Ana R. Cavalli

dblp:51/5965 · also Ana Rosa Cavalli · DBLP profile ↗
← Back
106ranked-venue papers
14as first author
17since 2021 · last 2024
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 51 · 6 first-author · 5 since 2021Security and privacy · 18 · 8 since 2021Computer networks · 17 · 7 first-authorArtificial intelligence and machine learning · 7 · 2 first-authorSystems, architecture and hardware · 3 · 1 first-author · 1 since 2021Databases, data management, data science and information retrieval · 3Human-computer interaction and ubiquitous computing · 3 · 1 first-authorApplied, interdisciplinary, general and emerging computing · 3Theory of computation · 2 · 1 first-author
YearPublicationVenuePosition
2024 AI4SOAR: A Security Intelligence Tool for Automated Incident Response
abstract
The cybersecurity landscape is fraught with challenges stemming from the increasing volume and complexity of security alerts. Traditional manual or semi-automated approaches to threat analysis and incident response often result in significant delays in identifying and mitigating security threats. In this paper, we address these challenges by proposing AI4SOAR, a security intelligence tool for automated incident response. AI4SOAR leverages similarity learning techniques and integrates seamlessly with the open-source SOAR platform Shuffle. We conduct a comprehensive survey of existing open-source SOAR platforms, highlighting their strengths and weaknesses. Additionally, we present a similarity-based learning approach to quickly identify suitable playbooks for incoming alerts. We implement AI4SOAR and demonstrate its application through a use case for automated incident response against SSH brute-force attacks.
Manh-Dung Nguyen, Wissam Mallouli, Ana R. Cavalli, Edgardo Montes de Oca
ARES3
2024 Towards the adoption of automated cyber threat intelligence information sharing with integrated risk assessment
abstract
In the domain of cybersecurity, effective threat intelligence and information sharing are critical operations for ensuring appropriate and timely response against threats, but limited in automation, standardization, and ease of use in current platforms. This paper introduces a Cyber Threat Intelligence (CTI) Information Sharing platform, designed for critical infrastructures and cyber-physical systems. Our platform integrates existing cybersecurity tools and leverages digital twin technology, enhancing threat analysis and mitigation capabilities. It features an automated process for disseminating standardized and structured intelligence, utilizing the Malware Information Sharing Platform (MISP) for effective dissemination. A significant enhancement is the integration of risk assessment tools, which enriches the shared intelligence with detailed risk information, supporting an informed decision-making. The platform encompasses a user-friendly dashboard and a robust backend, streamlining the threat intelligence cycle and transforming raw data coming from diverse sources into actionable insights. Overall the CTI4BC platform presents a solution to overcome challenges in the CTI sharing, contributing to a more resilient cybersecurity domain.
Valeria Valdés Ríos, Fatiha Zaïdi, Ana R. Cavalli, Angel Rego
ARES3
2024 The SPATIAL Architecture: Design and Development Experiences from Gauging and Monitoring the AI Inference Capabilities of Modern Applications
abstract
Despite its enormous economical and societal impact, lack of human-perceived control and safety is re-defining the design and development of emerging AI-based technologies. New regulatory requirements mandate increased human control and oversight of AI, transforming the development practices and responsibilities of individuals interacting with AI. In this paper, we present the SPATIAL architecture, a system that augments modern applications with capabilities to gauge and monitor trustworthy properties of AI inference capabilities. To design SPATIAL, we first explore the evolution of modern system architectures and how AI components and pipelines are integrated. With this information, we then develop a proof-of- concept architecture that analyzes AI models in a human-in-the- loop manner. SPATIAL provides an AI dashboard for allowing individuals interacting with applications to obtain quantifiable insights about the AI decision process. This information is then used by human operators to comprehend possible issues that influence the performance of AI models and adjust or counter them. Through rigorous benchmarks and experiments in real- world industrial applications, we demonstrate that SPATIAL can easily augment modern applications with metrics to gauge and monitor trustworthiness, however, this in turn increases the complexity of developing and maintaining systems implementing AI. Our work highlights lessons learned and experiences from augmenting modern applications with mechanisms that support regulatory compliance of AI. In addition, we also present a road map of on-going challenges that require attention to achieve robust trustworthy analysis of AI and greater engagement of human oversight.
Abdul-Rasheed Ottun, Rasinthe Marasinghe, Toluwani Elemosho, Mohan Liyanage, Mohamad Ragab, Prachi Bagave, Marcus Westberg, Mehrdad Asadi, Michell Boerger, Chamara Sandeepa, Thulitha Senevirathna, Bartlomiej Siniarski, Madhusanka Liyanage, Vinh Hoa La, Manh-Dung Nguyen, Edgardo Montes de Oca, Tessa Oomen, João Fernando Ferreira Gonçalves, Illija Tanaskovic, Sasa Klopanovic, Nicolas Kourtellis, Claudio Soriente, Jason Pridmore, Ana R. Cavalli, Drasko Draskovic, Samuel Marchal, Shen Wang 0006, David Solans Noguero, Nikolay Tcholtchev, Aaron Yi Ding, Huber Flores
ICDCS24
2024 Diagnosis Automation Using Similarity Analysis: Application to Industrial Systems
abstract
International audience
Ivan Orefice, Wissam Mallouli, Ana R. Cavalli, Filip Sebek, Alberto Lizarduy
ICSOFT3
2023 HTTP/2 Attacks Generation using 5Greplay
abstract
5G networks become increasingly pervasive, ensuring the robustness and integrity of network functions. The adoption of HTTP/2 in 5G core functions brings notable performance benefits but also introduces potential security risks. By analyzing HTTP/2 related threats, this research aims to shed light on the security challenges faced by 5G networks. The paper proposes effective security testing methodologies using an open-source solution called 5Greplay to detect these security breaches, enabling network operators to protect against potential attacks, safeguard user privacy, and ensure uninterrupted service continuity. By addressing the specific concerns of HTTP/2 related threats, this research contributes to the overall security posture of 5G network functions and provides valuable insights for the secure deployment of 5G networks in an evolving threat landscape.
Francesco G. Caccavale, Huu Nghia Nguyen, Ana R. Cavalli, Edgardo Montes de Oca, Wissam Mallouli
ARES3
2023 A deep learning anomaly detection framework with explainability and robustness
abstract
The prevalence of encrypted Internet traffic has resulted in a pressing need for advanced analysis techniques for traffic analysis and classification. Traditional rule-based and signature-based approaches have been hindered by the introduction of network encryption methods. With the emergence of machine learning (ML) and deep learning (DL), several preliminary works have been developed for anomaly detection in encrypted network traffic. However, complex Artificial Intelligence (AI) models like neural networks lack explainability, limiting the understanding of their predictions. To address this limitation, eXplainable Artificial Intelligence (XAI) has emerged, aiming to provide users with a rationale for understanding AI system outputs and fostering trust. However, existing explainable frameworks still lack comprehensive support for adversarial attacks and defenses.
Manh-Dung Nguyen, Anis Bouaziz, Valeria Valdés Ríos, Ana R. Cavalli, Wissam Mallouli, Edgardo Montes de Oca
ARES4
2023 The DYNABIC approach to resilience of critical infrastructures
abstract
With increasing interdependencies and evolving threats, maintaining operational continuity in critical systems has become a significant challenge. This paper presents the DYNABIC (Dynamic business continuity of critical infrastructures on top of adaptive multi-level cybersecurity) approach as a comprehensive framework to enhance the resilience of critical infrastructures. The DYNABIC approach provides the resilience enhancement through dynamic adaptation, automated response, collaboration, risk assessment, and continuous improvement. By fostering a proactive and collaborative approach to resilience, the DYNABIC framework empowers critical infrastructure sectors to effectively mitigate disruptions and recover from incidents. The paper explores the key components and architecture of the DYNABIC approach and highlights its potential to strengthen the resilience of critical infrastructures using the concept of Digital Twins in the face of evolving threats and complex operating environments involving cascading effects.
Erkuden Rios, Eider Iturbe, Angel Rego, Nicolas Ferry 0001, Jean-Yves Tigli, Stéphane Lavirotte, Gérald Rocher, Phu Hong Nguyen, Rustem Dautov, Wissam Mallouli, Ana R. Cavalli
ARES12
2023 5G SUCI Catcher: Attack and Detection
abstract
The deployment of 5G networks opens up new possibilities for communication and connectivity. However, it also introduces new security threats. This paper explores one cyber threat: 5G SUCI Catcher attack. The 5G SUCI Catcher attack is a proof of concept involving monitoring from nearby mobile devices in the 5G paradigm. SUCI Catchers act as fake base stations by exploiting weaknesses of the 5G authentication and encryption protocol. In this paper, SUCI Catcher attack and detection rules are implemented in a 5G experimental environment. The detection solution demonstrates practically the capability to efficiently mitigate the risks associated with this 5G attack.
Lorens Barraud, Francesco G. Caccavale, Jean-Baptiste Peyrat, Wissam Mallouli, Véronique Capdevielle, Hicham Khalife, Ana R. Cavalli
CloudCom7
2023 Towards Smarter Security Orchestration and Automatic Response for CPS and IoT
abstract
Current security orchestration and response (SOAR) approaches have primarily focused on specific layers of systems, such as Intrusion Detection Systems, the network layer, or the application layer. We aim to find the gaps in the existing SOAR approaches for IoT/CPS-based systems, especially critical infrastructures, and propose some directions to fill in these gaps. This paper presents a literature survey and future research directions for advancing SOAR towards increased automation and more holistic operation, especially for the cyber-physical security of critical infrastructures. We have found 14 primary SOAR studies and discussed the gaps in general. There is a significant gap when it comes to a comprehensive and systematic approach to SOAR for multi-layered systems using IoT/CPS and considering the computing continuum perspective. To address the gap, we present our on-going work on a framework of multi-layer SOAR decision-making methods and orchestration tools that leverage Reinforcement Learning (RL)-based adaptation intelligence, virtual reality, avatar-human interaction and advanced Cyber Threat Intelligence (CTI) tools.
Phu Hong Nguyen, Rustem Dautov, Angel Rego, Eider Iturbe, Erkuden Rios, Diego Sagasti, Gonzalo Nicolas, Valeria Valdés Ríos, Wissam Mallouli, Ana R. Cavalli, Nicolas Ferry 0001
CloudCom11
2023 Testing techniques to assess impact and cascading effects
abstract
The rapid evolution of digital environments and their integration into critical operations of our society have led to substantial challenges in advancing cybersecurity to ensure the proper functioning of these systems . In the face of over-evolving cyber threats and attacks, systems must be equipped with robust mechanisms for protection. In this context, resilience techniques aim to mitigate such treats. However, the evaluation of these techniques is a crucial process, enabling informed decision-making and proactive threat mitigation. This article introduces a methodology based on regression testing for evaluating the impact and cascading effects of resilience strategies. It delves into the methodology’s adaptability across different scenarios and provides insights about the evaluation process.
Valeria Valdés Ríos, Ana R. Cavalli, Fatiha Zaïdi, Wissam Mallouli
CloudCom2
2023 Study on Adversarial Attacks Techniques, Learning Methods and Countermeasures: Application to Anomaly Detection
abstract
International audience
Anis Bouaziz, Manh-Dung Nguyen, Valeria Valdés Ríos, Ana R. Cavalli, Wissam Mallouli
ICSOFT4
2022 A Formal Approach for Complex Attacks Generation based on Mutation of 5G Network Traffic
abstract
International audience
Zujany Salazar, Fatiha Zaïdi, Wissam Mallouli, Ana R. Cavalli, Huu Nghia Nguyen, Edgardo Montes de Oca
ICSOFT4
2022 Switched-based Control Testbed to Assure Cyber-physical Resilience by Design
abstract
International audience
Mariana Segovia, Jose Rubio-Hernan, Ana R. Cavalli, Joaquín García 0001
SECRYPT3
2022 Special issue on information systems quality for digital transformation
Ricardo Pérez-Castillo, Ana C. R. Paiva, Ana R. Cavalli
Softw. Qual. J.3
2021 5Greplay: a 5G Network Traffic Fuzzer - Application to Attack Injection
abstract
The fifth generation of mobile broadband is more than just an evolution to provide more mobile bandwidth, massive machine-type communications, and ultra-reliable and low-latency communications. It relies on a complex, dynamic and heterogeneous environment that implies addressing numerous testing and security challenges. In this paper we present 5Greplay, an open-source 5G network traffic fuzzer that enables the evaluation of 5G components by replaying and modifying 5G network traffic by creating and injecting network scenarios into a target that can be a 5G core service (e.g., AMF, SMF) or a RAN network (e.g., gNodeB). The tool provides the ability to alter network packets online or offline in both control and data planes in a very flexible manner. The experimental evaluation conducted against open-source based 5G platforms, showed that the target services accept traffic being altered by the tool, and that it can reach up to 9.56 Gbps using only 1 processor core to replay 5G traffic.
Zujany Salazar, Huu Nghia Nguyen, Wissam Mallouli, Ana R. Cavalli, Edgardo Montes de Oca
ARES4
2021 SANCUS: Multi-layers Vulnerability Management Framework for Cloud-native 5G networks
abstract
Abstract: Security, Trust and Reliability are crucial issues in mobile 5G networks from both hardware and software perspectives. These issues are of significant importance when considering implementations over distributed environments, i.e., corporate Cloud environment over massively virtualized infrastructures as envisioned in the 5G service provision paradigm. The SANCUS1 solution intends providing a modular framework integrating different engines in order to enable next‐generation 5G system networks to perform automated and intelligent analysis of their firmware images at massive scale, as well as the validation of applications and services. SANCUS also proposes a proactive risk assessment of network applications and services by means of maximising the overall system resilience in terms of security, privacy and reliability. This paper presents an overview of the SANCUS architecture in its current release as well as the pilots use cases that will be demonstrated at the end of the project and used for validating the concepts.
Charilaos C. Zarakovitis, Dimitrios Klonidis, Zujany Salazar, Anna Prudnikova, Arash Bozorgchenani, Qiang Ni, Charalambos Klitis, George Guirgis, Ana R. Cavalli, Nicholas Sgouros, Eftychia Makri, Antonios Lalas, Konstantinos Votis, George Amponis, Wissam Mallouli
ARES9
2021 A Framework for Security Monitoring of Real IoT Testbeds
abstract
International audience
Vinh Hoa La, Edgardo Montes de Oca, Wissam Mallouli, Ana R. Cavalli
ICSOFT4
2020 Metrics-driven DevSecOps
Wissam Mallouli, Ana R. Cavalli, Alessandra Bagnato, Edgardo Montes de Oca
ICSOFT2
2020 Cyber-Resilience Evaluation of Cyber-Physical Systems
abstract
Cyber-Physical Systems (CPS) use computational resources to control physical processes and provide critical services. For this reason, an attack in these systems may have dangerous consequences in the physical world. Hence, cyber- resilience is a fundamental property to ensure the safety of the people, the environment and the controlled physical processes. In this paper, we present metrics to quantify the cyber-resilience level based on the design, structure, stability, and performance under the attack of a given CPS. The metrics provide reference points to evaluate whether the system is better prepared or not to face the adversaries. This way, it is possible to quantify the ability to recover from an adversary using its mathematical model based on actuators saturation. Finally, we validate our approach using a numeric simulation on the Tennessee Eastman control challenge problem.
Mariana Segovia, Jose Rubio-Hernan, Ana R. Cavalli, Joaquín García 0001
NCA3
2019 Verifying Complex Software Control Systems from Test Objectives: Application to the ETCS System
abstract
International audience
Rabéa Ameur-Boulifa, Ana R. Cavalli, Stéphane Maag
ICSOFT2
2019 A Methodology for Enterprise Resource Planning Automation Testing Application to the Open Source ERP-ODOO
abstract
International audience
Thierno Birahime Sambe, Stéphane Maag, Ana R. Cavalli
ICSOFT3
2019 Attack Tolerance for Services-Based Applications in the Cloud
Georges Ouffoue, Fatiha Zaïdi, Ana R. Cavalli
ICTSS3
2019 Industrial IoT Security Monitoring and Test on Fed4Fire+ Platforms
Edgardo Montes de Oca, Wissam Mallouli, Ana R. Cavalli, Brecht Vermeulen, Matevz Vucnik
ICTSS4
2019 Guest Editorial: Special issue on Testing Software and Systems
Hüsnü Yenigün, Nina Yevtushenko 0001, Ana R. Cavalli
Softw. Qual. J.3
2018 Enhancing Software Development Process Quality based on Metrics Correlation and Suggestion
abstract
International audience
Sarah A. Dahab, Erika Silva, Stéphane Maag, Ana R. Cavalli, Wissam Mallouli
ICSOFT4
2018 A Framework for Testing and Monitoring Security Policies: Application to an Electronic Voting System
abstract
Testing and monitoring the effectiveness of security policies under pervasive system architectures is still a major challenging problem for the research community as well as industrials. The inherent characteristics of these systems such as the heterogeneous communicating devices and the multiple used technologies make the burden more overwhelming when dealing with security measures and policies. This paper aims to bridge this gap through the introduction of a formal design of security policies to make security monitoring operation more efficient. Hence, a formal framework is proposed to actively test web-based systems, as an example of these pervasive architectures. The goal of our technique is to check the compliance of the targeted web application to a set of generic security requirements such as confidentiality, integrity and availability as well as to a set of user-related security constraints. Our approach has been applied to a real industrial electronic voting application provided by the Scytl company. Several experiments show the merit of our technique in verifying the correctness of security measures of the targeted application. This framework is part of the INTER-TRUST solution intended to ensure secure inter-operation between communicating systems and provide solutions to test and monitor them.
Khalifa Toumi, Mohamed H. E. Aouadi, Ana R. Cavalli, Wissam Mallouli, Jordi Puiggali, Pol Valletb Montfort
Comput. J.3
2017 A Study of Threat Detection Systems and Techniques in the Cloud
Pamela Carvallo, Ana R. Cavalli, Natalia Kushik
CRiSIS2
2017 Multi-cloud Applications Security Monitoring
Pamela Carvallo, Ana R. Cavalli, Wissam Mallouli, Erkuden Rios
GPC2
2017 Automatic Derivation and Validation of a Cloud Dataset for Insider Threat Detection
abstract
International audience
Pamela Carvallo, Ana R. Cavalli, Natalia Kushik
ICSOFT2
2017 How Web Services Can Be Tolerant to Intruders through Diversification
abstract
The efforts and findings of the last decades of research on the formalization and the verification of Web services have given a certain level of assurance on Web services. However new challenges such as high availability and security issues are not fully addressed. In fact, Web services are exposed to attacks that appear continuously. These issues have naturally paved the way to a new research topic that aims at providing new techniques for making Web services attack tolerant. In this paper, we present a state of the art of attack tolerance, especially for Web services. We also present our approach to address such issues through a combination of techniques leveraging in particular diversification. The paper ends with our promising results and a discussion to highlight the perspectives and research direction.
Georges Ouffoue, Fatiha Zaïdi, Ana R. Cavalli, Mounir Lallali
ICWS3
2016 Network Monitoring Using MMT: An Application Based on the User-Agent Field in HTTP Headers
abstract
Despite recent emerging development in intrusion detection or network monitoring, malicious attacks and misbehavior remain a high-risk issue within network traffic. In this paper, we present a proactive solution called MMT (Montimage1 Monitoring Tool) that allows facilitating network security and performance monitoring and operation troubleshooting. We demonstrate the improvements of MMT in comparison with other similar tools. Especially, we assess MMT to deal with a practical case-study in which we analyze the User-Agent field in HTTP headers to determine abnormal activities. Indeed, novel observations figure out the usefulness of the User-Agent field in HTTP requests as a good source to facilitate abnormal activities detection within an abundant traffic. There are eventually several researches alarming the vulnerabilities of the User-Agent field and proposing some manual solution including a combination of tools. However, existing countermeasures are rather passive and do not allow real-time detection. In the context of our research, MMT provides an automated detection of malicious traffic abusing vulnerable User-Agent field. Analyzing abnormal User-Agent strings is also useful to rapidly detect existing evil objects in the network (e.g., bots). The experimental results confirm the improvements of our implementation in comparison with other intrusion detection system (SNORT) and packet analyzing tool (TCPdump).
Vinh Hoa La, Raul A. Fuentes-Samaniego, Ana R. Cavalli
AINA3
2016 A novel monitoring solution for 6LoWPAN-based Wireless Sensor Networks
abstract
Internet of Things (IoT) has emerged these last years as one of the most attractive subjects in both the research community and the public. As a sub-domain, Wireless Sensor Networks (WSNs) have been attracting a lot of interest. However, the resource-constraint characteristics of physical objects in those networks presumably limit the design and development of security protocols. Whilst, sensor nodes usually operating in unattended and even harsh environments are prone to failures and malicious attacks. Monitoring them for attack/intrusion detection and for troubleshooting becomes thus an important issue. In this paper, we present a monitoring solution, MMT (Montimage Monitoring Tool), which enables data capture, events extraction, statistics collection, traffic analysis and reporting. The tool is applicable to 6LoWPAN-based (IPv6 over Low power Wireless Personal Area Networks) WSNs. Experiments have been performed on a real test-bed to validate and evaluate our proposition.
Vinh Hoa La, Raul A. Fuentes-Samaniego, Ana R. Cavalli
APCC3
2016 A Framework to Reduce the Cost of Monitoring and Diagnosis Using Game Theory
Rui Abreu 0001, César Andrés, Ana R. Cavalli
CRiSIS3
2016 Opportunistic media sharing for mobile networks
abstract
Nowadays there is a proliferation of smart devices used for media consumption. Usually, media contents are streamed from a Content Distribution Network (CDN), through a cellular network, which can get overloaded when there is a large number of active users per cell. At the same time the devices, i.e. smartphones, typically possess a set of wireless interfaces such as WiFi and Bluetooth that can be used to communicate with other devices in its proximity. In this work we propose a publish/subscribe, opportunistic network protocol aimed at off-load infrastructure network nodes. It contributes to optimize the cellular network usage among mobile devices and to reduce the costs and energy consumption induced by the reproduction of media that are temporally popular.
Jorge Visca, Raul A. Fuentes-Samaniego, Ana R. Cavalli, Javier Baliosian
NOMS3
2016 Improving Protocol Passive Testing through "Gedanken" Experiments with Finite State Machines
abstract
This paper is devoted to study the use of 'gedanken' experiments with Finite State Machines (FSMs) for protocol passive testing optimization. We discuss how the knowledge obtained from the state identification of an implementation under test (IUT) can be utilized for effective IUT monitoring. Differently from active testing techniques, such identification is performed by only observing the IUT behavior. If the state identification is possible (at least partially), then this fact allows to reduce the number of properties (test purposes) to be checked at certain execution point(s). Correspondingly, this allows to simplify and/or accelerate, i.e. improve the monitoring process by verifying the system behavior only at critical states against the appropriate set of properties associated with a given state. The paper discusses which 'gedanken' experiments can be considered for this purpose and how they can be derived for various specifications of communication protocols. The results presented in the paper are followed by an illustrative protocol example that demonstrates the efficiency of the proposed approach.
Natalia Kushik, Jorge López, Ana R. Cavalli, Nina Yevtushenko 0001
QRS3
2016 Effectively Testing of Timed Composite Systems using Test Case Prioritization
abstract
A composite system consists of several components which can be developed separately and deployed in distributed environments.Executing test cases on such kind of systems requires more effort due to their size and their distributed environments.A critical issue is to prioritize efficient test cases to be firstly executed.We present in this paper a framework to generate test cases and to select the efficient ones to test the composite systems with taking into account time properties.Particularly, the framework generates a set of test cases based on a model of the system, which cover a given test objective.The test cases are then prioritized in an execution order to detect quickly faults, thus reducing the efforts of test execution and increasing the effectiveness of the testing process.The framework is complemented with an open-source toolchain for automating test case generation.It has been experimentally evaluated on the European Train Control System case study.The initial results show that the approach can save 40% of test execution effort.
Huu Nghia Nguyen, Fatiha Zaïdi, Ana R. Cavalli
SEKE3
2016 Path sampling, a robust alternative to gossiping for opportunistic network routing
abstract
Opportunistic Networks have been designed for transmitting data in difficult environments, characterized by high mobility, sporadic connectivity, and constrained resources. To sustain these networks, the literature describes methods such as Epidemic and Spray&Wait, which do not learn from the network behaviour, and Gossiping-based algorithms that collect historical network data to improve efficiency. In this paper, we show that Gossiping-based solutions suffer from pathological behaviour in some simple network scenarios. Under certain conditions almost all the data transmitted by some nodes may get lost in the network, not reaching its destination. To address this problem we have proposed an algorithm that responds in a more robust manner while staying relatively simple. In this work, we show that our algorithm achieves delivery rates comparable to gossiping-based algorithms, while being more robust and providing better fairness. To illustrate this result, we test native implementations of our solution, Path Sampling, and related algorithms on a network simulator.
Jorge Visca, Javier Baliosian, Raul A. Fuentes-Samaniego, Ana R. Cavalli
WiMob4
2016 On adaptive experiments for nondeterministic finite state machines
Natalia Kushik, Khaled El-Fakih, Nina Yevtushenko 0001, Ana R. Cavalli
Int. J. Softw. Tools Technol. Transf.4
2015 An Active Testing Tool for Security Testing of Distributed Systems
abstract
This paper describes the TestGen-IF tool, that allows the automatic generation of test cases based on model based active testing techniques. This paper describes the overall functionality and architecture of the tool, discusses its strengths and weaknesses, and reports our experience with using the tool on a case study, the Dynamic Route Planning (DRP) service of Vehicular Networks. This case study demonstrates how to use our testing tool to verify the system implementation against its security requirements. This paper also proposes improvements to this tool in the form of a GUI interface to facilitate its use and an approach which permits a gain in time and efficiency by generating test objectives.
Mohamed H. E. Aouadi, Khalifa Toumi, Ana R. Cavalli
ARES3
2015 QoE Evaluation Based on QoS and QoBiz Parameters Applied to an OTT Service
abstract
In this paper, we present a framework for evaluating the QoE of a service that includes functional and non-functional service requirements. Non-functional requirements are classified into objective, subjective, and business parameters that affect Quality of Service (QoS), Quality of Experience (QoE), and Quality of Business (QoBiz), correspondingly. As those metrics have a strong dependency between each other, we discuss how the QoE of a web-based Over-The-Top service (OTT) can be evaluated taking into account subjective, objective and business parameters. The functional service behavior is described by an Extended Finite State Machine (EFSM) in which non-functional objective, subjective and business-related parameters are tracked using context variables and corresponding updating functions. These parameters are used to evaluate the QoE of the service. We show that the corresponding model allows to keep a track of a user-service interaction. Moreover, the model of the service integrates subjective, objective and business parameters, and thus, can be applied to the QoE evaluation of any OTT service.
Natalia Kushik, Camila Fuenzalida, Ana R. Cavalli, Nina Yevtushenko 0001
ICWS4
2015 An Abstraction for the Interoperability Analysis of Security Policies
Javier Baliosian, Ana R. Cavalli
NSS2
2014 QoE Estimation for Web Service Selection Using a Fuzzy-Rough Hybrid Expert System
abstract
With the proliferation of web services on the Inter-net, it has become important for service providers to select the best services for their clients in accordance to their functional and non-functional requirements. Generally, QoS parameters are used to select the most performing web services, however, these parameters do not necessarily reflect the user's satisfaction. Therefore, it is necessary to estimate the quality of web services on the basis of user satisfaction, i.e., Quality of Experience(QoE). In this paper, we propose a novel method based on a fuzzy-rough hybrid expert system for estimating QoE of web services for web service selection. It also presents how different QoS parameters impact the QoE of web services. For this, we conducted subjective tests in controlled environment with real users to correlate QoS parameters to subjective QoE. Based on this subjective test, we derive membership functions and inference rules for the fuzzy system. Membership functions are derived using a probabilistic approach and inference rules are generated using Rough Set Theory (RST). We evaluated our system in a simulated environment in MATLAB. The simulation results show that the estimated web quality from our system has a high correlation with the subjective QoE obtained from the participants in controlled tests.
Jeevan Pokhrel, Felipe Lalanne, Ana R. Cavalli, Wissam Mallouli
AINA3
2014 A Framework for Distributed Testing of Timed Composite Systems
abstract
Software systems are more and more complex. They are usually constructed by combining several components which can be implemented separately and deployed in distributed environments. This paper presents a framework for testing these kind of systems. Particularly, each component of a system is tested by a tester and there is no communication between testers. The tester is guided by local test cases that are generated from the composition of models of components where the communication among components may be synchronous or asynchronous. The framework is complemented with a tool chain for automating test generation. The paper presents also a case study on the European Train Control System.
Huu Nghia Nguyen, Fatiha Zaïdi, Ana R. Cavalli
APSEC (1)3
2014 ISER: A Platform for Security Interoperability of Multi-source Systems
Khalifa Toumi, Fabien Autrel, Ana R. Cavalli, Sammy Haddad
CRiSIS3
2014 How to Evaluate Trust Using MMT
Khalifa Toumi, Wissam Mallouli, Edgardo Montes de Oca, César Andrés, Ana R. Cavalli
NSS5
2014 Testing Network Protocols: formally, at runtime and online
Xiaoping Che, Stéphane Maag, Jorge López, Ana R. Cavalli
SEKE4
2014 Formal Verification of Coordination Systems' Requirements - A Case Study on the European Train Control System
Huu Nghia Nguyen, Ana R. Cavalli
SEKE2
2014 Evaluating Web Service QoE by Learning Logic Networks
abstract
International audience
Natalia Kushik, Nina Yevtushenko 0001, Ana R. Cavalli, Wissam Mallouli, Jeevan Pokhrel
WEBIST (1)3
2014 A Distributed and Collaborative Intrusion Detection Architecture for Wireless Mesh Networks
Anderson Morais Paiva Morais, Ana R. Cavalli
Mob. Networks Appl.2
2013 Estimation of QoE of video traffic using a fuzzy expert system
abstract
Quality of experience (QoE) in multimedia traffic has been the focus of extensive research in the last decade. The estimation of the QoE provides valuable input in order to measure the user satisfaction of a particular service. QoE estimation is challenging as it tries to measure a subjective metric where the user experience depends on a number of factors that cannot simply be measured. In this work, we present a methodology and a system based on fuzzy expert system to estimate the impact of network conditions (QoS) on the QoE of video traffic. At first, we conducted subjective tests to correlate network QoS metrics with participants' perceived QoE of video traffic. Second, we propose a No Reference method based on fuzzy expert system to estimate the network impact on the video QoE. The membership functions of the proposed fuzzy system are derived from normalized probability distributions correlating the QoS metrics with QoE. We propose a simple methodology to build the fuzzy inference rules. We evaluated our system in two different sets of experiments. The estimated video quality showed high correlation with the subjective QoE obtained from the participants in a controlled test. We integrated our system as part of a monitoring tool in an industrial IPTV test bed and compared its output with standard Video Quality Monitoring (VQM). The evaluation results show that the proposed video quality estimation method based on fuzzy expert system can effectively measure the network impact on the QoE.
Jeevan Pokhrel, Bachar Wehbi, Anderson Nunes Paiva Morais, Ana R. Cavalli, Eric Allilaire
CCNC4
2013 Monitoring Based on IOSTS for Testing Functional and Security Properties: Application to an Automotive Case Study
abstract
Monitoring for passive conformance testing is a way of checking if the system meets its requirements. Several formal approaches have been proposed these last years, but most of them only consider the control portion of the protocol neglecting the data portions, or are confronted with an overloaded amount of data values to consider. In this work, we propose a novel approach to define protocol properties in terms of Input-Output Symbolic Transition Systems (IOSTS) and show how they can be tested on real execution traces taking into account the data and control portions. These properties can be designed to test the conformance of a protocol as well as security aspects. A parametric trace slicing approach is defined to match trace and property. Besides, a prototype is here developed and experimented. Our approach is illustrated by its application to a set of real execution traces extracted from a real automotive Bluetooth framework with functional and security properties.
Pramila Mouttappa, Stéphane Maag, Ana R. Cavalli
COMPSAC3
2013 Evaluating Quality of Web Services: A Short Survey
abstract
This paper presents a short survey on the quality evaluation of web services. The most popular metrics for estimating such quality and user perception of web services are Quality of Service (QoS) and Quality of Experience (QoE), which represent objective and subjective assessments correspondingly. For different types of web services, the values of QoS and QoE are measured in different ways. In this paper, we consider various definitions of QoS based on web service parameters and describe several methods for evaluating QoS and QoE. We start with experimental evaluation of QoS based on network traffic analysis and further turn to model based methods for QoS estimating. Existing relationships between different kinds of service quality evaluation are also discussed.
Olga Kondratyeva, Natalia Kushik, Ana R. Cavalli, Nina Yevtushenko 0001
ICWS3
2013 Using passive testing based on symbolic execution and slicing techniques: Application to the validation of communication protocols
Pramila Mouttappa, Stéphane Maag, Ana R. Cavalli
Comput. Networks3
2013 ICST 2010 Special Issue
abstract
This special issue contains extended versions of three papers from the Third IEEE International Conference on Software Testing, Verification and Validation (ICST 2010). These papers were selected on the basis of the reviews from members of the programme committee and subsequently subjected to additional rounds of review and revision. We issued nine invitations to this special issue. Two were not selected after submission, one chose not to revise the paper after being reviewed, three never submitted a major revision, and three papers were eventually accepted. The first paper is ‘Covering and Uncovering Equivalent Mutants’ by Schuler and Zeller. The conference version won the best paper award at ICST 2010. This paper addresses the problem of identifying equivalent mutants. A study is performed on seven real-life programs to assess the percentage of equivalent mutants, which are found to range from 25% to 70%. An approach that uses changes in test coverage to detect nonequivalent mutants is proposed and demonstrated to be superior to state-of-the-art techniques. The approach is implemented as part of the open-source JAVALANCHE framework. The second paper is ‘Efficient Mutation Testing of Multithreaded Code’ by Gligoric, Jagannath, Luo and Marinov. This paper presents a framework for efficiently exploring thread schedules during mutation testing of multithreaded programs. Five techniques are presented and implemented in a tool called MuTMuT. Evaluation studies performed on 12 multithreaded programs show that the techniques can substantially reduce the time required for mutation testing of multithreaded code. The third paper is ‘Formal Specification and Analysis of Functional Properties of Graph Rewriting-based Model Transformation’ by Asztalos, Lengyel and Levendovszky. This paper proposes a language for formally specifying the functional properties of a model transformation. The model transformations are described in a declarative way. Automated algorithms are proposed to analyse the transformations. We express our thanks to the people who contributed to the success of ICST 2010 and this special issue. The steering committee members provided valuable advice, and we were assisted by industry chairs Paul Baker, Wolfgang Grieskamp, Dominique Potier and Andreas Ulrich; workshop chairs Paul Ammann, Benoit Baudry and Ina Schieferdecker; PhD Symposium chairs Atif Memon, Manuel Nunez and Fatiha Zaidi; and the general chair Marie-Claude Gaudel. Thanks go to all the reviewers who provided detailed and timely reviews for the ICST submissions as well as the manuscripts submitted to the special issue. We are also indebted to the ICST 2010 publicity chairs Khaled El-Fakih, Vahid Garousi, Yves Le Traon and Elaine Martins and the Web chair Stephane Maag. We thank the authors for sharing their ideas and results with us. Finally, thanks go to editors-in-chief Jeff Offutt and Robert Hierons for their support and enthusiasm. ANA CAVALLI SUDIPTO GHOSH Co-chairs, Technical Program Committee ICST 2010 10 May 2013
Ana R. Cavalli, Sudipto Ghosh 0001
Softw. Test. Verification Reliab.1
2012 A vector based model approach for defining trust in Multi-Organization Environments
abstract
A Multi-Organization Environment is composed of several players that depend on each other for resources and services. In order to manage the security of the exchange process we introduce the concept of trust. We show how this aspect of the cooperative work allows us to increase some security aspects. In particular, we provide a framework where the concepts of trust requirement and trust evaluation play important roles for defining trust vectors. These vectors evaluate a set of requirements, under some conditions, and provide a degree of confidence. In our framework we consider two different types of vectors. On the one hand a vector that relates a user to an organization and on the other hand a vector that links two organizations. Finally we show how these vectors are evaluated and shared among the different organizations, and how we combine the provided trust information in order to enhance the security.
Khalifa Toumi, César Andrés, Ana R. Cavalli, Mazen El Maarabani
CRiSIS3
2012 Testing Interoperability Security Policies
Mazen El Maarabani, César Andrés, Ana R. Cavalli
SEKE3
2012 A systematic approach to integrate common timed security rules within a TEFSM-based system specification
Amel Mammar, Wissam Mallouli, Ana R. Cavalli
Inf. Softw. Technol.3
2012 An advanced approach for modeling and detecting software vulnerabilities
Nahid Shahmehri, Amel Mammar, Edgardo Montes de Oca, David Byers, Ana R. Cavalli, Shanai Ardi, Willy Jimenez
Inf. Softw. Technol.5
2012 Tight bound on the length of distinguishing sequences for non-observable nondeterministic Finite-State Machines with a polynomial number of inputs and outputs
Iksoon Hwang, Nina Yevtushenko 0001, Ana R. Cavalli
Inf. Process. Lett.3
2012 InRob: An approach for testing interoperability and robustness of real-time embedded software
Fátima Mattiello-Francisco, Eliane Martins, Ana R. Cavalli, Edgar Toshiro Yano
J. Syst. Softw.3
2012 Applying formal methods to PCEP: an industrial case study from modeling to test generation
abstract
SUMMARY This paper presents the experimental results in applying formal methods to an industrial protocol for constraint‐based path computation, called Path Computation Element Communication Protocol (PCEP). The experiments include a number of major activities in model‐based testing from modeling to test generation. From the PCEP specification defined by IETF (Internet Engineering Task Force), the functionalities of PCEP are divided into two parts: application and protocol. The protocol part of PCEP is then described in the IF (Intermediate Format) language which is based on communicating timed automata. A number of basic requirements are identified from the PCEP specification and then described as properties in IF. Based on these properties, the validation and verification of the formal specification are carried out using the IF toolset. Test cases are generated using an automatic test generation tool, called TestGen‐IF, which uses partial state space exploration guided by test purposes. As a result, some errors and ambiguities have been found in the PCEP standard specification. Copyright © 2011 John Wiley & Sons, Ltd.
Iksoon Hwang, Ana R. Cavalli, Mounir Lallali, Dominique Verchère
Softw. Test. Verification Reliab.2
2011 Route Manipulation Attack in Wireless Mesh Networks
abstract
Wireless Mesh Network (WMN) is an emerging technology that has played an important role in the wireless communication scenario. Wireless Mesh Networks are becoming popular as a way of providing Internet access in a cost-effective, easy, and fast manner. However, due to their intrinsic characteristics such as open medium, WMNs are vulnerable to various types of attacks, which aim at disrupting their routing operations. Infected mesh nodes can generate malicious traffic, which puts the other mesh nodes at risk. In this paper, we present a routing manipulation attack against Better Approach To Mobile Ad hoc Network (BATMAN), a proactive routing protocol designed especially for WMNs. We provide a detailed analysis of the attack and demonstrate its feasibility through a virtualized network environment running BATMAN protocol instances in virtual machines. After, we present a mechanism to detect this kind of attack and identify the source of the attack.
Anderson Nunes Paiva Morais, Ana R. Cavalli
AINA2
2011 Using Testing Techniques for Vulnerability Detection in C Programs
Amel Mammar, Ana R. Cavalli, Willy Jimenez, Wissam Mallouli, Edgardo Montes de Oca
ICTSS2
2011 A model-based attack injection approach for security validation
abstract
Communication systems are inherently buggy. These flaws can lead to security breaches in applications, which a malicious user could exploit to cause security failures in the system and, under certain circumstances, to take complete control of the vulnerable system. In this paper, we introduce a novel attack injection approach based on attack modeling to perform security testing and detect potential security vulnerabilities. We use attack trees to describe the system flaws and derive corresponding attack scenarios. The attack scenarios are refined to executable scripts for testing tools that are in charge of injecting the attacks against the system. The approach is applied to the Wireless Application Protocol (WAP) currently used in low-tier mobile devices. We carried out experiments using real attacks such as Denial of Service (DoS) and Cipher Suite Rollback attacks. The experimental results show that the approach can achieve high efficiency in the role of uncovering vulnerabilities.
Anderson Nunes Paiva Morais, Ana R. Cavalli, Eliane Martins
SIN2
2010 WebMov: A Dedicated Framework for the Modelling and Testing of Web Services Composition
abstract
This paper presents a methodology and a set of tools for the modelling, validation and testing of Web service composition, conceived and developed within the French national project WebMov. This methodology includes several modelling techniques, based mainly on some variations of Timed Extended Finite State Machines (TEFSM) formalism, which provide a formal model of the BPEL description of Web services composition. These models are used as a reference for the application of different test generation and passive testing techniques for conformance and robustness checking. The whole WebMov methodology is integrated within a dedicated framework, composed by a set of tools that implement the model representation, the test generation and passive testing algorithms. This framework also permits the interaction of these tools to achieve specific modelling and testing activities in a complementary way. A case study based on a real service, a Travel Reservation Web Service, is presented as well as the results of the application of the proposed WebMov methodology and tools.
Ana R. Cavalli, Tien-Dung Cao, Wissam Mallouli, Eliane Martins, Andrey Sadovykh, Sébastien Salva, Fatiha Zaïdi
ICWS1
2010 Timed Extended Invariants for the Passive Testing of Web Services
abstract
The service-oriented approach is becoming more and more popular to integrate highly heterogeneous systems. Web services are the natural evolution of conventional middleware technologies to support Web-based and enterprise level integration. Formal testing of such Web-based technology is a key point to guarantee its reliability. In this paper, we choose a non-intrusive approach based on monitoring to propose a conformance passive testing methodology to check that a composed Web service respects its functional requirements. This methodology is based on a set of formal invariants representing properties to be tested including data and time constraints. Passive testing of an industrial system (that uses a composition of Web services) is briefly presented to demonstrate the effectiveness of the proposed approach.
Gerardo Morales, Stéphane Maag, Ana R. Cavalli, Wissam Mallouli, Edgardo Montes de Oca, Bachar Wehbi
ICWS3
2010 Testing Web Service Orchestrators in Context: A Symbolic Approach
abstract
An orchestrator in a Web Service system is a locally deployed piece of software used both to allow users to interact with the system and to communicate with remote components (Web Services) in order to fulfill a goal. We propose a symbolic model based approach to test orchestrators in the context of the systems they pilot. Our approach only takes as input a model of the orchestrator and no models of the Web Services. Besides, the testing architecture is a parameter: communications between Web Services and the orchestrator can be either simulated, or hidden or observable. When they are simulated, the orchestrator is tested in isolation and our approach comes to already defined classical model-based unit testing approaches. When the System Under Test is connected with Web Services (that is, in actual usage) it is no longer fully controlled by the tester, but tested in context In that case two situations may occur: either communications with Web Services are observable or they are hidden. Our approach copes with those cases. We give theorems relating our notion of conformance in context with regard to classical conformance of components in isolation. We present a test case generation algorithm based on symbolic execution techniques: it takes into account the status (controllable, hidden, or observable) of communication channels between the orchestrator and Web Services. The algorithm has been implemented and is illustrated on a small case study.
Jose Pablo Escobedo, Christophe Gaston, Pascale Le Gall, Ana R. Cavalli
SEFM4
2010 Transmit and Reserve (TAR): A Coordinated Channel Access for IEEE 802.11 Networks
abstract
This paper considers the medium access problem in the IEEE 802.11 standard. Although the transmission bit rates have clearly increased, some MAC related problems remain yet unsolved. The random channel contention suffers from short term unfairness and from the considerable reduction of the effective throughput due to the collision probability that increases with the number of contending nodes in the network. Our objective is to define a coordinated access mechanism that improves the effective throughput and grants a fair sharing of network resources among the different nodes. We propose Transmit And Reserve (TAR), a novel packet based coordinated channel access mechanism that combines advantages of random access and channel assignment. The idea of TAR mechanism is simple: Prior to transmitting a packet, the sender node selects in advance the backoff value for its next packet and advertises this selection within the currently transmitted packet. The neighbor nodes avoid then choosing the same backoff value as the advertised one. The simulation results showed that TAR leads to higher throughput and fairness, and lower collision rate than IEEE 802.11. TAR adapts fast to the network load and to the number of active nodes.
Bachar Wehbi, Anis Laouiti, Ana R. Cavalli
WCNC3
2010 Testing a probabilistic FSM using interval estimation
Iksoon Hwang, Ana R. Cavalli
Comput. Networks2
2010 FSM-based conformance testing methods: A survey annotated with experimental evaluation
Rita Dorofeeva, Khaled El-Fakih, Stéphane Maag, Ana R. Cavalli, Nina Yevtushenko 0001
Inf. Softw. Technol.4
2009 Analysis of the OLSR Protocol by Using Formal Passive Testing
abstract
In this paper we apply a passive testing methodology to the analysis of a non-trivial system. In our framework, so-called invariants provide us with a formal representation of the requirements of the system. In order to precisely express new properties in multi-node environments, in this paper we introduce a new kind of invariants. We apply the resulting framework to perform a complete study of a MANET routing protocol: The optimized link state routing protocol.
César Andrés, Stéphane Maag, Ana R. Cavalli, Mercedes G. Merayo, Manuel Núñez 0001
APSEC3
2009 A Formal Framework to Integrate Timed Security Rules within a TEFSM-Based System Specification
abstract
Formal methods are very useful in software industry and are becoming of paramount importance in practical engineering techniques. They involve the design and the modeling of various system aspects expressed usually through different paradigms. In this paper, we propose to combine two modeling formalisms in order to express both functional and security timed requirements of a system. First, the system behavior is specified based on its functional requirements using TEFSM (timed extended finite state machine) formalism. Second, this model is augmented by applying a set of dedicated algorithms to integrate timed security requirements specified in Nomad language. This language is well adapted to express security properties such as permissions, prohibitions and obligations with time considerations. The resulting secure model can be used for several purposes such as code generation, specification correctness proof, model checking or automatic test generation. In this paper, we applied our approach to a France Telecom(France Telecom is the main telecommunication company in France) Travel service in order to demonstrate its feasibility.
Wissam Mallouli, Amel Mammar, Ana R. Cavalli
APSEC3
2009 A Statistical Approach to Test Stochastic and Probabilistic Systems
Mercedes G. Merayo, Iksoon Hwang, Manuel Núñez 0001, Ana R. Cavalli
ICFEM4
2009 An Automated Passive Testing Approach for the IMS PoC Service
abstract
Although the adoption of the IP Multimedia Subsystem (IMS) keeps growing, IMS applications are often integrated to the system without being formally tested. In this work, we are interested in the IMS Push over Cellular (PoC) service, an OMA standard. We propose a conformance passive testing approach to check that its implementation respects the main standard requirements. This approach is based on a set of formal invariants representing the most relevant expected properties to be tested. Two testing phases are applied: the verification of the invariants against the service specification and their testing on the PoC collected execution traces.
Felipe Lalanne, Stéphane Maag, Edgardo Montes de Oca, Ana R. Cavalli, Wissam Mallouli, Arnaud Gonguet
ASE4
2008 Context Ontology for Secure Interoperability
abstract
During interoperability exchanges, organizations are jointly conducting computation and sharing tasks. However, organizations can have different security policies. To guarantee good interoperability exchanges, organizations need to share with other participants information about the services they provide. In addition, to be compliant with security requirements during interoperability, security policies have to be dynamic. One purpose of this paper is to provide this dynamic behavior by taking care about context of access parameters. The context-aware security requirements may be met by using a contextual access control model to define the security policy of each party involved in the interaction, and OrBAC (Organization based Access Control) is an adequate model for this purpose. Elaborating an ontology based security model provides a mean to ensure sharing of understandable knowledge, in particular knowledge needed to derive the authorized accesses and usages during the interoperability sessions. In this paper, we thus suggest a context ontology to be combined with an ontological representation of the OrBAC model and show how it can be used to ease the security rules definition and derivation during interoperability sessions.
Céline Coma, Nora Cuppens, Frédéric Cuppens, Ana R. Cavalli
ARES4
2008 Two Complementary Tools for the Formal Testing of Distributed Systems with Time Constraints
abstract
The complexity and the variety of the deployed time dependent systems, as well as the high degree of reliability required for their global functioning, justify the care provided to the design of the best possible tests. Moreover,it is significant to automate these steps with an aim of reducing the time and the development cost and especially of increasing the reliability of the offered products. In this paper, we present two different tools to test systems with time constraints. The first one allows to automatically generate test cases based on model-based active testing techniques. Whereas the second tool is based on passive testing approach to check that the collected system traces respect a set of formal properties called Invariants.
Ana R. Cavalli, Edgardo Montes de Oca, Wissam Mallouli, Mounir Lallali
DS-RT1
2008 Modeling System Security Rules with Time Constraints Using Timed Extended Finite State Machines
abstract
Security and reliability are of paramount importance in designing and building real-time systems because any security failure can put the public and the environment at risk. In this paper, we propose a framework to take timed security requirements into account from the design stage of the system building. Our approach consists of two main steps. First, the system behavior is specified based on its functional requirements using TEFSM (Timed Extended Finite State Machine) formalism. Second, this model is augmented by applying a set of dedicated algorithms to integrate timed security properties specified in Nomad language. Nomad is a formal language well adapted to express timed security properties with timed constraints. We also briefly present a France Telecom Travel system as a case study to demonstrate the reliability of our framework.
Wissam Mallouli, Amel Mammar, Ana R. Cavalli
DS-RT3
2008 Security Rules Specification and Analysis Based on Passive Testing
abstract
Security is a critical issue in dynamic and open distributed environments such as network-based services or wireless networks. To ensure that a certain level of security is maintained in such environments, the system behavior has to be restrained by a security policy in order to regulate the nature and the context of actions that can be performed within the system, according to specific roles. In this paper, we propose a passive testing approach that permits to check whether a system respects its security policy. To reach this goal, we specify this policy using 'Nomad' formal language which is based on deontic and temporal logics. This language is well adapted to passive testing methods that aim to analyze collected system execution traces in order to give a verdict about their conformity with to the system security requirements. Finally, we apply our methodology to an industrial case study provided by SAP group to demonstrate its reliability.
Wissam Mallouli, Fayçal Bessayah, Ana R. Cavalli, Azzedine Benameur
GLOBECOM3
2008 Efficient time synchronization mechanism for wireless multi hop networks
abstract
This paper considers the time synchronization problem in wireless multihop networks. The objective is to design a protocol that synchronizes the network nodes with respect to one reference node. A set of sender nodes forming a connected dominating set is created to guide the synchronization process in a multihop environment. Each node estimates its clock offset and frequency error parameters to build an adjustment function that transforms its local time to that of the reference node. Our protocol estimates the clock offset and the frequency error on different time scales leading to significant gain in terms of synchronization accuracy. We give the theoretical bounds on the synchronization precision and show its performance through extensive simulations.
Bachar Wehbi, Anis Laouiti, Ana R. Cavalli
PIMRC3
2008 A formal validation methodology for MANET routing protocols based on nodes' self similarity
Stéphane Maag, Cyril Grepet, Ana R. Cavalli
Comput. Commun.3
2007 Specification of Timed EFSM Fault Models in SDL
Samrat S. Batth, Elisangela Rodrigues Vieira, Ana R. Cavalli, M. Ümit Uyar
FORTE3
2007 Towards an Automated Test Generation with Delayed Transitions for Timed Systems
abstract
In this paper we analyze the influence of the urgency in the timed transitions, and as consequence, in the test suite generation. As result, we formalize rules to generate sequences where the messages exchanged may be instantaneous or delayed. In addition, the generated scenarios are able to detect timing faults. For test generation, we use a prototype tool called HJ2IF. It is based on a test purpose algorithm, called hit-or-jump and it is applied for systems specified using Intermediate Format language (IF).
Elisangela Rodrigues Vieira, Ana R. Cavalli
RTCSA2
2007 A formal approach for testing security rules
abstract
Nowadays, security policies are the key point of every modern infrastructure. The specification and the testing of such policies are the fundamental steps in the development of a secure system since any error in a set of rules is likely to harm the global security. To address both challenges, we propose a framework to specify security policies and test their implementation on a system. Our framework makes it possible to generate in an automatic manner, test sequences, in order to validate the conformance of a security policy. system behavior is specified using a formal description technique based on extended finite state machine (EFSM) [12]. The integration of security rules within the system specification is performed by specific algorithms. Then, the automatic tests generation is performed using a dedicated tool, called SIRIUS, developed in our laboratory. Finally, we briefly present a weblog system as a case study to demonstrate the reliability of our framework.
Wissam Mallouli, Jean-Marie Orset, Ana R. Cavalli, Nora Cuppens, Frédéric Cuppens
SACMAT3
2006 A Security Model for OLSR MANET Protocol
abstract
In this paper, we propose a formal security model to detect attacks on the Optimized Link State Routing protocol (OLSR). We make use of a combination of deontic and temporal logic to specify the correct behaviour of a node and also to express complex security properties such as obligations, roles and deadlines within specific contexts. We investigate different attacks targeting the link sensing mechanism of the protocol and describe security policies to prevent them. We argue that our approach allows to detect complex threats on OLSR.
Jean-Marie Orset, Ana R. Cavalli
MDM2
2006 Light Client Management Protocol for Wireless Mesh Networks
abstract
The future of wireless networks evolves toward more simple ways for users to get connected while on the move. In this perspective, Wireless Mesh Networks constitutes one of the key technologies for next generation wireless networks. In this paper we present LCMP, a new protocol for client management in wireless mesh networks. LCMP performs on-demand path setup for clients and supports clients mobility by introducing new light mechanisms that take full advantage of the mesh architecture. The work on LCMP and mesh routing is still in progress at LOMNT laboratory. In this papel; we highlight some ongoing work.
Bachar Wehbi, Wissam Mallouli, Ana R. Cavalli
MDM3
2005 An EFSM-Based Intrusion Detection System for Ad Hoc Networks
Jean-Marie Orset, Baptiste Alcalde, Ana R. Cavalli
ATVA3
2005 Experimental Evaluation of FSM-Based Testing Methods
abstract
The development of test cases is an important issue for testing software, communication protocols and other reactive systems. A number of methods are known for the development of a test suite based on a formal specification given in the form of a finite state machine. Well-known methods are called the W, Wp, UIO, UIOv, DS, H and HIS test derivation methods. These methods have been extensively used by research community in the last years; however no proper comparison has been made between them. In this paper, we experiment with these methods to assess their complexity, applicability, completeness, fault detection capability, length and derivation time of their test suites. The experiments are conducted on randomly generated specifications and on a realistic protocol called the simple connection protocol.
Rita Dorofeeva, Nina Yevtushenko 0001, Khaled El-Fakih, Ana R. Cavalli
SEFM4
2005 Secure hosts auto-configuration in mobile ad hoc networks
Ana R. Cavalli, Jean-Marie Orset
Ad Hoc Networks1
2005 A passive testing approach based on invariants: application to the WAP
Emmanuel Bayse, Ana R. Cavalli, Manuel Núñez 0001, Fatiha Zaïdi
Comput. Networks2
2004 Network Protocol System Passive Testing for Fault Management: A Backward Checking Approach
Baptiste Alcalde, Ana R. Cavalli, Dongluo Chen, Davy Khuu, David Lee 0001
FORTE2
2003 New approaches for passive testing using an Extended Finite State Machine specification
Ana R. Cavalli, Caroline Gervy, Svetlana Prokopenko
Inf. Softw. Technol.1
2003 Test suite minimization for testing in context
abstract
Abstract Testing a component embedded into a complex system, in which all other components are assumed fault‐free, is known as embedded testing. This paper proposes a method for minimizing a test suite to perform embedded testing. The minimized test suite maintains the fault coverage of the original test suite with respect to faults within the embedded component. The minimization uses the fact that the system is composed of a fault‐free context and a component under test, specified as communicating, possibly non‐deterministic finite state machines (FSMs). The method is illustrated using an example of telephone services on an intelligent network architecture. Other applications of the proposed approach for testing a system of communicating FSMs are also discussed. Copyright © 2003 John Wiley & Sons, Ltd.
Ricardo Anido, Ana R. Cavalli, Luiz Augusto de Paula Lima, Nina Yevtushenko 0001
Softw. Test. Verification Reliab.2
2002 A New Algorithm for Service Interaction Detection
Ana R. Cavalli, Stéphane Maag
ICFEM1
2001 A Service-Component Testing Method and a Suitable CORBA Architecture
abstract
This paper presents a method for service-component testing and a suitable CORBA test architecture. This test environment allows the service validation from its components and is a close step towards the execution of the obtained tests on a CORBA environment. Two aspects are relevant: the test of components and the test architecture. The testing method for components is new: it is based on the generation of partial graphs and avoids the combinatorial explosion of number of states of the global system. The test architecture on a CORBA platform is also new, since there are few works on testing based on these environments. As an application we present a case study on a real conference call service.
Ana R. Cavalli, Bruno Defude, Christian Rinderknecht, Fatiha Zaïdi
ISCC1
1999 Hit-or-Jump: An algorithm for embedded testing with applications to IN services
Ana R. Cavalli, David Lee 0001, Christian Rinderknecht, Fatiha Zaïdi
FORTE1
1999 An Automatic and Optimized Test Generation Technique Applying to TCP/IP Protocol
abstract
In this paper an automatic and optimized technique for test generation for communication protocol control and data portion is described, the goal is to minimize the number of tests with a guaranteed coverage. The test generation algorithm is applied to the client layer part of the TCP/IP protocol. The protocol used for the experiment is TCP-Reno, which is specified in the SDL language and is one of the commonly referenced implementations. For such a sophisticated protocol, the algorithm efficiently constructs 22 tests that cover all the required portions of the protocol.
Cédric Besse, Ana R. Cavalli, David Lee 0001
ASE2
1999 Advanced Topics on SDL and MSC
Ana R. Cavalli
Comput. Networks1
1999 Passive testing and application to the GSM-MAP protocol
Marine Tabourier, Ana R. Cavalli
Inf. Softw. Technol.2
1998 Application of Embedded Testing Methods to Service Validation
abstract
Conformance testing is a critical phase in the life cycle of communicating systems. However, classical testing methods are not appropriate for use in all tasks concerning the test of telecommunications services (especially regression and integration tests). This is so because Intelligent Networks, into which these services are installed are modular architectures (composed of building blocks) evolving basically by the addition of new services/features that map share the same resources (reusability). The paper investigates how embedded conformance testing methods can be applied in the context of service validation, taking into account the different testing phases in the service life cycle. In order to illustrate their application, the validation of telephone services (Basic Call Service, Originating Call Screening and Call Forward Unconditional) on an intelligent network framework is presented. It is also shown how some cases of feature interaction can be detected.
Luiz Augusto de Paula Lima, Ana R. Cavalli
ICFEM2
1996 Testing Methods for SDL Systems
Ana R. Cavalli, Byoung-Moon Chin, Kilnam Chon
Comput. Networks ISDN Syst.1
1996 Standardization of Formal Methods in Conformance Testing of Communication Protocols
Ana R. Cavalli, Jean Philippe Favreau, Marc Phalippou
Comput. Networks ISDN Syst.1
1994 A modal based verification for LOTOS
Hacène Fouchal, Ana R. Cavalli
FORTE2
1994 A Compositional Verification Method for LOTOS
abstract
No abstract available.
Hacène Fouchal, Ana R. Cavalli
PODC2
1993 Improving Conformance Testing for LOTOS
Ana R. Cavalli, Sung Un Kim, Patrick Maigron
FORTE1
1988 Exhaustive Analysis and Simulation for Distributed Systems, both Sides of the Same Coin
Ana R. Cavalli, Etienne Paul
Distributed Comput.1
1984 A Decision Method for Linear Temporal Logic
Ana R. Cavalli, Luis Fariñas del Cerro
CADE1