Philippe Massonet

dblp:89/1060 · DBLP profile ↗
← Back
24ranked-venue papers
4as first author
3since 2021 · last 2026
0000-0003-1883-4188ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 8 · 1 first-author · 2 since 2021Artificial intelligence and machine learning · 4 · 1 first-authorSystems, architecture and hardware · 4 · 1 since 2021Security and privacy · 3 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 1 first-authorComputer networks · 1 · 1 first-authorDatabases, data management, data science and information retrieval · 1Theory of computation · 1
YearPublicationVenuePosition
2026 Multi-Partner Project: dAIEDGE - A Network of Excellence for Distributed, Trustworthy, Efficient and Scalable AI at the Edge
abstract
The dAIEDGE Network of Excellence (NoE) seeks to strengthen and support the development of a dynamic European cutting-edge Artificial intelligence (AI) ecosystem under the umbrella of the European Lighthouse for AI, and to sustain the development of advanced AI. dAIEDGE fosters the exchange of ideas, concepts, and trends on cutting-edge next generation AI, creating links between ecosystem actors to help both the European Commission (EC) and the European Union (EU) and the peripheral AI constituency identify strategies for future developments in Europe. Our main objective is to advance Europe’s innovation and technology base by developing a comprehensive policy and governance approach to AI in order for the EU to become a world leader in innovation in the data economy and its applications.
Alain Pagani, Haralampos-G. D. Stratigopoulos, Aysajan Abidin, Mhd Rashed Al Koutayni, Luca Benini, Angelos Bilas, Alessandro Capotondi, Roberto Cavicchioli, Brian Clerkin, Oscar Déniz-Suárez, Margaux Divernois, Baptiste Dupertuis, Dorvan Favre, Giulio Gambardella, Ander García Gangoiti, Carlo Augusto Grazia, Dominik Günzel, Jude Haris, Klodjan K. Hidri, Maïck Huguenin-Vuillemin, Manal Jammal, Paul Kling, Christos Kozanitis, Xavier Lessage, Srikanth Mandapati, Philippe Massonet, Alfio Di Mauro, Varesh Mishra, Juan Odriozola, Javier Parra 0001, Nuria Pazos, Viviane Potocnik, Miguel de Prado, Rohit Prasad, Spyridon Raptis, Gregoire Rebstein, Ignacio Sanudo Olmedo, Mohamed Selim, Chinmay Satish Shrivastav, Noelia Vállez, Giorgos Vasiliadis, Micaela Verrucchi, Enrico Vincenzi, Damian Vizár, Devendra Vyas, Stefan Wiehle
DATE27
2022 Survey and Guidelines about Learning Cyber Security Risk Assessment
Christophe Ponsard, Philippe Massonet
ICISSP2
2021 A goal-driven approach for the joint deployment of safety and security standards for operators of essential services
abstract
Summary Designing safety‐critical software in domains ensuring essential services like transportation, energy, or health requires high assurance techniques and compliance with domain specific standards. As a result of the global interconnectivity and the evolution toward cyber‐physical systems, the increasing exposure to cyber threats calls for the adoption of cyber security standards and frameworks. Although safety and security have different cultures, both fields share similar concepts and tools and are worth being investigated together. This paper provides the background to understand emerging co‐engineering approaches. It advocates for the use of a model‐based approach to provide a sound risk‐oriented process and to capture rationales interconnecting top‐level standards/directives to concrete safety/security measures. We show the benefits of adopting goal‐oriented analysis that can be transposed later to domain‐specific frameworks. Both qualitative and quantitative reasoning aspects are analyzed and discussed, especially to support trade‐off analysis. Our work is driven by a representative case study in drinking water utility in the scope of the NIS regulation for operator of essential services.
Christophe Ponsard, Jeremy Grandclaudon, Philippe Massonet
J. Softw. Evol. Process.3
2018 Reprint of "Towards a security-enhanced PaaS platform for multi-cloud applications"
Kyriakos Kritikos, Tom Kirkham, Bartosz Kryza, Philippe Massonet
Future Gener. Comput. Syst.4
2017 Network Monitoring in Federated Cloud Environment
abstract
With a growing number of infrastructure cloud services becoming available there are many benefits to interconnecting several cloud services. However, seamless cloud interoperability is the complex issue, especially when different cloud platforms are interconnected. One of the major aspects of federating clouds resources is network federation. Federated networks must deal not only with heterogeneous cloud platforms, but also with different virtualization technologies and the added complexity of multi-layer virtualization. In order to allow monitoring and analysis of the complex heterogeneous environment, there is a need to present a user with the full aggregated view of the federated network including cloud interconnect and with the match between different layers and platforms. In this paper we present a framework that uses Skydive tool for network monitoring and analysis in BEACON federated network environment.
Anna Levin, Konstantin Dorfman, Dean H. Lorenz, Sylvain Afchain, Philippe Massonet
SMARTCOMP5
2017 End-To-End Security Architecture for Federated Cloud and IoT Networks
abstract
Smart Internet of Things (IoT) applications will rely on advanced IoT platforms that not only provide access to IoT sensors and actuators, but also provide access to cloud services and data analytics. Future IoT platforms should thus provide connectivity and intelligence. One approach to connecting IoT devices, IoT networks to cloud networks and services is to use network federation mechanisms over the internet to create network slices across heterogeneous platforms. Network slices also need to be protected from potential external and internal threats. In this paper we describe an approach for enforcing global security policies in the federated cloud and IoT networks. Our approach allows a global security to be defined in the form of a single service manifest and enforced across all federation network segments. It relies on network function virtualisation (NFV) and service function chaining (SFC) to enforce the security policy. The approach is illustrated with two case studies: one for a user that wishes to securely access IoT devices and another in which an IoT infrastructure administrator wishes to securely access some remote cloud and data analytics services.
Philippe Massonet, Laurent Deru, Amel Achour, Sébastien Dupont, Anna Levin, Massimo Villari
SMARTCOMP1
2017 Deployment-Time Multi-Cloud Application Security
abstract
The Internet is an open networked system containing much inherent vulnerability, especially around the implementation and management of the services that run there. Application owners and service providers require automated deployment time security in order to protect the services that will be exposed to public and private networks. At the moment, manual intervention is required causing a period of vulnerability to these exposed services. The topic of the paper is how better to address this vulnerable period with automated solutions. We want cloud deployments to be secure from cyber attack as quickly as possible during the transition from deployment to a runtime environment without the need for manual intervention. Commonly, current practice involves making services live and undertaken reactive security measures manually, resulting in costly cyber security breaches. There is an identifiable cyber security issue highlighting the lack of deployment time security automation. The problem is addressed, solvable and we suggest a potential solution. A solution is proposed and claimed as the most effective approach in comparison to other options. This entails implementing all required security measures to an application and its container in an automated way at the point of deployment. The contribution of the paper therefore is to identify how today's cyber threats are potentially serious in particular to newly deployed applications in a cloud space. Subsequently, an elegant solution is put forward involving automated techniques to protect an application both inside and outside the application container. The solution consists of a vulnerability assessment of the system containing the application, the creation of an automatic firewall perimeter and automatically patching applications against vulnerabilities. This is an approach based on prevention rather than detection.
Craig Sheridan, Philippe Massonet, Andrew Phee
SMARTCOMP2
2017 Towards a security-enhanced PaaS platform for multi-cloud applications
Kyriakos Kritikos, Tom Kirkham, Bartosz Kryza, Philippe Massonet
Future Gener. Comput. Syst.4
2016 A Discrete Event Simulation Approach for Quantifying Risks in Manufacturing Processes
abstract
S.313-322
Renaud De Landtsheer, Gustavo Ospina, Philippe Massonet, Christophe Ponsard, Stephan Printz, Lasse Härtel, Johann Philipp von Cube
ICORES3
2016 An architecture for securing federated cloud networks with Service Function Chaining
abstract
Capacity, availability or resilience of clouds can be increased by interconnecting two or more cloud computing environments to form a cloud federation and share resources. Shared resources include compute and storage resources but also networking resources. By integrating software defined networks/ virtual networks (SDN), network function virtualization (NFV) and network function chaining (SFC) technologies into cloud management platforms it is possible to create more advanced and flexible cloud federation mechanisms. In this paper we show how to secure federated cloud networks and how to customise the security of each individual federated cloud network running in a cloud federation. We propose an architecture for securing federated cloud networks by enforcing a global security policy to all network segments of a federation, and local security policies on each network of the federation. Cloud stakeholders can specify the required security virtual network functions (VNF), how to configure them, and how to chain them in a service manifest. The proposed architecture is illustrated with a deep packet inspection case study. Future work on implementing the proposed architecture in an OpenStack federation is briefly discussed.
Philippe Massonet, Sébastien Dupont, Arnaud Michot, Anna Levin, Massimo Villari
ISCC1
2016 Enforcement of global security policies in federated cloud networks with virtual network functions
abstract
Federated cloud networks are formed by federating virtual network segments from different clouds, e.g. in a hybrid cloud, into a single federated network. Such networks should be protected with a global federated cloud network security policy. The availability of network function virtualisation and service function chaining in cloud platforms offers an opportunity for implementing and enforcing global federated cloud network security policies. In this paper we describe an approach for enforcing global security policies in federated cloud networks. The approach relies on a service manifest that specifies the global network security policy. From this manifest configurations of the security functions for the different clouds of the federation are generated. This enables automated deployment and configuration of network security functions across the different clouds. The approach is illustrated with a case study where communications between trusted and untrusted clouds, e.g. public clouds, are encrypted. The paper discusses future work on implementing this architecture for the OpenStack cloud platform with the service function chaining API.
Philippe Massonet, Sébastien Dupont, Arnaud Michot, Anna Levin, Massimo Villari
NCA1
2016 A Survey on Risk-management and Tooling Support for Procurement Processes in Supply Chains
abstract
S.327-332
Stephan Printz, Johann Philipp von Cube, Christophe Ponsard, Renaud De Landtsheer, Gustavo Ospina, Philippe Massonet, Robert H. Schmitt, Sabina Jeschke
SIMULTECH6
2014 A Formal Model for Forensic Storage Media Preparation Tools
abstract
This paper defines a model of a special type of digital forensics tools, known as digital media preparation forensic tools, using the formal refinement language Event-B. The complexity and criticality of many types of computer and Cyber crime nowadays combined with improper or incorrect use of digital forensic tools calls for the evidence produced by such tools to be able to meet the minimum admissibility standards the legal system requires, in general implying that it must be generated from reliable and robust tools. Despite the fact that some research and effort has been spent on the validation of digital media preparation forensic tools by means of testing (e.g. within NIST), the verification of such tools and the formal specification of their expected behaviour remains largely under-researched. The goal of this work is to provide a formal specification against which the implementations of such tools can be analysed and tested in the future.
Benjamin Aziz, Philippe Massonet, Christophe Ponsard
SECRYPT2
2012 A Linked Data Approach for Querying Heterogeneous Sources - Assisting Researchers in Finding Answers to Complex Clinical Questions
Nikolaos Matskanis, Vassiliki Andronikou, Philippe Massonet, Konstantinos Mourtzoukos, Joseph Roumier
KEOD3
2010 Special section: Security, trust and privacy in Grid systems
Álvaro Enrique Arenas, Philippe Massonet
Future Gener. Comput. Syst.2
2008 Model Based Development of Quality-Aware Software Services
abstract
Modelling languages and development frameworks give support for functional and structural description of software architectures. But quality-aware applications require languages which allow expressing QoS as a first-class concept during architecture design and service composition, and to extend existing tools and infrastructures adding support for modelling, evaluating, managing and monitoring QoS aspects. In addition to its functional behaviour and internal structure, the developer of each service must consider the fulfilment of its quality requirements. If the service is flexible, the output quality depends both on input quality and available resources (e.g., amounts of CPU execution time and memory). From the software engineering point of view, modelling of quality-aware requirements and architectures require modelling support for the description of quality concepts, support for the analysis of quality properties (e.g. model checking and consistencies of quality constraints, assembly of quality), tool support for the transition from quality requirements to quality-aware architectures, and from quality-aware architecture to service run-time infrastructures. Quality management in run-time service infrastructures must give support for handling quality concepts dynamically. QoS-aware modeling frameworks and QoS-aware runtime management infrastructures require a common evolution to get their integration.
Miguel A. de Miguel, Philippe Massonet, Juan Pedro Silva, Javier Fernández Briones
ISORC2
2007 Early verification and validation of mission critical systems
Christophe Ponsard, Philippe Massonet, Jean-François Molderez, André Rifaut, Axel van Lamsweerde, Hung Tran Van
Formal Methods Syst. Des.2
2006 Security Requirements Model for Grid Data Management Systems
Syed Naqvi, Philippe Massonet, Álvaro Enrique Arenas
CRITIS2
2004 Goal-Oriented Requirements Animation
Hung Tran Van, Axel van Lamsweerde, Philippe Massonet, Christophe Ponsard
RE3
2003 FAUST: Formal Analysis Using Specification Tools
abstract
Developing high quality requirements specifications is a necessity for a number of critical industrial systems. An integrated toolset, called FAUST, is proposed to assist in the production of such specifications based on the KAOS goal-driven methodology. The tool suite is designed to naturally extend the existing semiformal modeling framework and to allow formalizing only the relevant critical parts. Two tools from the toolset are presented. The requirements checker performs KAOS goal-level checks using existing model checking technology. The requirements animator produces domain-level animations hiding formality even further.
André Rifaut, Philippe Massonet, Jean-François Molderez, Christophe Ponsard, Pierre Stadnik, Axel van Lamsweerde, Hung Tran Van
RE2
1997 GRAIL/KAOS: An Environment for Goal-Driven Requirements Engineering
abstract
No abstract available.
Robert Darimont, Emmanuelle Delor, Philippe Massonet, Axel van Lamsweerde
ICSE3
1997 GRAIL/KAOS: An Environment for Goal-Driven Requirements Analysis, Integration and Layout
abstract
The KAOS methodology provides a language, a method, and meta-level knowledge for goal-driven requirements elaboration. The language provides a rich ontology for capturing requirements in terms of goals, constraints, objects, actions, agents etc. Links between requirements are represented its well to capture refinements, conflicts, operationalizations, responsibility assignments, etc. The KAOS specification language is a multi-paradigm language with a two-level structure: an outer semantic net layer for declaring concepts, their attributes and links to other concepts, and an inner formal assertion layer for formally defining the concept. The latter combines a real-time temporal logic for the specification of goals, constraints, and objects, and standard pre-/postconditions for the specification of actions and their strengthening to ensure the constraints.
Robert Darimont, Emmanuelle Delor, Philippe Massonet, Axel van Lamsweerde
RE3
1997 Analogical Reuse of Requirements Frameworks
abstract
Reusing similar requirements fragments is one of the most promising ways to reduce the elaboration time and increase the requirements' quality. This paper investigates the application of analogical reasoning techniques to complete partial requirement specifications. A case base is assumed to be available; it contains requirements frameworks involving goals, constraints, objects, actions and agents from systems which have already been specified. We show how a rich requirements meta-model, coupled with an expressive formal assertion language, may increase the effectiveness of analogical reuse. An acquisition problem is first specified by a requirements engineer as a query formulated in the vocabulary of the specification fragments built so far. Source cases and partial mappings are found by query generalization followed by a search through the case base. Once analogies have been confirmed, mappings are completed by the use of relevance rules that distinguish, in the formal assertions, what is relevant to the analogy from what is irrelevant. The best analogies are then selected and extended in such a way that the logical properties of the answers to the query may be verified, thus increasing confidence in the analogy. The approach is illustrated by analogical acquisition of specifications of a meeting scheduler in the KAOS goal-oriented specification language.
Philippe Massonet, Axel van Lamsweerde
RE1
1995 Goal-directed elaboration of requirements for a meeting scheduler: problems and lessons learnt
abstract
Recently a number of requirements engineering languages and methods have flourished that not only address 'what' questions but also 'why', 'who' and 'when' questions. The objective of the paper is twofold: to assess the strengths and weaknesses of one of these methodologies on a nontrivial benchmark; and to illustrate and discuss a number of challenging issues that need to be addressed for such methodologies to become effective in supporting real, complex requirements engineering tasks. The problem considered here is that of a distributed meeting scheduler system; the methodology considered is the KAOS goal directed language and method. The issues raised from this case study include goal identification, the "deidelization" of unachievable goals, the handling of interfering goals, the impact of early formal reasoning, the merits of early reuse of abstract descriptions and categories, requirements traceability and the need to link requirements to retractable assumptions, and the potential benefits of hybrid acquisition strategies.
Axel van Lamsweerde, Robert Darimont, Philippe Massonet
RE3