Romain Fontugne

dblp:13/7972 · DBLP profile ↗
← Back
36ranked-venue papers
14as first author
16since 2021 · last 2026
0000-0002-9816-5625ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 24 · 8 first-author · 12 since 2021Security and privacy · 6 · 3 first-author · 4 since 2021Graphics, computer vision, multimedia, augmented reality and games · 4 · 3 first-author
YearPublicationVenuePosition
2026 IXP dependencies: Measuring the role of IXPs in the Internet topology
Malte Tashiro, Romain Fontugne, Kensuke Fukuda
Comput. Commun.2
2025 ru-RPKI-ready: the Road Left to Full ROA Adoption
abstract
Resource Public Key Infrastructure (RPKI) has emerged as a standard for enhancing the security of Internet routing. Currently, more than 50% BGP prefixes are covered by RPKI Route Origin Authorizations (ROAs), enabling networks to validate the origin of prefix advertisements in BGP. Despite this progress, ROA adoption remains non-uniform, with key stakeholders encountering significant barriers in the adoption process. In this paper, we combine a product adoption framework with data-driven analysis of global RPKI adoption to identify persistent disparities and pinpoint the stages of the adoption process that hinder broader growth. Our study reveals that, although RPKI awareness has grown, the complexity of planning and deploying ROAs remains a significant challenge. Since no unified workflow and documentation exist for ROA planning, many organizations are left without clear operational guidance. To address this challenge, we propose a systematic framework for ROA planning and introduce ru-RPKI-ready, a platform designed to provide data and insights to facilitate ROA planning. Using ru-RPKI-ready, we characterize the routed address space not covered by RPKI ROAs. We find that 47% IPv4 and 71% IPv6 prefixes not in RPKI could be covered with minimal technical effort. Our analysis also reveals that if as few as ten organizations were to take the necessary actions, the global ROA coverage could increase by 7% for IPv4 and 19% for IPv6.
Deepak Gouda, Romain Fontugne, Cecilia Testart
IMC2
2025 Pythia: Facilitating Access to Internet Data Using LLMs and IYP
abstract
Internet data analysis is essential for policymakers and regulators to make informed decisions. Despite the various datasets made available by the research community, the analysis of these datasets is challenging due to their various formats and required analysis tools. The Internet Yellow Pages (IYP) database is designed to simplify Internet data analysis by combining many datasets into a single format. Hence, IYP enables users to retrieve data from various Internet datasets using a single querying language called Cypher. However, learning Cypher and understanding IYP’s schema is still challenging. Large Language Models (LLMs) offer the potential to generate Cypher queries from English text. In this paper, we assess the ability of different LLMs to generate Cypher queries. We introduce CypherEval, a dataset for evaluating LLM-generated Cypher queries, and we propose a methodology to benchmark LLMs for IYP. Finally, we present Pythia, a system for the generation of IYP Cypher queries.
Dimitrios Panteleimon Giakatos, Malte Tashiro, Romain Fontugne
LCN3
2025 A multipath redundancy communication framework for enhancing 5G mobile communication quality
abstract
As networks increasingly become the backbone of modern society, the demands placed on them by various applications have become more complex. In particular, the demand for high-capacity, low-latency services such as real-time streaming is increasing every year. Although 5G has been deployed to meet these needs, its effectiveness can vary significantly by location and time, and sometimes falls short of requirements. Traditionally, much of the research to improve communication stability has focused on TCP-based systems, which do not translate well to real-time UDP streaming applications. To address the above challenges, we propose a multipath redundant communication framework designed to improve the quality of real-time media streaming. This framework has been tested using multipath redundant communication over two mobile networks with a moving vehicle in an urban environment. Using a real-time streaming application based on WebRTC, our framework demonstrates a significant reduction in packet loss and an increase in bitrate, outperforming existing multipath redundant communication systems without interfering with the application’s congestion control mechanisms. • Proposal of a Framework: The paper proposes a multipath redundant communication framework to improve the streaming quality via multipath redundant communications in 5G networks, particularly focusing on UDP media streaming applications. • Implementation and Verification: The framework has been implemented and verified using multipath communication over two mobile networks, with a vehicle moving in a real experiment, leveraging a real-time streaming application based on WebRTC. • Significant Improvements Demonstrated in a real experiment: Results from the implementation show significant reductions in packet loss and increases in bitrate, which notably outperforms existing multipath redundant communication systems without disrupting the applications’ congestion control mechanisms. • Challenges Addressed: The paper discusses the specific challenges related to the traditional approaches of multipath redundancy, especially in maintaining communication quality across varied network fields and discusses the advantages of the proposed method. • Future Research Directions: The paper concludes by discussing potential future research directions, including the necessity to further evaluate the framework in varied environments to verify its general applicability and latency performance.
Koki Ito, Jin Nakazato, Romain Fontugne, Manabu Tsukada, Hiroshi Esaki
Comput. Commun.3
2025 Metis: Selecting Diverse Atlas Vantage Points
abstract
The popularity of the RIPE Atlas measurement platform comes primarily from its openness and unprecedented scale. The platform provides users with over ten thousand vantage points, called probes, and is usually considered as giving a reasonably faithful view of the Internet. A good use of Atlas, however, requires a clear understanding of its limitations and bias. In this work we highlight the influence of probe locations on Atlas measurements and advocate the importance of selecting a diverse set of probes for fair measurements. We propose Metis, a data-driven probe selection method, that picks a diverse set of probes based on topological properties (e.g., round-trip time or AS-path length). Using real experiments we show that, compared to Atlas’ default probe selection, Metis’ probe selections collect more comprehensive measurement results in terms of geographical, topological, RIR, and industry-type coverage. Metis triples the number of probes from the underrepresented AFRINIC and LACNIC regions, and improves geographical diversity by increasing the number of unique countries included in the probe set by up to 59%. In addition, we extend Metis to identify locations on the Internet where new probes would be the most beneficial for improving Atlas’ footprint. Finally, we present a website where we publish periodically updated results and provide easy integration of Metis’ selections with Atlas.
Malte Tashiro, Emile Aben, Romain Fontugne
IEEE Trans. Netw. Serv. Manag.3
2024 Sublet Your Subnet: Inferring IP Leasing in the Wild
abstract
IPv4 addresses have become a commodity with monetary value since the exhaustion of unallocated IPv4 space. This led to the rise of a secondary market for buying, selling, and leasing IPv4 addresses. While prior work has studied the IPv4 transfer behavior, the IPv4 leasing ecosystem remains largely unexplored. In this paper, we analyze the IPv4 leasing ecosystem by designing a methodology to infer leased address space for all RIRs and study its impact on routing and hosting security. We infer that 4.1% of all advertised IPv4 prefixes (0.9% of routed v4 address space) were leased in April 2024. Our method achieves 98% precision when evaluated against our validated dataset. Finally, we show that leased address space is five times more likely to be abused compared to non-leased space.
Ben Du, Romain Fontugne, Cecilia Testart, Alex C. Snoeren, K. C. Claffy
IMC2
2024 The Wisdom of the Measurement Crowd: Building the Internet Yellow Pages a Knowledge Graph for the Internet
abstract
The Internet measurement community has significantly advanced our understanding of the Internet by documenting its various components. Subsequent research often builds on these efforts, using previously published datasets. This process is fundamental for researchers, but a laborious task due to the diverse data formats, terminologies, and areas of expertise involved. Additionally, the time-consuming task of merging datasets is undertaken only if the expected benefits are worthwhile, posing a barrier to simple exploration and innovation. In this paper we present the Internet Yellow Pages (IYP), a knowledge graph for Internet resources. By leveraging the flexibility of graph databases and ontology-based data integration, we compile datasets (currently 46) from diverse and independent sources into a single harmonized database where the meaning of each entity and relationship is unequivocal. Using simple examples, we illustrate how IYP allows us to seamlessly navigate data coming from numerous underlying sources. As a result, IYP significantly reduces time to insight, which we demonstrate by reproducing two past studies and extending them by incorporating additional datasets available in IYP. Finally, we discuss how IYP can foster the sharing of datasets as it provides a universal platform for querying and describing data. This is a seminal effort to bootstrap what we envision as a community-driven project where dataset curation and ontology definitions evolve with the Internet measurement community.
Romain Fontugne, Malte Tashiro, Raffaele Sommese, Mattijs Jonker, Zachary S. Bischof, Emile Aben
IMC1
2024 A Tale of Two Synergies: Uncovering RPKI Practices for RTBH at IXPs
Ioana Livadariu, Romain Fontugne, Amreesh Phokeer, Massimo Candela, Massimiliano Stucchi
PAM (2)2
2024 Following the Data Trail: An Analysis of IXP Dependencies
Malte Tashiro, Romain Fontugne, Kensuke Fukuda
PAM (2)2
2024 Inside the Engine Room: Investigating Steam's Content Delivery Platform Infrastructure in the Era of 100GB Games
Christoff Visser, Romain Fontugne
PAM (1)2
2023 On the Importance of Being an AS: An Approach to Country-Level AS Rankings
abstract
Recent geopolitical events demonstrate that control of Internet infrastructure in a region is critical to economic activity and defense against armed conflict. This geopolitical importance necessitates novel empirical techniques to assess which countries remain susceptible to degraded or severed Internet connectivity because they rely heavily on networks based in other nation states. Currently, two preeminent BGP-based methods exist to identify influential or market-dominant networks on a global scale-network-level customer cone size and path hegemony-but these metrics fail to capture regional or national differences.
Bradley Huffaker, Romain Fontugne, Alexander Marder, K. C. Claffy
IMC2
2023 RoVista: Measuring and Analyzing the Route Origin Validation (ROV) in RPKI
abstract
The Resource Public Key Infrastructure (RPKI) is a system to add security to the Internet routing. In recent years, the publication of Route Origin Authorization (ROA) objects, which bind IP prefixes to their legitimate origin ASN, has been rapidly increasing. However, ROAs are effective only if the routers use them to verify and filter invalid BGP announcements, a process called Route Origin Validation (ROV).
Weitong Li, Zhexiao Lin, Md. Ishtiaq Ashiq, Emile Aben, Romain Fontugne, Amreesh Phokeer, Taejoong Chung
IMC5
2023 RPKI Time-of-Flight: Tracking Delays in the Management, Control, and Data Planes
Romain Fontugne, Amreesh Phokeer, Cristel Pelsser, Kevin Vermeulen, Randy Bush
PAM1
2023 Poster: Taking the Low Road: How RPKI Invalids Propagate
abstract
The Border Gateway Protocol (BGP) includes no mechanism to verify the correctness of routing information exchanged between networks. To defend against unauthorized use of address space, the IETF developed the Resource Public Key Infrastructure (RPKI), a cryptographically attested database system that facilitates validation of BGP messages. Networks can use RPKI to check whether the Autonomous System (AS) at the origin of the AS path in a BGP announcement is authorized to originate the IP prefixes being announced.
Ben Du, Cecilia Testart, Romain Fontugne, Alex C. Snoeren, K. C. Claffy
SIGCOMM3
2023 Poster: Evaluation of IPv6-only-Capable Iterative Resolvers
abstract
This paper introduces an "IPv6-only-Capable resolver" to address the issue of many zones remaining unresolvable due to a lack of IPv6 connectivity in authoritative name servers. The proposed method utilizes NAT64 to transmit packets to IPv4-only authoritative name servers and increases resolution success rates with competitive response times compared to a traditional IPv6-only resolver.
Momoka Yamamoto, Jin Nakazato, Romain Fontugne, Manabu Tsukada, Hiroshi Esaki
SIGCOMM3
2022 Mind your MANRS: measuring the MANRS ecosystem
abstract
Mutually Agreed Norms on Routing Security (MANRS) is an industry-led initiative to improve Internet routing security by encouraging participating networks to implement a series of mandatory or recommended actions. MANRS members must register their IP prefixes in a trusted routing database and use such information to prevent propagation of invalid routing information. MANRS membership has increased significantly in recent years, but the impact of the MANRS initiative on the overall Internet routing security remains unclear. In this paper, we provide the first independent look into the MANRS ecosystem by using publicly available data to analyze the routing behavior of participant networks. We quantify MANRS participants' level of conformance with the stated requirements, and compare the behavior of MANRS and non-MANRS networks. While not all MANRS members fully comply with all required actions, we find that they are more likely to implement routing security practices described in MANRS actions. We assess the relevance of the MANRS effort in securing the overall routing ecosystem. We found that as of May 2022, over 83% of MANRS networks were conformant to the route filtering requirement by dropping BGP messages with invalid information according to authoritative records, and over 95% were conformant to the routing information facilitation requirement, registering their resources in authoritative databases.
Ben Du, Cecilia Testart, Romain Fontugne, Gautam Akiwate, Alex C. Snoeren, K. C. Claffy
IMC3
2020 Persistent Last-mile Congestion: Not so Uncommon
abstract
Last-mile is the centerpiece of broadband connectivity, as poor last-mile performance generally translates to poor quality of experience. In this work we investigate last-mile latency using traceroute data from RIPE Atlas probes located in 646 ASes and focus on recurrent performance degradation. We find that in normal times probes in only 10% ASes experience persistent last-mile congestion but we recorded 55% more congested ASes during the COVID-19 outbreak. Persistent last-mile congestion is not uncommon, it is usually seen in large eyeball networks and may span years. With the help of CDN access log data, we dissect results for major ISPs in Japan, the most severely affected country in our study, and ascertain bottlenecks in the shared legacy infrastructure.
Romain Fontugne, Anant Shah, Kenjiro Cho
Internet Measurement Conference1
2020 The Internet in Crimea: a Case Study on Routing Interregnum
Romain Fontugne, Ksenia Ermoshina, Emile Aben
Networking1
2019 Detecting Network Disruptions At Colocation Facilities
abstract
Colocation facilities and Internet eXchange Points (IXPs) provide neutral places for concurrent networks to daily exchange terabytes of data traffic. Although very reliable, these facilities are not immune to failure and may experience difficulties that can have significant impacts on exchanged traffic. In this paper we devise a methodology to identify collocation facilities in traceroute data and to monitor delay and routing patterns between facilities. We also present an anomaly detection technique to report abnormal traffic changes usually due to facilities outages. We evaluate this method with eight months of traceroute data from the RIPE Atlas measurement platform and manually inspect the most prominent events, that are: an IXP outage, a DDoS attack, and a power failure in a facility. These case studies validate the benefits of the proposed system to detect real world outages from traceroute data. We also investigate the impact of anomalies at the metropolitan-level and identify outages that span across up to eight facilities.
Alexandros Milolidakis, Romain Fontugne, Xenofontas A. Dimitropoulos
INFOCOM2
2019 BGP Zombies: An Analysis of Beacons Stuck Routes
Romain Fontugne, Esteban Bautista, Colin Petrie, Yutaro Nomura, Patrice Abry, Paulo Gonçalves 0001, Kensuke Fukuda, Emile Aben
PAM1
2018 Untangling the world-wide mesh of undersea cables
abstract
The growth of global Internet traffic has driven an exponential expansion of the submarine cable network, both in terms of the sheer number of links and its total capacity. Today, a complex mesh of hundreds of cables, stretching over 1 million kilometers, connects nearly every corner of the earth and is instrumental in closing the remaining connectivity gaps. Despite the scale and critical role of the submarine network for both business and society at large, our community has mostly ignored it, treating it as a black box in most Internet studies, from connectivity to inter-domain traffic and reliability. We make the case for a new research agenda focused on characterizing the global submarine network and the critical role it plays as a basic component of any inter-continental end-to-end connection.
Zachary S. Bischof, Romain Fontugne, Fabián E. Bustamante
HotNets2
2018 The (Thin) Bridges of AS Connectivity: Measuring Dependency Using AS Hegemony
Romain Fontugne, Anant Shah, Emile Aben
PAM1
2017 High-end LTE service evolution in Korea: 4 years of nationwide mobile network measurements
abstract
This paper provides a temporal cellular and WiFi networks analysis from a nationwide crowdsourcing measurement study. Our dataset consists of 2.98M user-initiated quality tests on 3G/LTE/WiFi involving 157K mobile devices from Nov. 2012 to July 2016 (187 weeks) in South Korea. Our analysis explains changes in QoS from the user perspective, not Mobile Network Operators (MNO). We revealed that WiFi shows twice higher compounded quarterly growth rate for download throughput against LTE. Yet, LTE and WiFi show almost no difference in absolute download throughput value as of mid 2016. Second, LTE delivers relatively low latency, less-varying loss rate, and higher throughput in overall. Finally, the result shows that the evolution for the high-end LTE services has been faster than user adoption, where the majority of the LTE users stays below 75 Mbps of throughput.
Jonghwan Hyun, Youngjoon Won, Kenjiro Cho, Romain Fontugne, Jae Yoon Chung, James Won-Ki Hong
CNSM4
2017 Online Empirical Mode Decomposition
abstract
The success of Empirical Mode Decomposition (EMD) resides in its practical approach to dissect non-stationary data. EMD repetitively goes through the entire data span to iteratively extract Intrinsic Mode Functions (IMFs). This approach, however, is not suitable for data stream as the entire data set has to be reconsidered every time a new point is added. To overcome this, we propose Online EMD, an algorithm that extracts IMFs on the fly. The two key elements of Online EMD are a sliding window to compute local IMFs, and a stitching procedure to gradually append local IMFs to the final result. Using synthetic data we show that the decomposition quality of Online EMD is similar to classical EMD. We also present results obtained with a real data set to expose the practical advantages of Online EMD when dealing with data stream or large data set.
Romain Fontugne, Pierre Borgnat, Patrick Flandrin
ICASSP1
2017 Pinpointing delay and forwarding anomalies using large-scale traceroute measurements
abstract
Understanding data plane health is essential to improving Internet reliability and usability. For instance, detecting disruptions in distant networks can identify repairable connectivity problems. Currently this task is difficult and time consuming as operators have poor visibility beyond their network's border. In this paper we leverage the diversity of RIPE Atlas traceroute measurements to solve the classic problem of monitoring in-network delays and get credible delay change estimations to monitor network conditions in the wild. We demonstrate a set of complementary methods to detect network disruptions and report them in near real time. The first method detects delay changes for intermediate links in traceroutes. Second, a packet forwarding model predicts traffic paths and identifies faulty routers and links in cases of packet loss. In addition, we define an alarm score that aggregates changes into a single value per AS in order to easily monitor its sanity, reducing the effect of uninteresting alarms. Using only existing public data we monitor hundreds of thousands of link delays while adding no burden to the network. We present three cases demonstrating that the proposed methods detect real disruptions and provide valuable insights, as well as surprising findings, on the location and impact of the identified events.
Romain Fontugne, Cristel Pelsser, Emile Aben, Randy Bush
Internet Measurement Conference1
2017 Scaling in Internet Traffic: A 14 Year and 3 Day Longitudinal Study, With Multiscale Analyses and Random Projections
abstract
In the mid 1990s, it was shown that the statistics of aggregated time series from Internet traffic departed from those of traditional short range-dependent models, and were instead characterized by asymptotic self-similarity. Following this seminal contribution, over the years, many studies have investigated the existence and form of scaling in Internet traffic. This contribution first aims at presenting a methodology, combining multiscale analysis (wavelet and wavelet leaders) and random projections (or sketches), permitting a precise, efficient and robust characterization of scaling, which is capable of seeing through non-stationary anomalies. Second, we apply the methodology to a data set spanning an unusually long period: 14 years, from the MAWI traffic archive, thereby allowing an in-depth longitudinal analysis of the form, nature, and evolutions of scaling in Internet traffic, as well as network mechanisms producing them. We also study a separate three-day long trace to obtain complementary insight into intra-day behavior. We find that a biscaling (two ranges of independent scaling phenomena) regime is systematically observed: long-range dependence over the large scales, and multifractallike scaling over the fine scales. We quantify the actual scaling ranges precisely, verify to high accuracy the expected relationship between the long range dependent parameter and the heavy tail parameter of the flow size distribution, and relate fine scale multifractal scaling to typical IP packet inter-arrival and to round-trip time distributions.
Romain Fontugne, Patrice Abry, Kensuke Fukuda, Darryl Veitch, Kenjiro Cho, Pierre Borgnat, Herwig Wendt
IEEE/ACM Trans. Netw.1
2016 Non-linear regression for bivariate self-similarity identification - application to anomaly detection in Internet traffic based on a joint scaling analysis of packet and byte counts
abstract
Internet traffic monitoring is a crucial task for network security. Self-similarity, a key property for a relevant description of internet traffic statistics, has already been massively and successfully involved in anomaly detection. Self-similar analysis was however so far applied either to byte or Packet count time series independently, while both signals are jointly collected and technically deeply related. The present contribution elaborates on a recently proposed multivariate self-similar model, Operator fractional Brownian Motion (OfBm), to analyze jointly self-similarity in bytes and packets. A non-linear regression procedure, based on an original Branch & Bound resolution procedure, is devised for the full identification of bivariate OfBm. The estimation performance is assessed by means of Monte Carlo simulations. Further, an Internet traffic anomaly detection procedure is proposed, that makes use of the vector of Hurst exponents underlying the OfBm based Internet data modeling. Applied to a large set of high quality and modern Internet data from the MAWI repository, proof-of-concept results in anomaly detection are detailed and discussed.
Jordan Frécon, Romain Fontugne, Gustavo Didier, Nelly Pustelnik, Kensuke Fukuda, Patrice Abry
ICASSP2
2015 Random projection and multiscale wavelet leader based anomaly detection and address identification in internet traffic
abstract
We present a new anomaly detector for data traffic, ‘SMS’, based on combining random projections (sketches) with multiscale analysis, which has low computational complexity. The sketches allow ‘normal’ traffic to be automatically and robustly extracted, and anomalies detected, without the need for training data. The multiscale analysis extracts statistical descriptors, using wavelet leader tools developed recently for multifractal analysis, without any need for timescales to be selected a priori. The proposed detector is illustrated using a large recent dataset of Internet backbone traffic from the MAWI archive, and compared against existing detectors.
Romain Fontugne, Patrice Abry, Kensuke Fukuda, Pierre Borgnat, Johan Mazel, Herwig Wendt, Darryl Veitch
ICASSP1
2015 An empirical mixture model for large-scale RTT measurements
abstract
Monitoring delays in the Internet is essential to understand the network condition and ensure the good functioning of time-sensitive applications. Large-scale measurements of round-trip time (RTT) are promising data sources to gain better insights into Internet-wide delays. However, the lack of efficient methodology to model RTTs prevents researchers from leveraging the value of these datasets. In this work, we propose a log-normal mixture model to identify, characterize, and monitor spatial and temporal dynamics of RTTs. This data-driven approach provides a coarse grained view of numerous RTTs in the form of a graph, thus, it enables efficient and systematic analysis of Internet-wide measurements. Using this model, we analyze more than 13 years of RTTs from about 12 millions unique IP addresses in passively measured backbone traffic traces. We evaluate the proposed method by comparison with external data sets, and present examples where the proposed model highlights interesting delay fluctuations due to route changes or congestion. We also introduce an application based on the proposed model to identify hosts deviating from their typical RTTs fluctuations, and we envision various applications for this empirical model.
Romain Fontugne, Johan Mazel, Kensuke Fukuda
INFOCOM1
2014 A taxonomy of anomalies in backbone network traffic
abstract
The potential threat of network anomalies on Internet has led to a constant effort by the research community to design reliable detection methods. Detection is not enough, however, because network administrators need additional information on the nature of events occurring in a network. Several works try to classify detected events or establish a taxonomy of known events. But, these works are non-overlapping in terms of anomaly type coverage. On the one hand, existing classification methods use a limited set of labels. On the other hand, taxonomies often target a single type of anomaly or, when they have wider scope, fail to present the full spectrum of what really happens in the wild. We thus present a new taxonomy of network anomalies with wide coverage of existing work. We also provide a set of signatures that assign taxonomy labels to events. We present a preliminary study applying this taxonomy with six years of real network traffic from the MAWI repository. We classify previously documented anomalous events and draw to main conclusions. First, the taxonomy-based analysis provides new insights regarding events previous classified by heuristic rule labeling. For example, some RST events are now classified as network scan response and the majority of ICMP events are split into network scans and network scan responses. Moreover, some previously unknown events now account for a substantial number of all UDP network scans, network scan responses and port scans. Second, the number of unknown events decreases from 20 to 10% of all events with the proposed taxonomy as compared to the heuristic approach.
Johan Mazel, Romain Fontugne, Kensuke Fukuda
IWCMC2
2013 Mining anomalous electricity consumption using Ensemble Empirical Mode Decomposition
abstract
Sensor deployments in large buildings allow the administrators to supervise the building infrastructure and identify abnormalities. Nevertheless, the numerous data streams reported by the increasing number of sensors overwhelm the building administrators. We propose a methodology that assists them to identify abnormal devices usages. The proposed method takes advantage of Ensemble Empirical Mode Decomposition (E-EMD) to uncover the patterns of power-draw signals, thereby enabling us to estimate the intrinsic inter-device correlations. By monitoring the devices correlations over time we compute the usual usage of the devices and report the devices that deviate from their normal usage. Our evaluation with 10 weeks of real data shows the efficiency of the proposed method to uncover the devices intrinsic relationships and detect peculiar events that require the administrators attention.
Romain Fontugne, Nicolas Tremblay, Pierre Borgnat, Patrick Flandrin, Hiroshi Esaki
ICASSP1
2013 Nine years of observing traffic anomalies: Trending analysis in backbone networks
Youngjoon Won, Romain Fontugne, Kenjiro Cho, Hiroshi Esaki, Kensuke Fukuda
IM2
2013 Strip, bind, and search: a method for identifying abnormal energy consumption in buildings
abstract
A typical large building contains thousands of sensors, monitoring the HVAC system, lighting, and other operational sub-systems. With the increased push for operational efficiency, operators are relying more on historical data processing to uncover opportunities for energy-savings. However, they are overwhelmed with the deluge of data and seek more efficient ways to identify potential problems. In this paper, we present a new approach called the Strip, Bind and Search (SBS); a method for uncovering abnormal equipment behavior and in-concert usage patterns. SBS uncovers relationships between devices and constructs a model for their usage pattern relative to other devices. It then flags deviations from the model. We run SBS on a set of building sensor traces; each containing hundred sensors reporting data flows over 18 weeks from two separate buildings with fundamentally different infrastructures. We demonstrate that, in many cases, SBS uncovers misbehavior corresponding to inefficient device usage that leads to energy waste. The average waste uncovered is as high as 2500~kWh per device.
Romain Fontugne, Jorge Ortiz 0001, Nicolas Tremblay, Pierre Borgnat, Patrick Flandrin, Kensuke Fukuda, David E. Culler, Hiroshi Esaki
IPSN1
2013 ADMIRE: Anomaly detection method using entropy-based PCA with three-step sketches
Yoshiki Kanda, Romain Fontugne, Kensuke Fukuda, Toshiharu Sugawara
Comput. Commun.2
2010 MAWILab: combining diverse anomaly detectors for automated anomaly labeling and performance benchmarking
abstract
Evaluating anomaly detectors is a crucial task in traffic monitoring made particularly difficult due to the lack of ground truth. The goal of the present article is to assist researchers in the evaluation of detectors by providing them with labeled anomaly traffic traces. We aim at automatically finding anomalies in the MAWI archive using a new methodology that combines different and independent detectors. A key challenge is to compare the alarms raised by these detectors, though they operate at different traffic granularities. The main contribution is to propose a reliable graph-based methodology that combines any anomaly detector outputs. We evaluated four unsupervised combination strategies; the best is the one that is based on dimensionality reduction. The synergy between anomaly detectors permits to detect twice as many anomalies as the most accurate detector, and to reject numerous false positive alarms reported by the detectors. Significant anomalous traffic features are extracted from reported alarms, hence the labels assigned to the MAWI archive are concise. The results on the MAWI traffic are publicly available and updated daily. Also, this approach permits to include the results of upcoming anomaly detectors so as to improve over time the quality and variety of labels.
Romain Fontugne, Pierre Borgnat, Patrice Abry, Kensuke Fukuda
CoNEXT1
2010 Estimating Speed of Scanning Activities with a Hough Transform
abstract
In this paper, we propose a method to detect scanning activities in darknet traffic and to estimate their speed of change in time and feature space (e.g., destination address, source port, or destination port). The main idea of the algorithm relies on an image processing technique applied to a two-dimensional image that represents unwanted traffic. Thus, on the two-dimensional image, packets are represented as pixels in the time and feature coordinates, and unwanted activity as a set of pixels. The use of a Progressive Probabilistic Hough Transform (PPHT) that is a known technique to detect edges in an image enables us to detect such unwanted activities as ``lines'' in a traffic trace. We apply our method to darknet traffic traces for three years to investigate the property of such unwanted activities. Our main findings are following: In destination IP address space we confirmed typical host scanning speeds (i.e., a slanted line in the image) although the most of activities are characterized by intensive scans to a specific host (i.e., a horizontal line). Also, we confirmed few port scanning over wide destination port space, meaning that a targeted port attack is dominant in the current network. On the other hand, the consecutive change of source port was also observed; those activities are not tracked by other features. We obtain that 80-90\% of unique source IP addresses appeared in the trace is confirmed by this method. Thus, most unwanted activities is still characterized by some kind of trajectory to be detected in packet feature space, though the rest of them behaves like ``noise''.
Kensuke Fukuda, Romain Fontugne
ICC2