VLDB 2026 Research / reviewers in the wild / expert
Philippe Massonet
dblp:89/1060
· DBLP profile ↗
24ranked-venue papers
4as first author
3since 2021 · last 2026
0000-0003-1883-4188ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 8 · 1 first-author · 2 since 2021Artificial intelligence and machine learning · 4 · 1 first-authorSystems, architecture and hardware · 4 · 1 since 2021Security and privacy · 3 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 1 first-authorComputer networks · 1 · 1 first-authorDatabases, data management, data science and information retrieval · 1Theory of computation · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Multi-Partner Project: dAIEDGE - A Network of Excellence for Distributed, Trustworthy, Efficient and Scalable AI at the EdgeabstractThe dAIEDGE Network of Excellence (NoE) seeks to strengthen and support the development of a dynamic European cutting-edge Artificial intelligence (AI) ecosystem under the umbrella of the European Lighthouse for AI, and to sustain the development of advanced AI. dAIEDGE fosters the exchange of ideas, concepts, and trends on cutting-edge next generation AI, creating links between ecosystem actors to help both the European Commission (EC) and the European Union (EU) and the peripheral AI constituency identify strategies for future developments in Europe. Our main objective is to advance Europe’s innovation and technology base by developing a comprehensive policy and governance approach to AI in order for the EU to become a world leader in innovation in the data economy and its applications. Alain Pagani, Haralampos-G. D. Stratigopoulos, Aysajan Abidin, Mhd Rashed Al Koutayni, Luca Benini, Angelos Bilas, Alessandro Capotondi, Roberto Cavicchioli, Brian Clerkin, Oscar Déniz-Suárez, Margaux Divernois, Baptiste Dupertuis, Dorvan Favre, Giulio Gambardella, Ander García Gangoiti, Carlo Augusto Grazia, Dominik Günzel, Jude Haris, Klodjan K. Hidri, Maïck Huguenin-Vuillemin, Manal Jammal, Paul Kling, Christos Kozanitis, Xavier Lessage, Srikanth Mandapati, Philippe Massonet, Alfio Di Mauro, Varesh Mishra, Juan Odriozola, Javier Parra 0001, Nuria Pazos, Viviane Potocnik, Miguel de Prado, Rohit Prasad, Spyridon Raptis, Gregoire Rebstein, Ignacio Sanudo Olmedo, Mohamed Selim, Chinmay Satish Shrivastav, Noelia Vállez, Giorgos Vasiliadis, Micaela Verrucchi, Enrico Vincenzi, Damian Vizár, Devendra Vyas, Stefan Wiehle |
DATE | 27 |
| 2022 | Survey and Guidelines about Learning Cyber Security Risk Assessment
Christophe Ponsard, Philippe Massonet |
ICISSP | 2 |
| 2021 | A goal-driven approach for the joint deployment of safety and security standards for operators of essential servicesabstractSummary Designing safety‐critical software in domains ensuring essential services like transportation, energy, or health requires high assurance techniques and compliance with domain specific standards. As a result of the global interconnectivity and the evolution toward cyber‐physical systems, the increasing exposure to cyber threats calls for the adoption of cyber security standards and frameworks. Although safety and security have different cultures, both fields share similar concepts and tools and are worth being investigated together. This paper provides the background to understand emerging co‐engineering approaches. It advocates for the use of a model‐based approach to provide a sound risk‐oriented process and to capture rationales interconnecting top‐level standards/directives to concrete safety/security measures. We show the benefits of adopting goal‐oriented analysis that can be transposed later to domain‐specific frameworks. Both qualitative and quantitative reasoning aspects are analyzed and discussed, especially to support trade‐off analysis. Our work is driven by a representative case study in drinking water utility in the scope of the NIS regulation for operator of essential services. Christophe Ponsard, Jeremy Grandclaudon, Philippe Massonet |
J. Softw. Evol. Process. | 3 |
| 2018 | Reprint of "Towards a security-enhanced PaaS platform for multi-cloud applications"
Kyriakos Kritikos, Tom Kirkham, Bartosz Kryza, Philippe Massonet |
Future Gener. Comput. Syst. | 4 |
| 2017 | Network Monitoring in Federated Cloud EnvironmentabstractWith a growing number of infrastructure cloud services becoming available there are many benefits to interconnecting several cloud services. However, seamless cloud interoperability is the complex issue, especially when different cloud platforms are interconnected. One of the major aspects of federating clouds resources is network federation. Federated networks must deal not only with heterogeneous cloud platforms, but also with different virtualization technologies and the added complexity of multi-layer virtualization. In order to allow monitoring and analysis of the complex heterogeneous environment, there is a need to present a user with the full aggregated view of the federated network including cloud interconnect and with the match between different layers and platforms. In this paper we present a framework that uses Skydive tool for network monitoring and analysis in BEACON federated network environment. Anna Levin, Konstantin Dorfman, Dean H. Lorenz, Sylvain Afchain, Philippe Massonet |
SMARTCOMP | 5 |
| 2017 | End-To-End Security Architecture for Federated Cloud and IoT NetworksabstractSmart Internet of Things (IoT) applications will rely on advanced IoT platforms that not only provide access to IoT sensors and actuators, but also provide access to cloud services and data analytics. Future IoT platforms should thus provide connectivity and intelligence. One approach to connecting IoT devices, IoT networks to cloud networks and services is to use network federation mechanisms over the internet to create network slices across heterogeneous platforms. Network slices also need to be protected from potential external and internal threats. In this paper we describe an approach for enforcing global security policies in the federated cloud and IoT networks. Our approach allows a global security to be defined in the form of a single service manifest and enforced across all federation network segments. It relies on network function virtualisation (NFV) and service function chaining (SFC) to enforce the security policy. The approach is illustrated with two case studies: one for a user that wishes to securely access IoT devices and another in which an IoT infrastructure administrator wishes to securely access some remote cloud and data analytics services. Philippe Massonet, Laurent Deru, Amel Achour, Sébastien Dupont, Anna Levin, Massimo Villari |
SMARTCOMP | 1 |
| 2017 | Deployment-Time Multi-Cloud Application SecurityabstractThe Internet is an open networked system containing much inherent vulnerability, especially around the implementation and management of the services that run there. Application owners and service providers require automated deployment time security in order to protect the services that will be exposed to public and private networks. At the moment, manual intervention is required causing a period of vulnerability to these exposed services. The topic of the paper is how better to address this vulnerable period with automated solutions. We want cloud deployments to be secure from cyber attack as quickly as possible during the transition from deployment to a runtime environment without the need for manual intervention. Commonly, current practice involves making services live and undertaken reactive security measures manually, resulting in costly cyber security breaches. There is an identifiable cyber security issue highlighting the lack of deployment time security automation. The problem is addressed, solvable and we suggest a potential solution. A solution is proposed and claimed as the most effective approach in comparison to other options. This entails implementing all required security measures to an application and its container in an automated way at the point of deployment. The contribution of the paper therefore is to identify how today's cyber threats are potentially serious in particular to newly deployed applications in a cloud space. Subsequently, an elegant solution is put forward involving automated techniques to protect an application both inside and outside the application container. The solution consists of a vulnerability assessment of the system containing the application, the creation of an automatic firewall perimeter and automatically patching applications against vulnerabilities. This is an approach based on prevention rather than detection. Craig Sheridan, Philippe Massonet, Andrew Phee |
SMARTCOMP | 2 |
| 2017 | Towards a security-enhanced PaaS platform for multi-cloud applications
Kyriakos Kritikos, Tom Kirkham, Bartosz Kryza, Philippe Massonet |
Future Gener. Comput. Syst. | 4 |
| 2016 | A Discrete Event Simulation Approach for Quantifying Risks in Manufacturing ProcessesabstractS.313-322 Renaud De Landtsheer, Gustavo Ospina, Philippe Massonet, Christophe Ponsard, Stephan Printz, Lasse Härtel, Johann Philipp von Cube |
ICORES | 3 |
| 2016 | An architecture for securing federated cloud networks with Service Function ChainingabstractCapacity, availability or resilience of clouds can be increased by interconnecting two or more cloud computing environments to form a cloud federation and share resources. Shared resources include compute and storage resources but also networking resources. By integrating software defined networks/ virtual networks (SDN), network function virtualization (NFV) and network function chaining (SFC) technologies into cloud management platforms it is possible to create more advanced and flexible cloud federation mechanisms. In this paper we show how to secure federated cloud networks and how to customise the security of each individual federated cloud network running in a cloud federation. We propose an architecture for securing federated cloud networks by enforcing a global security policy to all network segments of a federation, and local security policies on each network of the federation. Cloud stakeholders can specify the required security virtual network functions (VNF), how to configure them, and how to chain them in a service manifest. The proposed architecture is illustrated with a deep packet inspection case study. Future work on implementing the proposed architecture in an OpenStack federation is briefly discussed. Philippe Massonet, Sébastien Dupont, Arnaud Michot, Anna Levin, Massimo Villari |
ISCC | 1 |
| 2016 | Enforcement of global security policies in federated cloud networks with virtual network functionsabstractFederated cloud networks are formed by federating virtual network segments from different clouds, e.g. in a hybrid cloud, into a single federated network. Such networks should be protected with a global federated cloud network security policy. The availability of network function virtualisation and service function chaining in cloud platforms offers an opportunity for implementing and enforcing global federated cloud network security policies. In this paper we describe an approach for enforcing global security policies in federated cloud networks. The approach relies on a service manifest that specifies the global network security policy. From this manifest configurations of the security functions for the different clouds of the federation are generated. This enables automated deployment and configuration of network security functions across the different clouds. The approach is illustrated with a case study where communications between trusted and untrusted clouds, e.g. public clouds, are encrypted. The paper discusses future work on implementing this architecture for the OpenStack cloud platform with the service function chaining API. Philippe Massonet, Sébastien Dupont, Arnaud Michot, Anna Levin, Massimo Villari |
NCA | 1 |
| 2016 | A Survey on Risk-management and Tooling Support for Procurement Processes in Supply ChainsabstractS.327-332 Stephan Printz, Johann Philipp von Cube, Christophe Ponsard, Renaud De Landtsheer, Gustavo Ospina, Philippe Massonet, Robert H. Schmitt, Sabina Jeschke |
SIMULTECH | 6 |
| 2014 | A Formal Model for Forensic Storage Media Preparation ToolsabstractThis paper defines a model of a special type of digital forensics tools, known as digital media preparation forensic tools, using the formal refinement language Event-B. The complexity and criticality of many types of computer and Cyber crime nowadays combined with improper or incorrect use of digital forensic tools calls for the evidence produced by such tools to be able to meet the minimum admissibility standards the legal system requires, in general implying that it must be generated from reliable and robust tools. Despite the fact that some research and effort has been spent on the validation of digital media preparation forensic tools by means of testing (e.g. within NIST), the verification of such tools and the formal specification of their expected behaviour remains largely under-researched. The goal of this work is to provide a formal specification against which the implementations of such tools can be analysed and tested in the future. Benjamin Aziz, Philippe Massonet, Christophe Ponsard |
SECRYPT | 2 |
| 2012 | A Linked Data Approach for Querying Heterogeneous Sources - Assisting Researchers in Finding Answers to Complex Clinical Questions
Nikolaos Matskanis, Vassiliki Andronikou, Philippe Massonet, Konstantinos Mourtzoukos, Joseph Roumier |
KEOD | 3 |
| 2010 | Special section: Security, trust and privacy in Grid systems
Álvaro Enrique Arenas, Philippe Massonet |
Future Gener. Comput. Syst. | 2 |
| 2008 | Model Based Development of Quality-Aware Software ServicesabstractModelling languages and development frameworks give support for functional and structural description of software architectures. But quality-aware applications require languages which allow expressing QoS as a first-class concept during architecture design and service composition, and to extend existing tools and infrastructures adding support for modelling, evaluating, managing and monitoring QoS aspects. In addition to its functional behaviour and internal structure, the developer of each service must consider the fulfilment of its quality requirements. If the service is flexible, the output quality depends both on input quality and available resources (e.g., amounts of CPU execution time and memory). From the software engineering point of view, modelling of quality-aware requirements and architectures require modelling support for the description of quality concepts, support for the analysis of quality properties (e.g. model checking and consistencies of quality constraints, assembly of quality), tool support for the transition from quality requirements to quality-aware architectures, and from quality-aware architecture to service run-time infrastructures. Quality management in run-time service infrastructures must give support for handling quality concepts dynamically. QoS-aware modeling frameworks and QoS-aware runtime management infrastructures require a common evolution to get their integration. Miguel A. de Miguel, Philippe Massonet, Juan Pedro Silva, Javier Fernández Briones |
ISORC | 2 |
| 2007 | Early verification and validation of mission critical systems
Christophe Ponsard, Philippe Massonet, Jean-François Molderez, André Rifaut, Axel van Lamsweerde, Hung Tran Van |
Formal Methods Syst. Des. | 2 |
| 2006 | Security Requirements Model for Grid Data Management Systems
Syed Naqvi, Philippe Massonet, Álvaro Enrique Arenas |
CRITIS | 2 |
| 2004 | Goal-Oriented Requirements Animation
Hung Tran Van, Axel van Lamsweerde, Philippe Massonet, Christophe Ponsard |
RE | 3 |
| 2003 | FAUST: Formal Analysis Using Specification ToolsabstractDeveloping high quality requirements specifications is a necessity for a number of critical industrial systems. An integrated toolset, called FAUST, is proposed to assist in the production of such specifications based on the KAOS goal-driven methodology. The tool suite is designed to naturally extend the existing semiformal modeling framework and to allow formalizing only the relevant critical parts. Two tools from the toolset are presented. The requirements checker performs KAOS goal-level checks using existing model checking technology. The requirements animator produces domain-level animations hiding formality even further. André Rifaut, Philippe Massonet, Jean-François Molderez, Christophe Ponsard, Pierre Stadnik, Axel van Lamsweerde, Hung Tran Van |
RE | 2 |
| 1997 | GRAIL/KAOS: An Environment for Goal-Driven Requirements EngineeringabstractNo abstract available. Robert Darimont, Emmanuelle Delor, Philippe Massonet, Axel van Lamsweerde |
ICSE | 3 |
| 1997 | GRAIL/KAOS: An Environment for Goal-Driven Requirements Analysis, Integration and LayoutabstractThe KAOS methodology provides a language, a method, and meta-level knowledge for goal-driven requirements elaboration. The language provides a rich ontology for capturing requirements in terms of goals, constraints, objects, actions, agents etc. Links between requirements are represented its well to capture refinements, conflicts, operationalizations, responsibility assignments, etc. The KAOS specification language is a multi-paradigm language with a two-level structure: an outer semantic net layer for declaring concepts, their attributes and links to other concepts, and an inner formal assertion layer for formally defining the concept. The latter combines a real-time temporal logic for the specification of goals, constraints, and objects, and standard pre-/postconditions for the specification of actions and their strengthening to ensure the constraints. Robert Darimont, Emmanuelle Delor, Philippe Massonet, Axel van Lamsweerde |
RE | 3 |
| 1997 | Analogical Reuse of Requirements FrameworksabstractReusing similar requirements fragments is one of the most promising ways to reduce the elaboration time and increase the requirements' quality. This paper investigates the application of analogical reasoning techniques to complete partial requirement specifications. A case base is assumed to be available; it contains requirements frameworks involving goals, constraints, objects, actions and agents from systems which have already been specified. We show how a rich requirements meta-model, coupled with an expressive formal assertion language, may increase the effectiveness of analogical reuse. An acquisition problem is first specified by a requirements engineer as a query formulated in the vocabulary of the specification fragments built so far. Source cases and partial mappings are found by query generalization followed by a search through the case base. Once analogies have been confirmed, mappings are completed by the use of relevance rules that distinguish, in the formal assertions, what is relevant to the analogy from what is irrelevant. The best analogies are then selected and extended in such a way that the logical properties of the answers to the query may be verified, thus increasing confidence in the analogy. The approach is illustrated by analogical acquisition of specifications of a meeting scheduler in the KAOS goal-oriented specification language. Philippe Massonet, Axel van Lamsweerde |
RE | 1 |
| 1995 | Goal-directed elaboration of requirements for a meeting scheduler: problems and lessons learntabstractRecently a number of requirements engineering languages and methods have flourished that not only address 'what' questions but also 'why', 'who' and 'when' questions. The objective of the paper is twofold: to assess the strengths and weaknesses of one of these methodologies on a nontrivial benchmark; and to illustrate and discuss a number of challenging issues that need to be addressed for such methodologies to become effective in supporting real, complex requirements engineering tasks. The problem considered here is that of a distributed meeting scheduler system; the methodology considered is the KAOS goal directed language and method. The issues raised from this case study include goal identification, the "deidelization" of unachievable goals, the handling of interfering goals, the impact of early formal reasoning, the merits of early reuse of abstract descriptions and categories, requirements traceability and the need to link requirements to retractable assumptions, and the potential benefits of hybrid acquisition strategies. Axel van Lamsweerde, Robert Darimont, Philippe Massonet |
RE | 3 |