VLDB 2026 Research / reviewers in the wild / expert
Jean-François Lalande
dblp:47/5983
· DBLP profile ↗
22ranked-venue papers
4as first author
5since 2021 · last 2025
0000-0003-4984-2199ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 14 · 2 first-author · 3 since 2021Systems, architecture and hardware · 3 · 1 first-authorArtificial intelligence and machine learning · 1 · 1 since 2021Computer networks · 1Software engineering, systems software and programming languages · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 first-authorTheory of computation · 1Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | CasinoLimit: An Offensive Dataset Labeled with MITRE ATT&CK TechniquesabstractCybersecurity exercises are a common way to train and evaluate the skills of cybersecurity professionals. These exercises also provide a unique opportunity to generate datasets with realistic attack traces on non-sensitive systems. Nevertheless, the collected logs are unlabeled, and deciding which logs are related to pentesters is a difficult problem. In this paper, we present a novel methodology to label efficiently both system and network logs using MITRE ATT&CK techniques. To demonstrate the effectiveness of our approach, we introduce CasinoLimit, a dataset generated from a pentest exercise that has been played by 114 participants where we collected 540 GB of attack data. We apply our methodology to accurately label these logs with a semiautomatic approach: labels are inferred from the shell sessions and propagated to the network sessions, and eventually corrected by a junior analyst. An expert analyst has manually reviewed all the labels that have been computed to ensure the quality of the labeling process. The results of the pentest exercise are deeply discussed. We show the variability of players’ behaviors and that players can be distinguished by their command line habits. In addition, the high level of granularity of labels coupled with the number of participants enables multiple other applications. With this paper, we release the full dataset and the associated labeling tool, Manatee, which can be used to browse the logs and labels. To support the generalization of our approach, we made it possible to load other datasets with this tool. Sébastien Kilian, Valérie Viet Triem Tong, Jean-François Lalande, Frédéric Majorczyk, Alexandre Sanchez, Natan Talon, Pierre-Victor Besson, Helene Orsini, Pierre Lledo, Pierre-François Gimenez |
RAID | 3 |
| 2024 | Evaluating the Reusability of Android Static Analysis Tools
Jean-Marie Mineau, Jean-François Lalande |
ICSR | 2 |
| 2024 | Modeling Analyst Intentions Using a Markov Chain for Investigative Action Recommendations
Romain Brisse, Simon Boche, Frédéric Majorczyk, Jean-François Lalande |
IFIP Int. Conf. Digital Forensics | 4 |
| 2023 | CERBERE: Cybersecurity Exercise for Red and Blue team Entertainment, REproducibilityabstractExperimenting in cybersecurity requires manipulating reliable and realistic data. In particular, labelled data derived from the observation of a complete campaign is rarely available, due to its high sensitivity and the difficulty of accurately labelling datasets. This situation harms the reproducibility of research results and therefore to their impact. In this article, we present the CERBERE project that addresses this issue through a reproducible attack-defense exercise and a labelled dataset usable for research purposes. The attack-defense exercise is first composed of an exercise for red teamers automatically deployed with variable attack scenarios. Second, an exercise for blue teamers can be operated using the system and network logs generated during the attack phase. We provide with this article, the software to rebuild the infrastructure for red teamers. We share a labelled dataset where we spot the ground truth, i.e. the log lines that have been involved in the attacker’s actions. Pierre-Victor Besson, Romain Brisse, Helene Orsini, Natan Talon, Jean-François Lalande, Frédéric Majorczyk, Alexandre Sanchez, Valérie Viet Triem Tong |
IEEE Big Data | 5 |
| 2022 | Debiasing Android Malware Datasets: How Can I Trust Your Results If Your Dataset Is Biased?abstractAndroid security has received a lot of attention over the last decade, especially malware investigation. Researchers attempt to highlight applications’ security-relevant characteristics to better understand malware and effectively distinguish malware from benign applications. The accuracy and the completeness of their proposals are evaluated experimentally on malware and goodware datasets. Thus, the quality of these datasets is of critical importance: if the datasets are outdated or not representative of the studied population, the conclusions may be flawed. We specify different types of experimental scenarios. Some of them require unlabeled but representative datasets of the entire population. Others require datasets labeled with valuable characteristics that may be difficult to compute, such as malware datasets. We discuss the irregularities of datasets used in experiments, questioning the validity of the performances reported in the literature. This article focuses on providing guidelines for designing debiased datasets. First, we propose guidelines for building representative datasets from unlabeled ones. Second, we propose and experiment a debiasing algorithm that, given a biased labeled dataset and a target representative dataset, builds a representative and labeled dataset. Finally, from the previous debiased datasets, we produce datasets for experiments on Android malware detection or classification with machine learning algorithms. Experiments show that debiased datasets perfom better when classifying with machine learning algorithms. Tomás Concepción Miranda, Pierre-François Gimenez, Jean-François Lalande, Valérie Viet Triem Tong, Pierre Wilke |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2019 | Orchestrating Android Malware ExperimentsabstractExperimenting with Android malware requires to manipulate a large amount of samples and to chain multiple analyses. Scripting such a sequence of analyses on a large malware dataset becomes a challenge: the analysis has to handle fails on the computer and crashes on the used smartphone, in case of dynamic analyses. We present a new tool, PyMaO, for handling such experiments on a regular desktop PC with the highest performance throughput. PyMaO helps to write sequences of analyses and handle partial experiments that should be restarted after a crash or continued with new unknown analyses. The tool also offers a post processing capability for generating number tables or bar graphs from the analyzed datasets. Jean-François Lalande, Pierre Graux, Tomás Concepción Miranda |
MASCOTS | 1 |
| 2019 | Teaching Android Mobile SecurityabstractAt present, computer science studies generally offer courses addressing mobile development and they use mobile technologies for illustrating theoretical concepts such as operating system, design patterns, and compilation because Android and iOS use a large variety of technologies for developing applications. Teaching courses on security is also becoming an important concern for academics, and the use of mobile platforms (such as Android) as supporting material is becoming a reasonable option. In this paper, we intend to bridge a gap in the literature by reversing this paradigm: Android is not only an opportunity to learn security concepts but requires strong pedagogical efforts for covering all the aspects of mobile security. Thus, we propose teaching Android mobile security through a two-dimensional approach. The first dimension addresses the cognitive process of the Bloom taxonomy, and the second dimension addresses the technical layers of the architecture of the Android operating system. We describe a set of comprehensive security laboratory courses covering various concepts, ranging from the application development perspective to a deep investigation of the Android Open Source Project and its interaction with the Linux kernel. We evaluated this approach, and our results verify that the designed security labs impart the required knowledge to the students. Jean-François Lalande, Valérie Viet Triem Tong, Pierre Graux, Guillaume Hiet, Wojciech Mazurczyk, Habiba Chaoui, Pascal Berthomé |
SIGCSE | 1 |
| 2019 | Formally verified software countermeasures for control-flow integrity of smart card C code
Karine Heydemann, Jean-François Lalande, Pascal Berthomé |
Comput. Secur. | 2 |
| 2017 | Information Flows at OS Level Unmask Sophisticated Android MalwareabstractInternational audience Valérie Viet Triem Tong, Aurélien Trulla, Mourad Leslous, Jean-François Lalande |
SECRYPT | 4 |
| 2016 | Seeing the Unseen: Revealing Mobile Malware Hidden Communications via Energy Consumption and Artificial IntelligenceabstractModern malware uses advanced techniques to hide from static and dynamic analysis tools. To achieve stealthiness when attacking a mobile device, an effective approach is the use of a covert channel built by two colluding applications to exchange data locally. Since this process is tightly coupled with the used hiding method, its detection is a challenging task, also worsened by the very low transmission rates. As a consequence, it is important to investigate how to reveal the presence of malicious software using general indicators, such as the energy consumed by the device. In this perspective, this paper aims to spot malware covertly exchanging data using two detection methods based on artificial intelligence tools, such as neural networks and decision trees. To verify their effectiveness, seven covert channels have been implemented and tested over a measurement framework using Android devices. Experimental results show the feasibility and effectiveness of the proposed approach to detect the hidden data exchange between colluding applications. Luca Caviglione, Mauro Gaggero, Jean-François Lalande, Wojciech Mazurczyk, Marcin Urbanski |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2015 | Practical and Privacy-Preserving TEE Migration
Ghada Arfaoui, Said Gharout, Jean-François Lalande, Jacques Traoré |
WISTP | 3 |
| 2015 | A Practical Set-Membership Proof for Privacy-Preserving NFC Mobile TicketingabstractAbstract To ensure the privacy of users in transport systems, researchers are working on new protocols providing the best security guarantees while respecting functional requirements of transport operators. In this paper1, we design a secure NFC m-ticketing protocol for public transport that preserves users’ anonymity and prevents transport operators from tracing their customers’ trips. To this end, we introduce a new practical set-membership proof that does not require provers nor verifiers (but in a specific scenario for verifiers) to perform pairing computations. It is therefore particularly suitable for our (ticketing) setting where provers hold SIM/UICC cards that do not support such costly computations. We also propose several optimizations of Boneh-Boyen type signature schemes, which are of independent interest, increasing their performance and efficiency during NFC transactions. Our m-ticketing protocol offers greater flexibility compared to previous solutions as it enables the post-payment and the off-line validation of m-tickets. By implementing a prototype using a standard NFC SIM card, we show that it fulfils the stringent functional requirement imposed by transport operators whilst using strong security parameters. In particular, a validation can be completed in 184.25ms when the mobile is switched on, and in 266.52ms when the mobile is switched off or its battery is flat. Ghada Arfaoui, Jean-François Lalande, Jacques Traoré, Nicolas Desmoulins, Pascal Berthomé, Said Gharout |
Proc. Priv. Enhancing Technol. | 2 |
| 2014 | Software Countermeasures for Control Flow Integrity of Smart Card C Codes
Jean-François Lalande, Karine Heydemann, Pascal Berthomé |
ESORICS (2) | 1 |
| 2014 | An extended attribute based access control model with trust and privacy: Application to a collaborative crisis management system
Waleed W. Smari, Patrice Clemente, Jean-François Lalande |
Future Gener. Comput. Syst. | 3 |
| 2013 | Hiding Privacy Leaks in Android Applications Using Low-Attention Raising Covert ChannelsabstractCovert channels enable a policy-breaking communication not foreseen by a system's design. Recently, covert channels in Android were presented and it was shown that these channels can be used by malware to leak confidential information (e.g., contacts) between applications and to the Internet. Performance aspects as well as means to counter these covert channels were evaluated. In this paper, we present novel covert channel techniques linked to a minimized footprint to achieve a high covertness. Therefore, we developed a malware that slowly leaks collected private information and sends it synchronously based on four covert channel techniques. We show that some of our covert channels do not require any extra permission and escape well know detection techniques like TaintDroid. Experimental results confirm that the obtained throughput is correlated to the user interaction and show that these new covert channels have a low energy consumption - both aspects contribute to the stealthiness of the channels. Finally, we discuss concepts for novel means capable to counter our covert channels and we also discuss the adaption of network covert channel features to Android-based covert channels. Jean-François Lalande, Steffen Wendzel |
ARES | 1 |
| 2013 | Improving Mandatory Access Control for HPC clusters
Mathieu Blanc, Jean-François Lalande |
Future Gener. Comput. Syst. | 2 |
| 2012 | Repackaging Android Applications for Auditing Access to Private DataabstractOne of the most important threats for Android users is the collection of private data by malware put on the market. Most of the proposed approaches that help to guarantee the user's privacy rely on modified versions of the Android operating system. In this paper, we propose to automatically detect when an application accesses private data and to log this access in a third-party application. This detection should be performed without any modification to the operating system. The proposed methodology relies on the repackaging of a compiled application and the injection of a reporter at bytecode level. Thus, such a methodology enables the user to audit suspicious applications that ask permissions to access private data and to know if such an access has occurred. We show that the proposed methodology can also be implemented as an IPS, in order to prevent such accesses. Experimental results show the efficiency of the methodology on a set of 18 regular applications of the Android market that deal with contacts. Our prototype detected 66% of the accesses to the user's contacts. We also experimented the detection of privacy violations with 5 known malware that send premium-rate SMS. Pascal Berthomé, Thomas Fécherolle, Nicolas Guilloteau, Jean-François Lalande |
ARES | 4 |
| 2012 | High Level Model of Control Flow Attacks for Smart Card Functional SecurityabstractSmart card software has to implement software countermeasures to face attacks. Some of these attacks are physical disruptions of chip components that cause a misbehavior in the code execution. A successful functional attack may reveal a secret or grant an undesired authorization. In this paper, we propose to model fault attacks at source level and then simulate these attacks to find out which ones are harmful. After discussing the effects of physical attacks at assembly level and going back to their consequences at source code level, the paper focuses on control flow attacks. Such attacks are good candidates for the proposed model that can be used to exhaustively test the robustness of the attacked program. On the bzip2 software, the paper's results show that up to 21% of the assembly simulated control flow attacks are covered by the C model with 30 times less test cases. Pascal Berthomé, Karine Heydemann, Xavier Kauffmann-Tourkestansky, Jean-François Lalande |
ARES | 4 |
| 2012 | HoneyCloud: Elastic Honeypots - On-attack Provisioning of High-interaction Honeypots
Patrice Clemente, Jean-François Lalande, Jonathan Rouzaud-Cornabas |
SECRYPT | 2 |
| 2011 | SYNEMA: Visual Monitoring of Network and System Security Sensors
Aline Bousquet, Patrice Clemente, Jean-François Lalande |
SECRYPT | 3 |
| 2005 | Quasi-optimal bandwidth allocation for multi-spot MFTDMA satellitesabstractThis paper presents an algorithm for resource allocation in satellite networks. It deals with planning a time/frequency plan for a set of terminals with a known geometric configuration under interference constraints. Our objective is to maximize the system throughput while guaranteeing that the different types of demands are satisfied, each type using a different amount of bandwidth. The proposed algorithm relies on two main techniques. The first generates admissible configurations for the interference constraints, whereas the second uses linear and integer programming with column generation. The obtained solution estimates a possible allocation plan with optimality guarantees, and highlights the frequency interferences which degrade the construction of good solutions. Sara Alouf, Eitan Altman, Jérôme Galtier, Jean-François Lalande, Corinne Touati |
INFOCOM | 4 |
| 2003 | Approximate Multicommodity Flow for WDM Networks Design
Mohamed Bouklit, David Coudert, Jean-François Lalande, Christophe Paul, Hervé Rivano |
SIROCCO | 3 |