VLDB 2026 Research / reviewers in the wild / expert
Guillaume Doyen
dblp:56/5177
· DBLP profile ↗
39ranked-venue papers
0as first author
15since 2021 · last 2026
0000-0002-9996-0145ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 17 · 4 since 2021Security and privacy · 4 · 2 since 2021Software engineering, systems software and programming languages · 2 · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1Human-computer interaction and ubiquitous computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Deep learning-based sequential detection of attacks on low-Latency network servicesabstractThis paper addresses the problem of monitoring network traffic metrics for the detection of attacks in computer networks. More precisely, we consider attacks on emerging low-latency services, which typically require a specific traffic management system. These new services are subject to novel types of attacks, including traffic that does not respond normally to Explicit Congestion Notification (ECN) as this behaviour can prevent normal operation of the low-latency management system. Therefore, novel methods are required to detect novel types of attacks on novel types of services. We present a simple yet very efficient hybrid method that takes advantage of both autoencoder and transformer models for early detection of the unresponsive ECN attack, a novel type of attack targeting low-latency services. The original method is compared with the current state-of-the-art on a large real-life dataset of network traffic to show the relevance of the proposed approach is evident, achieving more than a 10% reduction in detection error rate, particularly at low false-positive rates, where the proposed detection method reaches over 90% true-positive detection for a false-alarm rate below 10 − 4 . The issue of quickest detection is also considered empirically and a trade-off between reliable detection and fast response is proposed on numerical evaluation. An ablation analysis shows that the efficiency of the method relies on the combination of the two methods jointly used in our hybrid model. Rémi Cogranne, Marius Letourneau, Guillaume Doyen |
J. Inf. Secur. Appl. | 3 |
| 2025 | Exploiting Congestion Control Parameter Manipulation in QUIC for Security ImplicationsabstractQUIC has emerged as a fundamental transport protocol for modern Internet infrastructure, serving as the foundation for HTTP/3. Although QUIC implements congestion control algorithms ($C C A$) to ensure fair network resource allocation, its user-space implementation architecture creates significant security vulnerabilities through accessible parameter manipulation. As transport layers become increasingly programmable, these vulnerabilities represent a broader security challenge for future network infrastructures where applications may deploy custom transport implementations. This paper presents a systematic analysis of selfish behaviors in QUIC through deliberate congestion control parameter (CCPM). Using the aioquic implementation, we experimentally demonstrate how strategic parameter manipulation in both NewReno and CUBIC algorithms provides substantial unfair bandwidth ($\boldsymbol{B} \boldsymbol{W}$) advantages. NewReno exhibits a major vulnerability with Loss Reduction Factor (LRF) and Congestion Avoidance Growth Rate (CAGR) manipulation, while CUBIC demonstrates better resilience, but remains exploitable, with combined LRF ($\beta_{\text {cubic }}$) and Maximum Idle Time (MIT) manipulations. Y A Joarder, Surajit Sinha, Guillaume Doyen, Carol J. Fung |
CNSM | 3 |
| 2025 | Towards Context-aware Intrusion Detection in Individual-oriented Information Systems: An Empirical Study on Android MalwareabstractIn recent years, the range and volume of Internet services utilized by an individual have significantly expanded. This growing relationship between an individual user and diverse digital services has led to the emergence of Individualoriented Information System (IIS) that encompasses the user, their physical devices, and the information systems they interact with. Current security approaches within an IIS suffer from three main limitations: (1) they are restricted to specific services, (2) they require intrusive instrumentation of each user single device, or (3) they rely on specific integration between client and server components. As a result, they fail to globally protect against attackers who possess enough information to bypass standalone security schemes. To overcome these constraints, we propose to (1) consider a network-oriented approach to detect intrusions which may occur within an IIS and (2) to make sensors taking part of the IIS contribute to the intrusion detection by providing user-related contextual data. In the absence of any suitable dataset that mixes network and physical contextual data, we construct a new integrated dataset comprising benign data captured through an in-situ experiment and intrusion traces extracted from CIC-AndMal2017-a widely referenced dataset in the literature. Our evaluation confirms that considering both user physical context and network features improves the performance of intrusion detection, thereby making IIS more resilient to attackers. Van-Tien Nguyen, Renzo E. Navas, Guillaume Doyen |
CNSM | 3 |
| 2025 | On the relevance of Blockchains for DDoS Mitigation: a Methodological Assessment and Performance Evaluation of Hyperledger FabricabstractThe expanding attack surface and increasing complexity of information systems render human responses insufficient against modern threats. The introduction of concepts such as self-protection and collaborative cybersecurity opens up possibilities for new defence systems tailored to today’s requirements. Distributed Denial-of-Service (DDoS) attacks, in particular, demand automated and wide-reaching responses due to their disruptive nature and broad impact across networks. Recent research is exploring blockchain-based solutions to address the fundamental challenge of trust among collaborators, as blockchain provides a secure and transparent framework for sharing threat intelligence and enforcing consensus. However, the literature did not establish the relevance of blockchain technology for collaborative DDoS mitigation before its application. The contribution of this paper is twofold. First, we methodologically analyse the relevance of blockchain technology for our use-case and determine that Hyperledger Fabric (HLF) is a promising solution. Second, we evaluate the performance impacts of HLF combined with the SmartBFT consensus algorithm for collaborative DDoS attack mitigation. Our performance analysis measured system durations ranging from 200 to 1500 ms under various network configurations, influenced by topological size (number of nodes) and geographical size (communication delays). The modeling of our results showed quadratic scaling with the number of HLF orderers and stronger, linear scaling with communication delays. These findings provide actionable insights to optimise collaborative blockchain-based DDoS mitigation solutions. Constant Rohmer, Pierre Alain, Mohamed Aymen Chalouf, Guillaume Doyen |
ICCCN | 4 |
| 2025 | Dissecting 5G New-Radio Latency: Interacting Layers and Latency-Generating Operations
Virgil Hamici-Aubert, Julien Saint-Martin, Renzo E. Navas, Georgios Z. Papadopoulos, Guillaume Doyen, Xavier Lagrange |
Networking | 5 |
| 2025 | NEAT: A Nile-English Aligned Translation corpus based on a robust methodology for Intent Based NetworkingabstractThe rise of Intent Based Networking (IBN) has paved the way for more efficient network and security management, reduced errors, and accelerated deployment times by leveraging AI processes capable of translating natural language intents into policies or configurations. Specialized neural networks could offer a promising solution at the core of translation operations. Still, they require dedicated, large-scale corpora for training generative models, which are not currently available due to the restricted and confidential nature of the information they convey. This paper fills this gap by proposing a novel methodology for creating a corpus specifically tailored to train a Large Language Model (LLM) for this translation task. Our approach leverages advancements in Natural Language Processing (NLP) to overcome the challenges posed by the limited training data, enabling accurate interpretation and translation of high-level performance and security directives from natural language into structured, actionable formats, represented by the intermediate Network Intent LanguagE (Nile). Our experimental evaluations, grounded by human experts, indicate that our corpus generation methodology yields promising results in terms of translation accuracy and language naturalness. As a result, we have been able to generate Nile-English Aligned Translations (NEAT), a corpus, which is to date two orders of magnitude larger than currently available datasets, exhibits a wide coverage of the Nile syntax, and has much lower perplexity values than other generated corpora. NEAT has been made publicly available to facilitate further research and development in adapting generative models to network management and security. Daisy Munson, Pierre Alain, Guillaume Doyen |
Comput. Networks | 3 |
| 2024 | Leveraging Overshadowing for Time-Delay Attacks in 4G/5G Cellular Networks: An Empirical AssessmentabstractEnsuring both reliable and low-latency communications over 4G or 5G Radio Access Network (RAN) is a key feature for services such as smart power grids and the metaverse. However, the lack of appropriate security mechanisms at the lower-layer protocols of the RAN–a heritage from 4G networks–opens up vulnerabilities that can be exploited to conduct stealthy Reduction-of-Quality attacks against the latency guarantees. This paper presents an empirical assessment of a proposed time-delay attack that leverages overshadowing to exploit the reliability mechanisms of the Radio Link Control (RLC) in Acknowledged Mode. By injecting falsified RLC Negative Acknowledgements, an attacker can maliciously trigger retransmissions at the victim User Equipment (UE), degrading the uplink latency of application flows. Extensive experimental evaluations on open-source and commercial off-the-shelf UEs demonstrate the attack’s effectiveness in increasing latency, network load, and buffer occupancy. The attack impact is quantified by varying the bitrate representing different applications and the number of injected negative acknowledgments controlling the attack intensity. This work studies a realistic threat against the latency quality of service in 4G/5G RANs and highlights the urgent need to revisit protocol security at the lower-RAN layers for 5G (and beyond) networks. Virgil Hamici-Aubert, Julien Saint-Martin, Renzo E. Navas, Georgios Z. Papadopoulos, Guillaume Doyen, Xavier Lagrange |
ARES | 5 |
| 2024 | How Fast Does Malware Leveraging EternalBlue Propagate? The case of WannaCry and NotPetyaabstractMalware attacks pose a critical threat to digital infrastructures particularly given their potential for widespread and fast propagation. Mitigating them involves limiting their expansion, which requires a thorough understanding of their propagation mechanisms. However, few studies have been conducted on their propagation behaviors in large-scale networks. In this paper, we present the results of an empirical study focusing on the propagation strategy of WannaCry and NotPetya, two malware instances leveraging EternalBlue, an exploit developed by the NSA and stolen by The Shadow Brokers hacker group, which has been used to implement rapid spreading in some mal-ware instances. Our experiments qualify the speed of infection, epidemic behavior, and spreading strategies in a local network of 50 VMs. We have especially measured for WannyCry that (1) nearly 20% of infections are processed in less than 50 seconds, and (2) up to 16 hosts are infected in a 100-second period. Our results provide meaningful insights on malware propagation to support the design of effective countermeasures. Do Duc Anh Nguyen, Pierre Alain, Fabien Autrel, Ahmed Bouabdallah, Jérôme François, Guillaume Doyen |
NetSoft | 6 |
| 2024 | Lightweight Security for IoT Systems leveraging Moving Target Defense and Intrusion DetectionabstractAs more and more devices have communication capabilities, our world is becoming increasingly interconnected. This paradigm is called the Internet of Things (IoT). Most IoT devices have limitations in memory, computing capacity, and energy, thus making impossible to integrate fully-fledged secured solutions into them. Intrusion Detection Systems (IDS) and Moving Target Defense (MTD) are two acknowledged cyber defense techniques that have attracted researchers’ attention but need to fit within the constraints of IoT systems. In this paper, based on our previous MTD work, we propose an innode MTD strategy exhibiting hybrid (i.e., event- and time-based) movement. We specifically explore the MTD interaction with a lightweight detection mechanism to provide reactive defense on top of the by-design proactive-time-based MTD. We implemented and evaluated our proposal in a real IoT platform exposed to a Reduction-of-Quality (RoQ) attack by measuring the roundtrip time and packet-loss rate of the system in four scenarios. Notably, we compared our proposal against a time-based-only MTD alternative, which demonstrates the promising results of our hybrid strategy. Van-Tien Nguyen, Renzo E. Navas, Guillaume Doyen |
NOMS | 3 |
| 2024 | A Fair Sharing Approach for Micro-Services Function Chains Placement in Ultra-Low Latency ServicesabstractThe evolution of Internet services, such as drone piloting or metaverse, tends toward ultra-Low Latency (LL) requirements, thus inducing new challenges in the placement of Service Function Chains (SFCs) deployed over virtualized infrastructures. On the one hand, this challenge requires novel optimization means. In particular, decomposing monolithic Network Functions (NFs) into micro-services acts as a promising approach thanks to their mutualization and highly parallelization characteristics, which makes it possible to reduce the length of the service chains and consequently their execution latency. On the other hand, since a core feature of the Internet relies on the coexistence of several types of services, fair sharing of resources between LL SFCs and Best Effort (BE) services appears as a core question to address. In this paper, we present an optimization model, which leverages the characteristics of micro-services to place and chains different types of SFCs in a common infrastructure. We first consider the case of standalone LL SFCs to demonstrate the benefits of mutualization and parallelization. Then, we consider the more complex situation of a fair cohabitation between BE and LL SFCs. This leads us to propose and compare three variants of our initial objective function, all supporting different resource sharing strategies. By confronting our model to several realistic scenarios in terms of topology and service function chains, we demonstrate (1) to what extent it improves the overall performance of SFCs by minimising the gap between expected and actual latency, and (2) it allows LL and BE SFCs to coexist without impacting the latency of the deployed LL SFCs. Hichem Magnouche, Guillaume Doyen, Caroline Prodhon |
IEEE Trans. Netw. Serv. Manag. | 2 |
| 2023 | A Lightweight Heuristic for Micro-Services Placement and Chaining in Low Latency ServicesabstractThe rise of novel Low-Latency (LL) applications, such as cloud gaming or the metaverse, imposes rigorous end-to-end LL constraints. Decomposing Virtualized Network Functions (VNFs) into micro-services has proven its effectiveness to reduce the Service Function Chaining (SFC) latency thanks to key characteristics: lighter entities, less resource consumption, and a strong capacity to operate in parallel. However, to make such a promising technology actually deployed in real operated networks, novel dedicated placement and chaining methods are required. Current solutions either do not fit with tied LL constraints or exhibit a prohibitive computation time by relying on exact resolution methods. In this paper, we propose a heuristic method dedicated to the placement and chaining of micro-services. Its purpose is to maximize the deployment of SFCs while respecting the required LL by considering intrinsic features of micro-services and integrating suitable load balancing, which makes it highly scalable. A comprehensive evaluation campaign highlights that generated solutions achieve results that are at most a factor of 1.1 to the optimal with an execution time up to 20,000 times faster. Hichem Magnouche, Guillaume Doyen, Caroline Prodhon |
CNSM | 2 |
| 2023 | A Robust Approach for the Detection and Prevention of Conflicts in I2NSF Security PoliciesabstractIn order to maintain a sufficient protection level of their infrastructure, automating security management is at the core of current operators issues. The Interface to Network Security Function (I2NSF) is a framework that takes part of the Intent-Based Networking (IBN) paradigm. It consists of automating the translation of high-level policies into low-level configurations of Network Security Functions (NSF) and appears as a promising way to overcome the complexity of this challenging task. However, if the I2NSF framework provides a comprehensive architectural and data model for such an automation, it provides neither detection nor prevention mechanisms against conflicting security requirements. In this paper, we assess to what extent state-of-the-art mechanisms can shift the initial I2NSF proposal toward a robust framework. As such, we extend (1) the reference architecture to integrate some checking components and (2) the consumer-facing data model to enforce separation constraints and partial ordering relationships. By considering a large set of rules and conflicting situations, we evaluate the performance of our solution within an early implementation of I2NSF achieved in an IETF Hackathon. Do Duc Anh Nguyen, Fabien Autrel, Ahmed Bouabdallah, Guillaume Doyen |
NOMS | 4 |
| 2023 | A Comprehensive P4-based Monitoring Framework for L4S leveraging In-band Network TelemetryabstractThe Low-Latency Low-Loss Scalable throughput (L4S) architecture has recently been proposed to reduce the network latency of low-latency services and to allow their flows to coexist with classic ones in the same domain. This coexistence implies monitoring and security challenges. However current monitoring methods, primarily based-on sampling and polling, exhibit performance and granularity limitations. This paper describes the challenges for monitoring LL services and details our solution when introducing a fine-grained and real-time monitoring capability in our P4-based L4S implementation using In-band Network Telemetry. The initial experimental evaluation shows that our solution is able to monitor the metrics of an L4S switch with very few networking and processing overhead and without disturbing the L4S behaviour. Huu Nghia Nguyen, Bertrand Mathieu, Marius Letourneau, Guillaume Doyen, Stéphane Tuffin, Edgardo Montes de Oca |
NOMS | 4 |
| 2022 | Leveraging Micro-Services for Ultra-Low Latency: An optimization Model for Service Function Chains PlacementabstractThe evolution of the Internet tends toward ever requiring lower latency services. Cloud robotics or drone piloting are service use-cases in which the latency of traffic cannot exceed a few milliseconds. Reducing the latency can be achieved through several means, and micro-services deployed over virtual infrastructures appears as a promising way by enabling service chain reductions, micro-function mutualization and parallelism. However, the placement and routing of such components appears as an harder task to achieve as compared to monolithic approaches of the state of the art. Consequently, we propose in this paper a comprehensive optimization model in charge of placing micro-services in a virtualized network infrastructure, under ultra-low latency constraints while preserving resource consumption. By challenging our model with several realistic scenarios in terms of topology and service function chains (SFC), we demonstrate to what extent it improves the overall performance of SFC by especially minimizing the gap between the expected latency and the actual one, as compared to several competitors, thus making it a well-fitted approach for ultra-low latency services. Hichem Magnouche, Guillaume Doyen, Caroline Prodhon |
NetSoft | 2 |
| 2021 | Assessing the Threats Targeting Low Latency Traffic: the Case of L4SabstractNew types of services with low-latency requirements have become a major challenge for the future Internet. Many optimizations, all targeting the latency reduction have been proposed. Among them, jointly re-architecting congestion control and active queue management has been particularly considered. In this effort, the L4S (Low Latency, Low Loss and Scalable Throughput) proposal aims at allowing both classic and low-latency traffic to cohabit within a single node architecture. Although this architecture sounds promising for latency improvement, it can be exploited by an attacker to perform malicious actions whose purposes are to defeat its low-latency feature and consequently make their supported applications unusable. In this paper, we analyze a set of weaknesses of L4S architecture and show that application-layer protocols such as QUIC can easily be hacked in order to exploit the over-sensitivity of those new services to network variations. By implementing undesirable flows in a real testbed and evaluating how they impact the proper delivery of low-latency flows, we demonstrate their reality and relevance for future deployments. Marius Letourneau, Kouame Boris N'Djore, Guillaume Doyen, Bertrand Mathieu, Rémi Cogranne, Huu Nghia Nguyen |
CNSM | 3 |
| 2019 | Towards Content-Centric Control Plane Supporting Efficient Anomaly Detection FunctionsabstractAnomaly detection remains a challenging task due to both the ever more complex functions that need to be executed and the evolution of current networking devices which induces limitation of computational resources such as the Internet of Things (IoT). Furthermore, results of anomaly function computations can be repeated gradually over time or executed in neighboring nodes, thus leading to a waste of such limited computing resources in constrained nodes. To tackle these issues, the content-centric paradigm enhanced with computing features offers a promising solution to reduce the computation resources and finally improve the scalability of anomaly detection functions. In this paper, we propose a first step toward a content-oriented control plane which enables the distribution of the processing and the sharing of results of anomaly detection functions in the network. We present the way we leverage NFN to support Bayesian Network inference to detect anomalies in network traffic. The relevance and performance of our proposed approach are demonstrated by considering the Content Poisoning Attack (CPA) through numerous experiment data. Hoang Long Mai, Guillaume Doyen, Wissam Mallouli, Edgardo Montes de Oca, Olivier Festor |
CNSM | 2 |
| 2019 | Toward Content-Oriented Orchestration: SDN and NFV as Enabling Technologies for NDN
Hoang Long Mai, Messaoud Aouadj, Guillaume Doyen, Wissam Mallouli, Edgardo Montes de Oca, Olivier Festor |
IM | 3 |
| 2019 | Reliable Detection of Interest Flooding Attack in Real Deployment of Named Data NetworkingabstractNamed data networking (NDN) is a disruptive yet promising architecture for the future Internet, in which the content diffusion mechanisms are shifted from the conventional host-centric to content-centric ones so that the data delivery can be significantly improved. After a decade of research and development, NDN and the related NDN forwarding daemon implementations are now mature enough to enable stakeholders, such as telcos, to consider them for a real deployment. Consequently, NDN and IP will likely cohabit, and the future Internet may be formed of isolated administrative domains, each deploying one of these two network paradigms. The security question of the resulting architecture naturally arises. In this paper, we consider the case of denial of service. Even though the interest flooding attack (IFA) has been largely studied and mitigated through NACK packets in pure NDN networks, we demonstrate in this paper through experimental assessments that there are still some ways to mount such an attack, and especially in the context of coupling NDN with IP, which can hardly be addressed by current solutions. Subsequently, we leverage the hypothesis testing theory to develop a generalized likelihood ratio test adapted to evolve IFA attacks. Simulations show the relevance of the proposed model for guaranteeing the prescribed probability of false alarm and highlight the trade-off between detection power and delay. Finally, we consider a real deployment scenario where NDN is coupled with IP to carry HTTP traffic. We show that the model of IFA attacks is not very accurate in practice and further develops a sequential detector to keep a high detection accuracy. By considering data from the testbed, we show the efficiency of the overall detection method. Tan N. Nguyen, Hoang Long Mai, Rémi Cogranne, Guillaume Doyen, Wissam Mallouli, Luong Nguyen, Moustapha El Aoun, Edgardo Montes de Oca, Olivier Festor |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2018 | Towards a security monitoring plane for named data networking and its application against content poisoning attackabstractNamed Data Networking (NDN) is the most mature proposal of the Information Centric Networking paradigm, a clean-slate approach for the Future Internet. Although NDN was designed to tackle security issues inherent to IP networks natively, newly introduced security attacks in its transitional phase threaten NDN's practical deployment. Therefore, a security monitoring plane for NDN is indispensable before any potential deployment of this novel architecture in an operating context by any provider. We propose an approach for the monitoring and anomaly detection in NDN nodes leveraging Bayesian Network techniques. A list of monitored metrics is introduced as a quantitative measure to feature the behavior of an NDN node. By leveraging the hypothesis testing theory, a micro detector is developed to detect whenever the metric significantly changes from its normal behavior. A Bayesian network structure that correlates alarms from micro detectors is designed based on the expert knowledge of the NDN specification and the NFD implementation. The relevance and performance of our security monitoring approach are demonstrated by considering the Content Poisoning Attack (CPA), one of the most critical attacks in NDN, through numerous experiment data collected from a real NDN deployment. Hoang Long Mai, Tan N. Nguyen, Guillaume Doyen, Rémi Cogranne, Wissam Mallouli, Edgardo Montes de Oca, Olivier Festor |
NOMS | 3 |
| 2018 | Leveraging NFV for the deployment of NDN: Application to HTTP traffic transportabstractFor a few years, Network-Function Virtualization (NFV) acts as the most promising solution for the flexible implementation and management of future network services. If most of current efforts in this area focus on IP-based Virtual Network Functions (VNF), the case of Information-Centric Networking (ICN) is interesting since it can demonstrate that NFV is a promising technology for ISP to deploy such new innovative network stacks. In this context, we propose to design and implement a NFV compliant architecture to easily deploy ICN islands. Especially, at the core of this architecture, we present an HTTP/NDN gateway, which enables our network to carry real HTTP traffic. Finally, we show early functional experimental results of an initial testbed deployment exhibiting the capability of our global infrastructure to retrieve the top- 1000 of the most popular web sites. Xavier Marchal, Moustapha El Aoun, Bertrand Mathieu, Thibault Cholez, Guillaume Doyen, Wissam Mallouli, Olivier Festor |
NOMS | 5 |
| 2018 | Detecting Botclouds at Large Scale: A Decentralized and Robust Detection Method for Multi-Tenant Virtualized EnvironmentsabstractCloud computing has gained an important role in providing high quality and cost-effective IT services by outsourcing part of their operations to dedicated cloud providers. If intrinsic security issues of this architecture have been extensively studied, it has recently been considered as a ready-to-use platform able to perform malicious activities, thus offering new targets for indirect threats. However, its large scale, the heterogeneous and dynamic nature of the activities it executes, as well as multi-tenancy and privacy-related issues, make the security operation complex. Consequently, cloud providers can hardly detect and mitigate malicious activities they unknowingly host. Leveraging the autonomic paradigm represents a promising solution to face such a complexity, but it requires efficient grounded monitoring and analysis functions to efficiently detect malicious activities hidden within the large number of legitimate ones. In this effort, this paper presents a robust and cost-effective solution to detect malicious activities in a public virtualized environment. Its contribution is twofold: 1) a scalable and robust workload estimation of the virtual host activities in a cloud and 2) a detection algorithm able to discriminate infected hosts with low malicious activities hidden within their legitimate workload and potentially scattered across several tenants. For both of these contributions, we establish their theoretical performance, which demonstrates their optimality, and we evaluate their efficiency on a dataset made of real data collected on PlanetLab. Finally, we study the scalability on a large dataset that consists of simulated data resulting from the real dataset modeling. This demonstrates to what extent the proposal exhibits an excellent sharpness and a reasonable cost, even at a very large scale. Rémi Cogranne, Guillaume Doyen, Nisrine Ghadban, Badis Hammi |
IEEE Trans. Netw. Serv. Manag. | 2 |
| 2017 | A decentralized approach for adaptive workload estimation in virtualized environmentsabstractCloud computing is gaining an important role in providing high quality IT services. However, the heterogeneous and dynamic nature of the activities it hosts makes the related management operations, serving performance or security purposes, complexes. Leveraging the autonomic paradigm, represents a promising solution but it requires efficient grounded monitoring and analysis functions which can in turn implement advanced control algorithms. In this effort, this paper presents a robust and cost effective solution to monitor and estimate the workload in a virtualized environment. It consists in a decentralized algorithm leveraging an incremental Principal Component Analysis (PCA) featuring the system activity of multi-tenants execution environments. To evaluate the relevance of our proposal in terms of both performance and cost, we consider real execution traces of more than one thousand PlanetLab containers hosted on more than forty servers belonging to more than one hundred tenants. Nisrine Ghadban, Rémi Cogranne, Guillaume Doyen |
IM | 3 |
| 2017 | Content Poisoning in Named Data Networking: Comprehensive characterization of real deploymentabstractInformation Centric Networking (ICN) is seen as a promising solution to re-conciliate the Internet usage with its core architecture. However, to be considered as a realistic alternative to IP, ICN must evolve from a pure academic proposition deployed in test environments to an operational solution in which security is assessed from the protocol design to its running implementation. Among ICN solutions, Named Data Networking (NDN), together with its reference implementation NDN Forwarding Daemon (NFD), acts as the most mature proposal but its vulnerability against the Content Poisoning Attack (CPA) is considered as a critical threat that can jeopardize this architecture. So far, existing works in that area have fallen into the pit of coupling a biased and partial phenomenon analysis with a proposed solution, hence lacking a comprehensive understanding of the attack's feasibility and impact in a real network. In this paper, we demonstrate through an experimental measurement campaign that CPA can easily and widely affect NDN. Our contribution is threefold: (1) we propose three realistic attack scenarios relying on both protocol design and implementation weaknesses; (2) we present their implementation and evaluation in a testbed based on the latest NFD version; and (3) we analyze their impact on the different ICN nodes (clients, access and core routers, content provider) composing a realistic topology. Tan N. Nguyen, Xavier Marchal, Guillaume Doyen, Thibault Cholez, Rémi Cogranne |
IM | 3 |
| 2015 | Monitoring and Securing New Functions Deployed in a Virtualized Networking EnvironmentabstractNetwork operators are currently very cautious before deploying a new network equipment. This is done only if the new networking solution is fully monitored, secured and can provide rapid revenues (short Return of Investment). For example, the NDN (Named Data Networking) solution is admitted as promising but still uncertain, thus making network operators reluctant to deploy it. Having a flexible environment would allow network operators to initiate the deployment of new network solutions at low cost and low risk. The virtualization techniques, appeared a few years ago, can help to provide such a flexible networking architecture. However, with it, emerge monitoring and security issues which should be solved. In this paper, we present our secure virtualized networking environment to deploy new functions and protocol stacks in the network, with a specific focus on the NDN use-case as one of the potential Future Internet technology. As strong requirements for a network operator, we then focus on monitoring and security components, highlighting where and how they can be deployed and used. Finally, we introduce our preliminary evaluation, with a focus on security, before presenting the test bed, involving end-users consuming real contents, that we will set up for the assessment of our approach. Bertrand Mathieu, Guillaume Doyen, Wissam Mallouli, Thomas Silverston, Olivier Bettan, François-Xavier Aguessy, Thibault Cholez, Abdelkader Lahmadi, Patrick Truong, Edgardo Montes de Oca |
ARES | 2 |
| 2015 | A collaborative approach for a source based detection of botcloudsabstractSince the last years, cloud computing is playing an important role in providing high quality of IT services. However, beyond a legitimate usage, the numerous advantages it presents are now exploited by attackers, and botnets supporting DDoS attacks are among the greatest beneficiaries of this malicious use. In this paper, we present an original approach that enables a collaborative egress detection of DDoS attacks leveraged by a botcloud. We provide an early evaluation of our approach using simulations that rely on real workload traces, showing our detection system effectiveness and low overhead, as well as its support for incremental deployment in real cloud infrastructures. Badis Hammi, Guillaume Doyen, Rida Khatoun |
IM | 2 |
| 2015 | An optimal statistical test for robust detection against interest flooding attacks in CCNabstractConfronting the changing demand of users, the current Internet is revealing its limitations. Information Centric Network (ICN) are Future Internet proposals which are based on named data objects. In order to actually replace its predecessor, ICN must be able to resist existent threats in the current Internet, especially the Denial of Service (DoS) attack. In this paper, we focus on Interest flooding - a new type of DoS attack in Content Centric Network (CCN). Several solutions for this threat have been introduced, but they do not solve the problem in a satisfying way because of some drawbacks in either their detection performance, scalability support or restricted scenario of usage. Our goal is to design a reliable, low resources-consuming detection method against Interest flooding attack in CCN. A detection scheme must be attended since a lot of resources consumed by unnecessarily continuous countermeasure can be saved by a dependable detector. Like no other detectors in proposed solutions, our detector is based on statistical hypotheses testing theory. The achieved result is a low resources-consuming detector that can be deployed globally on each CCN router. The false alarm probability of our detector can be controlled at will. Its statistical power can be theoretically established and evaluated precisely. To validate our contribution, numerical results show the relevance of the proposed approach and the sharpness of theoretical results. Tan N. Nguyen, Rémi Cogranne, Guillaume Doyen |
IM | 3 |
| 2014 | Understanding botclouds from a system perspective: A principal component analysisabstractCloud computing is gaining ground and becoming one of the fast growing segments of the IT industry. However, if its numerous advantages are mainly used to support a legitimate activity, it is now exploited for a use it was not meant for: malicious users leverage its power and fast provisioning to turn it into an attack support. Botnets supporting DDoS attacks are among the greatest beneficiaries of this malicious use since they can be setup on demand and at very large scale without requiring a long dissemination phase nor an expensive deployment costs. For cloud service providers, preventing their infrastructure from being turned into an Attack as a Service delivery model is very challenging since it requires detecting threats at the source, in a highly dynamic and heterogeneous environment. In this paper, we present the result of an experiment campaign we performed in order to understand the operational behavior of a botcloud used for a DDoS attack. The originality of our work resides in the consideration of system metrics that, while never considered for state-of-the-art botnets detection, can be leveraged in the context of a cloud to enable a source based detection. Our study considers both attacks based on TCP-flood and UDP-storm and for each of them, we provide statistical results based on a principal component analysis, that highlight the recognizable behavior of a botcloud as compared to other legitimate workloads. Badis Hammi, Guillaume Doyen, Rida Khatoun |
NOMS | 2 |
| 2013 | Toward user-classified P2P IPTV systems: A persona-based approach
Ihsan Ullah 0001, Grégory Bonnet, Guillaume Doyen, Dominique Gaïti |
IM | 3 |
| 2013 | Towards user-aware Peer-to-Peer live video streaming systems
Ihsan Ullah 0001, Guillaume Doyen, Dominique Gaïti |
IM | 2 |
| 2013 | Detection and mitigation of localized attacks in a widely deployed P2P network
Thibault Cholez, Isabelle Chrisment, Olivier Festor, Guillaume Doyen |
Peer-to-Peer Netw. Appl. | 4 |
| 2012 | An autonomous topology management framework for QoS enabled P2P video streaming systems
Ihsan Ullah 0001, Guillaume Doyen, Grégory Bonnet, Dominique Gaïti |
CNSM | 2 |
| 2012 | Decentralized documents authoring system for decentralized teamwork: matching architecture with organizational structureabstractWhile systems for collaborative distributed works focus on enhancing distributed work group productivity, little attention has been paid to their architecture. In fact, most of these systems rely on centralized ones for both user communications and data hosting. These architectures raise issues about the administrative control, maintenance and management of the central entity. In this paper, we present a new architecture based on peer-to-peer (P2P) model driven by user relationship. In our architecture, users choose the trusted co-workers they are connected with. Thus, only the most trusted users manage to obtain a high number of connections which grant them a relative authority inside the system. Frédéric Merle, Aurélien Bénel, Guillaume Doyen, Dominique Gaïti |
GROUP | 3 |
| 2012 | SAAM: A self-adaptive aggregation mechanism for autonomous management systemsabstractIn this paper, we propose a decentralized Self-Adaptive Aggregation Mechanism (SAAM) that adapts itself to the supporting network operational behavior by dynamically selecting the best aggregation approach to use. SAAM is based on (1) a fuzzy-based model that estimates the cost and performance of each aggregation scheme and (2) Multiple Attribute Decision Making (MADM) to make decisions on the best approach to use in this context. We validate SAAM by evaluating its fuzzy model and adaptation cost, and by comparing its utility to the one of existing situated and global schemes. Rafik Makhloufi, Guillaume Doyen, Grégory Bonnet, Dominique Gaïti |
NOMS | 2 |
| 2012 | A Bayesian approach for user aware peer-to-peer video streaming systems
Ihsan Ullah 0001, Guillaume Doyen, Grégory Bonnet, Dominique Gaïti |
Signal Process. Image Commun. | 2 |
| 2011 | Towards self-adaptive management frameworks: The case of aggregated information monitoring
Rafik Makhloufi, Guillaume Doyen, Grégory Bonnet, Dominique Gaïti |
CNSM | 2 |
| 2011 | Situated vs. global aggregation schemes for autonomous management systemsabstractIn the context of autonomous network management, the Autonomic Managers (AMs) need to collect management information from other elements in order to infer an overall state of the network considered by the decision making process. Two concurrent strategies are commonly used to achieve this operation. On one hand, approaches based on a situated view only gather information in a bounded neighborhood, thus providing a high reactivity to AMs for control operations. On the other hand, approaches based on a global view provide a good accuracy at the cost of a larger convergence time. Being able to choose the best approach in a given context is crucial to ensure the efficiency of an autonomous management system. Thus, in this paper, we perform an exhaustive performance analysis of these approaches by considering typical schemes of both of them, namely a one-hop and two-hops situated view against gossip- and tree-based global aggregation schemes. Metrics we consider are the convergence time, communication and computation cost, scalability and the accuracy of estimated aggregates. Given them, we show under which conditions an approach outperforms the others. Rafik Makhloufi, Guillaume Doyen, Grégory Bonnet, Dominique Gaïti |
Integrated Network Management | 2 |
| 2011 | User behavior anticipation in P2P live video streaming systems through a Bayesian networkabstractIn recent years, Peer-to-Peer (P2P) architectures have emerged as a scalable, low cost and easily deployable solution for live video streaming applications. In these systems, the load of video transmission is distributed over end-hosts by enabling them to relay the content to each other. Since end-hosts are controlled by users, their behavior directly impact the performance of the system. To understand it, massive measurement campaigns covering large-scale systems and long time periods have been performed. In this paper, we gathered and synthesized results obtained through these measurements and propose a Bayesian network that captures and integrates all of them into a synthetic model. We apply this model to the anticipation of peer departures which is an important challenge toward the performance improvement of these systems and especially churn resilience. The validation of our proposal is performed through intensive simulations that consider a streaming system composed of thousand users over two hundred days. We especially study two deployment scenarios: a system-scale one and a local one. We also compare our proposal with two standard estimators and we show under which conditions an estimator outperforms the others. Ihsan Ullah 0001, Guillaume Doyen, Grégory Bonnet, Dominique Gaïti |
Integrated Network Management | 2 |
| 2011 | Content pollution quantification in large P2P networks : A measurement study on KADabstractContent pollution is one of the major issues affecting P2P file sharing networks. However, since early studies on FastTrack and Overnet, no recent investigation has reported its impact on current P2P networks. In this paper, we present a method and the supporting architecture to quantify the pollution of contents in the KAD network. We first collect information on many popular files shared in this network. Then, we propose a new way to detect content pollution by analyzing all filenames linked to a content with a metric based on the Tversky index and which gives very low error rates. By analyzing a large number of popular files, we show that 2/3 of the contents are polluted, one part by index poisoning but the majority by a new, more dangerous, form of pollution that we call index falsification. Guillaume Montassier, Thibault Cholez, Guillaume Doyen, Rida Khatoun, Isabelle Chrisment, Olivier Festor |
Peer-to-Peer Computing | 3 |
| 2003 | An SMIng-centric Proxy Agent for Integrated Monitoring and Provisioning
Emmanuel Nataf, Olivier Festor, Guillaume Doyen |
Integrated Network Management | 3 |