VLDB 2026 Research / reviewers in the wild / expert
Ana R. Cavalli
dblp:51/5965 · also Ana Rosa Cavalli
· DBLP profile ↗
106ranked-venue papers
14as first author
17since 2021 · last 2024
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 51 · 6 first-author · 5 since 2021Security and privacy · 18 · 8 since 2021Computer networks · 17 · 7 first-authorArtificial intelligence and machine learning · 7 · 2 first-authorSystems, architecture and hardware · 3 · 1 first-author · 1 since 2021Databases, data management, data science and information retrieval · 3Human-computer interaction and ubiquitous computing · 3 · 1 first-authorApplied, interdisciplinary, general and emerging computing · 3Theory of computation · 2 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | AI4SOAR: A Security Intelligence Tool for Automated Incident ResponseabstractThe cybersecurity landscape is fraught with challenges stemming from the increasing volume and complexity of security alerts. Traditional manual or semi-automated approaches to threat analysis and incident response often result in significant delays in identifying and mitigating security threats. In this paper, we address these challenges by proposing AI4SOAR, a security intelligence tool for automated incident response. AI4SOAR leverages similarity learning techniques and integrates seamlessly with the open-source SOAR platform Shuffle. We conduct a comprehensive survey of existing open-source SOAR platforms, highlighting their strengths and weaknesses. Additionally, we present a similarity-based learning approach to quickly identify suitable playbooks for incoming alerts. We implement AI4SOAR and demonstrate its application through a use case for automated incident response against SSH brute-force attacks. Manh-Dung Nguyen, Wissam Mallouli, Ana R. Cavalli, Edgardo Montes de Oca |
ARES | 3 |
| 2024 | Towards the adoption of automated cyber threat intelligence information sharing with integrated risk assessmentabstractIn the domain of cybersecurity, effective threat intelligence and information sharing are critical operations for ensuring appropriate and timely response against threats, but limited in automation, standardization, and ease of use in current platforms. This paper introduces a Cyber Threat Intelligence (CTI) Information Sharing platform, designed for critical infrastructures and cyber-physical systems. Our platform integrates existing cybersecurity tools and leverages digital twin technology, enhancing threat analysis and mitigation capabilities. It features an automated process for disseminating standardized and structured intelligence, utilizing the Malware Information Sharing Platform (MISP) for effective dissemination. A significant enhancement is the integration of risk assessment tools, which enriches the shared intelligence with detailed risk information, supporting an informed decision-making. The platform encompasses a user-friendly dashboard and a robust backend, streamlining the threat intelligence cycle and transforming raw data coming from diverse sources into actionable insights. Overall the CTI4BC platform presents a solution to overcome challenges in the CTI sharing, contributing to a more resilient cybersecurity domain. Valeria Valdés Ríos, Fatiha Zaïdi, Ana R. Cavalli, Angel Rego |
ARES | 3 |
| 2024 | The SPATIAL Architecture: Design and Development Experiences from Gauging and Monitoring the AI Inference Capabilities of Modern ApplicationsabstractDespite its enormous economical and societal impact, lack of human-perceived control and safety is re-defining the design and development of emerging AI-based technologies. New regulatory requirements mandate increased human control and oversight of AI, transforming the development practices and responsibilities of individuals interacting with AI. In this paper, we present the SPATIAL architecture, a system that augments modern applications with capabilities to gauge and monitor trustworthy properties of AI inference capabilities. To design SPATIAL, we first explore the evolution of modern system architectures and how AI components and pipelines are integrated. With this information, we then develop a proof-of- concept architecture that analyzes AI models in a human-in-the- loop manner. SPATIAL provides an AI dashboard for allowing individuals interacting with applications to obtain quantifiable insights about the AI decision process. This information is then used by human operators to comprehend possible issues that influence the performance of AI models and adjust or counter them. Through rigorous benchmarks and experiments in real- world industrial applications, we demonstrate that SPATIAL can easily augment modern applications with metrics to gauge and monitor trustworthiness, however, this in turn increases the complexity of developing and maintaining systems implementing AI. Our work highlights lessons learned and experiences from augmenting modern applications with mechanisms that support regulatory compliance of AI. In addition, we also present a road map of on-going challenges that require attention to achieve robust trustworthy analysis of AI and greater engagement of human oversight. Abdul-Rasheed Ottun, Rasinthe Marasinghe, Toluwani Elemosho, Mohan Liyanage, Mohamad Ragab, Prachi Bagave, Marcus Westberg, Mehrdad Asadi, Michell Boerger, Chamara Sandeepa, Thulitha Senevirathna, Bartlomiej Siniarski, Madhusanka Liyanage, Vinh Hoa La, Manh-Dung Nguyen, Edgardo Montes de Oca, Tessa Oomen, João Fernando Ferreira Gonçalves, Illija Tanaskovic, Sasa Klopanovic, Nicolas Kourtellis, Claudio Soriente, Jason Pridmore, Ana R. Cavalli, Drasko Draskovic, Samuel Marchal, Shen Wang 0006, David Solans Noguero, Nikolay Tcholtchev, Aaron Yi Ding, Huber Flores |
ICDCS | 24 |
| 2024 | Diagnosis Automation Using Similarity Analysis: Application to Industrial SystemsabstractInternational audience Ivan Orefice, Wissam Mallouli, Ana R. Cavalli, Filip Sebek, Alberto Lizarduy |
ICSOFT | 3 |
| 2023 | HTTP/2 Attacks Generation using 5Greplayabstract5G networks become increasingly pervasive, ensuring the robustness and integrity of network functions. The adoption of HTTP/2 in 5G core functions brings notable performance benefits but also introduces potential security risks. By analyzing HTTP/2 related threats, this research aims to shed light on the security challenges faced by 5G networks. The paper proposes effective security testing methodologies using an open-source solution called 5Greplay to detect these security breaches, enabling network operators to protect against potential attacks, safeguard user privacy, and ensure uninterrupted service continuity. By addressing the specific concerns of HTTP/2 related threats, this research contributes to the overall security posture of 5G network functions and provides valuable insights for the secure deployment of 5G networks in an evolving threat landscape. Francesco G. Caccavale, Huu Nghia Nguyen, Ana R. Cavalli, Edgardo Montes de Oca, Wissam Mallouli |
ARES | 3 |
| 2023 | A deep learning anomaly detection framework with explainability and robustnessabstractThe prevalence of encrypted Internet traffic has resulted in a pressing need for advanced analysis techniques for traffic analysis and classification. Traditional rule-based and signature-based approaches have been hindered by the introduction of network encryption methods. With the emergence of machine learning (ML) and deep learning (DL), several preliminary works have been developed for anomaly detection in encrypted network traffic. However, complex Artificial Intelligence (AI) models like neural networks lack explainability, limiting the understanding of their predictions. To address this limitation, eXplainable Artificial Intelligence (XAI) has emerged, aiming to provide users with a rationale for understanding AI system outputs and fostering trust. However, existing explainable frameworks still lack comprehensive support for adversarial attacks and defenses. Manh-Dung Nguyen, Anis Bouaziz, Valeria Valdés Ríos, Ana R. Cavalli, Wissam Mallouli, Edgardo Montes de Oca |
ARES | 4 |
| 2023 | The DYNABIC approach to resilience of critical infrastructuresabstractWith increasing interdependencies and evolving threats, maintaining operational continuity in critical systems has become a significant challenge. This paper presents the DYNABIC (Dynamic business continuity of critical infrastructures on top of adaptive multi-level cybersecurity) approach as a comprehensive framework to enhance the resilience of critical infrastructures. The DYNABIC approach provides the resilience enhancement through dynamic adaptation, automated response, collaboration, risk assessment, and continuous improvement. By fostering a proactive and collaborative approach to resilience, the DYNABIC framework empowers critical infrastructure sectors to effectively mitigate disruptions and recover from incidents. The paper explores the key components and architecture of the DYNABIC approach and highlights its potential to strengthen the resilience of critical infrastructures using the concept of Digital Twins in the face of evolving threats and complex operating environments involving cascading effects. Erkuden Rios, Eider Iturbe, Angel Rego, Nicolas Ferry 0001, Jean-Yves Tigli, Stéphane Lavirotte, Gérald Rocher, Phu Hong Nguyen, Rustem Dautov, Wissam Mallouli, Ana R. Cavalli |
ARES | 12 |
| 2023 | 5G SUCI Catcher: Attack and DetectionabstractThe deployment of 5G networks opens up new possibilities for communication and connectivity. However, it also introduces new security threats. This paper explores one cyber threat: 5G SUCI Catcher attack. The 5G SUCI Catcher attack is a proof of concept involving monitoring from nearby mobile devices in the 5G paradigm. SUCI Catchers act as fake base stations by exploiting weaknesses of the 5G authentication and encryption protocol. In this paper, SUCI Catcher attack and detection rules are implemented in a 5G experimental environment. The detection solution demonstrates practically the capability to efficiently mitigate the risks associated with this 5G attack. Lorens Barraud, Francesco G. Caccavale, Jean-Baptiste Peyrat, Wissam Mallouli, Véronique Capdevielle, Hicham Khalife, Ana R. Cavalli |
CloudCom | 7 |
| 2023 | Towards Smarter Security Orchestration and Automatic Response for CPS and IoTabstractCurrent security orchestration and response (SOAR) approaches have primarily focused on specific layers of systems, such as Intrusion Detection Systems, the network layer, or the application layer. We aim to find the gaps in the existing SOAR approaches for IoT/CPS-based systems, especially critical infrastructures, and propose some directions to fill in these gaps. This paper presents a literature survey and future research directions for advancing SOAR towards increased automation and more holistic operation, especially for the cyber-physical security of critical infrastructures. We have found 14 primary SOAR studies and discussed the gaps in general. There is a significant gap when it comes to a comprehensive and systematic approach to SOAR for multi-layered systems using IoT/CPS and considering the computing continuum perspective. To address the gap, we present our on-going work on a framework of multi-layer SOAR decision-making methods and orchestration tools that leverage Reinforcement Learning (RL)-based adaptation intelligence, virtual reality, avatar-human interaction and advanced Cyber Threat Intelligence (CTI) tools. Phu Hong Nguyen, Rustem Dautov, Angel Rego, Eider Iturbe, Erkuden Rios, Diego Sagasti, Gonzalo Nicolas, Valeria Valdés Ríos, Wissam Mallouli, Ana R. Cavalli, Nicolas Ferry 0001 |
CloudCom | 11 |
| 2023 | Testing techniques to assess impact and cascading effectsabstractThe rapid evolution of digital environments and their integration into critical operations of our society have led to substantial challenges in advancing cybersecurity to ensure the proper functioning of these systems . In the face of over-evolving cyber threats and attacks, systems must be equipped with robust mechanisms for protection. In this context, resilience techniques aim to mitigate such treats. However, the evaluation of these techniques is a crucial process, enabling informed decision-making and proactive threat mitigation. This article introduces a methodology based on regression testing for evaluating the impact and cascading effects of resilience strategies. It delves into the methodology’s adaptability across different scenarios and provides insights about the evaluation process. Valeria Valdés Ríos, Ana R. Cavalli, Fatiha Zaïdi, Wissam Mallouli |
CloudCom | 2 |
| 2023 | Study on Adversarial Attacks Techniques, Learning Methods and Countermeasures: Application to Anomaly DetectionabstractInternational audience Anis Bouaziz, Manh-Dung Nguyen, Valeria Valdés Ríos, Ana R. Cavalli, Wissam Mallouli |
ICSOFT | 4 |
| 2022 | A Formal Approach for Complex Attacks Generation based on Mutation of 5G Network TrafficabstractInternational audience Zujany Salazar, Fatiha Zaïdi, Wissam Mallouli, Ana R. Cavalli, Huu Nghia Nguyen, Edgardo Montes de Oca |
ICSOFT | 4 |
| 2022 | Switched-based Control Testbed to Assure Cyber-physical Resilience by DesignabstractInternational audience Mariana Segovia, Jose Rubio-Hernan, Ana R. Cavalli, Joaquín García 0001 |
SECRYPT | 3 |
| 2022 | Special issue on information systems quality for digital transformation
Ricardo Pérez-Castillo, Ana C. R. Paiva, Ana R. Cavalli |
Softw. Qual. J. | 3 |
| 2021 | 5Greplay: a 5G Network Traffic Fuzzer - Application to Attack InjectionabstractThe fifth generation of mobile broadband is more than just an evolution to provide more mobile bandwidth, massive machine-type communications, and ultra-reliable and low-latency communications. It relies on a complex, dynamic and heterogeneous environment that implies addressing numerous testing and security challenges. In this paper we present 5Greplay, an open-source 5G network traffic fuzzer that enables the evaluation of 5G components by replaying and modifying 5G network traffic by creating and injecting network scenarios into a target that can be a 5G core service (e.g., AMF, SMF) or a RAN network (e.g., gNodeB). The tool provides the ability to alter network packets online or offline in both control and data planes in a very flexible manner. The experimental evaluation conducted against open-source based 5G platforms, showed that the target services accept traffic being altered by the tool, and that it can reach up to 9.56 Gbps using only 1 processor core to replay 5G traffic. Zujany Salazar, Huu Nghia Nguyen, Wissam Mallouli, Ana R. Cavalli, Edgardo Montes de Oca |
ARES | 4 |
| 2021 | SANCUS: Multi-layers Vulnerability Management Framework for Cloud-native 5G networksabstractAbstract: Security, Trust and Reliability are crucial issues in mobile 5G networks from both hardware and software perspectives. These issues are of significant importance when considering implementations over distributed environments, i.e., corporate Cloud environment over massively virtualized infrastructures as envisioned in the 5G service provision paradigm. The SANCUS1 solution intends providing a modular framework integrating different engines in order to enable next‐generation 5G system networks to perform automated and intelligent analysis of their firmware images at massive scale, as well as the validation of applications and services. SANCUS also proposes a proactive risk assessment of network applications and services by means of maximising the overall system resilience in terms of security, privacy and reliability. This paper presents an overview of the SANCUS architecture in its current release as well as the pilots use cases that will be demonstrated at the end of the project and used for validating the concepts. Charilaos C. Zarakovitis, Dimitrios Klonidis, Zujany Salazar, Anna Prudnikova, Arash Bozorgchenani, Qiang Ni, Charalambos Klitis, George Guirgis, Ana R. Cavalli, Nicholas Sgouros, Eftychia Makri, Antonios Lalas, Konstantinos Votis, George Amponis, Wissam Mallouli |
ARES | 9 |
| 2021 | A Framework for Security Monitoring of Real IoT TestbedsabstractInternational audience Vinh Hoa La, Edgardo Montes de Oca, Wissam Mallouli, Ana R. Cavalli |
ICSOFT | 4 |
| 2020 | Metrics-driven DevSecOps
Wissam Mallouli, Ana R. Cavalli, Alessandra Bagnato, Edgardo Montes de Oca |
ICSOFT | 2 |
| 2020 | Cyber-Resilience Evaluation of Cyber-Physical SystemsabstractCyber-Physical Systems (CPS) use computational resources to control physical processes and provide critical services. For this reason, an attack in these systems may have dangerous consequences in the physical world. Hence, cyber- resilience is a fundamental property to ensure the safety of the people, the environment and the controlled physical processes. In this paper, we present metrics to quantify the cyber-resilience level based on the design, structure, stability, and performance under the attack of a given CPS. The metrics provide reference points to evaluate whether the system is better prepared or not to face the adversaries. This way, it is possible to quantify the ability to recover from an adversary using its mathematical model based on actuators saturation. Finally, we validate our approach using a numeric simulation on the Tennessee Eastman control challenge problem. Mariana Segovia, Jose Rubio-Hernan, Ana R. Cavalli, Joaquín García 0001 |
NCA | 3 |
| 2019 | Verifying Complex Software Control Systems from Test Objectives: Application to the ETCS SystemabstractInternational audience Rabéa Ameur-Boulifa, Ana R. Cavalli, Stéphane Maag |
ICSOFT | 2 |
| 2019 | A Methodology for Enterprise Resource Planning Automation Testing Application to the Open Source ERP-ODOOabstractInternational audience Thierno Birahime Sambe, Stéphane Maag, Ana R. Cavalli |
ICSOFT | 3 |
| 2019 | Attack Tolerance for Services-Based Applications in the Cloud
Georges Ouffoue, Fatiha Zaïdi, Ana R. Cavalli |
ICTSS | 3 |
| 2019 | Industrial IoT Security Monitoring and Test on Fed4Fire+ Platforms
Edgardo Montes de Oca, Wissam Mallouli, Ana R. Cavalli, Brecht Vermeulen, Matevz Vucnik |
ICTSS | 4 |
| 2019 | Guest Editorial: Special issue on Testing Software and Systems
Hüsnü Yenigün, Nina Yevtushenko 0001, Ana R. Cavalli |
Softw. Qual. J. | 3 |
| 2018 | Enhancing Software Development Process Quality based on Metrics Correlation and SuggestionabstractInternational audience Sarah A. Dahab, Erika Silva, Stéphane Maag, Ana R. Cavalli, Wissam Mallouli |
ICSOFT | 4 |
| 2018 | A Framework for Testing and Monitoring Security Policies: Application to an Electronic Voting SystemabstractTesting and monitoring the effectiveness of security policies under pervasive system architectures is still a major challenging problem for the research community as well as industrials. The inherent characteristics of these systems such as the heterogeneous communicating devices and the multiple used technologies make the burden more overwhelming when dealing with security measures and policies. This paper aims to bridge this gap through the introduction of a formal design of security policies to make security monitoring operation more efficient. Hence, a formal framework is proposed to actively test web-based systems, as an example of these pervasive architectures. The goal of our technique is to check the compliance of the targeted web application to a set of generic security requirements such as confidentiality, integrity and availability as well as to a set of user-related security constraints. Our approach has been applied to a real industrial electronic voting application provided by the Scytl company. Several experiments show the merit of our technique in verifying the correctness of security measures of the targeted application. This framework is part of the INTER-TRUST solution intended to ensure secure inter-operation between communicating systems and provide solutions to test and monitor them. Khalifa Toumi, Mohamed H. E. Aouadi, Ana R. Cavalli, Wissam Mallouli, Jordi Puiggali, Pol Valletb Montfort |
Comput. J. | 3 |
| 2017 | A Study of Threat Detection Systems and Techniques in the Cloud
Pamela Carvallo, Ana R. Cavalli, Natalia Kushik |
CRiSIS | 2 |
| 2017 | Multi-cloud Applications Security Monitoring
Pamela Carvallo, Ana R. Cavalli, Wissam Mallouli, Erkuden Rios |
GPC | 2 |
| 2017 | Automatic Derivation and Validation of a Cloud Dataset for Insider Threat DetectionabstractInternational audience Pamela Carvallo, Ana R. Cavalli, Natalia Kushik |
ICSOFT | 2 |
| 2017 | How Web Services Can Be Tolerant to Intruders through DiversificationabstractThe efforts and findings of the last decades of research on the formalization and the verification of Web services have given a certain level of assurance on Web services. However new challenges such as high availability and security issues are not fully addressed. In fact, Web services are exposed to attacks that appear continuously. These issues have naturally paved the way to a new research topic that aims at providing new techniques for making Web services attack tolerant. In this paper, we present a state of the art of attack tolerance, especially for Web services. We also present our approach to address such issues through a combination of techniques leveraging in particular diversification. The paper ends with our promising results and a discussion to highlight the perspectives and research direction. Georges Ouffoue, Fatiha Zaïdi, Ana R. Cavalli, Mounir Lallali |
ICWS | 3 |
| 2016 | Network Monitoring Using MMT: An Application Based on the User-Agent Field in HTTP HeadersabstractDespite recent emerging development in intrusion detection or network monitoring, malicious attacks and misbehavior remain a high-risk issue within network traffic. In this paper, we present a proactive solution called MMT (Montimage1 Monitoring Tool) that allows facilitating network security and performance monitoring and operation troubleshooting. We demonstrate the improvements of MMT in comparison with other similar tools. Especially, we assess MMT to deal with a practical case-study in which we analyze the User-Agent field in HTTP headers to determine abnormal activities. Indeed, novel observations figure out the usefulness of the User-Agent field in HTTP requests as a good source to facilitate abnormal activities detection within an abundant traffic. There are eventually several researches alarming the vulnerabilities of the User-Agent field and proposing some manual solution including a combination of tools. However, existing countermeasures are rather passive and do not allow real-time detection. In the context of our research, MMT provides an automated detection of malicious traffic abusing vulnerable User-Agent field. Analyzing abnormal User-Agent strings is also useful to rapidly detect existing evil objects in the network (e.g., bots). The experimental results confirm the improvements of our implementation in comparison with other intrusion detection system (SNORT) and packet analyzing tool (TCPdump). Vinh Hoa La, Raul A. Fuentes-Samaniego, Ana R. Cavalli |
AINA | 3 |
| 2016 | A novel monitoring solution for 6LoWPAN-based Wireless Sensor NetworksabstractInternet of Things (IoT) has emerged these last years as one of the most attractive subjects in both the research community and the public. As a sub-domain, Wireless Sensor Networks (WSNs) have been attracting a lot of interest. However, the resource-constraint characteristics of physical objects in those networks presumably limit the design and development of security protocols. Whilst, sensor nodes usually operating in unattended and even harsh environments are prone to failures and malicious attacks. Monitoring them for attack/intrusion detection and for troubleshooting becomes thus an important issue. In this paper, we present a monitoring solution, MMT (Montimage Monitoring Tool), which enables data capture, events extraction, statistics collection, traffic analysis and reporting. The tool is applicable to 6LoWPAN-based (IPv6 over Low power Wireless Personal Area Networks) WSNs. Experiments have been performed on a real test-bed to validate and evaluate our proposition. Vinh Hoa La, Raul A. Fuentes-Samaniego, Ana R. Cavalli |
APCC | 3 |
| 2016 | A Framework to Reduce the Cost of Monitoring and Diagnosis Using Game Theory
Rui Abreu 0001, César Andrés, Ana R. Cavalli |
CRiSIS | 3 |
| 2016 | Opportunistic media sharing for mobile networksabstractNowadays there is a proliferation of smart devices used for media consumption. Usually, media contents are streamed from a Content Distribution Network (CDN), through a cellular network, which can get overloaded when there is a large number of active users per cell. At the same time the devices, i.e. smartphones, typically possess a set of wireless interfaces such as WiFi and Bluetooth that can be used to communicate with other devices in its proximity. In this work we propose a publish/subscribe, opportunistic network protocol aimed at off-load infrastructure network nodes. It contributes to optimize the cellular network usage among mobile devices and to reduce the costs and energy consumption induced by the reproduction of media that are temporally popular. Jorge Visca, Raul A. Fuentes-Samaniego, Ana R. Cavalli, Javier Baliosian |
NOMS | 3 |
| 2016 | Improving Protocol Passive Testing through "Gedanken" Experiments with Finite State MachinesabstractThis paper is devoted to study the use of 'gedanken' experiments with Finite State Machines (FSMs) for protocol passive testing optimization. We discuss how the knowledge obtained from the state identification of an implementation under test (IUT) can be utilized for effective IUT monitoring. Differently from active testing techniques, such identification is performed by only observing the IUT behavior. If the state identification is possible (at least partially), then this fact allows to reduce the number of properties (test purposes) to be checked at certain execution point(s). Correspondingly, this allows to simplify and/or accelerate, i.e. improve the monitoring process by verifying the system behavior only at critical states against the appropriate set of properties associated with a given state. The paper discusses which 'gedanken' experiments can be considered for this purpose and how they can be derived for various specifications of communication protocols. The results presented in the paper are followed by an illustrative protocol example that demonstrates the efficiency of the proposed approach. Natalia Kushik, Jorge López, Ana R. Cavalli, Nina Yevtushenko 0001 |
QRS | 3 |
| 2016 | Effectively Testing of Timed Composite Systems using Test Case PrioritizationabstractA composite system consists of several components which can be developed separately and deployed in distributed environments.Executing test cases on such kind of systems requires more effort due to their size and their distributed environments.A critical issue is to prioritize efficient test cases to be firstly executed.We present in this paper a framework to generate test cases and to select the efficient ones to test the composite systems with taking into account time properties.Particularly, the framework generates a set of test cases based on a model of the system, which cover a given test objective.The test cases are then prioritized in an execution order to detect quickly faults, thus reducing the efforts of test execution and increasing the effectiveness of the testing process.The framework is complemented with an open-source toolchain for automating test case generation.It has been experimentally evaluated on the European Train Control System case study.The initial results show that the approach can save 40% of test execution effort. Huu Nghia Nguyen, Fatiha Zaïdi, Ana R. Cavalli |
SEKE | 3 |
| 2016 | Path sampling, a robust alternative to gossiping for opportunistic network routingabstractOpportunistic Networks have been designed for transmitting data in difficult environments, characterized by high mobility, sporadic connectivity, and constrained resources. To sustain these networks, the literature describes methods such as Epidemic and Spray&Wait, which do not learn from the network behaviour, and Gossiping-based algorithms that collect historical network data to improve efficiency. In this paper, we show that Gossiping-based solutions suffer from pathological behaviour in some simple network scenarios. Under certain conditions almost all the data transmitted by some nodes may get lost in the network, not reaching its destination. To address this problem we have proposed an algorithm that responds in a more robust manner while staying relatively simple. In this work, we show that our algorithm achieves delivery rates comparable to gossiping-based algorithms, while being more robust and providing better fairness. To illustrate this result, we test native implementations of our solution, Path Sampling, and related algorithms on a network simulator. Jorge Visca, Javier Baliosian, Raul A. Fuentes-Samaniego, Ana R. Cavalli |
WiMob | 4 |
| 2016 | On adaptive experiments for nondeterministic finite state machines
Natalia Kushik, Khaled El-Fakih, Nina Yevtushenko 0001, Ana R. Cavalli |
Int. J. Softw. Tools Technol. Transf. | 4 |
| 2015 | An Active Testing Tool for Security Testing of Distributed SystemsabstractThis paper describes the TestGen-IF tool, that allows the automatic generation of test cases based on model based active testing techniques. This paper describes the overall functionality and architecture of the tool, discusses its strengths and weaknesses, and reports our experience with using the tool on a case study, the Dynamic Route Planning (DRP) service of Vehicular Networks. This case study demonstrates how to use our testing tool to verify the system implementation against its security requirements. This paper also proposes improvements to this tool in the form of a GUI interface to facilitate its use and an approach which permits a gain in time and efficiency by generating test objectives. Mohamed H. E. Aouadi, Khalifa Toumi, Ana R. Cavalli |
ARES | 3 |
| 2015 | QoE Evaluation Based on QoS and QoBiz Parameters Applied to an OTT ServiceabstractIn this paper, we present a framework for evaluating the QoE of a service that includes functional and non-functional service requirements. Non-functional requirements are classified into objective, subjective, and business parameters that affect Quality of Service (QoS), Quality of Experience (QoE), and Quality of Business (QoBiz), correspondingly. As those metrics have a strong dependency between each other, we discuss how the QoE of a web-based Over-The-Top service (OTT) can be evaluated taking into account subjective, objective and business parameters. The functional service behavior is described by an Extended Finite State Machine (EFSM) in which non-functional objective, subjective and business-related parameters are tracked using context variables and corresponding updating functions. These parameters are used to evaluate the QoE of the service. We show that the corresponding model allows to keep a track of a user-service interaction. Moreover, the model of the service integrates subjective, objective and business parameters, and thus, can be applied to the QoE evaluation of any OTT service. Natalia Kushik, Camila Fuenzalida, Ana R. Cavalli, Nina Yevtushenko 0001 |
ICWS | 4 |
| 2015 | An Abstraction for the Interoperability Analysis of Security Policies
Javier Baliosian, Ana R. Cavalli |
NSS | 2 |
| 2014 | QoE Estimation for Web Service Selection Using a Fuzzy-Rough Hybrid Expert SystemabstractWith the proliferation of web services on the Inter-net, it has become important for service providers to select the best services for their clients in accordance to their functional and non-functional requirements. Generally, QoS parameters are used to select the most performing web services, however, these parameters do not necessarily reflect the user's satisfaction. Therefore, it is necessary to estimate the quality of web services on the basis of user satisfaction, i.e., Quality of Experience(QoE). In this paper, we propose a novel method based on a fuzzy-rough hybrid expert system for estimating QoE of web services for web service selection. It also presents how different QoS parameters impact the QoE of web services. For this, we conducted subjective tests in controlled environment with real users to correlate QoS parameters to subjective QoE. Based on this subjective test, we derive membership functions and inference rules for the fuzzy system. Membership functions are derived using a probabilistic approach and inference rules are generated using Rough Set Theory (RST). We evaluated our system in a simulated environment in MATLAB. The simulation results show that the estimated web quality from our system has a high correlation with the subjective QoE obtained from the participants in controlled tests. Jeevan Pokhrel, Felipe Lalanne, Ana R. Cavalli, Wissam Mallouli |
AINA | 3 |
| 2014 | A Framework for Distributed Testing of Timed Composite SystemsabstractSoftware systems are more and more complex. They are usually constructed by combining several components which can be implemented separately and deployed in distributed environments. This paper presents a framework for testing these kind of systems. Particularly, each component of a system is tested by a tester and there is no communication between testers. The tester is guided by local test cases that are generated from the composition of models of components where the communication among components may be synchronous or asynchronous. The framework is complemented with a tool chain for automating test generation. The paper presents also a case study on the European Train Control System. Huu Nghia Nguyen, Fatiha Zaïdi, Ana R. Cavalli |
APSEC (1) | 3 |
| 2014 | ISER: A Platform for Security Interoperability of Multi-source Systems
Khalifa Toumi, Fabien Autrel, Ana R. Cavalli, Sammy Haddad |
CRiSIS | 3 |
| 2014 | How to Evaluate Trust Using MMT
Khalifa Toumi, Wissam Mallouli, Edgardo Montes de Oca, César Andrés, Ana R. Cavalli |
NSS | 5 |
| 2014 | Testing Network Protocols: formally, at runtime and online
Xiaoping Che, Stéphane Maag, Jorge López, Ana R. Cavalli |
SEKE | 4 |
| 2014 | Formal Verification of Coordination Systems' Requirements - A Case Study on the European Train Control System
Huu Nghia Nguyen, Ana R. Cavalli |
SEKE | 2 |
| 2014 | Evaluating Web Service QoE by Learning Logic NetworksabstractInternational audience Natalia Kushik, Nina Yevtushenko 0001, Ana R. Cavalli, Wissam Mallouli, Jeevan Pokhrel |
WEBIST (1) | 3 |
| 2014 | A Distributed and Collaborative Intrusion Detection Architecture for Wireless Mesh Networks
Anderson Morais Paiva Morais, Ana R. Cavalli |
Mob. Networks Appl. | 2 |
| 2013 | Estimation of QoE of video traffic using a fuzzy expert systemabstractQuality of experience (QoE) in multimedia traffic has been the focus of extensive research in the last decade. The estimation of the QoE provides valuable input in order to measure the user satisfaction of a particular service. QoE estimation is challenging as it tries to measure a subjective metric where the user experience depends on a number of factors that cannot simply be measured. In this work, we present a methodology and a system based on fuzzy expert system to estimate the impact of network conditions (QoS) on the QoE of video traffic. At first, we conducted subjective tests to correlate network QoS metrics with participants' perceived QoE of video traffic. Second, we propose a No Reference method based on fuzzy expert system to estimate the network impact on the video QoE. The membership functions of the proposed fuzzy system are derived from normalized probability distributions correlating the QoS metrics with QoE. We propose a simple methodology to build the fuzzy inference rules. We evaluated our system in two different sets of experiments. The estimated video quality showed high correlation with the subjective QoE obtained from the participants in a controlled test. We integrated our system as part of a monitoring tool in an industrial IPTV test bed and compared its output with standard Video Quality Monitoring (VQM). The evaluation results show that the proposed video quality estimation method based on fuzzy expert system can effectively measure the network impact on the QoE. Jeevan Pokhrel, Bachar Wehbi, Anderson Nunes Paiva Morais, Ana R. Cavalli, Eric Allilaire |
CCNC | 4 |
| 2013 | Monitoring Based on IOSTS for Testing Functional and Security Properties: Application to an Automotive Case StudyabstractMonitoring for passive conformance testing is a way of checking if the system meets its requirements. Several formal approaches have been proposed these last years, but most of them only consider the control portion of the protocol neglecting the data portions, or are confronted with an overloaded amount of data values to consider. In this work, we propose a novel approach to define protocol properties in terms of Input-Output Symbolic Transition Systems (IOSTS) and show how they can be tested on real execution traces taking into account the data and control portions. These properties can be designed to test the conformance of a protocol as well as security aspects. A parametric trace slicing approach is defined to match trace and property. Besides, a prototype is here developed and experimented. Our approach is illustrated by its application to a set of real execution traces extracted from a real automotive Bluetooth framework with functional and security properties. Pramila Mouttappa, Stéphane Maag, Ana R. Cavalli |
COMPSAC | 3 |
| 2013 | Evaluating Quality of Web Services: A Short SurveyabstractThis paper presents a short survey on the quality evaluation of web services. The most popular metrics for estimating such quality and user perception of web services are Quality of Service (QoS) and Quality of Experience (QoE), which represent objective and subjective assessments correspondingly. For different types of web services, the values of QoS and QoE are measured in different ways. In this paper, we consider various definitions of QoS based on web service parameters and describe several methods for evaluating QoS and QoE. We start with experimental evaluation of QoS based on network traffic analysis and further turn to model based methods for QoS estimating. Existing relationships between different kinds of service quality evaluation are also discussed. Olga Kondratyeva, Natalia Kushik, Ana R. Cavalli, Nina Yevtushenko 0001 |
ICWS | 3 |
| 2013 | Using passive testing based on symbolic execution and slicing techniques: Application to the validation of communication protocols
Pramila Mouttappa, Stéphane Maag, Ana R. Cavalli |
Comput. Networks | 3 |
| 2013 | ICST 2010 Special IssueabstractThis special issue contains extended versions of three papers from the Third IEEE International Conference on Software Testing, Verification and Validation (ICST 2010). These papers were selected on the basis of the reviews from members of the programme committee and subsequently subjected to additional rounds of review and revision. We issued nine invitations to this special issue. Two were not selected after submission, one chose not to revise the paper after being reviewed, three never submitted a major revision, and three papers were eventually accepted. The first paper is ‘Covering and Uncovering Equivalent Mutants’ by Schuler and Zeller. The conference version won the best paper award at ICST 2010. This paper addresses the problem of identifying equivalent mutants. A study is performed on seven real-life programs to assess the percentage of equivalent mutants, which are found to range from 25% to 70%. An approach that uses changes in test coverage to detect nonequivalent mutants is proposed and demonstrated to be superior to state-of-the-art techniques. The approach is implemented as part of the open-source JAVALANCHE framework. The second paper is ‘Efficient Mutation Testing of Multithreaded Code’ by Gligoric, Jagannath, Luo and Marinov. This paper presents a framework for efficiently exploring thread schedules during mutation testing of multithreaded programs. Five techniques are presented and implemented in a tool called MuTMuT. Evaluation studies performed on 12 multithreaded programs show that the techniques can substantially reduce the time required for mutation testing of multithreaded code. The third paper is ‘Formal Specification and Analysis of Functional Properties of Graph Rewriting-based Model Transformation’ by Asztalos, Lengyel and Levendovszky. This paper proposes a language for formally specifying the functional properties of a model transformation. The model transformations are described in a declarative way. Automated algorithms are proposed to analyse the transformations. We express our thanks to the people who contributed to the success of ICST 2010 and this special issue. The steering committee members provided valuable advice, and we were assisted by industry chairs Paul Baker, Wolfgang Grieskamp, Dominique Potier and Andreas Ulrich; workshop chairs Paul Ammann, Benoit Baudry and Ina Schieferdecker; PhD Symposium chairs Atif Memon, Manuel Nunez and Fatiha Zaidi; and the general chair Marie-Claude Gaudel. Thanks go to all the reviewers who provided detailed and timely reviews for the ICST submissions as well as the manuscripts submitted to the special issue. We are also indebted to the ICST 2010 publicity chairs Khaled El-Fakih, Vahid Garousi, Yves Le Traon and Elaine Martins and the Web chair Stephane Maag. We thank the authors for sharing their ideas and results with us. Finally, thanks go to editors-in-chief Jeff Offutt and Robert Hierons for their support and enthusiasm. ANA CAVALLI SUDIPTO GHOSH Co-chairs, Technical Program Committee ICST 2010 10 May 2013 Ana R. Cavalli, Sudipto Ghosh 0001 |
Softw. Test. Verification Reliab. | 1 |
| 2012 | A vector based model approach for defining trust in Multi-Organization EnvironmentsabstractA Multi-Organization Environment is composed of several players that depend on each other for resources and services. In order to manage the security of the exchange process we introduce the concept of trust. We show how this aspect of the cooperative work allows us to increase some security aspects. In particular, we provide a framework where the concepts of trust requirement and trust evaluation play important roles for defining trust vectors. These vectors evaluate a set of requirements, under some conditions, and provide a degree of confidence. In our framework we consider two different types of vectors. On the one hand a vector that relates a user to an organization and on the other hand a vector that links two organizations. Finally we show how these vectors are evaluated and shared among the different organizations, and how we combine the provided trust information in order to enhance the security. Khalifa Toumi, César Andrés, Ana R. Cavalli, Mazen El Maarabani |
CRiSIS | 3 |
| 2012 | Testing Interoperability Security Policies
Mazen El Maarabani, César Andrés, Ana R. Cavalli |
SEKE | 3 |
| 2012 | A systematic approach to integrate common timed security rules within a TEFSM-based system specification
Amel Mammar, Wissam Mallouli, Ana R. Cavalli |
Inf. Softw. Technol. | 3 |
| 2012 | An advanced approach for modeling and detecting software vulnerabilities
Nahid Shahmehri, Amel Mammar, Edgardo Montes de Oca, David Byers, Ana R. Cavalli, Shanai Ardi, Willy Jimenez |
Inf. Softw. Technol. | 5 |
| 2012 | Tight bound on the length of distinguishing sequences for non-observable nondeterministic Finite-State Machines with a polynomial number of inputs and outputs
Iksoon Hwang, Nina Yevtushenko 0001, Ana R. Cavalli |
Inf. Process. Lett. | 3 |
| 2012 | InRob: An approach for testing interoperability and robustness of real-time embedded software
Fátima Mattiello-Francisco, Eliane Martins, Ana R. Cavalli, Edgar Toshiro Yano |
J. Syst. Softw. | 3 |
| 2012 | Applying formal methods to PCEP: an industrial case study from modeling to test generationabstractSUMMARY This paper presents the experimental results in applying formal methods to an industrial protocol for constraint‐based path computation, called Path Computation Element Communication Protocol (PCEP). The experiments include a number of major activities in model‐based testing from modeling to test generation. From the PCEP specification defined by IETF (Internet Engineering Task Force), the functionalities of PCEP are divided into two parts: application and protocol. The protocol part of PCEP is then described in the IF (Intermediate Format) language which is based on communicating timed automata. A number of basic requirements are identified from the PCEP specification and then described as properties in IF. Based on these properties, the validation and verification of the formal specification are carried out using the IF toolset. Test cases are generated using an automatic test generation tool, called TestGen‐IF, which uses partial state space exploration guided by test purposes. As a result, some errors and ambiguities have been found in the PCEP standard specification. Copyright © 2011 John Wiley & Sons, Ltd. Iksoon Hwang, Ana R. Cavalli, Mounir Lallali, Dominique Verchère |
Softw. Test. Verification Reliab. | 2 |
| 2011 | Route Manipulation Attack in Wireless Mesh NetworksabstractWireless Mesh Network (WMN) is an emerging technology that has played an important role in the wireless communication scenario. Wireless Mesh Networks are becoming popular as a way of providing Internet access in a cost-effective, easy, and fast manner. However, due to their intrinsic characteristics such as open medium, WMNs are vulnerable to various types of attacks, which aim at disrupting their routing operations. Infected mesh nodes can generate malicious traffic, which puts the other mesh nodes at risk. In this paper, we present a routing manipulation attack against Better Approach To Mobile Ad hoc Network (BATMAN), a proactive routing protocol designed especially for WMNs. We provide a detailed analysis of the attack and demonstrate its feasibility through a virtualized network environment running BATMAN protocol instances in virtual machines. After, we present a mechanism to detect this kind of attack and identify the source of the attack. Anderson Nunes Paiva Morais, Ana R. Cavalli |
AINA | 2 |
| 2011 | Using Testing Techniques for Vulnerability Detection in C Programs
Amel Mammar, Ana R. Cavalli, Willy Jimenez, Wissam Mallouli, Edgardo Montes de Oca |
ICTSS | 2 |
| 2011 | A model-based attack injection approach for security validationabstractCommunication systems are inherently buggy. These flaws can lead to security breaches in applications, which a malicious user could exploit to cause security failures in the system and, under certain circumstances, to take complete control of the vulnerable system. In this paper, we introduce a novel attack injection approach based on attack modeling to perform security testing and detect potential security vulnerabilities. We use attack trees to describe the system flaws and derive corresponding attack scenarios. The attack scenarios are refined to executable scripts for testing tools that are in charge of injecting the attacks against the system. The approach is applied to the Wireless Application Protocol (WAP) currently used in low-tier mobile devices. We carried out experiments using real attacks such as Denial of Service (DoS) and Cipher Suite Rollback attacks. The experimental results show that the approach can achieve high efficiency in the role of uncovering vulnerabilities. Anderson Nunes Paiva Morais, Ana R. Cavalli, Eliane Martins |
SIN | 2 |
| 2010 | WebMov: A Dedicated Framework for the Modelling and Testing of Web Services CompositionabstractThis paper presents a methodology and a set of tools for the modelling, validation and testing of Web service composition, conceived and developed within the French national project WebMov. This methodology includes several modelling techniques, based mainly on some variations of Timed Extended Finite State Machines (TEFSM) formalism, which provide a formal model of the BPEL description of Web services composition. These models are used as a reference for the application of different test generation and passive testing techniques for conformance and robustness checking. The whole WebMov methodology is integrated within a dedicated framework, composed by a set of tools that implement the model representation, the test generation and passive testing algorithms. This framework also permits the interaction of these tools to achieve specific modelling and testing activities in a complementary way. A case study based on a real service, a Travel Reservation Web Service, is presented as well as the results of the application of the proposed WebMov methodology and tools. Ana R. Cavalli, Tien-Dung Cao, Wissam Mallouli, Eliane Martins, Andrey Sadovykh, Sébastien Salva, Fatiha Zaïdi |
ICWS | 1 |
| 2010 | Timed Extended Invariants for the Passive Testing of Web ServicesabstractThe service-oriented approach is becoming more and more popular to integrate highly heterogeneous systems. Web services are the natural evolution of conventional middleware technologies to support Web-based and enterprise level integration. Formal testing of such Web-based technology is a key point to guarantee its reliability. In this paper, we choose a non-intrusive approach based on monitoring to propose a conformance passive testing methodology to check that a composed Web service respects its functional requirements. This methodology is based on a set of formal invariants representing properties to be tested including data and time constraints. Passive testing of an industrial system (that uses a composition of Web services) is briefly presented to demonstrate the effectiveness of the proposed approach. Gerardo Morales, Stéphane Maag, Ana R. Cavalli, Wissam Mallouli, Edgardo Montes de Oca, Bachar Wehbi |
ICWS | 3 |
| 2010 | Testing Web Service Orchestrators in Context: A Symbolic ApproachabstractAn orchestrator in a Web Service system is a locally deployed piece of software used both to allow users to interact with the system and to communicate with remote components (Web Services) in order to fulfill a goal. We propose a symbolic model based approach to test orchestrators in the context of the systems they pilot. Our approach only takes as input a model of the orchestrator and no models of the Web Services. Besides, the testing architecture is a parameter: communications between Web Services and the orchestrator can be either simulated, or hidden or observable. When they are simulated, the orchestrator is tested in isolation and our approach comes to already defined classical model-based unit testing approaches. When the System Under Test is connected with Web Services (that is, in actual usage) it is no longer fully controlled by the tester, but tested in context In that case two situations may occur: either communications with Web Services are observable or they are hidden. Our approach copes with those cases. We give theorems relating our notion of conformance in context with regard to classical conformance of components in isolation. We present a test case generation algorithm based on symbolic execution techniques: it takes into account the status (controllable, hidden, or observable) of communication channels between the orchestrator and Web Services. The algorithm has been implemented and is illustrated on a small case study. Jose Pablo Escobedo, Christophe Gaston, Pascale Le Gall, Ana R. Cavalli |
SEFM | 4 |
| 2010 | Transmit and Reserve (TAR): A Coordinated Channel Access for IEEE 802.11 NetworksabstractThis paper considers the medium access problem in the IEEE 802.11 standard. Although the transmission bit rates have clearly increased, some MAC related problems remain yet unsolved. The random channel contention suffers from short term unfairness and from the considerable reduction of the effective throughput due to the collision probability that increases with the number of contending nodes in the network. Our objective is to define a coordinated access mechanism that improves the effective throughput and grants a fair sharing of network resources among the different nodes. We propose Transmit And Reserve (TAR), a novel packet based coordinated channel access mechanism that combines advantages of random access and channel assignment. The idea of TAR mechanism is simple: Prior to transmitting a packet, the sender node selects in advance the backoff value for its next packet and advertises this selection within the currently transmitted packet. The neighbor nodes avoid then choosing the same backoff value as the advertised one. The simulation results showed that TAR leads to higher throughput and fairness, and lower collision rate than IEEE 802.11. TAR adapts fast to the network load and to the number of active nodes. Bachar Wehbi, Anis Laouiti, Ana R. Cavalli |
WCNC | 3 |
| 2010 | Testing a probabilistic FSM using interval estimation
Iksoon Hwang, Ana R. Cavalli |
Comput. Networks | 2 |
| 2010 | FSM-based conformance testing methods: A survey annotated with experimental evaluation
Rita Dorofeeva, Khaled El-Fakih, Stéphane Maag, Ana R. Cavalli, Nina Yevtushenko 0001 |
Inf. Softw. Technol. | 4 |
| 2009 | Analysis of the OLSR Protocol by Using Formal Passive TestingabstractIn this paper we apply a passive testing methodology to the analysis of a non-trivial system. In our framework, so-called invariants provide us with a formal representation of the requirements of the system. In order to precisely express new properties in multi-node environments, in this paper we introduce a new kind of invariants. We apply the resulting framework to perform a complete study of a MANET routing protocol: The optimized link state routing protocol. César Andrés, Stéphane Maag, Ana R. Cavalli, Mercedes G. Merayo, Manuel Núñez 0001 |
APSEC | 3 |
| 2009 | A Formal Framework to Integrate Timed Security Rules within a TEFSM-Based System SpecificationabstractFormal methods are very useful in software industry and are becoming of paramount importance in practical engineering techniques. They involve the design and the modeling of various system aspects expressed usually through different paradigms. In this paper, we propose to combine two modeling formalisms in order to express both functional and security timed requirements of a system. First, the system behavior is specified based on its functional requirements using TEFSM (timed extended finite state machine) formalism. Second, this model is augmented by applying a set of dedicated algorithms to integrate timed security requirements specified in Nomad language. This language is well adapted to express security properties such as permissions, prohibitions and obligations with time considerations. The resulting secure model can be used for several purposes such as code generation, specification correctness proof, model checking or automatic test generation. In this paper, we applied our approach to a France Telecom(France Telecom is the main telecommunication company in France) Travel service in order to demonstrate its feasibility. Wissam Mallouli, Amel Mammar, Ana R. Cavalli |
APSEC | 3 |
| 2009 | A Statistical Approach to Test Stochastic and Probabilistic Systems
Mercedes G. Merayo, Iksoon Hwang, Manuel Núñez 0001, Ana R. Cavalli |
ICFEM | 4 |
| 2009 | An Automated Passive Testing Approach for the IMS PoC ServiceabstractAlthough the adoption of the IP Multimedia Subsystem (IMS) keeps growing, IMS applications are often integrated to the system without being formally tested. In this work, we are interested in the IMS Push over Cellular (PoC) service, an OMA standard. We propose a conformance passive testing approach to check that its implementation respects the main standard requirements. This approach is based on a set of formal invariants representing the most relevant expected properties to be tested. Two testing phases are applied: the verification of the invariants against the service specification and their testing on the PoC collected execution traces. Felipe Lalanne, Stéphane Maag, Edgardo Montes de Oca, Ana R. Cavalli, Wissam Mallouli, Arnaud Gonguet |
ASE | 4 |
| 2008 | Context Ontology for Secure InteroperabilityabstractDuring interoperability exchanges, organizations are jointly conducting computation and sharing tasks. However, organizations can have different security policies. To guarantee good interoperability exchanges, organizations need to share with other participants information about the services they provide. In addition, to be compliant with security requirements during interoperability, security policies have to be dynamic. One purpose of this paper is to provide this dynamic behavior by taking care about context of access parameters. The context-aware security requirements may be met by using a contextual access control model to define the security policy of each party involved in the interaction, and OrBAC (Organization based Access Control) is an adequate model for this purpose. Elaborating an ontology based security model provides a mean to ensure sharing of understandable knowledge, in particular knowledge needed to derive the authorized accesses and usages during the interoperability sessions. In this paper, we thus suggest a context ontology to be combined with an ontological representation of the OrBAC model and show how it can be used to ease the security rules definition and derivation during interoperability sessions. Céline Coma, Nora Cuppens, Frédéric Cuppens, Ana R. Cavalli |
ARES | 4 |
| 2008 | Two Complementary Tools for the Formal Testing of Distributed Systems with Time ConstraintsabstractThe complexity and the variety of the deployed time dependent systems, as well as the high degree of reliability required for their global functioning, justify the care provided to the design of the best possible tests. Moreover,it is significant to automate these steps with an aim of reducing the time and the development cost and especially of increasing the reliability of the offered products. In this paper, we present two different tools to test systems with time constraints. The first one allows to automatically generate test cases based on model-based active testing techniques. Whereas the second tool is based on passive testing approach to check that the collected system traces respect a set of formal properties called Invariants. Ana R. Cavalli, Edgardo Montes de Oca, Wissam Mallouli, Mounir Lallali |
DS-RT | 1 |
| 2008 | Modeling System Security Rules with Time Constraints Using Timed Extended Finite State MachinesabstractSecurity and reliability are of paramount importance in designing and building real-time systems because any security failure can put the public and the environment at risk. In this paper, we propose a framework to take timed security requirements into account from the design stage of the system building. Our approach consists of two main steps. First, the system behavior is specified based on its functional requirements using TEFSM (Timed Extended Finite State Machine) formalism. Second, this model is augmented by applying a set of dedicated algorithms to integrate timed security properties specified in Nomad language. Nomad is a formal language well adapted to express timed security properties with timed constraints. We also briefly present a France Telecom Travel system as a case study to demonstrate the reliability of our framework. Wissam Mallouli, Amel Mammar, Ana R. Cavalli |
DS-RT | 3 |
| 2008 | Security Rules Specification and Analysis Based on Passive TestingabstractSecurity is a critical issue in dynamic and open distributed environments such as network-based services or wireless networks. To ensure that a certain level of security is maintained in such environments, the system behavior has to be restrained by a security policy in order to regulate the nature and the context of actions that can be performed within the system, according to specific roles. In this paper, we propose a passive testing approach that permits to check whether a system respects its security policy. To reach this goal, we specify this policy using 'Nomad' formal language which is based on deontic and temporal logics. This language is well adapted to passive testing methods that aim to analyze collected system execution traces in order to give a verdict about their conformity with to the system security requirements. Finally, we apply our methodology to an industrial case study provided by SAP group to demonstrate its reliability. Wissam Mallouli, Fayçal Bessayah, Ana R. Cavalli, Azzedine Benameur |
GLOBECOM | 3 |
| 2008 | Efficient time synchronization mechanism for wireless multi hop networksabstractThis paper considers the time synchronization problem in wireless multihop networks. The objective is to design a protocol that synchronizes the network nodes with respect to one reference node. A set of sender nodes forming a connected dominating set is created to guide the synchronization process in a multihop environment. Each node estimates its clock offset and frequency error parameters to build an adjustment function that transforms its local time to that of the reference node. Our protocol estimates the clock offset and the frequency error on different time scales leading to significant gain in terms of synchronization accuracy. We give the theoretical bounds on the synchronization precision and show its performance through extensive simulations. Bachar Wehbi, Anis Laouiti, Ana R. Cavalli |
PIMRC | 3 |
| 2008 | A formal validation methodology for MANET routing protocols based on nodes' self similarity
Stéphane Maag, Cyril Grepet, Ana R. Cavalli |
Comput. Commun. | 3 |
| 2007 | Specification of Timed EFSM Fault Models in SDL
Samrat S. Batth, Elisangela Rodrigues Vieira, Ana R. Cavalli, M. Ümit Uyar |
FORTE | 3 |
| 2007 | Towards an Automated Test Generation with Delayed Transitions for Timed SystemsabstractIn this paper we analyze the influence of the urgency in the timed transitions, and as consequence, in the test suite generation. As result, we formalize rules to generate sequences where the messages exchanged may be instantaneous or delayed. In addition, the generated scenarios are able to detect timing faults. For test generation, we use a prototype tool called HJ2IF. It is based on a test purpose algorithm, called hit-or-jump and it is applied for systems specified using Intermediate Format language (IF). Elisangela Rodrigues Vieira, Ana R. Cavalli |
RTCSA | 2 |
| 2007 | A formal approach for testing security rulesabstractNowadays, security policies are the key point of every modern infrastructure. The specification and the testing of such policies are the fundamental steps in the development of a secure system since any error in a set of rules is likely to harm the global security. To address both challenges, we propose a framework to specify security policies and test their implementation on a system. Our framework makes it possible to generate in an automatic manner, test sequences, in order to validate the conformance of a security policy. system behavior is specified using a formal description technique based on extended finite state machine (EFSM) [12]. The integration of security rules within the system specification is performed by specific algorithms. Then, the automatic tests generation is performed using a dedicated tool, called SIRIUS, developed in our laboratory. Finally, we briefly present a weblog system as a case study to demonstrate the reliability of our framework. Wissam Mallouli, Jean-Marie Orset, Ana R. Cavalli, Nora Cuppens, Frédéric Cuppens |
SACMAT | 3 |
| 2006 | A Security Model for OLSR MANET ProtocolabstractIn this paper, we propose a formal security model to detect attacks on the Optimized Link State Routing protocol (OLSR). We make use of a combination of deontic and temporal logic to specify the correct behaviour of a node and also to express complex security properties such as obligations, roles and deadlines within specific contexts. We investigate different attacks targeting the link sensing mechanism of the protocol and describe security policies to prevent them. We argue that our approach allows to detect complex threats on OLSR. Jean-Marie Orset, Ana R. Cavalli |
MDM | 2 |
| 2006 | Light Client Management Protocol for Wireless Mesh NetworksabstractThe future of wireless networks evolves toward more simple ways for users to get connected while on the move. In this perspective, Wireless Mesh Networks constitutes one of the key technologies for next generation wireless networks. In this paper we present LCMP, a new protocol for client management in wireless mesh networks. LCMP performs on-demand path setup for clients and supports clients mobility by introducing new light mechanisms that take full advantage of the mesh architecture. The work on LCMP and mesh routing is still in progress at LOMNT laboratory. In this papel; we highlight some ongoing work. Bachar Wehbi, Wissam Mallouli, Ana R. Cavalli |
MDM | 3 |
| 2005 | An EFSM-Based Intrusion Detection System for Ad Hoc Networks
Jean-Marie Orset, Baptiste Alcalde, Ana R. Cavalli |
ATVA | 3 |
| 2005 | Experimental Evaluation of FSM-Based Testing MethodsabstractThe development of test cases is an important issue for testing software, communication protocols and other reactive systems. A number of methods are known for the development of a test suite based on a formal specification given in the form of a finite state machine. Well-known methods are called the W, Wp, UIO, UIOv, DS, H and HIS test derivation methods. These methods have been extensively used by research community in the last years; however no proper comparison has been made between them. In this paper, we experiment with these methods to assess their complexity, applicability, completeness, fault detection capability, length and derivation time of their test suites. The experiments are conducted on randomly generated specifications and on a realistic protocol called the simple connection protocol. Rita Dorofeeva, Nina Yevtushenko 0001, Khaled El-Fakih, Ana R. Cavalli |
SEFM | 4 |
| 2005 | Secure hosts auto-configuration in mobile ad hoc networks
Ana R. Cavalli, Jean-Marie Orset |
Ad Hoc Networks | 1 |
| 2005 | A passive testing approach based on invariants: application to the WAP
Emmanuel Bayse, Ana R. Cavalli, Manuel Núñez 0001, Fatiha Zaïdi |
Comput. Networks | 2 |
| 2004 | Network Protocol System Passive Testing for Fault Management: A Backward Checking Approach
Baptiste Alcalde, Ana R. Cavalli, Dongluo Chen, Davy Khuu, David Lee 0001 |
FORTE | 2 |
| 2003 | New approaches for passive testing using an Extended Finite State Machine specification
Ana R. Cavalli, Caroline Gervy, Svetlana Prokopenko |
Inf. Softw. Technol. | 1 |
| 2003 | Test suite minimization for testing in contextabstractAbstract Testing a component embedded into a complex system, in which all other components are assumed fault‐free, is known as embedded testing. This paper proposes a method for minimizing a test suite to perform embedded testing. The minimized test suite maintains the fault coverage of the original test suite with respect to faults within the embedded component. The minimization uses the fact that the system is composed of a fault‐free context and a component under test, specified as communicating, possibly non‐deterministic finite state machines (FSMs). The method is illustrated using an example of telephone services on an intelligent network architecture. Other applications of the proposed approach for testing a system of communicating FSMs are also discussed. Copyright © 2003 John Wiley & Sons, Ltd. Ricardo Anido, Ana R. Cavalli, Luiz Augusto de Paula Lima, Nina Yevtushenko 0001 |
Softw. Test. Verification Reliab. | 2 |
| 2002 | A New Algorithm for Service Interaction Detection
Ana R. Cavalli, Stéphane Maag |
ICFEM | 1 |
| 2001 | A Service-Component Testing Method and a Suitable CORBA ArchitectureabstractThis paper presents a method for service-component testing and a suitable CORBA test architecture. This test environment allows the service validation from its components and is a close step towards the execution of the obtained tests on a CORBA environment. Two aspects are relevant: the test of components and the test architecture. The testing method for components is new: it is based on the generation of partial graphs and avoids the combinatorial explosion of number of states of the global system. The test architecture on a CORBA platform is also new, since there are few works on testing based on these environments. As an application we present a case study on a real conference call service. Ana R. Cavalli, Bruno Defude, Christian Rinderknecht, Fatiha Zaïdi |
ISCC | 1 |
| 1999 | Hit-or-Jump: An algorithm for embedded testing with applications to IN services
Ana R. Cavalli, David Lee 0001, Christian Rinderknecht, Fatiha Zaïdi |
FORTE | 1 |
| 1999 | An Automatic and Optimized Test Generation Technique Applying to TCP/IP ProtocolabstractIn this paper an automatic and optimized technique for test generation for communication protocol control and data portion is described, the goal is to minimize the number of tests with a guaranteed coverage. The test generation algorithm is applied to the client layer part of the TCP/IP protocol. The protocol used for the experiment is TCP-Reno, which is specified in the SDL language and is one of the commonly referenced implementations. For such a sophisticated protocol, the algorithm efficiently constructs 22 tests that cover all the required portions of the protocol. Cédric Besse, Ana R. Cavalli, David Lee 0001 |
ASE | 2 |
| 1999 | Advanced Topics on SDL and MSC
Ana R. Cavalli |
Comput. Networks | 1 |
| 1999 | Passive testing and application to the GSM-MAP protocol
Marine Tabourier, Ana R. Cavalli |
Inf. Softw. Technol. | 2 |
| 1998 | Application of Embedded Testing Methods to Service ValidationabstractConformance testing is a critical phase in the life cycle of communicating systems. However, classical testing methods are not appropriate for use in all tasks concerning the test of telecommunications services (especially regression and integration tests). This is so because Intelligent Networks, into which these services are installed are modular architectures (composed of building blocks) evolving basically by the addition of new services/features that map share the same resources (reusability). The paper investigates how embedded conformance testing methods can be applied in the context of service validation, taking into account the different testing phases in the service life cycle. In order to illustrate their application, the validation of telephone services (Basic Call Service, Originating Call Screening and Call Forward Unconditional) on an intelligent network framework is presented. It is also shown how some cases of feature interaction can be detected. Luiz Augusto de Paula Lima, Ana R. Cavalli |
ICFEM | 2 |
| 1996 | Testing Methods for SDL Systems
Ana R. Cavalli, Byoung-Moon Chin, Kilnam Chon |
Comput. Networks ISDN Syst. | 1 |
| 1996 | Standardization of Formal Methods in Conformance Testing of Communication Protocols
Ana R. Cavalli, Jean Philippe Favreau, Marc Phalippou |
Comput. Networks ISDN Syst. | 1 |
| 1994 | A modal based verification for LOTOS
Hacène Fouchal, Ana R. Cavalli |
FORTE | 2 |
| 1994 | A Compositional Verification Method for LOTOSabstractNo abstract available. Hacène Fouchal, Ana R. Cavalli |
PODC | 2 |
| 1993 | Improving Conformance Testing for LOTOS
Ana R. Cavalli, Sung Un Kim, Patrick Maigron |
FORTE | 1 |
| 1988 | Exhaustive Analysis and Simulation for Distributed Systems, both Sides of the Same Coin
Ana R. Cavalli, Etienne Paul |
Distributed Comput. | 1 |
| 1984 | A Decision Method for Linear Temporal Logic
Ana R. Cavalli, Luis Fariñas del Cerro |
CADE | 1 |