VLDB 2026 Research / reviewers in the wild / expert
Olivier Festor
dblp:f/OlivierFestor
· DBLP profile ↗
109ranked-venue papers
3as first author
13since 2021 · last 2025
0000-0002-3181-7967ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 51 · 3 first-author · 5 since 2021Security and privacy · 11Software engineering, systems software and programming languages · 4 · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | QoE Evaluation of BPP Packet Wash Using ROI-Based Scalable Video CodingabstractLatency-sensitive multimedia applications, such as cloud gaming, require advanced streaming solutions that provide both low latency and high visual quality to ensure seamless user experience. Conventional transport protocols often struggle under sudden bandwidth fluctuations, resulting in latency spikes, packet loss, and ultimately gameplay interruptions. To address these limitations, this work explores the capabilities of the Big Packet Protocol (BPP) packet wash mechanism combined with Region of Interest (ROI) coding by Scalable Video Coding (SVC) for$\text{2 K}$video games to satisfy the Quality of Experience (QoE) under network congestion. BPP packet wash dynamically discards non-critical enhancement layer chunks at the network edge during congestion, ensuring a critical Quality of Service (QoS)-preserving remediation before the application's Control Congestion Algorithm (CCA) comes into play to adapt the bitrate. Comparative experiments for various coding strategies after applying packet wash show that ROI SVC can handle bandwidth drops more efficiently, up to$\text{5 2} {\%}$reduction, while still maintaining uninterrupted gameplay and satisfactory visual quality in the most critical regions of the game, according to QoE evaluation involving real users. These results indicate that packet wash with ROI SVC provides an effective solution for real-time interactive multimedia streaming, such as cloud gaming. Mohammadreza Ghafari, Thibault Cholez, Olivier Festor |
ISM | 3 |
| 2024 | Vulnet: Learning Navigation in an Attack GraphabstractNowadays, new flaws or vulnerabilities are frequently discovered. Analyzing how these vulnerabilities can be used by attackers to gain access to different parts of a network allows to provide better protection and defense. Amongst the diverse analysis techniques, simulations do not necessitate a full infrastructure deployment and recently benefited from advances in reinforcement learning to better mimic an attacker’s behavior. However, such simulations are resource consuming. By representing the interconnected hosts of a network and their vulnerabilities as attack graphs and leveraging machine learning, our method, Vulnet, is capable to generalize knowledge generated by simulation and gives insight about attacker capabilities. It can predict instantaneously the overall performance of an attacker to compromise a system with a mean error of 0.07. Enzo d'Andréa, Jérôme François, Abdelkader Lahmadi, Olivier Festor |
NetSoft | 4 |
| 2023 | Efficient Identification of Cloud Gaming Traffic at the EdgeabstractCloud Gaming (CG) has been gaining a lot of interest and major actors have entered this market such as Google, Nvidia, Sony or Microsoft. They operate CG platforms that attract an increasing number of players worldwide. This type of traffic is highly demanding for network infrastructures because it requests simultaneously high bandwidth, low delay and no traffic degradation (interruptions or jitter) to ensure a good end-user’s QoE. To improve the delivery of low-latency applications, new Active Queue Management architectures like L4S (Low Latency, Low Loss, Scalable Throughput) are proposed. Currently, traffic is routed to a low-latency queue only based on the presence of the Explicit Congestion Notification bit (ECN) in the IP header, but this is too restrictive and can be easily manipulated. Instead, we aim at analyzing and detecting CG traffic based on its inherent characteristics, to forward the packets in the low-latency queue. This paper presents our models to efficiently detect CG traffic based on flow-level features among other highbitrate applications transported over UDP. The evaluation proves that our model based on decision trees achieves very good results (98.5% accuracy) and can be realistically deployed as a Virtualized Network Function at the edge, handling more than 10Gb/s of medium-sized flows on a low-end server. Our network captures and source code are open to ensure reproducible results. Philippe Graff, Xavier Marchal, Thibault Cholez, Bertrand Mathieu, Olivier Festor |
NOMS | 5 |
| 2023 | HiFiPot: a High-Fidelity Emulation Framework for Internet of Things HoneypotsabstractInternet of Things (IoT) devices are easy targets for attackers. Preventing and counter-fighting this threat impose to capture and analyze attackers’ behaviors. Several IoT-oriented honeypots have been proposed recently while, in parallel, emulation techniques for IoT devices have been improved to allow firmware analysis of this type of devices.In this paper, our objective is to consolidate these two facets in a single framework called HiFiPot. It is capable of creating a high-interaction honeypot on-the-fly with a high fidelity, i.e. from a firmware image. Our technique improves the most recent stateof-the-art solution to emulate an IoT device without scarifying the furtiveness. It is based on an iterative learning procedure to automatically correct emulation errors and to ensure Internet connectivity while maintaining these corrections invisible to the attackers. Out of the 1,000 firmware images tested, 443 (44,3%) can be deployed as honeypot. More than 500 instances of HiFiPot were deployed in the wild, and received about 1,900 HTTP traversal attacks, and downloaded 31 distinct malware binaries (out of 909) among which eight were unknown. Pierre-Marie Junges, Jérôme François, Olivier Festor |
NOMS | 3 |
| 2023 | Multi-label Classification of Hosts Observed through a DarknetabstractTo observe compromised hosts at Internet-scale, a darknet or network telescope collects Internet background radiation that includes large-scale phenomena like DDoS (Distributed Denial-of-Service) or scanning. Gathered data is however very partial and labeling such traffic to precise activities thanks to external databases is far from being satisfactory (8.4% of IP addresses in our case). In addition, as compromised hosts are used for multiple malicious activities, they cannot be classified in a unique category. We propose in this paper a new multi-label classification method by representing traffic generated by a host as a graph and leveraging machine learning algorithms (Node embedding and Graph Convolutional Networks). From partial information about IP addresses, our method can label addresses with a precision of 0.80 and recall of 0.81. Enzo d'Andréa, Jérôme François, Olivier Festor, Mehdi Zakroum |
NOMS | 3 |
| 2023 | Stateful InREC: Stateful In-Network Real Number Computation With Recursive FunctionsabstractThe current generation of Reconfigurable Match-Action Tables switches are highly programmable, able to support stateful operations and pipeline specifications using languages like P4. Nevertheless, these switches do not offer primitives to support real-valued operations on the data plane, thus requiring support from external servers or middle boxes to perform advanced operations. We introduce Stateful InREC, a system that extends the capabilities of programmable switches to support in-network real-valued operations using the IEEE half-precision floating point representation. Stateful InREC relies on decomposing real-valued functions into lookup tables taking into account the RMT model constraints to reach the right trade-off between accuracy and resource usage. It also supports state management for the computation of recursive function over time series. Stateful InREC prototype on Barefoot Tofino switches demonstrates the efficiency of Stateful InREC for in-network computation of different types of operations and its application for in-network logistic regression models used for classification problems. We also demonstrate the use of Stateful InREC to implement an ARIMA model on a Tofino switch for DDoS detection. Our evaluation of Stateful InREC shows that it is possible to implement complex in-network applications with high accuracy and low latency. Matthews Jose, Kahina Lazri, Jérôme François, Olivier Festor |
IEEE Trans. Netw. Serv. Manag. | 4 |
| 2022 | NetREC: Network-wide in-network REal-value ComputationabstractThe current generation of networks empowers the use of programmable switches whose behaviour can be defined using languages like P4. Nevertheless, these languages do not support network-wide deployment of stateful real-value functions. This paper presents NetREC, an extension of RMT programmable data planes designed to enable stateful real-value functions computation across multiple switches. NetREC first decomposes the real-value functions into a dependency graph of elementary operations that are distributed among the network. This distribution is carried out by dynamically generating and solving an integer linear program. We deploy a prototype of NetREC on a network of Tofino switches and demonstrate its capability of computing recursive real-value functions like exponential weighted moving average. Matthews Jose, Kahina Lazri, Jérôme François, Olivier Festor |
NetSoft | 4 |
| 2021 | An Analysis of Cloud Gaming Platforms Behavior under Different Network ConstraintsabstractWith the recent technological evolutions in networks and increased deployment of multi-tier clouds, cloud gaming (CG) is gaining renewed interest and is expected to become a major Internet service in the upcoming years. Many companies have launched powerful platforms such as Google Stadia, Nvidia GeForce Now, Microsoft xCloud, Sony PlayStation Now among others, to attract players. However, for all end-users to fully enjoy their gaming sessions over the wide range of network access qualities, CG platforms must adapt their traffic. In this paper, we present the outcome of real-life measurements performed between April and July 2021 on the four aforementioned CG platforms, configuring different network constraints like packet loss, throughput decrease, latency increase and jitter variation to observe the behavior of these CG platforms under extreme network conditions. Our findings show that the four platforms exhibit different adaptation behaviors. Moreover, many cases result in a degraded QoS, leaving room for further improvements at both application and/or network levels. Philippe Graff, Xavier Marchal, Thibault Cholez, Stéphane Tuffin, Bertrand Mathieu, Olivier Festor |
CNSM | 6 |
| 2021 | Inferring Software Composition and Credentials of Embedded Devices from Partial KnowledgeabstractInternet-of-Things (IoT) devices or more generally embedded devices are nowadays commonly deployed in public, personal or work spaces despite suffering from security issues often related to their bad design and/or configuration. For instance, IoT botnets such as Mirai successfully compromised thousands of devices using a bruteforce method on a set of known credentials. Although brute-force attacks against a particular service (e.g. SSH, telnet) generate many packets which can be easily detected and mitigated, attackers can easily rely on TCP scans to assess the services present on a device while maintaining a high level of stealthiness. In this paper, we present a method to reconstruct precise information about an IoT device configuration (brand name, usernames, passwords, software components) from partial knowledge such as open ports revealed by a TCP scan. It relies on constituting a knowledge base from a large dataset of publicly accessible firmware serving as training multiple Random Forest (RF) classifiers. Using a dataset of 6935 embedded devices, the HTTP, SSH or DNS software names can be predicted with a precision higher than 80% with a limited knowledge. The correct HTTP, SSH or DNS versions can be inferred in more than 95% of cases after 1.4 trials on average. Similarly, our technique also predicts the password of at least one valid user in more than 97% of the cases after 1.15 trials on average. Pierre-Marie Junges, Jérôme François, Olivier Festor |
CNSM | 3 |
| 2021 | InREC: In-network REal Number Computation
Matthews Jose, Kahina Lazri, Jérôme François, Olivier Festor |
IM | 4 |
| 2021 | Leveraging in-network real-value computation for home network device recognition
Matthews Jose, Kahina Lazri, Jérôme François, Olivier Festor |
IM | 4 |
| 2021 | Software-based Analysis of the Security by Design in Embedded Devices
Pierre-Marie Junges, Jérôme François, Olivier Festor |
IM | 3 |
| 2021 | Towards Automating Security Enhancement for Cloud Services
Mohamed Oulaaffart, Rémi Badonnel, Olivier Festor |
IM | 3 |
| 2020 | From virtualization security issues to cloud protection opportunities: An in-depth analysis of system virtualization models
Maxime Compastié, Rémi Badonnel, Olivier Festor, Ruan He |
Comput. Secur. | 3 |
| 2019 | Towards Content-Centric Control Plane Supporting Efficient Anomaly Detection FunctionsabstractAnomaly detection remains a challenging task due to both the ever more complex functions that need to be executed and the evolution of current networking devices which induces limitation of computational resources such as the Internet of Things (IoT). Furthermore, results of anomaly function computations can be repeated gradually over time or executed in neighboring nodes, thus leading to a waste of such limited computing resources in constrained nodes. To tackle these issues, the content-centric paradigm enhanced with computing features offers a promising solution to reduce the computation resources and finally improve the scalability of anomaly detection functions. In this paper, we propose a first step toward a content-oriented control plane which enables the distribution of the processing and the sharing of results of anomaly detection functions in the network. We present the way we leverage NFN to support Bayesian Network inference to detect anomalies in network traffic. The relevance and performance of our proposed approach are demonstrated by considering the Content Poisoning Attack (CPA) through numerous experiment data. Hoang Long Mai, Guillaume Doyen, Wissam Mallouli, Edgardo Montes de Oca, Olivier Festor |
CNSM | 5 |
| 2019 | Passive Inference of User Actions through IoT Gateway Encrypted Traffic Analysis
Pierre-Marie Junges, Jérôme François, Olivier Festor |
IM | 3 |
| 2019 | Toward Content-Oriented Orchestration: SDN and NFV as Enabling Technologies for NDN
Hoang Long Mai, Messaoud Aouadj, Guillaume Doyen, Wissam Mallouli, Edgardo Montes de Oca, Olivier Festor |
IM | 6 |
| 2019 | A TOSCA-Oriented Software-Defined Security Approach for Unikernel-Based Protected CloudsabstractCloud infrastructures provide new facilities to build elaborated added-value services by composing and configuring a large variety of computing resources, from virtualized hardware devices to software products. In the meantime, they are further exposed to security attacks than traditional environments. The complexity of security management tasks has been increased by the multi-tenancy, heterogeneity and geographical distribution of these resources. They introduce critical issues for cloud service providers and their customers, with respect to security programmability and scenarios of adaptation to contextual changes. In this paper, we propose a software-defined security approach based on the TOSCA language, to enable unikernel-based protected clouds. We first introduce extensions of this language to describe unikernels and specify security constraints for their orchestrations. We then describe an architecture exploiting this extended version of TOSCA for automatically generating, deploying and adjusting cloud resources in the form of protected unikernels with a low attack surface. We finally detail a proof-of-concept prototype, and evaluate the proposed solution through extensive series of experiments. Maxime Compastié, Rémi Badonnel, Olivier Festor, Ruan He |
NetSoft | 3 |
| 2019 | Reliable Detection of Interest Flooding Attack in Real Deployment of Named Data NetworkingabstractNamed data networking (NDN) is a disruptive yet promising architecture for the future Internet, in which the content diffusion mechanisms are shifted from the conventional host-centric to content-centric ones so that the data delivery can be significantly improved. After a decade of research and development, NDN and the related NDN forwarding daemon implementations are now mature enough to enable stakeholders, such as telcos, to consider them for a real deployment. Consequently, NDN and IP will likely cohabit, and the future Internet may be formed of isolated administrative domains, each deploying one of these two network paradigms. The security question of the resulting architecture naturally arises. In this paper, we consider the case of denial of service. Even though the interest flooding attack (IFA) has been largely studied and mitigated through NACK packets in pure NDN networks, we demonstrate in this paper through experimental assessments that there are still some ways to mount such an attack, and especially in the context of coupling NDN with IP, which can hardly be addressed by current solutions. Subsequently, we leverage the hypothesis testing theory to develop a generalized likelihood ratio test adapted to evolve IFA attacks. Simulations show the relevance of the proposed model for guaranteeing the prescribed probability of false alarm and highlight the trade-off between detection power and delay. Finally, we consider a real deployment scenario where NDN is coupled with IP to carry HTTP traffic. We show that the model of IFA attacks is not very accurate in practice and further develops a sequential detector to keep a high detection accuracy. By considering data from the testbed, we show the efficiency of the overall detection method. Tan N. Nguyen, Hoang Long Mai, Rémi Cogranne, Guillaume Doyen, Wissam Mallouli, Luong Nguyen, Moustapha El Aoun, Edgardo Montes de Oca, Olivier Festor |
IEEE Trans. Inf. Forensics Secur. | 9 |
| 2018 | Demo: On-the-fly generation of unikernels for software-defined security in cloud infrastructuresabstractThe programmability of security mechanisms through software-defined security permits the outsourcing of security management to a dedicated plan. Unikernels offer new perspectives for supporting this programmability, and addressing the challenges with respect to the heterogeneity and the dynamics of cloud resources. In this demo, we demonstrate how unikernel properties may enable an adequate security enforcement at the resource level. We present a framework for integrating security mechanisms into unikernel virtual machines, and align them to a given security policy, through the on-the-fly unikernel VM generation. We showcase an implementation prototype and confront it to cloud exploitation scenarios. Maxime Compastié, Rémi Badonnel, Olivier Festor, Ruan He |
NOMS | 3 |
| 2018 | Unikernel-based approach for software-defined security in cloud infrastructuresabstractThe heterogeneity of cloud resources implies substantial overhead to deploy and configure adequate security mechanisms. In that context, we propose a software-defined security strategy based on unikernels to support the protection of cloud infrastructures. This approach permits to address management issues by uncoupling security policy from their enforcement through programmable security interfaces. It also takes benefits from unikernel virtualization properties to support this enforcement and provide resources with low attack surface. These resources correspond to highly constrained configurations with the strict minimum for a given period. We describe the management framework supporting this software-defined security strategy, formalizing the generation of unikernel images that are dynamically built to comply with security requirements over time. Through an implementation based on MirageOS, and extensive experiments, we show that the cost induced by our security integration mechanisms is small while the gains in limiting the security exposure are high. Maxime Compastié, Rémi Badonnel, Olivier Festor, Ruan He, Mohamed Kassi-Lahlou |
NOMS | 3 |
| 2018 | Towards a security monitoring plane for named data networking and its application against content poisoning attackabstractNamed Data Networking (NDN) is the most mature proposal of the Information Centric Networking paradigm, a clean-slate approach for the Future Internet. Although NDN was designed to tackle security issues inherent to IP networks natively, newly introduced security attacks in its transitional phase threaten NDN's practical deployment. Therefore, a security monitoring plane for NDN is indispensable before any potential deployment of this novel architecture in an operating context by any provider. We propose an approach for the monitoring and anomaly detection in NDN nodes leveraging Bayesian Network techniques. A list of monitored metrics is introduced as a quantitative measure to feature the behavior of an NDN node. By leveraging the hypothesis testing theory, a micro detector is developed to detect whenever the metric significantly changes from its normal behavior. A Bayesian network structure that correlates alarms from micro detectors is designed based on the expert knowledge of the NDN specification and the NFD implementation. The relevance and performance of our security monitoring approach are demonstrated by considering the Content Poisoning Attack (CPA), one of the most critical attacks in NDN, through numerous experiment data collected from a real NDN deployment. Hoang Long Mai, Tan N. Nguyen, Guillaume Doyen, Rémi Cogranne, Wissam Mallouli, Edgardo Montes de Oca, Olivier Festor |
NOMS | 7 |
| 2018 | Leveraging NFV for the deployment of NDN: Application to HTTP traffic transportabstractFor a few years, Network-Function Virtualization (NFV) acts as the most promising solution for the flexible implementation and management of future network services. If most of current efforts in this area focus on IP-based Virtual Network Functions (VNF), the case of Information-Centric Networking (ICN) is interesting since it can demonstrate that NFV is a promising technology for ISP to deploy such new innovative network stacks. In this context, we propose to design and implement a NFV compliant architecture to easily deploy ICN islands. Especially, at the core of this architecture, we present an HTTP/NDN gateway, which enables our network to carry real HTTP traffic. Finally, we show early functional experimental results of an initial testbed deployment exhibiting the capability of our global infrastructure to retrieve the top- 1000 of the most popular web sites. Xavier Marchal, Moustapha El Aoun, Bertrand Mathieu, Thibault Cholez, Guillaume Doyen, Wissam Mallouli, Olivier Festor |
NOMS | 7 |
| 2017 | Advanced interest flooding attacks in named-data networkingabstractThe Named-Data Networking (NDN) has emerged as a clean-slate Internet proposal on the wave of Information-Centric Networking. Although the NDN's data-plane seems to offer many advantages, e.g., native support for multicast communications and flow balance, it also makes the network infrastructure vulnerable to a specific DDoS attack, the Interest Flooding Attack (IFA). In IFAs, a botnet issuing unsatisfiable content requests can be set up effortlessly to exhaust routers' resources and cause a severe performance drop to legitimate users. So far several countermeasures have addressed this security threat, however, their efficacy was proved by means of simplistic assumptions on the attack model. Therefore, we propose a more complete attack model and design an advanced IFA. We show the efficiency of our novel attack scheme by extensively assessing some of the state-of-the-art countermeasures. Further, we release the software to perform this attack as open source tool to help design future more robust defense mechanisms. Salvatore Signorello, Samuel Marchal, Jérôme François, Olivier Festor, Radu State |
NCA | 4 |
| 2017 | Understanding disruptive monitoring capabilities of programmable networksabstractThe design shift proposed by OpenFlow, with its simple stateless dataplane, initially contributed to the success of Software-Defined Networks. Its lack of state, however, prevents the implementation of many dataplane algorithms. Network applications must therefore offload stateful operations to the control plane, thereby increasing latency and limiting network scalability. Thus, recent research efforts centered on the addition of stateful properties to switches. In this paper, we discuss the impact of emerging programmable dataplane abstractions on network monitoring. In particular, we investigate the need for dataplane states in the design of scalable monitoring applications. We argue that these abstractions are ill-suited for software switches as they retain hardware-specific limitations. Furthermore, we analyse the impact of stateful dataplane designs on the control plane visibility of the network. Finally, we identify opportunities for improvement in the design of stateful software switches. Paul Chaignon, Kahina Lazri, Jérôme François, Olivier Festor |
NetSoft | 4 |
| 2016 | A Software-Defined Security Strategy for Supporting Autonomic Security Enforcement in Distributed CloudabstractWe propose in this paper a software-defined security framework, for supporting the enforcement of security policies in distributed cloud environments. These ones require security mechanisms able to cape with their multi-tenancy and multi-cloud properties. This framework relies on the autonomic paradigm to dynamically configure and adjust these mechanisms to distributed cloud constraints, and exploit the software-defined logic to express and propagate security policies to the considered cloud resources. The proposed framework is evaluated through a set of validation scenarios corresponding to a realistic use cases including cloud resource allocation/deallocation, cloud resource state change, and dynamic access control. Maxime Compastié, Rémi Badonnel, Olivier Festor, Ruan He, Mohamed Kassi-Lahlou |
CloudCom | 3 |
| 2015 | Behavioral and dynamic security functions chaining for Android devicesabstractWe present an approach for dynamically outsourcing and composing security functions for mobile devices, according to the network behavior of their running applications. Applications are characterized from a network point of view using data mining and clustering techniques with the aim to select their appropriate security functions. Software-defined networking mechanisms are employed to chain the selected functions and to redirect mobile apps traffic through the resulting security compositions. Those ones can be fully outsourced or split between in-cloud and on-device. Both a prototype and extensive simulations demonstrate the feasibility of the approach and assess its benefits. Gaetan Hurel, Rémi Badonnel, Abdelkader Lahmadi, Olivier Festor |
CNSM | 4 |
| 2015 | A Comparison of Caching Strategies for Content Centric NetworkingabstractContent Centric Networking (CCN) is a new architecture for a future Internet. CCN relies on in-network caching capabilities of nodes and the efficiency of this architecture depends drastically on performances of caching strategies. Thus, there have been a lot of studies proposing new caching strategies to improve the performances of CCN. However, among all these strategies, it is still unclear which one performs better as there is a lack of common environment to compare these strategies. In this paper, we compare the performances of CCN caching strategies within the same simulation environment. We build a common evaluation scenario and we compare via simulation five relevant caching strategies: Leave Copy Everywhere (LCE), Leave Copy Down (LCD), ProbCache, Cache "Less" For More and MAGIC. We analyze the performances of all the strategies in terms of Cache Hit, Stretch, Diversity and Complexity, and determine the cache strategy that fits the best with every scenario. César Bernardini, Thomas Silverston, Olivier Festor |
GLOBECOM | 3 |
| 2015 | Evaluation of the Anonymous I2P Network's Design Choices Against Performance and SecurityabstractInternational audience Juan Pablo Timpanaro, Thibault Cholez, Isabelle Chrisment, Olivier Festor |
ICISSP | 4 |
| 2015 | Towards cloud-based compositions of security functions for mobile devicesabstractIn order to prevent attacks against smartphones and tablets, dedicated security applications are usually deployed on the mobile devices themselves. However, these applications may have a significant impact on the device resources, and users may be tempted to uninstall or disable them. In this paper, we propose a new approach to outsource mobile security functions and build transparent in-path security compositions for mobile devices. The functions are dynamically activated, configured and composed using software-defined networking and virtualization capabilities. We present a mathematical formalization to model the security compositions, and describe the functional architecture. We provide an implementation prototype and evaluate the solution through an extensive set of experiments. Gaetan Hurel, Rémi Badonnel, Abdelkader Lahmadi, Olivier Festor |
IM | 4 |
| 2015 | A platform for the analysis and visualization of network flow data of android environmentsabstractIn this demo, we present a monitoring platform dedicated to the collection, storage, analysis and visualization of logs and network flow data of mobile applications. The platform relies on a set of on-device probes to monitor network and system activities of these applications. The data are collected from these probes and parsed through generic and flexible collectors relying on Flume agents that we have adapted and extended. We are storing the collected data using a column oriented Hbase storage engine which is the Hadoop database. Finally, after being parsed, the data are made available within the Elasticsearch engine to search and visualize them using the Kibana tool. Abdelkader Lahmadi, Frédéric Beck, Eric Finickel, Olivier Festor |
IM | 4 |
| 2014 | SONETOR: A social network traffic generatorabstractThe Online Social Networks (OSN) have become an important trend in current networks. Due to the susceptible nature of the private data available in OSN, the acquisition of data sets is not an easy task. In this paper and based on the state of the art of measurement studies, we present SONETOR, a synthetic social network traffic generator, characterized by ease of use and flexibility. SONETOR represents current social network behavior such as user publishing and consuming content, users sharing and commenting on information with their friends. We also proceed to study the impact of OSN in the network traffic with SONETOR. In particular, our social network traffic generator allows capturing the effect of the flash-crowd phenomenon. SONETOR is an open-source and multi-platform tool freely available. The generated traces can be widely distributed without restrictions and they are still privacy compliant. César Bernardini, Thomas Silverston, Olivier Festor |
ICC | 3 |
| 2014 | Empirical analysis of Android logs using self-organizing mapsabstractIn this paper, we present an empirical analysis of the logs generated by the logging system available in Android environments. The logs are mainly related to the execution of the different components of applications and services running on an Android device. We have analysed the logs using self organizing maps where our goal is to establish behavioural fingerprints of Android applications. Each fingerprint is build using information available in logs and related to the structure of an application and its interaction with the system. The developed methodology allows us the better understand Android Apps regarding their granted permissions and performed actions and it proves to be promising for the analysis of malware applications with a minimal overhead and cost. Eric Finickel, Abdelkader Lahmadi, Frédéric Beck, Olivier Festor |
ICC | 4 |
| 2014 | A Pin is worth a thousand words: Characterization of publications in PinterestabstractOnline Social Networking (OSN) has become one of the main applications on the Internet. Pinterest is an emerging social network that is gaining a lot of popularity and mostly focuses on images. In this work, we crawled during several months the Pinterest website and collected all the relevant information to characterize this social network (e.g., users' profiles, publications and activities). More precisely, we investigate the interaction of users in Pinterest such as the type of activities, the published images and the lexical analysis of their descriptions.We study as well the importance of this OSN to leverage traffic into external websites. Throughout this paper, we emphasize on the specific characteristics of Pinterest with regards to other well-adopted OSN (Facebook and Twitter). In particular, Pinterest is a retransmission network, in which 84% of the publications comes directly from other users. This fact and the Pinterest architecture have a direct impact on website ranking in search engines. Finally, as Facebok or Twitter target social relationships or breaking news, Pinterest has a different nature and is mostly devoted to leisure and entertainment. César Bernardini, Thomas Silverston, Olivier Festor |
IWCMC | 3 |
| 2014 | Socially-aware caching strategy for content centric networkingabstractContent Centric Networking (CCN) emerged as a replacement architecture for the current Internet. CCN resorts to in-network caching to enhance end-user delivery performance. At the same time, Online Social Networks (OSN) have become the common paradigm to exchange information between users. OSNs carry extremely valuable information about their users and their relationships. This knowledge can help to drastically improve the efficiency of CCN. We present a novel caching strategy for CCN based on social information. We conjecture a small number of users — the Influential users — dominate the activity, receive most attention from other users and produce content more likely to be consumed. Our caching strategy privileges the Influential users and cache pro-actively their content in the network. Through extensive simulation experiments based on two social network scenarios, LastFM and Facebook, and substantial number of users in a CCN topology, we demonstrate the value of our approach. We also implemented and deployed our strategy on PlanetLab and it improves drastically the caching performances of CCN. César Bernardini, Thomas Silverston, Olivier Festor |
Networking | 3 |
| 2014 | Named data aggregation in wireless sensor networksabstractIn this paper, we present a novel named data aggregation method dedicated to wireless sensor networks. The method relies on an adaptation of the CCNx protocol implementation that we have extended with in-network processing functions to aggregate named data efficiently. We have implemented and tested our solution with the Contiki operating system which is an operating system for resources-constrained embedded systems and wireless sensor networks. Our simulation and measurement results using the Cooja simulator and physical nodes show that our solution has a small overhead in terms of exchanged messages and provides acceptable data retrieval delays. Younes Abid, Bilel Saadallah, Abdelkader Lahmadi, Olivier Festor |
NOMS | 4 |
| 2014 | A SAT-based autonomous strategy for security vulnerability managementabstractComputer and network systems are consistently exposed to security threats, making their management even more complex. The management of known vulnerabilities plays a crucial role for ensuring their safe configurations and preventing security attacks. However, this activity should not generate new vulnerable states. In this paper we present a novel approach for autonomously assessing and remediating vulnerabilities. We describe a detailed mathematical model that supports this activity and we formalize the remediation decision process as a SAT problem. We present a framework that is able to assess OVAL vulnerability descriptions and perform corrective actions by using XCCDF-based descriptions of future machine states and the NETCONF protocol. We also provide details of our implementation and evaluate its feasibility through a comprehensive set of experiments. Martín Barrère, Rémi Badonnel, Olivier Festor |
NOMS | 3 |
| 2013 | A probabilistic cost-efficient approach for mobile security assessmentabstractThe development of mobile technologies and services has contributed to the large-scale deployment of smartphones and tablets. These environments are exposed to a wide range of security attacks and may contain critical information about users such as contact directories and phone calls. Assessing configuration vulnerabilities is a key challenge for maintaining their security, but this activity should be performed in a lightweight manner in order to minimize the impact on their scarce resources. In this paper we present a novel approach for assessing configuration vulnerabilities in mobile devices by using a probabilistic cost-efficient security framework. We put forward a probabilistic assessment strategy supported by a mathematical model and detail our assessment framework based on OVAL vulnerability descriptions. We also describe an implementation prototype and evaluate its feasibility through a comprehensive set of experiments. Martín Barrère, Gaetan Hurel, Rémi Badonnel, Olivier Festor |
CNSM | 4 |
| 2013 | Efficient distributed monitoring in 6LoWPAN networksabstractMonitoring constrained, low power and lossy networks is essential to many operations including troubleshooting, forensics, performance management. The main challenge for the monitoring plane in these networks is to efficiently cope with both frequently changing topologies and constrained resources. We present a novel algorithm and the supporting framework that improves a poller-pollee based architecture. We empower the poller-pollee placement decision process and operation by exploiting available routing data to monitor nodes status. In addition, monitoring data is efficiently embedded in any messages flowing through the network, drastically reducing monitoring overhead. Our approach is validated through both simulation, implementation and deployment on a 6LoWPAN-enabled network. Results demonstrate that our approach is less aggressive and less resource consuming than its competitors. Abdelkader Lahmadi, Alexandre Boeglin, Olivier Festor |
CNSM | 3 |
| 2013 | MPC: Popularity-based caching strategy for content centric networksabstractContent Centric Networking (CCN) has recently emerged as a promising architecture to deliver content at large-scale. It is based on named-data where a packet address names content and not its location. Then, the premise is to cache content on the network nodes along the delivery path. An important feature for CCN is therefore to manage the cache of the nodes. In this paper, we present Most Popular Content (MPC), a new caching strategy adapted to CCN networks. By caching only popular content, we show through extensive simulation experiments that MPC is able to cache less content while, at the same time, it still achieves a higher Cache Hit and outperforms existing default caching strategy in CCN. César Bernardini, Thomas Silverston, Olivier Festor |
ICC | 3 |
| 2013 | Improving present security through the detection of past hidden vulnerable states
Martín Barrère, Rémi Badonnel, Olivier Festor |
IM | 3 |
| 2013 | Ovaldroid: An OVAL-based vulnerability assessment framework for Android
Martín Barrère, Gaetan Hurel, Rémi Badonnel, Olivier Festor |
IM | 4 |
| 2013 | Monitoring anonymous P2P file-sharing systemsabstractAnonymous communications have been exponentially growing, where more and more users are shifting to a privacy-preserving Internet and anonymising their peer-to-peer communications. Anonymous systems allow users to access different services while preserving their anonymity. We aim to characterise these anonymous systems, with a special focus in the I2P network. Current statistics service for the I2P network do not provide values about the type of applications deployed in the network nor the geographical localisation of users. Our objective is to determine the number of users in the network, the number of anonymous applications, and the type of those applications. We also explore the possibility of inferring which group of users is responsible for the activity of an anonymous application. Thus, we improve the current I2P statistics and get better insights of the network. Juan Pablo Timpanaro, Isabelle Chrisment, Olivier Festor |
P2P | 3 |
| 2013 | Detection and mitigation of localized attacks in a widely deployed P2P network
Thibault Cholez, Isabelle Chrisment, Olivier Festor, Guillaume Doyen |
Peer-to-Peer Netw. Appl. | 3 |
| 2012 | Collaborative remediation of configuration vulnerabilities in autonomic networks and systems
Martín Barrère, Rémi Badonnel, Olivier Festor |
CNSM | 3 |
| 2012 | A Testing Framework for Discovering Vulnerabilities in 6LoWPAN NetworksabstractIn this work, we present the process of identifying potential vulnerabilities in 6LoWPAN enabled networks through fuzzing. The 6LowPAN protocol has been designed by the IETF as an adaptation layer of IPv6 for Low power and lossy networks. The fuzzing process is build upon the Scapy packets manipulation library. It provides different mutation algorithms to be applied on 6LoWPAN protocol messages to assess its implementations security and robustness. The protocol behaviors are described using an XML format to define different testing scenarios. Abdelkader Lahmadi, César Brandin, Olivier Festor |
DCOSS | 3 |
| 2012 | A trust-based strategy for addressing residual attacks in the RELOAD architectureabstractTelephony over IP has undergone a large-scale deployment thanks to the development of high-speed broadband access and the standardization of signalling protocols. A particular attention is currently given to P2PSIP networks which are exposed to many security threats. The RELOAD protocol defines a peer-to-peer signalling overlay designed to support these networks. It introduces a security framework based on certification mechanisms, but P2PSIP networks are still exposed to residual attacks, such as refusals of service. We propose in this work to address these residual attacks by integrating into the RELOAD architecture a dedicated trust model coupled with prevention countermeasures. We mathematically defines this trust-based strategy, and describe the considered prevention mechanisms implemented by safeguards and watchmen. We quantify the benefits and limits of our solution through an extensive set of experiments. Oussema Dabbebi, Rémi Badonnel, Olivier Festor |
ICC | 3 |
| 2012 | Towards the assessment of distributed vulnerabilities in autonomic networks and systemsabstractVulnerability management constitutes a crucial activity within autonomic networks and systems. Distributed vulnerabilities must be assessed over a consolidated view of the network in order to detect vulnerable states that may simultaneously involve two or more devices. In this work, we present a novel approach for describing and assessing distributed vulnerabilities in such self-governed environments. We put forward a mathematical construction for defining distributed vulnerabilities as well as an extension of the OVAL language called DOVAL for describing them. We then define a framework for assessing distributed vulnerabilities in autonomic environments that exploits the knowledge provided by such descriptions. We finally show the feasibility of our solution by analyzing the behavior of the proposed algorithms and strategies through a comprehensive set of experiments. Martín Barrère, Rémi Badonnel, Olivier Festor |
NOMS | 3 |
| 2012 | Dynamic exposure control in P2PSIP networksabstractVoice over IP services have undergone a large-scale deployment thanks to the development of high-speed broadband access and the standardization of dedicated signaling protocols. They offer new opportunities, in particular in the context of peer-to-peer networks. However they are exposed to multiple security attacks due to a lower confinement in comparison to traditional networks. Protection mechanisms are available, but may significantly impact the service performance. We propose in this paper a risk management strategy for dynamically adapting the exposure of P2PSIP networks. We describe the underlying mechanisms for mitigating risks based on a portfolio of countermeasures. We also detail the mathematical modeling which supports our solution based on the analysis of a case study. Finally we quantify the benefits and limits of this approach through an extensive set of experiments performed with the OMNET++ simulator. Oussema Dabbebi, Rémi Badonnel, Olivier Festor |
NOMS | 3 |
| 2012 | DNSSM: A large scale passive DNS security monitoring frameworkabstractWe present a monitoring approach and the supporting software architecture for passive DNS traffic. Monitoring DNS traffic can reveal essential network and system level activity profiles. Worm infected and botnet participating hosts can be identified and malicious backdoor communications can be detected. Any passive DNS monitoring solution needs to address several challenges that range from architectural approaches for dealing with large volumes of data up to specific Data Mining approaches for this purpose. We describe a framework that leverages state of the art distributed processing facilities with clustering techniques in order to detect anomalies in both online and offline DNS traffic. This framework entitled DNSSM is implemented and operational on several networks. We validate the framework against two large trace sets. Samuel Marchal, Jérôme François, Cynthia Wagner, Radu State, Alexandre Dulaunoy, Thomas Engel 0001, Olivier Festor |
NOMS | 7 |
| 2012 | A Bird's Eye View on the I2P Anonymous File-Sharing Environment
Juan Pablo Timpanaro, Isabelle Chrisment, Olivier Festor |
NSS | 3 |
| 2012 | A Framework for Automated Exploit Prevention from Known Vulnerabilities in Voice over IP ServicesabstractWe propose a prevention system for SIP-based networks which adopts a rule-based approach to build prevention specifications on SIP protocol activities that stop attacks exploiting an existing vulnerability before reaching their targets. Our approach innovates from existing solutions by making use of the contextual information of a vulnerability targeted by an attack to apply the prevention specification. Manually coding these prevention specifications is tedious and error-prone. Our method automatically infers prevention specifications by analyzing captured SIP exploit traffic. The detection engine uses an efficient method based on event graphs to match protocol activities against available prevention specifications. We describe the different components of our approach and show through an extended performance study of the implemented system its applicability to enterprise level VoIP protection. Abdelkader Lahmadi, Olivier Festor |
IEEE Trans. Netw. Serv. Manag. | 2 |
| 2011 | Supporting vulnerability awareness in autonomic networks and systems with OVAL
Martín Barrère, Rémi Badonnel, Olivier Festor |
CNSM | 3 |
| 2011 | Enforcing security with behavioral fingerprinting
Jérôme François, Radu State, Thomas Engel 0001, Olivier Festor |
CNSM | 4 |
| 2011 | Hinky: Defending against Text-Based Message Spam on SmartphonesabstractWe present a defense platform against text-based message SPAM on SmartPhones. We focus in particular on Short Message Service (SMS) based SPAM. Our solution relies on a social network based collaborative approach to filter this type of spam using Bloom filters and content hashing. We detail the design of the supporting framework and validate its efficiency in minimizing false positive and limiting the storage space. Abdelkader Lahmadi, Laurent Delosières, Olivier Festor |
ICC | 3 |
| 2011 | Artemisa: An open-source honeypot back-end to support security in VoIP domainsabstractVoice over IP (VoIP) and the Session Initiation Protocol (SIP) are establishing themselves as strong players in the field of multimedia communications over IP, leveraged by low cost services and easy management. Nevertheless, the security aspects are not yet fully mastered. In this paper we present an open-source implementation of a VoIP SIP-specific honeypot named Artemisa. The honeypot is designed to connect to a VoIP enterprise domain as a back-end user-agent in order to detect malicious activity at an early stage. Moreover, the honeypot can play a role in the real-time adjustment of the security policies of the enterprise domain where it is deployed. We aim, by this contribution, to encourage the deployment of such honeypots at large scale and the collection of attack traces. We test the capacity of the honeypot to handle a series of known SIP attacks and present results from diverse scenarios. Rodrigo do Carmo, Mohamed Nassar 0001, Olivier Festor |
Integrated Network Management | 3 |
| 2011 | A broad-spectrum strategy for runtime risk management in VoIP enterprise architecturesabstractTelephony over IP (ToIP) has known a large scale deployment and is supported by the standardization of dedicated signalling protocols. This service is less confined than traditional telephony and is exposed to multiple security attacks. In the meantime, protection mechanisms may seriously impact on its performance. Risk management provides new opportunities for dynamically controlling the service exposure while maintaining low security costs. We propose in this paper a broad-spectrum strategy for runtime risk management in VoIP networks and services. We first analyse and model VoIP attacks based on their observability properties. We then generalize a runtime risk model capable of automatically assessing and treating risks based on dynamic safeguards. In particular, we quantify the potentiality of VoIP attacks and the induced risks with respect to their observability. We evaluate the benefits as well as the limits of our solution through an implementation prototype and an extensive set of simulations. Oussema Dabbebi, Rémi Badonnel, Olivier Festor |
Integrated Network Management | 3 |
| 2011 | PTF: Passive Temporal FingerprintingabstractWe describe in this paper a tool named PTF (Passive and Temporal Fingerprinting) for fingerprinting network devices. The objective of device fingerprinting is to uniquely identify device types by looking at captured traffic from devices implementing that protocol. The main novelty of our approach consists in leveraging both temporal and behavioral features for this purpose. The key contribution is a fingerprinting scheme, where individual fingerprints are represented by tree-based temporal finite state machines. We have developed a fingerprinting scheme that leverages supervised learning approaches based on support vector machines for this purpose. Jérôme François, Humberto J. Abdelnur, Radu State, Olivier Festor |
Integrated Network Management | 4 |
| 2011 | YANG-based configuration modeling - The SecSIP IPS case study -abstractWe present our experience with the development of an XML-based configuration model for an Intrusion Prevention System (IPS) dedicated to the Session Initiation Protocol (SIP) used in voice over IP signaling. In previous works [AL-IM09, AL-NOMS10] we have presented the SecSIP framework, a prevention system for SIP-based networks, which adopts a rule-based approach for specifying preventions on SIP protocol activities to stop attacks exploiting known vulnerability before reaching their targets. The SecSIP framework relies on a proprietary language called VeTo to express the prevention rules. SecSIP uses a plain text configuration file in which specifications are authored and managed manually. While extending the deployment of the framework beyond our own lab, support for remote configuration was required. Given the promise of Netconf, we naturally turned our investigations towards this protocol and embraced the YANG data-modeling framework. In this paper we present the modeling result on the SecSIP configuration interface and share our experience with both YANG and Netconf. The first part of the paper is dedicated to the description of the data to be modeled, namely VeTo policies. The second part presents the Yang model built for VeTo policies and the Netconf framework put in place. Lessons learned during both modeling and coding phases are presented in a third part of the presentation. Finally some conclusions are given and future work is outlined. Abdelkader Lahmadi, Emmanuel Nataf, Olivier Festor |
Integrated Network Management | 3 |
| 2011 | Content pollution quantification in large P2P networks : A measurement study on KADabstractContent pollution is one of the major issues affecting P2P file sharing networks. However, since early studies on FastTrack and Overnet, no recent investigation has reported its impact on current P2P networks. In this paper, we present a method and the supporting architecture to quantify the pollution of contents in the KAD network. We first collect information on many popular files shared in this network. Then, we propose a new way to detect content pollution by analyzing all filenames linked to a content with a metric based on the Tversky index and which gives very low error rates. By analyzing a large number of popular files, we show that 2/3 of the contents are polluted, one part by index poisoning but the majority by a new, more dangerous, form of pollution that we call index falsification. Guillaume Montassier, Thibault Cholez, Guillaume Doyen, Rida Khatoun, Isabelle Chrisment, Olivier Festor |
Peer-to-Peer Computing | 6 |
| 2011 | Using decision trees for generating adaptive SPIT signaturesabstractWith the spread of new and innovative Internet services such as SIP-based communications, the challenge of protecting and defending these critical applications has been raised. In particular, SIP firewalls attempt to filter the signaling unwanted activities and attacks based on the knowledge of the SIP protocol. Optimizing the SIP firewall configuration at real-time by selecting the best filtering rules is problematic because it depends on both natures of the legal traffic and the unwanted activities. More precisely, we do not know exactly how the unwanted activities are reflected in the SIP messages and in what they differ from the legal ones. In this paper, we address the case of Spam over Internet Telephony (SPIT) mitigation. Mohamed Nassar 0001, Sylvain Martin, Guy Leduc, Olivier Festor |
SIN | 4 |
| 2011 | A survey on fraud and service misuse in voice over IP (VoIP) networks
Yacine Rebahi, Mohamed Nassar 0001, Thomas Magedanz, Olivier Festor |
Inf. Secur. Tech. Rep. | 4 |
| 2010 | Automated and secure IPv6 configuration in enterprise networksabstractOver the last decade, IPv6 has established itself as the most mature network protocol for the future Internet. Its recent deployment in core networks of operators, its availability to end customers of multiple ISPs together with the availability of native access to large services like Google assess the increasing penetration of IPv6. While its deployment from the inside of the network leading to the edges is successful, the transition remains an issue today for many enterprises which see it as a tedious and error prone task for network administrators. To fill this gap, we present the necessary algorithms and provide the supporting tools to enable this transition to become automatic. Based on a model of an IPv4 network, we describe the algorithms to build an optimized IPv6 adressing scheme and to automatically generate the adequate security plan as well as the corresponding configurations for the different devices in the network. Frédéric Beck, Olivier Festor, Isabelle Chrisment, Ralph E. Droms |
CNSM | 2 |
| 2010 | Risk management in VoIP infrastructures using support vector machinesabstractTelephony over IP is exposed to multiple security threats. Conventional protection mechanisms do not fit into the highly dynamic, open and large-scale settings of VoIP infrastructures, and may significantly impact on the performance of such a critical service. We propose in this paper a runtime risk management strategy based on anomaly detection techniques for continuously adapting the VoIP service exposure. This solution relies on support vector machines (SVM) and exploits dynamic security safeguards to reduce risks in a progressive manner. We describe how SVM parameters can be integrated into a runtime risk model, and show how this framework can be deployed into an Asterisk VoIP server. We evaluate the benefits and limits of our solution through a prototype and an extensive set of experimental results. Mohamed Nassar 0001, Oussema Dabbebi, Rémi Badonnel, Olivier Festor |
CNSM | 4 |
| 2010 | Monitoring and Controlling Content Access in KADabstractWe propose a new distributed architecture that aims to investigate and control the spread of contents in the KAD P2P network through the indexation of keywords and files. Our solution can control the DHT at a local level with a new strategy bypassing the Sybil attack protections inserted in KAD. For the targeted DHT entries, we can monitor all requests emitted by the peers, from the initial content publication or search, to the final download request of fake files, assessing accurately peers interest to access it. We demonstrate the efficiency of our approach through experiments performed on the worldwide KAD network. Thibault Cholez, Isabelle Chrisment, Olivier Festor |
ICC | 3 |
| 2010 | Multi-modeling and Co-simulation-Based Mobile Ubiquitous Protocols and Services Development and Assessment
Tom Leclerc, Julien Siebert, Vincent Chevrier, Laurent Ciarletta, Olivier Festor |
MobiQuitous | 5 |
| 2010 | Automated runtime risk management for voice over IP networks and servicesabstractVoice over IP (VoIP) has become a major paradigm for providing telephony services at a lower cost and with a higher flexibility. VoIP infrastructures are however exposed to multiple security issues both inherited from the IP layer and specific to the application layer. In the meantime, protection mechanisms are available but may seriously impact on the continuity and quality of such critical services. We propose in this paper an automated risk management schema for continuously adapting VoIP equipment exposure by activating security safeguards in a dynamic and progressive manner. We describe the architecture supporting our solution, the considered risk model taking into account VoIP properties and the algorithms for restricting and relaxing the risk level of the VoIP service at runtime. The benefits and limits of our solution are evaluated through an implementation prototype and an extensive set of experimental results in the case scenario of SPIT attacks. Oussema Dabbebi, Rémi Badonnel, Olivier Festor |
NOMS | 3 |
| 2010 | VeTo: An exploit prevention language from known vulnerabilities in SIP servicesabstractWe present VeTo a language to specify protection rules for VoIP systems, supported by the SecSip prevention framework. VeTo offers a unique way to specify both vulnerabilities and countermeasures to protect SIP services against known vulnerabilities. We illustrate the applicability of the language through the specification of several known attacks and assess its efficiency through a target testbed. Abdelkader Lahmadi, Olivier Festor |
NOMS | 2 |
| 2010 | End-to-end YANG-based configuration managementabstractNetworked resources are of increasing complexity and have to be configured properly to guarantee their operation. Within the IETF, current efforts are focused on both a protocol and a data model definition language for configuration management. The NETCONF protocol describes the communication between devices to be configured and configuration applications. NETCONF does not describe how configuration data is represented. This is addressed by the YANG data modeling language, the emerging proposal of the netmod standard working group. Emmanuel Nataf, Olivier Festor |
NOMS | 2 |
| 2010 | WiMFlow: a distributed, self-adaptive architecture for flow monitoring in Wireless Mesh NetworksabstractWe present WiMFlow, a dynamic and self-organized flow monitoring framework in Wireless Mesh Networks. The protocol allows for an autonomic organization of the probes, with the goal of monitoring all the flows in the backbone of the mesh network accurately and robustly, while minimizing the overhead introduced by the monitoring architecture. A new mechanism that adapts the control messages emission interval to changes in the topology is introduced to keep the cost of the monitoring overlay low. The proposed mechanism is described and the performance of the monitoring framework is evaluated by simulation and experiments on a small scale wireless mesh network testbed. Cristian Popi, Olivier Festor |
NOMS | 2 |
| 2010 | Improving Fuzz Testing Using Game TheoryabstractWe propose a game theoretical model for fuzz testing, consisting in generating unexpected input to search for software vulnerabilities. As of today, no performance guarantees or assessment frameworks for fuzzing exist. Our paper addresses these issues and describes a simple model that can be used to assess and identify optimal fuzzing strategies, by leveraging game theory. In this context, payoff functions are obtained using a tainted data analysis and instrumentation of a target application to assess the impact of different fuzzing strategies. Sheila Becker, Humberto J. Abdelnur, Jorge Lucángeli Obes, Radu State, Olivier Festor |
NSS | 5 |
| 2010 | A Framework for Monitoring SIP Enterprise NetworksabstractIn this paper we aim to enable security within SIP enterprise domains by providing monitoring capabilities at three levels: the network traffic, the server logs and the billing records. We propose an anomaly detection approach based on appropriate feature extraction and one-class Support Vector Machines (SVM). We propose methods for anomaly/attack type classification and attack source identification. Our approach is validated through experiments on a controlled test-bed using a customized normal traffic generation model and synthesized attacks. The results show promising performances in terms of accuracy, efficiency and usability. Mohamed Nassar 0001, Radu State, Olivier Festor |
NSS | 3 |
| 2010 | Machine Learning Techniques for Passive Network InventoryabstractBeing able to fingerprint devices and services, i.e., remotely identify running code, is a powerful service for both security assessment and inventory management. This paper describes two novel fingerprinting techniques supported by isomorphic based distances which are adapted for measuring the similarity between two syntactic trees. The first method leverages the support vector machines paradigm and requires a learning stage. The second method operates in an unsupervised manner thanks to a new classification algorithm derived from the ROCK and QROCK algorithms. It provides an efficient and accurate classification. We highlight the use of such classification techniques for identifying the remote running applications. The approaches are validated through extensive experimentations on SIP (Session Initiation Protocol) for evaluating the impact of the different parameters and identifying the best configuration before applying the techniques to network traces collected by a real operator. Jérôme François, Humberto J. Abdelnur, Radu State, Olivier Festor |
IEEE Trans. Netw. Serv. Manag. | 4 |
| 2009 | VoIP Malware: Attack Tool & Attack ScenariosabstractWith the appearance of new Internet services like Voice over IP and IP television, malwares are in the way to update and extend their targets. In this paper, we discuss the emergence of a new generation of malwares attacking VoIP infrastructures and services. Such malwares constitute a real threat to the currently deployed VoIP architectures without strong security measures in place. We present one implemented environment that can be used to evaluate such attacks. Our "VoIP bots" support a wide set of attacks ranging from SPIT to DDoS and are tested against several VoIP platforms. Mohamed Nassar 0001, Radu State, Olivier Festor |
ICC | 3 |
| 2009 | Monitoring and counter-profiling for Voice over IP networks and servicesabstractVoice over IP (VoIP) has become a major paradigm for providing lower operational costs and higher flexibility in networks and services. VoIP infrastructures are however facing multiple security issues. In particular, monitoring methods and techniques can be applied to VoIP traffic in order to profile and track network users. We present in this paper a counter-measure strategy for preventing VoIP profiling. We propose two functional architectures with different noise generation functions in order to dynamically generate fake VoIP messages and deteriorate the profiling performances. We quantify the benefits and limits of our approach through an implementation prototype and the analysis of experimental results obtained in the case scenario of profiling methods based on principal component analysis (PCA). Rémi Badonnel, Olivier Festor, Khaled Hamlaoui |
Integrated Network Management | 2 |
| 2009 | Performance of network and service monitoring frameworksabstractThe efficiency and the performance of management systems is becoming a hot research topic within the networks and services management community. This concern is due to the new challenges of large scale managed systems, where the management plane is integrated within the functional plane and where management activities have to carry accurate and up-to-date information. We defined a set of primary and secondary metrics to measure the performance of a management approach. Secondary metrics are derived from the primary ones and quantifies mainly the efficiency, the scalability and the impact of management activities. To validate our proposals, we have designed and developed a benchmarking platform dedicated to the measurement of the performance of a JMX manager-agent based management system. The second part of our work deals with the collection of measurement data sets from our JMX benchmarking platform. We mainly studied the effect of both load and the number of agents on the scalability, the impact of management activities on the user perceived performance of a managed server and the delays of JMX operations when carrying variables values. Our findings show that most of these delays follow a Weibull statistical distribution. We used this statistical model to study the behavior of a monitoring algorithm proposed in the literature, under heavy tail delays distribution. In this case, the view of the managed system on the manager side becomes noisy and out of date. Abdelkader Lahmadi, Laurent Andrey, Olivier Festor |
Integrated Network Management | 3 |
| 2009 | SecSip: A stateful firewall for SIP-based networksabstractSIP-based networks are becoming the de-facto standard for voice, video and instant messaging services. Being exposed to many threats while playing an major role in the operation of essential services, the need for dedicated security management approaches is rapidly increasing. In this paper we present an original security management approach based on a specific vulnerability aware SIP stateful firewall. Through known attack descriptions, we illustrate the power of the configuration language of the firewall which uses the capability to specify stateful objects that track data from multiple SIP elements within their lifetime. We demonstrate through measurements on a real implementation of the firewall its efficiency and performance. Abdelkader Lahmadi, Olivier Festor |
Integrated Network Management | 2 |
| 2009 | Automated Behavioral Fingerprinting
Jérôme François, Humberto J. Abdelnur, Radu State, Olivier Festor |
RAID | 4 |
| 2008 | Towards malware inspired management frameworksabstractScalability is a real challenge for network management due to the increase of the devices to be managed and their various locations. A potential solution is based on botnets basically used by attackers. To prove the efficiency of such a system, a model is needed. Since in a previous paper we propose an IRC botnet model, in this paper we introduce two kinds of P2P models, evaluate them and compare the three different models to determine a practicable solution for network management. Jérôme François, Radu State, Olivier Festor |
NOMS | 3 |
| 2008 | A scheme for dynamic monitoring and logging of topology information in Wireless Mesh NetworksabstractWe propose a distributed monitoring scheme for an ad-hoc/mesh network topology, and design a distributed hash table based peer-to-peer system to log the topology information. A manager can rebuild a model of the network topology at any time in the past of its history by querying any node in the network. Merging and splitting of the monitoring overlays over time are supported by our protocol. Cristian Popi, Olivier Festor |
NOMS | 2 |
| 2008 | Advanced Network Fingerprinting
Humberto J. Abdelnur, Radu State, Olivier Festor |
RAID | 3 |
| 2008 | Monitoring SIP Traffic Using Support Vector Machines
Mohamed Nassar 0001, Radu State, Olivier Festor |
RAID | 3 |
| 2008 | Self-configurable fault monitoring in ad-hoc networks
Rémi Badonnel, Radu State, Olivier Festor |
Ad Hoc Networks | 3 |
| 2007 | A model for checking consistency in access control policies for network managementabstractThis paper addresses the consistency of heterogeneous device access control in the network management area. It addresses well-know network management frameworks like SNMP (v3), CLI, Netconf and the lesser known TR-069 proposed in the framework of ADSL operators. For each of these, a formal definition of the access control model is proposed as well as the conversion towards a unified Role-Based Access Control model. Next, we show how to compare roles and permissions between the generated access control policies and to answer to questions like: which policy is more permissive, what are the common privileges between a set of roles? Vincent Cridlig, Radu State, Olivier Festor |
Integrated Network Management | 3 |
| 2007 | VoIP Honeypot ArchitectureabstractVoice over IP (VoIP) or telephony services over Internet announces a new revolution in the telecommunication world tor its management simplicity and cost reduction. VoIP security extends the existent risk range of IP protocols and infrastructures and introduces new attacks as well. Threats identification and standardization, secure signaling and media architectures, as well as intrusion detection and prevention mechanisms are currently under debate in the research community. We propose in this article a SIP (Session Initiation Protocol) specific honeypot We describe its design and implementation. We detail the inference mechanism which classifies the received messages. We show how the model investigates about a received call and raises an appropriate conclusion. Mohamed Nassar 0001, Radu State, Olivier Festor |
Integrated Network Management | 3 |
| 2007 | A Probabilistic Approach for Managing Mobile Ad-Hoc NetworksabstractA pure management approach where all the nodes are managed at any time is too strict for mobile ad-hoc networks. Instead of addressing the management of the whole network, we propose a probabilistic scheme where only a subset of nodes is managed in order to provide a light-weight and efficient management. These nodes are determined based on their network behavior to favor subsets of well connected and network participating nodes. With respect to such a selective management scheme, we derive probabilistic guarantees on the percentage of nodes to be managed. Our contribution is centered on a distributed self-organizing management algorithm at the application layer, its efficient deployment into a management architecture and on a comprehensive simulation study. We will show how to organize the management plane by extracting spatio-temporal components and by selecting manager nodes with several election mechanisms based on degree centrality, eigenvector centrality and K-means paradigm. Rémi Badonnel, Radu State, Olivier Festor |
IEEE Trans. Netw. Serv. Manag. | 3 |
| 2006 | Fault Monitoring in Ad-Hoc Networks Based on Information Theory
Rémi Badonnel, Radu State, Olivier Festor |
Networking | 3 |
| 2006 | Probabilistic Management of Ad-Hoc NetworksabstractThis paper proposes a new management approach for ad-hoc networks based on probabilistic guarantees. Instead of addressing the management of the whole network, we propose a scheme where a subset of nodes is managed in order to provide a light-weight and reliable management. These nodes are determined based on their network behavior to favor subsets of well connected and network participating nodes. With respect to such a selective management scheme, we derive probabilistic guarantees on the percentage of nodes to be managed. Our contribution is centered on a distributed management self-organizing algorithm at the application layer, its efficient deployment into a management architecture as well as on a comprehensive simulation study Rémi Badonnel, Radu State, Olivier Festor |
NOMS | 3 |
| 2006 | A VoIP Security Management Architecture
Vincent Cridlig, Humberto J. Abdelnur, Radu State, Olivier Festor |
NOMS | 4 |
| 2006 | Role-Based Access Control for XML enabled multi-protocol management gatewaysabstractWhile security is often supported in standard management frameworks, security is of major importance in the management plane. In this paper we address the provisioning of a security “continuum” for management frameworks based on multi-protocol gateways. We provide an in depth security extension of such a gateway using the Role Based Access Control paradigm and show how to integrate our approach within a broader XML-based management framework. Two case studies are investigated: while the first one proposes to map an XML-based RBAC policy to SNMP access control model, the second one maps the same policy to CLI security levels. The target objective is to provide consistent access control policies not only locally on each device whatever be the network management framework but also globally through the managed domain. Vincent Cridlig, Radu State, Olivier Festor |
IEEE Trans. Netw. Serv. Manag. | 3 |
| 2005 | Management of mobile ad-hoc networks: evaluating the network behaviorabstractThe increasing interest in deploying wireless networks without fixed infrastructure, based on ad-hoc networking, raises new challenges towards monitoring and managing them to provide optimal performance. We propose in this paper a management architecture based on filtering and graph dependency analysis to evaluate the behavior of mobile ad-hoc networks. We apply an analytical method based on contrast filtering to determine network traffic patterns such as routing paths and a second method based on dependency graphs to estimate node influence in the ad-hoc network. Rémi Badonnel, Radu State, Olivier Festor |
Integrated Network Management | 3 |
| 2005 | An integrated security framework for XML based managementabstractThis paper proposes an integrated security framework for XML based management in large enterprise networks. Our security framework extends the traditional role based access control model with a cryptographic mechanism allowing efficient updates of the roles to user associations and its integration within a security framework for XML based management, where access control per managed object, confidentiality, and integrity are tightly bound. Vincent Cridlig, Radu State, Olivier Festor |
Integrated Network Management | 3 |
| 2005 | Efficient Clustering for Multicast Key Distribution in MANETs
Mohamed Salah Bouassida, Isabelle Chrisment, Olivier Festor |
NETWORKING | 3 |
| 2004 | An Enhanced Hybrid Key Management Protocol for Secure Multicast in Ad Hoc Networks
Mohamed Salah Bouassida, Isabelle Chrisment, Olivier Festor |
NETWORKING | 3 |
| 2004 | An extensible agent toolkit for device managementabstractThe advent of multiple connected and interoperating devices is becoming almost commonplace in the modern lifestyle. The management of these devices is an important asset for providing acceptable services to end users. Novel approaches are being developed that respect the communication, processing and power capacities of these limited devices. One of these approaches is the SyncML Device Management. in this paper, we present an open-source agent toolkit built around the SyncML model and evaluate the performance and cost of this approach in the context of limited devices supposed to host management agents. Radu State, Olivier Festor, Benjamin Zores |
NOMS (1) | 2 |
| 2003 | An SMIng-centric Proxy Agent for Integrated Monitoring and Provisioning
Emmanuel Nataf, Olivier Festor, Guillaume Doyen |
Integrated Network Management | 2 |
| 2003 | A Highly Distributed Dynamic IP Multicast Accounting and Management Framework
Hassen Sallay, Olivier Festor |
Integrated Network Management | 2 |
| 2003 | Management of Wireless Dynamic InfrastructuresabstractThe advent of multi-technologies networks offering ubiquitous services over advanced wireless network infrastructure implies new challenges to integrated management. In this paper, we address this issue in building an integrated management approach for wireless and mobile infrastructures. We especially analyze the particularities of this environment and proposing a management architecture based on application based overlay networks. Radu State, Olivier Festor |
ISCC | 2 |
| 2002 | A hierarchical topology discovery service for IPv6 networksabstractBeing able to maintain an accurate image of the network topology is one of the basic requirements of any management solution. While the solution to this requirement is not obvious in IPv4 networks, it becomes even harder when IPv6 is deployed. The huge address space which prevents the use of any iterative method is, among others, a feature that makes the problem challenging. We address this subject by (1) identifying the parts of algorithms already used in IPv4 networks that can be reused in IPv6 networks; (2) enumerating all protocol and addressing features of an IPv6 network that make this problem challenging;(3) proposing a novel application based solely on IPv6 services that can be used in any LAN management platform to ensure discovery of layer 3 topology. Isabelle Astic, Olivier Festor |
NOMS | 2 |
| 2002 | A distributed management platform for integrated multicast monitoringabstractWhile multicast services are becoming very attractive, their large deployment and commercial use are currently slowed down partly due to the lack of integrated management solutions for the components that participate in the operation of these services at various levels. Excellent standalone components exist today and are good candidates for integration. Joined and interfaced with standard management platforms, they cover most of the functions related to multicast service monitoring. We present the resulting architecture of one integration effort which combines two multicast management tools (Mrinfo and Mtrace) for topology monitoring, pre-event testing and in-situ monitoring. The proposed architecture is used for service level monitoring and data collection. Hassen Sallay, Radu State, Olivier Festor |
NOMS | 3 |
| 2001 | Managing Highly Dynamic Services Using Extended Temporal Network Information ModelsabstractDynamic virtual private networks (DVPN) are virtual private networks with a high degree of change in terms of membership, implying the necessity for fast reconfiguration and provisioning. Their management requires a time and evolution aware network information model capable to capture both temporal and aggregate information. Such a model is proposed in this paper. The resulting model is used in the framework of a programmable and active network based management platform associated with a DVPN service. The particular DVPN service is used in the context of live TV broadcast to the subscribed residential users. Radu State, Olivier Festor, Emmanuel Nataf |
Integrated Network Management | 2 |
| 2000 | COJ: a free CMIS compliant Java API and its various implementationsabstractDespite the potential advantages of the Java technology, very few experiments have been made so far on trying to provide an in depth integration of this technology with the TMN framework. To foster the experimentation of these advantages, we present a generic and free Java API developed for both OSI CMIS Manager and Agent sides. The main objective of this API is provide a solid basis for researchers and developers in order to allow large OSI as well as integration environment developments to take advantage of the Java technology combined with the OSI framework. Laurent Andrey, Olivier Festor, Nizar Ben Youssef |
NOMS | 2 |
| 2000 | A Java based implementation of a network level information model for the ATM/frame relay interconnectionabstractIn this paper, we illustrate the use of the Java technology to implement a network information model which captures the essence of ATM and frame relay interconnection. We show how the TMN concepts stay valid and how the existing and extended information models can be reused and implemented according to the TMN principles in a full Java environment. Radu State, Emmanuel Nataf, Olivier Festor |
NOMS | 3 |
| 2000 | JTMN: a Java-based TMN development and experimentation environmentabstractJava technology has largely entered the world of element, network, and service management and has undoubtedly proven useful in combination with the SNMP framework for both manager and agent side developments. However, very few experiments have been made so far trying to provide an in-depth integration of this technology within the TMN framework. In this paper we present a free software which offers a generic environment which provides a basis for reaching this integration. This environment, called J/sup TMN/, is composed of a set of Java software packages which enable both development and deployment of TMN compliant components. Not bound to any specific management platform and easily portable to any TMN system, its goal is to allow experimentation and deployment of more advanced features such as mobile agents, active network management, and advanced delegation in harmony with existing TMN approaches. Laurent Andrey, Olivier Festor, Emmanuel Nataf, Radu State |
IEEE J. Sel. Areas Commun. | 2 |
| 1999 | Integration of WBEM-based Management Agents in the OSI FrameworkabstractIn this paper, we propose a set of mappings and an implementation of an integration agent allowing WBEM-based agents implementing a CIM information model to be managed by OSI-based management platforms and applications. Extending existing integration approaches, this paper provides three original items that are the support of the CIM meta-model in an OSI agent, the mapping of relationships onto GRM specifications as well as a full Java-based implementation of the Q.adapter. Olivier Festor, Paul Festor, Nizar Ben Youssef, Laurent Andrey |
Integrated Network Management | 1 |
| 1997 | RelMan: A GRM-based Relationship Manager
Emmanuel Nataf, Olivier Festor, Laurent Andrey |
Integrated Network Management | 2 |
| 1996 | Executable TMN-specifications in TIMSabstractCurrent TMN-based information model standards take too long to specify, standardise, implement, test and introduce. The TMN-based Information Model Simulator-TIMS-explores the possibilities of reducing this development life cycle. The TIMS-vision foresees a formally executable specification of the behavior of object interfaces which should enable: (1) rapid-prototyping of TMN agent and manager functions and later allow for (2) the generation of function reference configurations as well as (3) the automatic derivation of test-suites based on the formal specifications. Rolf Eberhardt, Dominique Sidou, Olivier Festor, Sandro Mazziotta, Jacques Labetoulle |
NOMS | 3 |
| 1995 | MODE: a development environment for managed objects based on formal methods
Olivier Festor |
Integrated Network Management | 1 |
| 1993 | Formal Description of Managed Object Behavior - A Rule Based Approach
Olivier Festor, Georg Zörntlein |
Integrated Network Management | 1 |