Frédéric Majorczyk

dblp:07/1233 · DBLP profile ↗
← Back
19ranked-venue papers
2as first author
8since 2021 · last 2026
0009-0008-9558-397XORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 16 · 2 first-author · 7 since 2021Human-computer interaction and ubiquitous computing · 2Artificial intelligence and machine learning · 1 · 1 since 2021Systems, architecture and hardware · 1Databases, data management, data science and information retrieval · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
YearPublicationVenuePosition
2026 GRAAL: GRAph-based Analysis of Logs for Advanced AI-based Intrusion Detection Systems
Fanny Dijoud, Pierre-François Gimenez, Michel Hurfin, Frédéric Majorczyk, Barbara Pilastre
EuroS&P4
2026 Graph2TTP: Knowledge Graph-Guided Paragraph-Level TTPs Identification from Cyber Threat Intelligence Reports
Patrick Zounon, Yufei Han 0001, Michel Hurfin, Frédéric Majorczyk
SECRYPT (1)4
2025 CasinoLimit: An Offensive Dataset Labeled with MITRE ATT&CK Techniques
abstract
Cybersecurity exercises are a common way to train and evaluate the skills of cybersecurity professionals. These exercises also provide a unique opportunity to generate datasets with realistic attack traces on non-sensitive systems. Nevertheless, the collected logs are unlabeled, and deciding which logs are related to pentesters is a difficult problem. In this paper, we present a novel methodology to label efficiently both system and network logs using MITRE ATT&CK techniques. To demonstrate the effectiveness of our approach, we introduce CasinoLimit, a dataset generated from a pentest exercise that has been played by 114 participants where we collected 540 GB of attack data. We apply our methodology to accurately label these logs with a semiautomatic approach: labels are inferred from the shell sessions and propagated to the network sessions, and eventually corrected by a junior analyst. An expert analyst has manually reviewed all the labels that have been computed to ensure the quality of the labeling process. The results of the pentest exercise are deeply discussed. We show the variability of players’ behaviors and that players can be distinguished by their command line habits. In addition, the high level of granularity of labels coupled with the number of participants enables multiple other applications. With this paper, we release the full dataset and the associated labeling tool, Manatee, which can be used to browse the logs and labels. To support the generalization of our approach, we made it possible to load other datasets with this tool.
Sébastien Kilian, Valérie Viet Triem Tong, Jean-François Lalande, Frédéric Majorczyk, Alexandre Sanchez, Natan Talon, Pierre-Victor Besson, Helene Orsini, Pierre Lledo, Pierre-François Gimenez
RAID4
2024 Modeling Analyst Intentions Using a Markov Chain for Investigative Action Recommendations
Romain Brisse, Simon Boche, Frédéric Majorczyk, Jean-François Lalande
IFIP Int. Conf. Digital Forensics3
2023 CERBERE: Cybersecurity Exercise for Red and Blue team Entertainment, REproducibility
abstract
Experimenting in cybersecurity requires manipulating reliable and realistic data. In particular, labelled data derived from the observation of a complete campaign is rarely available, due to its high sensitivity and the difficulty of accurately labelling datasets. This situation harms the reproducibility of research results and therefore to their impact. In this article, we present the CERBERE project that addresses this issue through a reproducible attack-defense exercise and a labelled dataset usable for research purposes. The attack-defense exercise is first composed of an exercise for red teamers automatically deployed with variable attack scenarios. Second, an exercise for blue teamers can be operated using the system and network logs generated during the attack phase. We provide with this article, the software to rebuild the infrastructure for red teamers. We share a labelled dataset where we spot the ground truth, i.e. the log lines that have been involved in the attacker’s actions.
Pierre-Victor Besson, Romain Brisse, Helene Orsini, Natan Talon, Jean-François Lalande, Frédéric Majorczyk, Alexandre Sanchez, Valérie Viet Triem Tong
IEEE Big Data6
2023 Towards Understanding Alerts raised by Unsupervised Network Intrusion Detection Systems
abstract
The use of Machine Learning for anomaly detection in cyber security-critical applications, such as intrusion detection systems, has been hindered by the lack of explainability. Without understanding the reason behind anomaly alerts, it is too expensive or impossible for human analysts to verify and identify cyber-attacks. Our research addresses this challenge and focuses on unsupervised network intrusion detection, where only benign network traffic is available for training the detection model. We propose a novel post-hoc explanation method, called AE-pvalues, which is based on the p-values of the reconstruction errors produced by an Auto-Encoder-based anomaly detection method. Our work identifies the most informative network traffic features associated with an anomaly alert, providing interpretations for the generated alerts. We conduct an empirical study using a large-scale network intrusion dataset, CICIDS2017, to compare the proposed AE-pvalues method with two state-of-the-art baselines applied in the unsupervised anomaly detection task. Our experimental results show that the AE-pvalues method accurately identifies abnormal influential network traffic features. Furthermore, our study demonstrates that the explanation outputs can help identify different types of network attacks in the detected anomalies, enabling human security analysts to understand the root cause of the anomalies and take prompt action to strengthen security measures.
Maxime Lanvin, Pierre-François Gimenez, Yufei Han 0001, Frédéric Majorczyk, Ludovic Mé, Eric Totel
RAID4
2022 Errors in the CICIDS2017 Dataset and the Significant Differences in Detection Performances It Makes
Maxime Lanvin, Pierre-François Gimenez, Yufei Han 0001, Frédéric Majorczyk, Ludovic Mé, Eric Totel
CRiSIS4
2022 Cross-domain alert correlation methodology for industrial control systems
Oualid Koucham, Stéphane Mocanu, Guillaume Hiet, Jean-Marc Thiriet, Frédéric Majorczyk
Comput. Secur.5
2018 Enhancing Collaboration Between Security Analysts in Security Operations Centers
Damien Crémilleux, Christophe Bidan, Frédéric Majorczyk, Nicolas Prigent
CRiSIS3
2016 VEGAS: Visualizing, exploring and grouping alerts
abstract
The large quantities of alerts generated by intrusion detection systems (IDS) make very difficult to distinguish on a network real threats from noise. To help solving this problem, we propose VEGAS, an alerts visualization and classification tool that allows first line security operators to group alerts visually based on their principal component analysis (PCA) representation. VEGAS is included in a workflow in such a way that once a set of similar alerts has been collected and diagnosed, a filter is generated that redirects forthcoming similar alerts to other security analysts that are specifically in charge of this set of alerts, in effect reducing the flow of raw undiagnosed alerts.
Damien Crémilleux, Christophe Bidan, Frédéric Majorczyk, Nicolas Prigent
NOMS3
2015 Towards Self Adaptable Security Monitoring in IaaS Clouds
abstract
Traditional intrusion detection systems are not adaptive enough to cope with the dynamic characteristics of cloud-hosted virtual infrastructures. This makes them unable to address new cloud-oriented security issues. In this paper we introduce SAIDS, a self-adaptable intrusion detection system tailored for cloud environments. SAIDS is designed to re-configure its components based on environmental changes. A prototype of SAIDS is described.
Anna Giannakou, Louis Rilling, Jean-Louis Pazat, Frédéric Majorczyk, Christine Morin
CCGRID4
2014 Automatic generation of correlation rules to detect complex attack scenarios
abstract
In large distributed information systems, alert correlation systems are necessary to handle the huge amount of elementary security alerts and to identify complex multi-step attacks within the flow of low level events and alerts. In this paper, we show that, once a human expert has provided an action tree derived from an attack tree, a fully automated transformation process can generate exhaustive correlation rules that would be tedious and error prone to enumerate by hand. The transformation relies on a detailed description of various aspects of the real execution environment (topology of the system, deployed services, etc.). Consequently, the generated correlation rules are tightly linked to the characteristics of the monitored information system. The proposed transformation process has been implemented in a prototype that generates correlation rules expressed in an attack description language.
Erwan Godefroy, Eric Totel, Michel Hurfin, Frédéric Majorczyk
IAS4
2014 CORGI: combination, organization and reconstruction through graphical interactions
abstract
In this article, we present CORGI, a security-oriented log visualization tool that allows security experts to visually explore and link numerous types of log files through relevant representations and global filtering. The analyst can mark values as values of interest and then use these values to pursue the exploration in other log files, allowing him to better understand events and reconstruct attack scenarios. We present the user interface and interactions that ensure these capabilities and provide two use cases based on challenges from VAST and from the Honeynet project.
Christopher Humphries, Nicolas Prigent, Christophe Bidan, Frédéric Majorczyk
VizSEC4
2013 ELVIS: Extensible Log VISualization
abstract
In this article, we propose ELVIS, a security-oriented log visualization tool that allows security experts to visually explore numerous types of log files through relevant representations. When a log file is loaded into ELVIS, a summary view is displayed. This view is the starting point for exploring the log. The analyst can then choose to explore certain fields or sets of fields from the dataset. To that end, ELVIS selects relevant representations according to the fields chosen by the analyst for display.
Christopher Humphries, Nicolas Prigent, Christophe Bidan, Frédéric Majorczyk
VizSEC4
2011 Detecting Illegal System Calls Using a Data-Oriented Detection Model
Jonathan-Christofer Demay, Frédéric Majorczyk, Eric Totel, Frédéric Tronel
SEC2
2009 Automated Instruction-Set Randomization for Web Applications in Diversified Redundant Systems
abstract
The use of diversity and redundancy in the security domain is an interesting approach to prevent or detect intrusions. Many researchers have proposed architectures based on those concepts where diversity is either natural or artificial. These architectures are based on the architecture of N-version programming and were often instantiated for web servers without taking into account the web application(s) running on those. In this article, we present a solution to protect the web applications running on this kind of architectures in order to detect and tolerate code injection intrusions. Our solution consists in creating diversity in the web application scripts by randomizing the language understood by the interpreter so that an injected code can not be executed by all the servers. We also present the issues related to the automatization of our solution and present some solutions to tackle these issues.
Frédéric Majorczyk, Jonathan-Christofer Demay
ARES1
2008 Anomaly Detection with Diagnosis in Diversified Systems using Information Flow Graphs
Frédéric Majorczyk, Eric Totel, Ludovic Mé, Ayda Saïdane
SEC1
2006 A Dependable Intrusion Detection Architecture Based on Agreement Services
Michel Hurfin, Jean-Pierre Le Narzul, Frédéric Majorczyk, Ludovic Mé, Ayda Saïdane, Eric Totel, Frédéric Tronel
SSS3
2005 COTS Diversity Based Intrusion Detection and Application to Web Servers
Eric Totel, Frédéric Majorczyk, Ludovic Mé
RAID2