Cody James Christopher

dblp:158/5061 · DBLP profile ↗
← Back
5ranked-venue papers
3as first author
3since 2021 · last 2025
0000-0001-8444-2292ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 2 · 2 since 2021Software engineering, systems software and programming languages · 2 · 2 first-authorArtificial intelligence and machine learning · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2025 TempoNet: Learning Realistic Communication and Timing Patterns for Network Traffic Simulation
abstract
Realistic network traffic simulation is critical for evaluating intrusion detection systems, stress-testing network protocols, and constructing high-fidelity environments for cybersecurity training. While attack traffic can often be layered into training environments using red-teaming or replay methods, generating authentic benign background traffic remains a core challenge-particularly in simulating the complex temporal and communication dynamics of real-world networks. This paper introduces TempoNet, a novel generative model that combines multi-task learning with multi-mark temporal point processes to jointly model inter-arrival times and all packet- and flow-header fields. TempoNet captures fine-grained timing patterns and higher-order correlations such as host- pair behavior and seasonal trends, addressing key limitations of GAN-, LLM-, and Bayesian-based methods that fail to reproduce structured temporal variation. TempoNet produces temporally consistent, high-fidelity traces, validated on real-world datasets. Furthermore, we show that intrusion detection models trained on TempoNet-generated background traffic perform comparably to those trained on real data, validating its utility for real-world security applications.
Kristen Moore, Diksha Goel, Cody James Christopher, Minjune Kim, Ahmed Ibrahim 0002, Ahmad Mohsin, Seyit Ahmet Çamtepe
ACSAC3
2024 Critical observations in model-based diagnosis
abstract
In this paper, we address the problem of finding the part of the observations that is useful for the diagnosis. We define a sub-observation as an abstraction of the observations. We then argue that a sub-observation is sufficient if it allows a diagnoser to derive the same minimal diagnosis as the original observations; and we define critical observations as a maximally abstracted sufficient sub-observation. We show how to compute a critical observation, and discuss a number of algorithmic improvements that also shed light on the theory of critical observations. Finally, we illustrate this framework on both state-based and event-based observations.
Cody James Christopher, Alban Grastien
Artif. Intell.1
2022 Modelling direct messaging networks with multiple recipients for cyber deception
abstract
Cyber deception is the practice of deliberately introducing fake or misleading artefacts into cyber systems. It is emerging as a promising approach to defending networks and systems against attackers and data thieves. However, despite being relatively cheap to deploy [1], the generation of realistic content at scale is very costly when it is hand-crafted. With recent improvements in Machine Learning, we now have the opportunity to bring scale and automation to the creation of realistic and enticing simulated content. In this work, we propose a framework to automate the generation of email and instant messaging-style group communications at scale. Such messaging platforms within organisations contain a lot of valuable information inside private communications and document attachments, making them an enticing target for an adversary. The presence of an active messaging platform also enhances the realism of a deceptive network simulation, contributing both traffic and message artefacts. We address two key aspects of simulating this type of system: modelling when and with whom participants communicate, and generating topical, multi-party text to populate simulated conversation threads. We present the LogNormMix-Net Temporal Point Process as an approach to the first of these, building upon the intensity-free modeling approach of Shchur et al. [2] to create a generative model for unicast and multi-cast communications. We demonstrate the use of fine-tuned, pretrained language models to generate convincing multi-party conversation threads. A live email server is simulated by uniting our LogNormMix-Net TPP (to generate the communication timestamp, sender and recipients) with the language model, which generates the contents of the multi-party email threads. We evaluate the generated content with respect to a number of realism-based properties, that encourage a model to learn to generate content that will engage the attention of an adversary to achieve a deception outcome. Our simulations run in real time, making them suitable for deployment in cyber deception as a honeypot in its own right, or as part of a larger deception environment.
Kristen Moore, Cody James Christopher, David Liebowitz, Surya Nepal, Renee Selvey
EuroS&P2
2017 Inference of fault signatures of discrete-event systems from event logs
abstract
In this paper, we propose a method to diagnose faults in a discrete event system that only relies on past observed logs and not on any behavioural model of the system. Given a set of tagged logs produced by the system, the first objective is to extract from them a set of fault signatures. These fault signatures are represented with a set of critical observations that are the support of the diagnosis method. We first propose a method to compute the fault signatures from an initial log journal and follow with detail on how the signatures can then be updated when new logs are available.
Cody James Christopher, Yannick Pencolé, Alban Grastien
DX1
2015 Formulating Event-Based Critical Observations in Diagnostic Problems
Cody James Christopher, Alban Grastien
DX1