threats. Conventional protection mechanisms do not fit into the highly dynamic, open and large-scale settings of VoIP infrastructures, and may significantly impact on the performance of such a critical service. We propose in this paper a runtime risk management strategy based on anomaly detection techniques for continuously adapting the VoIP service exposure. This solution relies on support vector machines (SVM) and exploits dynamic security safeguards to reduce risks in a progressive manner. We describe how SVM parameters can be integrated into a runtime risk model, and show how this framework can be deployed into an Asterisk VoIP server. We evaluate the benefits and limits of our solution through a prototype and an extensive set of experimental results. Mohamed Nassar 0001, Oussema Dabbebi, Rémi Badonnel, Olivier Festor |
CNSM | 3 |
| 2010 | Automated runtime risk management for voice over IP networks and servicesabstractVoice over IP (VoIP) has become a major paradigm for providing telephony services at a lower cost and with a higher flexibility. VoIP infrastructures are however exposed to multiple security issues both inherited from the IP layer and specific to the application layer. In the meantime, protection mechanisms are available but may seriously impact on the continuity and quality of such critical services. We propose in this paper an automated risk management schema for continuously adapting VoIP equipment exposure by activating security safeguards in a dynamic and progressive manner. We describe the architecture supporting our solution, the considered risk model taking into account VoIP properties and the algorithms for restricting and relaxing the risk level of the VoIP service at runtime. The benefits and limits of our solution are evaluated through an implementation prototype and an extensive set of experimental results in the case scenario of SPIT attacks. Oussema Dabbebi, Rémi Badonnel, Olivier Festor |
NOMS | 2 |
| 2009 | Monitoring and counter-profiling for Voice over IP networks and servicesabstractVoice over IP (VoIP) has become a major paradigm for providing lower operational costs and higher flexibility in networks and services. VoIP infrastructures are however facing multiple security issues. In particular, monitoring methods and techniques can be applied to VoIP traffic in order to profile and track network users. We present in this paper a counter-measure strategy for preventing VoIP profiling. We propose two functional architectures with different noise generation functions in order to dynamically generate fake VoIP messages and deteriorate the profiling performances. We quantify the benefits and limits of our approach through an implementation prototype and the analysis of experimental results obtained in the case scenario of profiling methods based on principal component analysis (PCA). Rémi Badonnel, Olivier Festor, Khaled Hamlaoui |
Integrated Network Management | 1 |
| 2008 | Dynamic pull-based load balancing for autonomic serversabstractThe growing autonomy of servers may significantly deteriorate the performance of traditional load-balancing strategies. Indeed, the authoritative decision belongs to the load-balancer, but the autonomous servers may reject the requests on their own convenience. We propose in this paper an original load-balancing strategy for transferring this authority from the load-balancer to the autonomous servers. We describe the underlying architecture and evaluate our solution based on a first set of experimentations. Rémi Badonnel, Mark Burgess |
NOMS | 1 |
| 2008 | Self-configurable fault monitoring in ad-hoc networks
Rémi Badonnel, Radu State, Olivier Festor |
Ad Hoc Networks | 1 |
| 2007 | A Probabilistic Approach for Managing Mobile Ad-Hoc NetworksabstractA pure management approach where all the nodes are managed at any time is too strict for mobile ad-hoc networks. Instead of addressing the management of the whole network, we propose a probabilistic scheme where only a subset of nodes is managed in order to provide a light-weight and efficient management. These nodes are determined based on their network behavior to favor subsets of well connected and network participating nodes. With respect to such a selective management scheme, we derive probabilistic guarantees on the percentage of nodes to be managed. Our contribution is centered on a distributed self-organizing management algorithm at the application layer, its efficient deployment into a management architecture and on a comprehensive simulation study. We will show how to organize the management plane by extracting spatio-temporal components and by selecting manager nodes with several election mechanisms based on degree centrality, eigenvector centrality and K-means paradigm. Rémi Badonnel, Radu State, Olivier Festor |
IEEE Trans. Netw. Serv. Manag. | 1 |
| 2006 | Fault Monitoring in Ad-Hoc Networks Based on Information Theory
Rémi Badonnel, Radu State, Olivier Festor |
Networking | 1 |
| 2006 | Probabilistic Management of Ad-Hoc NetworksabstractThis paper proposes a new management approach for ad-hoc networks based on probabilistic guarantees. Instead of addressing the management of the whole network, we propose a scheme where a subset of nodes is managed in order to provide a light-weight and reliable management. These nodes are determined based on their network behavior to favor subsets of well connected and network participating nodes. With respect to such a selective management scheme, we derive probabilistic guarantees on the percentage of nodes to be managed. Our contribution is centered on a distributed management self-organizing algorithm at the application layer, its efficient deployment into a management architecture as well as on a comprehensive simulation study Rémi Badonnel, Radu State, Olivier Festor |
NOMS | 1 |
| 2005 | Management of mobile ad-hoc networks: evaluating the network behaviorabstractThe increasing interest in deploying wireless networks without fixed infrastructure, based on ad-hoc networking, raises new challenges towards monitoring and managing them to provide optimal performance. We propose in this paper a management architecture based on filtering and graph dependency analysis to evaluate the behavior of mobile ad-hoc networks. We apply an analytical method based on contrast filtering to determine network traffic patterns such as routing paths and a second method based on dependency graphs to estimate node influence in the ad-hoc network. Rémi Badonnel, Radu State, Olivier Festor |
Integrated Network Management | 1 |