Alexandre Vernotte

dblp:133/4662 · DBLP profile ↗
← Back
6ranked-venue papers
2as first author
3since 2021 · last 2024
0000-0002-2113-4900ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 4 · 2 first-author · 2 since 2021Security and privacy · 2 · 1 since 2021
YearPublicationVenuePosition
2024 Generation of Regression Tests From Logs With Clustering Guided by Usage Patterns
abstract
ABSTRACT Clustering is increasingly being used to select the appropriate test suites. In this paper, we apply this approach to regression testing. Regression testing is the practice of verifying the robustness and reliability of software by retesting after changes have been made. Creating and maintaining functional regression tests is a laborious and costly activity. To be effective, these tests must represent the actual user journeys of the application. In addition, an optimal number of test cases is critical for the rapid execution of the regression test suite to stay within the time and computational resource budget as it is re‐run at each major iteration of the software development. Therefore, the selection and maintenance of functional regression tests based on the analysis of application logs has gained popularity in recent years. This paper presents a novel approach to improve regression testing by automating the creation of test suites using user traces fed into clustering pipelines. Our methodology introduces a new metric based on pattern mining to quantify the statistical coverage of prevalent user paths. This metric helps to determine the optimal number of clusters within a clustering pipeline, thus addressing the challenge of suboptimal test suite sizes. Additionally, we introduce two criteria, to systematically evaluate and rank clustering pipelines. Experimentation involving 33 variations of clustering pipelines across four datasets demonstrates the potential effectiveness of our automated approach compared with manually crafted test suites. (All the experiments and data on Scanner, Spree and Booked Scheduler are available at https://github.com/frederictamagnan/STVR2024 .) Then, we analyse the semantics of the clusters based on their principal composing patterns.
Frédéric Tamagnan, Alexandre Vernotte, Fabrice Bouquet, Bruno Legeard
Softw. Test. Verification Reliab.2
2022 CAE: Contextual auto-encoder for multivariate time-series anomaly detection in air transportation
Antoine Chevrot, Alexandre Vernotte, Bruno Legeard
Comput. Secur.2
2022 A domain-specific language to design false data injection tests for air traffic control systems
Alexandre Vernotte, Aymeric Cretin, Bruno Legeard, Fabien Peureux
Int. J. Softw. Tools Technol. Transf.1
2016 pwnPr3d: An Attack-Graph-Driven Probabilistic Threat-Modeling Approach
abstract
In this paper we introduce pwnPr3d, a probabilistic threat modeling approach for automatic attack graph generation based on network modeling. The aim is to provide stakeholders in organizations with a holistic approach that both provides high-level overview and technical details. Unlike many other threat modeling and attack graph approaches that rely heavily on manual work and security expertise, our language comes with built-in security analysis capabilities. pwnPr3d generates probability distributions over the time to compromise assets.
Pontus Johnson, Alexandre Vernotte, Mathias Ekstedt, Robert Lagerström
ARES2
2014 Risk-Based Vulnerability Testing Using Security Test Patterns
Julien Botella, Bruno Legeard, Fabien Peureux, Alexandre Vernotte
ISoLA (2)4
2013 Research Questions for Model-Based Vulnerability Testing of Web Applications
abstract
This paper presents my Ph.D. research that focuses on developing concepts and techniques for Model-Based Vulnerability Testing (MBVT) of Web Applications. This research bridges the gap between MBT techniques, which are usually addressed to functional testing, and vulnerability testing, which is mostly done manually or with the assistance of Web Vulnerability Scanners, both techniques having several flaws. In this document, we define the core of the research and its expected contributions to MBT and vulnerability testing. Then, we expose the major key challenges of the research, and finally provide early results.
Alexandre Vernotte
ICST1