VLDB 2026 Research / reviewers in the wild / expert
Abdelkader Lahmadi
dblp:49/5526
· DBLP profile ↗
54ranked-venue papers
9as first author
20since 2021 · last 2026
0000-0003-3882-1560ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 20 · 6 first-author · 5 since 2021Security and privacy · 5 · 3 since 2021Software engineering, systems software and programming languages · 3 · 2 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 1 since 2021Artificial intelligence and machine learning · 2 · 2 since 2021Databases, data management, data science and information retrieval · 2 · 2 since 2021Systems, architecture and hardware · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | In-Network Intelligence for Secure 6G SDN Leveraging Programmable Data Plane: Taxonomy, Limitations, and Opportunities
Imane Aziz, Anass Sebbar, Abdelkader Lahmadi, Ouassim Karrakchou, Mohammed Boulmalf |
IWCMC | 3 |
| 2025 | Deep Reinforcement Learning for In-Network Placement of ACL Rules Under Constraints
Wafik Zahwa, Abdelkader Lahmadi, Michaël Rusinowitch, Mondher Ayadi |
CNSM | 2 |
| 2025 | LLM-Driven Causal Discovery for Monitoring Metrics in Computing Continuum Systems: A Comparative StudyabstractMonitoring large-scale systems such as the Cloud–Edge–IoT continuum is challenging due to their distributed, heterogeneous, and evolving nature. Tracking all components—from cloud servers to IoT devices—demands intensive probe deployment and frequent data collection, causing network traffic, computation, and storage overhead. These challenges are intensified by the lack of prior knowledge about which metrics matter most, often leading to redundant monitoring. To address this, we explore whether Large Language Models (LLMs) can uncover causal relationships between metrics using only their textual descriptions. We propose a novel batch prompting strategy that allows LLMs to reason over multiple variables simultaneously, reducing query complexity while preserving interpretability. Our evaluation across several instruction-tuned LLMs shows stronger inter-model alignment than existing pairwise methods and reveals overlaps with causal graphs from traditional numerical algorithms. These results suggest that LLMs can support intelligent monitoring by identifying influential metrics and minimizing redundancy. Ahmad Atwi, Abdelkader Lahmadi |
LCN | 2 |
| 2025 | RAID: Root Cause Anomaly Identification and Diagnosis
Joël Roman Ky, Bertrand Mathieu, Abdelkader Lahmadi, Minqi Wang, Nicolas Marrot, Raouf Boutaba |
ECML/PKDD (8) | 3 |
| 2025 | Scalable and Generalizable RL Agents for Attack Path Discovery via Continuous Invariant SpacesabstractIdentifying critical attack paths in a net-work-sequences of vulnerabilities an attacker can chain to achieve a specific threat model-is crucial for pinpointing vulnerable areas where defensive measures should be focused. Recently, Reinforcement Learning (RL) has gained traction for training agents in identifying these critical paths. However, current solutions typically train RL agents tailored to a specific environment-defined by a fixed network structure and vulnerability set-requiring costly retraining whenever either changes. This limitation arises from optimizing the agent to map between discrete input and output spaces, treating network nodes and vulnerabilities as atomic discrete elements. In this paper, we propose a method for constructing continuous and invariant input and output spaces for RL agents, enabling them to learn transferable policies that generalize across diverse network configurations and vulnerability sets. We also release Continuous CyberBattleSim (C-CyberBattleSim), an enhanced version of Microsoft CyberBattleSim designed to train agents with the novel continuous spaces. The tool is further extended to integrate realworld vulnerability data and a new scenario generation pipeline to improve the realism of training and testing environments. Agents trained in continuous spaces are assessed in 800 scenarios with varying sizes and various allocations of 829 real-world vulnerabilities, demonstrating an average improvement of 9.3x in scalability against agents trained in discrete spaces, as well as an average generalization score of $89 \%$ to more complex scenarios when trained in simpler scenarios. A final study evaluates whether continuous agents trained in simulation can adapt to real-world and emulated scans. On average, agents achieve $75 \%$ of the score they would have if trained directly on the scans, demonstrating effective knowledge transfer. Franco Terranova, Abdelkader Lahmadi, Isabelle Chrisment |
RAID | 2 |
| 2025 | Assessing 5G Connectivity for Urbanloop: a Pod-based Autonomous Railway Transport SystemabstractSmart mobility aims to enhance the passenger experience by optimizing transportation modes while minimizing environmental impact. In this context, Urbanloop, a pioneering urban transportation system utilizing autonomous pod vehicles on dedicated rail circuits (loops), provides a low-energy, low-carbon, and personalized travel experience, free from intermediate stops or transfers. This innovative system not only sets a world record for the lowest energy consumption per kilometer per passenger but also successfully completed its first passenger deployment during the 2024 Olympic Games. Since the efficient monitoring and management of pod movements require stable, high-performance, and continuous communication, 5G emerges as a key enabler in meeting these demands. In this paper, we first introduce the core principles of the Urbanloop system and then examine the necessity of 5G integration by analyzing how communication QoS impacts system safety and performance. Using Veins-Simu5G, we evaluate the effects of packet loss and latency under various communication and mobility scenarios, and the related impacts on safety distance and pod deployment density. Finally, we validate our simulation findings through preliminary real-world testing with the OAIBOX platform, built upon the OpenAirInterface framework, confirming the practical relevance of our results for future deployments. Runbo Su, Abdelkader Lahmadi, Yeqiong Song, Jean Philippe Mangeot |
VTC2025-Fall | 2 |
| 2024 | CATS: Contrastive learning for Anomaly detection in Time SeriesabstractAnomaly detection (AD) plays a critical role in a wide variety of big data applications, including cybersecurity, monitoring, and network systems. It consists in finding patterns in time series data that indicate unexpected events such as faults or defects. Traditional AD approaches, predominantly based on reconstruction techniques, often yield suboptimal performance, particularly when anomalies are present in the training set. Conversely, contrastive learning (CL) has shown significant performance in image processing tasks and is increasingly applied in time series data classification and forecasting. However, traditional CL frameworks are not well-adapted for time series AD due to two key challenges. First, AD is typically performed only on normal instances, and thus CL does not benefit from knowledge about anomalous instances. Second, the temporal nature of time series data is often neglected when computing time series similarity, thereby hindering the effective learning of time series representation.To overcome these limitations, we propose CATS, a novel approach that leverages a temporal similarity measure to learn time series representations. Moreover, through negative data augmentation, CATS generates a more realistic distribution of anomalies, which enables anomaly-informed CL. Extensive experiments conducted on six real-world datasets demonstrate that CATS outperforms existing AD methods. Our results highlight the efficacy of CATS in enhancing time series AD performance in big data environment across various application domains. Joël Roman Ky, Bertrand Mathieu, Abdelkader Lahmadi, Raouf Boutaba |
IEEE Big Data | 3 |
| 2024 | An Empirical Study of Ransomware Vulnerabilities DescriptionsabstractInternational audience Claudia Lanza, Abdelkader Lahmadi, Fabian Osmond |
ICISSP | 2 |
| 2024 | Vulnet: Learning Navigation in an Attack GraphabstractNowadays, new flaws or vulnerabilities are frequently discovered. Analyzing how these vulnerabilities can be used by attackers to gain access to different parts of a network allows to provide better protection and defense. Amongst the diverse analysis techniques, simulations do not necessitate a full infrastructure deployment and recently benefited from advances in reinforcement learning to better mimic an attacker’s behavior. However, such simulations are resource consuming. By representing the interconnected hosts of a network and their vulnerabilities as attack graphs and leveraging machine learning, our method, Vulnet, is capable to generalize knowledge generated by simulation and gives insight about attacker capabilities. It can predict instantaneously the overall performance of an attacker to compromise a system with a mean error of 0.07. Enzo d'Andréa, Jérôme François, Abdelkader Lahmadi, Olivier Festor |
NetSoft | 3 |
| 2024 | SDN-based Mitigation of Synchronization Attacks on Distributed and Cooperative Controls in MicrogridabstractThe power grid has recently evolved through the integration of Information and Communication Technologies (ICT), leading to the emergence of the smart grid. A key component of the smart grid is the microgrid, a small-scale electrical network made of Distributed Generators (DGs) that nowadays use distributed and cooperative control systems to ensure the reliability of its operations. However, the communication networks employed to control data exchange between DGs are subject to synchronization attacks that can disrupt grid operations. These existing communication infrastructures often lack the flexibility to deploy efficient mitigation and security measures against attacks. Software-Defined Networking (SDN) emerges as a promising solution, providing a dynamic and resilient approach to mitigate synchronization attacks. In this work, we build an SDN-enabled microgrid hardware platform comprising DGs, Open vSwitches (OVSs) installed on Raspberry Pi devices, and a POX controller running on a laptop. In the demo, we will show two methods of mitigating Man-in-the-Middle (MitM) attacks to demonstrate the effectiveness of SDN in limiting their impact on the microgrid. Aurélie Kpoze, Abdelkader Lahmadi, Isabelle Chrisment, Jules R. Dégila |
NOMS | 2 |
| 2024 | Leveraging Deep Reinforcement Learning for Cyber-Attack Paths Prediction: Formulation, Generalization, and EvaluationabstractAttack paths represent the sequences of network nodes compromised by attackers while exploiting their respective vulnerabilities. Current methods for predicting such attack paths largely depend on existing human expertise or established heuristics. These traditional methods are time-consuming and require highly skilled threat-hunting analysts to identify these attack paths and proactively apply security measures. However, the task becomes challenging when facing large-scale and highly vulnerable networks. In this paper, we propose an alternative approach leveraging Deep Reinforcement Learning (DRL) techniques aiming to approximate the decision-making of attackers. Our approach embodies the attacker’s perspective and tactics to leverage discovered paths for proactive security analysis and establish defense strategies. We introduce a novel re-formulation of the problem with a local view for the DRL agent, representing the source and target node of the attack at each timestep. Additionally, our training methodology involves a diverse set of network topologies of different sizes and exploitable vulnerabilities, demonstrating the ability of DRL algorithms to navigate topologies, identify attack paths, and compromise nodes. Results highlight the capability of the learned policies to generalize within entirely new topologies, arriving to discover 80% ± 0.08% of the attack paths in 1500 steps. Franco Terranova, Abdelkader Lahmadi, Isabelle Chrisment |
RAID | 2 |
| 2023 | Automated Placement of In-Network ACL RulesabstractAutomatically deploying distributed Access Control Lists (ACLs) in a software-defined network can ensure their internal services and hosts connectivity, security and reliability. ACLs are often deployed in a switch using Ternary ContentAddressable Memory (TCAM). Since TCAM memory is often too limited to store a large ACL, one has to split the lists and distribute the parts on several switches in such a way that every packet travelling from a source to a destination undergoes the required match-action rules. In this paper, we develop and compare three algorithms based on graph theory and Reinforcement Learning (RL) techniques to automatically distribute ACLs across networks switches, while minimizing their TCAM memory occupancy. We compare the three algorithms on several network topologies to evaluate their efficiency in terms of memory occupancy. Wafik Zahwa, Abdelkader Lahmadi, Michaël Rusinowitch, Mondher Ayadi |
NetSoft | 2 |
| 2023 | An Experimental Testbed for 5G Network Security AssessmentabstractThe Fifth Generation (5G) mobile networks are designed to provide a large range of services with stringent requirements in robustness and security. Thus, it is important to ensure that these networks fulfill these requirements and are resilient against attacks. To meet this challenge, experimental testbeds and tools are required to test and evaluate the security of 5G networks. This work presents an experimentation testbed and support tools for generating and injecting on the fly 5G packets to realize multiple security assessing tasks in particular fuzzing operations for vulnerabilities discovery. Our tool is implemented and tested within a controlled testbed environment built on top of a 5G standalone core server provided by a hardware base station (gNb) and uses an Software Defined Radio(SDR) card for radio transmission. We validate our testbed and the developed tools by successfully injecting at the 5G air interface and the network control levels different messages including RRC and NGAP/NAS over already established communications. Karim Baccar, Abdelkader Lahmadi |
NOMS | 2 |
| 2023 | ML Models for Detecting QoE Degradation in Low-Latency Applications: A Cloud-Gaming Case StudyabstractDetecting abnormal network events is an important activity of Internet Service Providers particularly when running critical applications (e.g., ultra low-latency applications in mobile wireless networks). Abnormal events can stress the infrastructure and lead to severe degradation of user experience. Machine Learning (ML) models have demonstrated their relevance in many tasks including Anomaly Detection (AD). While promising remarkable performance compared to manual or threshold-based detection, applying ML-based AD methods is challenging for operators due to the proliferation of ML models and the lack of well-established methodology and metrics to evaluate them and select the most appropriate one. This paper presents a comprehensive evaluation of eight unsupervised ML models selected from different classes of ML algorithms and applied to AD in the context of cloud gaming applications. We collect cloud gaming Key Performance Indicators (KPIs) time-series datasets in real-world network conditions, and we evaluate and compare the selected ML models using the same methodology, and assess their robustness to data contamination, their efficiency and computational complexity. In addition to the traditional F1-score performance metric used in anomaly detection, we use Matthews Coefficient Correlation (MCC) to better differentiate between models’ efficiencies. Our proposed methodology relies on window-based anomaly detection techniques as they are more useful for network operators compared to single point detection approaches. However, we found most existing window-based approaches to lack in accuracy and may under or over-estimate a model’s performance. Therefore, in this paper, we propose a novel Window Anomaly Decision (WAD) approach that overcomes these drawbacks. We leverage our experimental results to provide insights about the most relevant models for detecting QoE degradation and offer recommendations on their suitability for different application requirements. Joël Roman Ky, Bertrand Mathieu, Abdelkader Lahmadi, Raouf Boutaba |
IEEE Trans. Netw. Serv. Manag. | 3 |
| 2022 | Assessing Unsupervised Machine Learning solutions for Anomaly Detection in Cloud Gaming SessionsabstractCloud gaming applications have gained great adoption on the Internet particularly benefiting from the wide availability of broadband access networks. However, they still fail to meet users’ quality requirements when accessed using cellular networks due to common wireless channel degradations. Machine Learning (ML) techniques can be leveraged to detect such anomalies during users’ cloud gaming sessions. In this respect, unsupervised ML approaches are particularly interesting since they do not require labeled datasets. In this work, we investigate these approaches to understand their performance and their robustness. Our dataset consists of game sessions played on the public Google Stadia Cloud Gaming servers. The game sessions are played using a 4G network emulation replicating the capacity variations sampled on a commercial 4G network. We compare different models ranging from traditional approaches to deep learning and we evaluate their default performance while varying the level of contamination in their training datasets. Our experiments show that Auto-Encoders models achieve the best performance without contamination while the OC-SVM and the Isolation Forest are the most robust to data contamination. Joël Roman Ky, Bertrand Mathieu, Abdelkader Lahmadi, Raouf Boutaba |
CNSM | 3 |
| 2022 | Automatically Distributing and Updating In-Network Management Rules for Software Defined NetworksabstractSoftware Defined Networks (SDN) heavily rely on diverse management rules (ACL, traffic control, etc. ) to satisfy security and business requirements of their associated services. As these networks are increasing in size and complexity, their management rules configured in devices are becoming more complex. These rules are constantly growing in size and it is challenging to distribute them across network devices with limited capacities. The most challenging task is to deploy rules updates in a fast and efficient way to avoid a security breach or to meet a service needs. In this paper, we extend our previous work on network management rules distribution by introducing an efficient update strategy. Through extensive experiments on several rule sets with single and multiple path topologies, we evaluate and analyze the performance of our strategy. Our obtained results show a reduction of up to 90% in update time. Ahmad Abboud, Rémi Garcia 0001, Abdelkader Lahmadi, Michaël Rusinowitch, Adel Bouhoula, Mondher Ayadi |
NOMS | 3 |
| 2022 | Benchmarking of lightweight cryptographic algorithms for wireless IoT networks
Soline Blanc, Abdelkader Lahmadi, Kévin Le Gouguec, Marine Minier, Lama Sleem |
Wirel. Networks | 2 |
| 2021 | HSL: a Cyber Security Research Facility for Sensitive Data Experiments
Frédéric Beck, Abdelkader Lahmadi, Jérôme François |
IM | 2 |
| 2021 | Multi-Attribute Monitoring for Anomaly Detection: a Reinforcement Learning Approach based on Unsupervised RewardabstractThis paper proposes a new method to solve the monitoring and anomaly detection problems of Low-power Internet of Things (IoT) devices. However, their performances are constrained by limited processing, memory, and communication, usually using battery-powered energy. Polling driven mechanisms for monitoring the security, performance, and quality of service of these networks should be efficient and with low overhead, which makes it particularly challenging. The present work proposes the design of a novel method based on a Deep Reinforcement Learning (DRL) algorithm coupled with an Unsupervised Learning reward technique to build a pooling monitoring of IoT networks. This combination makes the network more secure and optimizes predictions of the DRL agent in adaptive environments. Mohamed Said Frikha, Sonia Mettali Gammar, Abdelkader Lahmadi |
PEMWN | 3 |
| 2021 | Reinforcement and deep reinforcement learning for wireless Internet of Things: A survey
Mohamed Said Frikha, Sonia Mettali Gammar, Abdelkader Lahmadi, Laurent Andrey |
Comput. Commun. | 3 |
| 2020 | Management Plane for Differential Privacy Preservation Through Smart ContractsabstractBlockchain has emerged as a novel solution addressing a plethora of industrial issues in domains spanning from financial to educational. However, several challenges restrict the widespread adoption of the technology and data privacy, with throughput and scalability issues, ranks amongst the foremost. In this paper, we introduce a novel privacy management plane which integrates differential privacy to query existing relational databases through the blockchain as well as spearheads the use of blockchain for local differential privacy. The distinguishing feature in the latter is that the privacy management plane gives the data owners the right to perturb their data with the desired privacy budget, while in the former it gives the right to the data curator to change the privacy budget dynamically while answering queries through the blockchain. The paper also includes experimental evaluation of the developed privacy management plane and integrates management operations in it through another smart contract. The paper addresses the issue of GDPR and it's implications in the context of blockchain data, while highlighting the compliance of the proposed implementation. Nida Khan, Abdelkader Lahmadi, Zsófia Kräussl, Radu State |
AICCSA | 2 |
| 2020 | R2-D2: Filter Rule set Decomposition and Distribution in Software Defined NetworksabstractSoftware Defined Networks administrators can specify and smoothly deploy abstract network-wide policies. The rule sets of these policies are deployed in the forwarding tables of the available switches. In this paper, we propose a technique, named R2-D2, for decomposing and distributing a rule set on network switches of limited flow tables size, while preserving the network policy semantics. Through experiments on several rule sets with single dimension, we evaluate and analyse the performance of our rule decomposition techniques. Our results show that our technique is efficient in practice compared to existing techniques. Ahmad Abboud, Rémi Garcia 0001, Abdelkader Lahmadi, Michaël Rusinowitch, Adel Bouhoula |
CNSM | 3 |
| 2020 | Efficient Distribution of Security Policy Filtering Rules in Software Defined NetworksabstractSoftware Defined Networks administrators can specify and smoothly deploy abstract network-wide policies, and then the controller acting as a central authority implements them in the flow tables of the network switches. The rule sets of these policies are specified in the forwarding tables, which are usually accessed using very expensive and power-hungry ternary content-addressable memory (TCAM). Consequently, a given table can only contain a limited number of rules. However, various applications need large rule sets to perform filtering on diverse flows. In this paper, we propose several algorithms for decomposing and distributing a rule set on network switches of limited flow tables size, while preserving the network policy semantics. Through experiments on several rule sets with single and multiple dimensions, we evaluate and analyse the performance of our rule placement techniques. Our results show that our proposals are efficient in practice. Ahmad Abboud, Rémi Garcia 0001, Abdelkader Lahmadi, Michaël Rusinowitch, Adel Bouhoula |
NCA | 3 |
| 2020 | Leveraging Reinforcement Learning for Adaptive Monitoring of Low-Power IoT NetworksabstractLow-power Internet of Things (IoT) networks are widely deployed in various environments with resource-constrained devices, making their states monitoring particularly challenging. In this paper, we propose an adaptive monitoring mechanism for low-power IoT devices, by using a reinforcement learning (RL) method to automatically adapt the polling frequencies of the collected attributes. Our goal is to minimize the number of monitoring packets while keeping accurate and timely detection of threshold crossings associated with supervised attributes. We study the various RL parameter settings under different monitoring attribute behaviors using the OpenAi Gym simulator. We implement the RL based adaptive polling in Contiki OS, and we evaluate its performance using the Cooja simulator. Our results show that our approach converges to optimal polling frequencies and outperforms static periodic notification-based methods by reducing the number of monitoring packets, with a percentage of correctly detected threshold crossings exceeding 80%. Mohamed Said Frikha, Abdelkader Lahmadi, Sonia Mettali Gammar, Laurent Andrey |
WiMob | 2 |
| 2019 | Demonstration of Synchronization Attacks on Distributed and Cooperative Control in Microgrids
Abdelkader Lahmadi, Isabelle Chrisment |
IM | 2 |
| 2019 | Automated Factorization of Security Chains in Software-Defined Networks
Nicolas Schnepf, Rémi Badonnel, Abdelkader Lahmadi, Stephan Merz |
IM | 3 |
| 2019 | A Tool Suite for the Automated Synthesis of Security Function Chains
Nicolas Schnepf, Rémi Badonnel, Abdelkader Lahmadi, Stephan Merz |
IM | 3 |
| 2019 | SPONGE: Software-Defined Traffic Engineering to Absorb Influx of Network TrafficabstractExisting shortest path-based routing in wide area networks or equal cost multi-path routing in data center networks do not consider the load on the links while taking routing decisions. As a consequence, an influx of network traffic stemming from events such as distributed link flooding attacks and data shuffle during large scale analytics can congest network links despite the network having sufficient capacity on alternate paths to absorb the traffic. This can have several negative consequences such as service unavailability, delayed flow completion, packet losses, among others. In this regard, we propose SPONGE, a traffic engineering mechanism for handling sudden influx of network traffic. SPONGE models the network as a stochastic process, takes the switch queue occupancy and traffic rate as inputs, and leverages the multiple available paths in the network to route traffic in a way that minimizes the overall packet loss in the network. We demonstrate the practicality of SPONGE through an OpenFlow based implementation, where we periodically and pro-actively re-route network traffic to the routes computed by SPONGE. Mininet emulations using real network topologies show that SPONGE is capable of reducing packet drops by 20% on average even when the network is highly loaded because of an ongoing link flooding attack. Benoît Henry, Shihabur Rahman Chowdhury, Abdelkader Lahmadi, Romain Azaïs, Jérôme François, Raouf Boutaba |
LCN | 3 |
| 2019 | Poster : Minimizing range rules for packet filtering using a double mask representationabstractPacket filtering is widely used in multiple networking applications, including firewalls, intrusion detection systems, routers and load balances, to decide whether to accept or deny an incoming packet. This mechanism relies on packet's header fields to filter such traffic by using range rules of IP addresses or ports. However, the set of packet filters has to handle a growing number of connected nodes and many of them are compromised and used as sources of attacks. For instance, IP filter sets available in blacklists may reach several millions of entries, and may require large memory space for their storage in filtering appliances. In this paper, we propose a new method based on a double mask IP prefix representation associated to a linear transformation algorithm to build a reduced set of range rules. Our experiments show that the proposed method achieves a reduction ratio of up to 74% on synthetic range rule sets. Ahmad Abboud, Abdelkader Lahmadi, Michaël Rusinowitch, Miguel Couceiro, Adel Bouhoula |
Networking | 2 |
| 2018 | Exploratory Data Analysis of a Network Telescope Traffic and Prediction of Port Probing RatesabstractUnderstanding the properties exhibited by large scale network probing traffic would improve cyber threat intelligence. In addition, the prediction of probing rates is a key feature for security practitioners in their endeavors for making better operational decisions and for enhancing their defense strategy skills. In this work, we study different aspects of the traffic captured by a /20 network telescope. First, we perform an exploratory data analysis of the collected probing activities. The investigation includes probing rates at the port level, services interesting top network probers and the distribution of probing rates by geolocation. Second, we extract the network probers exploration patterns. We model these behaviors using transition graphs decorated with probabilities of switching from a port to another. Finally, we assess the capacity of Non-stationary Autoregressive and Vector Autoregressive models in predicting port probing rates as a first step towards using more robust models for better forecasting performance. Mehdi Zakroum, Abdellah Houmz, Mounir Ghogho, Ghita Mezzour, Abdelkader Lahmadi, Jérôme François, Mohammed Elkoutbi |
ISI | 5 |
| 2018 | Towards a management plane for smart contracts: Ethereum case studyabstractBlockchain is an emerging foundational technology with the potential to create a novel economic and social system. The complexity of the technology poses many challenges and foremost amongst these are monitoring and management of blockchain-based decentralized applications. In this paper, we design, implement and evaluate a novel system to enable management operations in smart contracts. A key aspect of our system is that it facilitates the integration of these operations through dedicated 'managing' smart contracts to provide data filtering as per the role of the smart contract-based application user. We evaluate the overhead costs of such data filtering operations after post-deployment analyses of five categories of smart contracts on the Ethereum public testnet, Rinkeby. We also build a monitoring tool to display public blockchain data using a dashboard coupled with a notification mechanism of any changes in private data to the administrator of the monitored decentralized application. Nida Khan, Abdelkader Lahmadi, Jérôme François, Radu State |
NOMS | 2 |
| 2018 | Synaptic: A formal checker for SDN-based security policiesabstractSoftware-defined networking offers new opportunities for protecting end users by designing dynamic security policies. In particular, security chains can be built by combining security functions, such as firewalls, intrusion detection systems and services for preventing data leakage. The configuration of these security functions and their associated policies is based on behavioural models of end-user applications when accessing the network. In this demo, we present our tool Synaptic, a SDN-based framework intended for the formal verification of security policies as well as for automatically generating such policies based on automata learning methods applied on NetFlow records of end-user applications collected at the device level. Nicolas Schnepf, Rémi Badonnel, Abdelkader Lahmadi, Stephan Merz |
NOMS | 3 |
| 2018 | Generation of SDN policies for protecting android environments based on automata learningabstractSoftware-defined networking offers new opportu-nities for protecting end users and their applications. In that context, dedicated chains can be built to combine different security functions, such as firewalls, intrusion detection systems and services for preventing data leakage. To configure these security chains, it is important to have an adequate model of the patterns that end user applications exhibit when accessing the network. We propose an automated strategy for learning the networking behavior of end applications using algorithms for generating finite state models. These models can be exploited for inferring SDN policies ensuring that applications respect the observed behavior: such policies can be formally verified and deployed on SDN infrastructures in a dynamic and flexible manner. Our solution is prototypically implemented as a collection of Python scripts that extend our Synaptic verification package. The performance of our strategy is evaluated through extensive experimentations and is compared to the Synoptic and Invarimint automata learning algorithms. Nicolas Schnepf, Rémi Badonnel, Abdelkader Lahmadi, Stephan Merz |
NOMS | 3 |
| 2017 | Automated verification of security chains in software-defined networks with synapticabstractSoftware-defined networks provide new facilities for deploying security mechanisms dynamically. In particular, it is possible to build and adjust security chains to protect the infrastructures, by combining different security functions, such as firewalls, intrusion detection systems and services for preventing data leakage. It is important to ensure that these security chains, in view of their complexity and dynamics, are consistent and do not include security violations. We propose in this paper an automated strategy for supporting the verification of security chains in software-defined networks. It relies on an architecture integrating formal verification methods for checking both the control and data planes of these chains, before their deployment. We describe algorithms for translating specifications of security chains into formal models that can then be verified by SMT1solving or model checking. Our solution is prototyped as a package, named Synaptic, built as an extension of the Frenetic family of SDN programming languages. The performances of our approach are evaluated through extensive experimentations based on the CVC4, veriT, and nuXmv checkers. Nicolas Schnepf, Rémi Badonnel, Abdelkader Lahmadi, Stephan Merz |
NetSoft | 3 |
| 2016 | Optimizing internet scanning for assessing industrial systems exposureabstractIndustrial systems are composed of multiple components whose security has not been addressed for a while. Even if recent propositions target to improve it, they are still often exposed to vulnerabilities, since their components are hard to update or replace. In parallel, they tend to be more and more exposed in the public Internet for convenience. Although awareness of such a problem has been raised, there is no precise evaluation of such a risk. In this paper, we define a methodology to measure the exposure of industrial systems through Internet. In particular, a carefully designed scanning approach, named WiScan, is proposed with a low footprint due to the high sensitivity and low resources of targeted systems. It has been applied on the entire IPv4 address space, by targeting specific SCADA ports. Jérôme François, Abdelkader Lahmadi, Valentín Giannini, Damien Cupif, Frédéric Beck, Bertrand Wallrich |
IWCMC | 2 |
| 2015 | Monitoring and Securing New Functions Deployed in a Virtualized Networking EnvironmentabstractNetwork operators are currently very cautious before deploying a new network equipment. This is done only if the new networking solution is fully monitored, secured and can provide rapid revenues (short Return of Investment). For example, the NDN (Named Data Networking) solution is admitted as promising but still uncertain, thus making network operators reluctant to deploy it. Having a flexible environment would allow network operators to initiate the deployment of new network solutions at low cost and low risk. The virtualization techniques, appeared a few years ago, can help to provide such a flexible networking architecture. However, with it, emerge monitoring and security issues which should be solved. In this paper, we present our secure virtualized networking environment to deploy new functions and protocol stacks in the network, with a specific focus on the NDN use-case as one of the potential Future Internet technology. As strong requirements for a network operator, we then focus on monitoring and security components, highlighting where and how they can be deployed and used. Finally, we introduce our preliminary evaluation, with a focus on security, before presenting the test bed, involving end-users consuming real contents, that we will set up for the assessment of our approach. Bertrand Mathieu, Guillaume Doyen, Wissam Mallouli, Thomas Silverston, Olivier Bettan, François-Xavier Aguessy, Thibault Cholez, Abdelkader Lahmadi, Patrick Truong, Edgardo Montes de Oca |
ARES | 8 |
| 2015 | Behavioral and dynamic security functions chaining for Android devicesabstractWe present an approach for dynamically outsourcing and composing security functions for mobile devices, according to the network behavior of their running applications. Applications are characterized from a network point of view using data mining and clustering techniques with the aim to select their appropriate security functions. Software-defined networking mechanisms are employed to chain the selected functions and to redirect mobile apps traffic through the resulting security compositions. Those ones can be fully outsourced or split between in-cloud and on-device. Both a prototype and extensive simulations demonstrate the feasibility of the approach and assess its benefits. Gaetan Hurel, Rémi Badonnel, Abdelkader Lahmadi, Olivier Festor |
CNSM | 3 |
| 2015 | Towards cloud-based compositions of security functions for mobile devicesabstractIn order to prevent attacks against smartphones and tablets, dedicated security applications are usually deployed on the mobile devices themselves. However, these applications may have a significant impact on the device resources, and users may be tempted to uninstall or disable them. In this paper, we propose a new approach to outsource mobile security functions and build transparent in-path security compositions for mobile devices. The functions are dynamically activated, configured and composed using software-defined networking and virtualization capabilities. We present a mathematical formalization to model the security compositions, and describe the functional architecture. We provide an implementation prototype and evaluate the solution through an extensive set of experiments. Gaetan Hurel, Rémi Badonnel, Abdelkader Lahmadi, Olivier Festor |
IM | 3 |
| 2015 | A platform for the analysis and visualization of network flow data of android environmentsabstractIn this demo, we present a monitoring platform dedicated to the collection, storage, analysis and visualization of logs and network flow data of mobile applications. The platform relies on a set of on-device probes to monitor network and system activities of these applications. The data are collected from these probes and parsed through generic and flexible collectors relying on Flume agents that we have adapted and extended. We are storing the collected data using a column oriented Hbase storage engine which is the Hadoop database. Finally, after being parsed, the data are made available within the Elasticsearch engine to search and visualize them using the Kibana tool. Abdelkader Lahmadi, Frédéric Beck, Eric Finickel, Olivier Festor |
IM | 1 |
| 2015 | Extracting Markov chain models from protocol execution traces for end to end delay evaluation in wireless sensor networksabstractMany WSN industrial applications impose requirements in terms of end to end delay. However, the end to end delay estimation in WSNs is not a simple task because of the high dynamic of networks, the use of duty-cycled MAC protocols as well as the impact of the routing protocols. Markov-based modelling is an interesting approach to deal with this problem aiming to provide an analytical model useful for understanding protocol's behavior and to estimate the end to end delay, among other performance parameters. However, existing Markov-based analytic models abstract the reality simplifying the analysis and thus resulting models are not accurate enough for estimating the end to end delay. Furthermore, establishing an accurate Markov model using classic approaches is very difficult considering the highly dynamic behavior of the sensor nodes. In this paper, we propose a novel approach to obtain the Markov chain model of sensor nodes by means of Process Mining techniques through the code execution trace. End to end delay is then computed based on this Markov chain. Experimentations were done using IoT-LAB testbed platform. Comparisons in terms of delay are presented for two different metrics of the RPL protocol (hop count and ETX). Francois Despaux, Yeqiong Song, Abdelkader Lahmadi |
WFCS | 3 |
| 2014 | Modelling and Performance Analysis of Wireless Sensor Networks Using Process Mining Techniques: ContikiMAC Use CaseabstractIn the current protocol stack for Internet of Things in general and wireless sensor network in particular, many devices rely on the Contiki MAC protocol at their MAC layer. This protocol is widely used and enabled by default for several industrial environments and time sensitive monitoring and control applications. However, few work exists regarding the performance of this protocol because it lacks of an underlying theoretical model for analysing its performance. In this paper, we propose a novel approach relying on process mining technique that aims to obtain a Markov chain model for networks running the Contiki MAC protocol. In particular, we present a comprehensive specification of the protocol and a Markov chain model obtained through the analysis and instrumentation of its reference implementation. We used the obtained Markov chain to analyze and estimate the end to end delay distribution for a multi-hops transmission with static routing. The approach can also be extended to a wide range of protocols. Francois Despaux, Yeqiong Song, Abdelkader Lahmadi |
DCOSS | 3 |
| 2014 | Empirical analysis of Android logs using self-organizing mapsabstractIn this paper, we present an empirical analysis of the logs generated by the logging system available in Android environments. The logs are mainly related to the execution of the different components of applications and services running on an Android device. We have analysed the logs using self organizing maps where our goal is to establish behavioural fingerprints of Android applications. Each fingerprint is build using information available in logs and related to the structure of an application and its interaction with the system. The developed methodology allows us the better understand Android Apps regarding their granted permissions and performed actions and it proves to be promising for the analysis of malware applications with a minimal overhead and cost. Eric Finickel, Abdelkader Lahmadi, Frédéric Beck, Olivier Festor |
ICC | 2 |
| 2014 | Towards performance analysis of wireless sensor networks using Process Mining TechniquesabstractPerformance analysis of wireless sensor networks is a difficult task because of the high dynamic of networks and the use of duty-cycled MAC protocols. Markov-based modelling is an interesting approach to deal with this problem. However, existing Markov-based analytic models, being MAC protocol-centric rather than network-centric, work under strong assumptions and do not allow to encompassing important network parameters like radio channel fading and capture effect, or actual implementation optimizations (not always specified in the protocol description). In this paper we propose a novel approach to obtain a Markov chain model for networks running different MAC protocols by means of Process Mining Techniques. We present the main aspects of our approach together with the results obtained for the standard IEEE 802.15.4. The obtained Markov model can be used to evaluate various performance parameters. The approach can also be extended to a wider range of protocols. Francois Despaux, Yeqiong Song, Abdelkader Lahmadi |
ISCC | 3 |
| 2014 | Named data aggregation in wireless sensor networksabstractIn this paper, we present a novel named data aggregation method dedicated to wireless sensor networks. The method relies on an adaptation of the CCNx protocol implementation that we have extended with in-network processing functions to aggregate named data efficiently. We have implemented and tested our solution with the Contiki operating system which is an operating system for resources-constrained embedded systems and wireless sensor networks. Our simulation and measurement results using the Cooja simulator and physical nodes show that our solution has a small overhead in terms of exchanged messages and provides acceptable data retrieval delays. Younes Abid, Bilel Saadallah, Abdelkader Lahmadi, Olivier Festor |
NOMS | 3 |
| 2013 | Efficient distributed monitoring in 6LoWPAN networksabstractMonitoring constrained, low power and lossy networks is essential to many operations including troubleshooting, forensics, performance management. The main challenge for the monitoring plane in these networks is to efficiently cope with both frequently changing topologies and constrained resources. We present a novel algorithm and the supporting framework that improves a poller-pollee based architecture. We empower the poller-pollee placement decision process and operation by exploiting available routing data to monitor nodes status. In addition, monitoring data is efficiently embedded in any messages flowing through the network, drastically reducing monitoring overhead. Our approach is validated through both simulation, implementation and deployment on a 6LoWPAN-enabled network. Results demonstrate that our approach is less aggressive and less resource consuming than its competitors. Abdelkader Lahmadi, Alexandre Boeglin, Olivier Festor |
CNSM | 1 |
| 2013 | Measurement-based Analysis of the Effect of Duty Cycle in IEEE 802.15.4 MAC PerformanceabstractIEEE 802.15.4 protocol stack is the basis of many wireless sensor networks (WSN) and has been proposed for low data rate and low power applications. The standard defines a duty cycle in order to allow devices to achieve efficient energy consumption. Defining the best duty cycle configuration becomes important to extend the network life time. Several works have been done in order to study the behavior of the protocol when considering duty cycle configuration and how this configuration impacts its performance parameters. Usually, the analysis is evaluated by using simulation tools. The objective of this paper is to bring an analysis of the IEEE 802.15.4 duty cycle when considering a real scenario over TinyOS and Telosb motes instead of using a simulation approach. We show through measurement how duty cycle impacts in performance metrics such as average delay and packet drop rate in realistic scenarios. Francois Despaux, Yeqiong Song, Abdelkader Lahmadi |
MASS | 3 |
| 2012 | Combining Analytical and Simulation Approaches for Estimating End-to-End Delay in Multi-hop Wireless NetworksabstractIn this work, we present an empirical support of an analytical approach which employs a frequency domain analysis for estimating end-to-end delay in multi-hop networks. The proposed analytical results of the end-to-end delay distribution are validated through simulation and compared with queueing based analysis by defining two concrete scenarios. Our results demonstrate that an analytical prediction schema is insufficient to provide an adequate estimation of the end-to-end delay distribution function, but it requires to be combined with a simulation method for detailed links and nodes latencies distribution. Francois Despaux, Yeqiong Song, Abdelkader Lahmadi |
DCOSS | 3 |
| 2012 | A Testing Framework for Discovering Vulnerabilities in 6LoWPAN NetworksabstractIn this work, we present the process of identifying potential vulnerabilities in 6LoWPAN enabled networks through fuzzing. The 6LowPAN protocol has been designed by the IETF as an adaptation layer of IPv6 for Low power and lossy networks. The fuzzing process is build upon the Scapy packets manipulation library. It provides different mutation algorithms to be applied on 6LoWPAN protocol messages to assess its implementations security and robustness. The protocol behaviors are described using an XML format to define different testing scenarios. Abdelkader Lahmadi, César Brandin, Olivier Festor |
DCOSS | 1 |
| 2012 | A Framework for Automated Exploit Prevention from Known Vulnerabilities in Voice over IP ServicesabstractWe propose a prevention system for SIP-based networks which adopts a rule-based approach to build prevention specifications on SIP protocol activities that stop attacks exploiting an existing vulnerability before reaching their targets. Our approach innovates from existing solutions by making use of the contextual information of a vulnerability targeted by an attack to apply the prevention specification. Manually coding these prevention specifications is tedious and error-prone. Our method automatically infers prevention specifications by analyzing captured SIP exploit traffic. The detection engine uses an efficient method based on event graphs to match protocol activities against available prevention specifications. We describe the different components of our approach and show through an extended performance study of the implemented system its applicability to enterprise level VoIP protection. Abdelkader Lahmadi, Olivier Festor |
IEEE Trans. Netw. Serv. Manag. | 1 |
| 2011 | Hinky: Defending against Text-Based Message Spam on SmartphonesabstractWe present a defense platform against text-based message SPAM on SmartPhones. We focus in particular on Short Message Service (SMS) based SPAM. Our solution relies on a social network based collaborative approach to filter this type of spam using Bloom filters and content hashing. We detail the design of the supporting framework and validate its efficiency in minimizing false positive and limiting the storage space. Abdelkader Lahmadi, Laurent Delosières, Olivier Festor |
ICC | 1 |
| 2011 | YANG-based configuration modeling - The SecSIP IPS case study -abstractWe present our experience with the development of an XML-based configuration model for an Intrusion Prevention System (IPS) dedicated to the Session Initiation Protocol (SIP) used in voice over IP signaling. In previous works [AL-IM09, AL-NOMS10] we have presented the SecSIP framework, a prevention system for SIP-based networks, which adopts a rule-based approach for specifying preventions on SIP protocol activities to stop attacks exploiting known vulnerability before reaching their targets. The SecSIP framework relies on a proprietary language called VeTo to express the prevention rules. SecSIP uses a plain text configuration file in which specifications are authored and managed manually. While extending the deployment of the framework beyond our own lab, support for remote configuration was required. Given the promise of Netconf, we naturally turned our investigations towards this protocol and embraced the YANG data-modeling framework. In this paper we present the modeling result on the SecSIP configuration interface and share our experience with both YANG and Netconf. The first part of the paper is dedicated to the description of the data to be modeled, namely VeTo policies. The second part presents the Yang model built for VeTo policies and the Netconf framework put in place. Lessons learned during both modeling and coding phases are presented in a third part of the presentation. Finally some conclusions are given and future work is outlined. Abdelkader Lahmadi, Emmanuel Nataf, Olivier Festor |
Integrated Network Management | 1 |
| 2010 | VeTo: An exploit prevention language from known vulnerabilities in SIP servicesabstractWe present VeTo a language to specify protection rules for VoIP systems, supported by the SecSip prevention framework. VeTo offers a unique way to specify both vulnerabilities and countermeasures to protect SIP services against known vulnerabilities. We illustrate the applicability of the language through the specification of several known attacks and assess its efficiency through a target testbed. Abdelkader Lahmadi, Olivier Festor |
NOMS | 1 |
| 2009 | Performance of network and service monitoring frameworksabstractThe efficiency and the performance of management systems is becoming a hot research topic within the networks and services management community. This concern is due to the new challenges of large scale managed systems, where the management plane is integrated within the functional plane and where management activities have to carry accurate and up-to-date information. We defined a set of primary and secondary metrics to measure the performance of a management approach. Secondary metrics are derived from the primary ones and quantifies mainly the efficiency, the scalability and the impact of management activities. To validate our proposals, we have designed and developed a benchmarking platform dedicated to the measurement of the performance of a JMX manager-agent based management system. The second part of our work deals with the collection of measurement data sets from our JMX benchmarking platform. We mainly studied the effect of both load and the number of agents on the scalability, the impact of management activities on the user perceived performance of a managed server and the delays of JMX operations when carrying variables values. Our findings show that most of these delays follow a Weibull statistical distribution. We used this statistical model to study the behavior of a monitoring algorithm proposed in the literature, under heavy tail delays distribution. In this case, the view of the managed system on the manager side becomes noisy and out of date. Abdelkader Lahmadi, Laurent Andrey, Olivier Festor |
Integrated Network Management | 1 |
| 2009 | SecSip: A stateful firewall for SIP-based networksabstractSIP-based networks are becoming the de-facto standard for voice, video and instant messaging services. Being exposed to many threats while playing an major role in the operation of essential services, the need for dedicated security management approaches is rapidly increasing. In this paper we present an original security management approach based on a specific vulnerability aware SIP stateful firewall. Through known attack descriptions, we illustrate the power of the configuration language of the firewall which uses the capability to specify stateful objects that track data from multiple SIP elements within their lifetime. We demonstrate through measurements on a real implementation of the firewall its efficiency and performance. Abdelkader Lahmadi, Olivier Festor |
Integrated Network Management | 1 |