VLDB 2026 Research / reviewers in the wild / expert
Johan Mazel
dblp:23/8082
· DBLP profile ↗
15ranked-venue papers
3as first author
5since 2021 · last 2025
0009-0002-0222-6794ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 5 · 1 first-author · 1 since 2021Security and privacy · 3 · 3 since 2021Artificial intelligence and machine learning · 2 · 1 since 2021Databases, data management, data science and information retrieval · 1Graphics, computer vision, multimedia, augmented reality and games · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Striking Back at Cobalt: Using Network Traffic Metadata to Detect Cobalt Strike Masquerading Command and Control Channels
Clément Parssegny, Johan Mazel, Olivier Levillain, Pierre Chifflier |
ARES (1) | 2 |
| 2025 | Overlapping Data in Network Protocols: Bridging OS and NIDS Reassembly Gap
Lucas Aubard, Johan Mazel, Gilles Guette, Pierre Chifflier |
DIMVA (2) | 2 |
| 2025 | Overlapping IPv4, IPv6, and TCP data: exploring errors, test case context, and multiple overlaps inside network stacks and NIDSes with PyrolyseabstractIP fragmentation and TCP segmentation allow for splitting large data packets into smaller ones, e.g., for transmission across network links of limited capacity. These mechanisms permit complete or partial overlaps with different data on the overlapping portions. IPv4, IPv6, and TCP reassembly policies, i.e., the data chunk preferences that depend on the overlap types, differ across protocol implementations. This leads to vulnerabilities, as NIDSes may interpret the packet differently from the monitored host OSes. Some NIDSes, such as Suricata or Snort, can be configured so that their policies are consistent with the monitored OSes. The first contribution of the paper is pyrolyse, an audit tool that exhaustively tests and describes the reassembly policies of various IP and TCP implementation types. This tool ensures that implementations reassemble overlapping chunk sequences without errors. The second contribution is the analysis of pyrolyse artifacts. We first show that the reassembly policies are much more diverse than previously thought. Indeed, by testing all the overlap possibilities for $n \leq 3$ test case chunks and different testing scenarios, we observe 15 different behaviors out of 23 tested implementations depending on the protocol. Second, we report eight errors impacting one OS, two NIDSes, and two embedded stacks, which can lead to security issues such as NIDS pattern-matching bypass or DoS attacks. A CVE [1] was assigned to a NIDS error. Finally, we show that implemented IP and TCP policies obtained through chunk pair testing are usually inconsistent with the observed triplet reassemblies. Therefore, contrary to what they currently do, NIDSes or other network traffic analysis tools should not apply $n=2$ pair policies when the number of overlapping chunks exceeds two. Lucas Aubard, Johan Mazel, Gilles Guette, Pierre Chifflier |
RAID | 2 |
| 2021 | Anomalous Cluster Detection in Large Networks with Diffusion-Percolation TestingabstractWe propose a computationally efficient procedure for elevated mean detection on a connected subgraph of a network with node-related scalar observations.Our approach relies on two intuitions: first, a significant concentration of high observations in a connected subgraph implies that the subgraph induced by the nodes associated with the highest observations has a large connected component.Secondly, a greater detection power can be obtained in certain cases by denoising the observations using the network structure.Numerical experiments show that our procedure's detection performance and computational efficiency are both competitive. Corentin Larroche, Johan Mazel, Stéphan Clémençon |
ESANN | 2 |
| 2021 | CNAME Cloaking-Based Tracking on the Web: Characterization, Detection, and ProtectionabstractThird-party tracking on the Web has been used for collecting and correlating user's browsing behavior. Due to the increasing use of ad-blocking and third-party tracking protections, tracking providers introduced a new technique called CNAME cloaking. It misleads Web browsers into believing that a request for a subdomain of the visited website originates from this particular website, while this subdomain uses a CNAME to resolve to a tracking-related third-party domain. This technique thus circumvents the third-party targeting privacy protections. The goals of this paper are to characterize, detect, and protect the end-user against CNAME cloaking based tracking. Firstly, we characterize CNAME cloaking-based tracking by crawling top pages of the Alexa Top 300,000 sites and analyzing the usage of CNAME cloaking with CNAME blocklist, including websites and tracking providers using this technique to track users' activities. We also point out that browsers and privacy protection extensions are largely ineffective to deal with CNAME cloaking-based tracking except for Firefox with a developer's version of the uBlock Origin extension. Secondly, we propose a supervised machine learning-based approach to detect CNAME cloaking-based tracking without the on-demand DNS lookup. We show that the proposed approach outperforms well-known tracking filter lists. Finally, to circumvent the lack of DNS API in Chrome-based browsers, we design and implement a prototype of the supervised machine learning-based browser extension to detect and filter out CNAME cloaking tracking, called CNAMETracking Uncloaker. Our evaluation shows that CNAMETracking Uncloaker is able to filter out CNAME cloaking-based tracking requests without performance degradation when compared with the vanilla setting on the Chrome browser. Ha Dao, Johan Mazel, Kensuke Fukuda |
IEEE Trans. Netw. Serv. Manag. | 2 |
| 2020 | Percolation-Based Detection of Anomalous Subgraphs in Complex NetworksabstractThe ability to detect an unusual concentration of extreme observations in a connected region of a graph is fundamental in a number of use cases, ranging from traffic accident detection in road networks to intrusion detection in computer networks. This task is usually performed using scan statistics-based methods, which require explicitly finding the most anomalous subgraph and thus are computationally intensive. We propose a more scalable method in the case where the observations are assigned to the edges of a large-scale network. The rationale behind our work is that if an anomalous cluster exists in the graph, then the subgraph induced by the most individually anomalous edges should contain an unexpectedly large connected component. We therefore reformulate our problem as the detection of anomalous sample paths of a percolation process on the graph, and our contribution can be seen as a generalization of previous work on percolation-based cluster detection. We evaluate our method through extensive simulations. Corentin Larroche, Johan Mazel, Stéphan Clémençon |
IDA | 2 |
| 2019 | A comparison of web privacy protection techniques
Johan Mazel, Richard Garnier, Kensuke Fukuda |
Comput. Commun. | 1 |
| 2015 | Random projection and multiscale wavelet leader based anomaly detection and address identification in internet trafficabstractWe present a new anomaly detector for data traffic, ‘SMS’, based on combining random projections (sketches) with multiscale analysis, which has low computational complexity. The sketches allow ‘normal’ traffic to be automatically and robustly extracted, and anomalies detected, without the need for training data. The multiscale analysis extracts statistical descriptors, using wavelet leader tools developed recently for multifractal analysis, without any need for timescales to be selected a priori. The proposed detector is illustrated using a large recent dataset of Internet backbone traffic from the MAWI archive, and compared against existing detectors. Romain Fontugne, Patrice Abry, Kensuke Fukuda, Pierre Borgnat, Johan Mazel, Herwig Wendt, Darryl Veitch |
ICASSP | 5 |
| 2015 | An empirical mixture model for large-scale RTT measurementsabstractMonitoring delays in the Internet is essential to understand the network condition and ensure the good functioning of time-sensitive applications. Large-scale measurements of round-trip time (RTT) are promising data sources to gain better insights into Internet-wide delays. However, the lack of efficient methodology to model RTTs prevents researchers from leveraging the value of these datasets. In this work, we propose a log-normal mixture model to identify, characterize, and monitor spatial and temporal dynamics of RTTs. This data-driven approach provides a coarse grained view of numerous RTTs in the form of a graph, thus, it enables efficient and systematic analysis of Internet-wide measurements. Using this model, we analyze more than 13 years of RTTs from about 12 millions unique IP addresses in passively measured backbone traffic traces. We evaluate the proposed method by comparison with external data sets, and present examples where the proposed model highlights interesting delay fluctuations due to route changes or congestion. We also introduce an application based on the proposed model to identify hosts deviating from their typical RTTs fluctuations, and we envision various applications for this empirical model. Romain Fontugne, Johan Mazel, Kensuke Fukuda |
INFOCOM | 2 |
| 2014 | Coping with 0-day attacks through Unsupervised Network Intrusion DetectionabstractTraditional Network Intrusion Detection Systems (NIDSs) rely on either specialized signatures of previously seen attacks, or on expensive and difficult to produce labeled traffic datasets for profiling and training. Both approaches share a common downside: they require the knowledge provided by an external agent, either in terms of signatures or as normal-operation profiles. In this paper we describe UNIDS, an Unsupervised NIDS capable of detecting 0-day attacks, i.e., network attacks for which no signature is yet available, without using any kind of signatures, labeled traffic, or training. UNIDS uses a novel unsupervised outliers detection approach based on Sub-Space Clustering and Multiple Evidence Accumulation techniques to pin-point different kinds of network intrusions and attacks such as DoS/DDoS, probing attacks, propagation of worms, buffer overflows, illegal access to network resources, etc. In this paper we make the strong point that the de-facto approach for NIDS, namely the application of rule-based detection techniques, can be highly harmful for the protected network in case of 0-day attacks. In contrast, we show how UNIDS can work as a complementary system to current NIDS to detect the occurrence of previously unseen attacks. For doing so, we compare the performance of a standard rule-based NIDS against UNIDS to detect 0-day attacks in the well-known KDD99 dataset. In addition, we also compare the performance of UNIDS against other popular unsupervised detection techniques to detect attacks in traces collected at two operation networks. Pedro Casas, Johan Mazel, Philippe Owezarski |
IWCMC | 2 |
| 2014 | A taxonomy of anomalies in backbone network trafficabstractThe potential threat of network anomalies on Internet has led to a constant effort by the research community to design reliable detection methods. Detection is not enough, however, because network administrators need additional information on the nature of events occurring in a network. Several works try to classify detected events or establish a taxonomy of known events. But, these works are non-overlapping in terms of anomaly type coverage. On the one hand, existing classification methods use a limited set of labels. On the other hand, taxonomies often target a single type of anomaly or, when they have wider scope, fail to present the full spectrum of what really happens in the wild. We thus present a new taxonomy of network anomalies with wide coverage of existing work. We also provide a set of signatures that assign taxonomy labels to events. We present a preliminary study applying this taxonomy with six years of real network traffic from the MAWI repository. We classify previously documented anomalous events and draw to main conclusions. First, the taxonomy-based analysis provides new insights regarding events previous classified by heuristic rule labeling. For example, some RST events are now classified as network scan response and the majority of ICMP events are split into network scans and network scan responses. Moreover, some previously unknown events now account for a substantial number of all UDP network scans, network scan responses and port scans. Second, the number of unknown events decreases from 20 to 10% of all events with the proposed taxonomy as compared to the heuristic approach. Johan Mazel, Romain Fontugne, Kensuke Fukuda |
IWCMC | 1 |
| 2012 | Unsupervised Network Intrusion Detection Systems: Detecting the Unknown without Knowledge
Pedro Casas, Johan Mazel, Philippe Owezarski |
Comput. Commun. | 2 |
| 2011 | Sub-Space clustering, Inter-Clustering Results Association & anomaly correlation for unsupervised network anomaly detection
Johan Mazel, Pedro Casas, Yann Labit, Philippe Owezarski |
CNSM | 1 |
| 2011 | On the use of Sub-Space Clustering & Evidence Accumulation for traffic analysis & classificationabstractDriven by the well-known limitations of port and payload-based analysis techniques, the use of Machine Learning for Internet traffic analysis and classification has become a fertile research area during the past half-decade. In this paper we introduce a novel unsupervised approach to identify different classes of IP flows sharing similar characteristics. The unsupervised analysis is accomplished by means of robust clustering techniques, using Sub-Space Clustering, Evidence Accumulation, and Hierarchical Clustering algorithms to explore inter-flows structure. Our approach permits to identify natural groupings of traffic flows, combining the evidence of data structure provided by different partitions of the same set of traffic flows. The technique is further used to build an automatic flow classification model, using a semi-supervised-learning-based approach. The approach uses only a reduced fraction of labeled flows to map the identified clusters into their associated most-probable originating application, which strongly simplifies its calibration. We evaluate the performance of our techniques using real traffic traces, additionally comparing their performance against previously proposed clustering-based classification methods. Pedro Casas, Johan Mazel, Philippe Owezarski |
IWCMC | 2 |
| 2011 | UNADA: Unsupervised Network Anomaly Detection Using Sub-space Outliers Ranking
Pedro Casas, Johan Mazel, Philippe Owezarski |
Networking (1) | 2 |