EDBT 2026 Demo / reviewers in the wild / expert
Ludovic Mé
dblp:11/6852
· DBLP profile ↗
27ranked-venue papers
1as first author
2since 2021 · last 2023
0009-0002-1103-2430ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 21 · 1 first-author · 2 since 2021Computer networks · 4Human-computer interaction and ubiquitous computing · 1Theory of computation · 1Applied, interdisciplinary, general and emerging computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2023 | Towards Understanding Alerts raised by Unsupervised Network Intrusion Detection SystemsabstractThe use of Machine Learning for anomaly detection in cyber security-critical applications, such as intrusion detection systems, has been hindered by the lack of explainability. Without understanding the reason behind anomaly alerts, it is too expensive or impossible for human analysts to verify and identify cyber-attacks. Our research addresses this challenge and focuses on unsupervised network intrusion detection, where only benign network traffic is available for training the detection model. We propose a novel post-hoc explanation method, called AE-pvalues, which is based on the p-values of the reconstruction errors produced by an Auto-Encoder-based anomaly detection method. Our work identifies the most informative network traffic features associated with an anomaly alert, providing interpretations for the generated alerts. We conduct an empirical study using a large-scale network intrusion dataset, CICIDS2017, to compare the proposed AE-pvalues method with two state-of-the-art baselines applied in the unsupervised anomaly detection task. Our experimental results show that the AE-pvalues method accurately identifies abnormal influential network traffic features. Furthermore, our study demonstrates that the explanation outputs can help identify different types of network attacks in the detected anomalies, enabling human security analysts to understand the root cause of the anomalies and take prompt action to strengthen security measures. Maxime Lanvin, Pierre-François Gimenez, Yufei Han 0001, Frédéric Majorczyk, Ludovic Mé, Eric Totel |
RAID | 5 |
| 2022 | Errors in the CICIDS2017 Dataset and the Significant Differences in Detection Performances It Makes
Maxime Lanvin, Pierre-François Gimenez, Yufei Han 0001, Frédéric Majorczyk, Ludovic Mé, Eric Totel |
CRiSIS | 5 |
| 2020 | Sec2graph: Network Attack Detection Based on Novelty Detection on Graph Structured Data
Laetitia Leichtnam, Eric Totel, Nicolas Prigent, Ludovic Mé |
DIMVA | 4 |
| 2017 | STARLORD: Linked security data exploration in a 3D graphabstractIn this paper, we present a novel model and visualization approach for heterogeneous sources of data. We represent our data by using a model inspired by STIX. Then, we use clustering algorithms to select interesting information to explore in a visualization panel. The visualization is based on a 3D graph representation that highlights the link between malicious event and allows to focus on relevant security artifacts. We illustrate our approach with two case studies using datasets containing network capture of the wannacry attack. Laetitia Leichtnam, Eric Totel, Nicolas Prigent, Ludovic Mé |
VizSEC | 4 |
| 2013 | Intrusion detection in distributed systems, an approach based on taint markingabstractThis paper presents a new framework for distributed intrusion detection based on taint marking. Our system tracks information flows between applications of multiple hosts gathered in groups (i.e. sets of hosts sharing the same distributed information flow policy) by attaching taint labels to system objects such as files, sockets, Inter Process Communication (IPC) abstractions, and memory mappings. Labels are carried over the network by tainting network packets. A distributed information flow policy is defined for each group at the host level by labeling information and defining how users and applications can legally access, alter or transfer information towards other trusted or untrusted hosts. As opposed to existing approaches, where information is most often represented by two security levels (low/high, public/private etc.), our model identifies each piece of information within a distributed system, and defines their legal interaction in a fine-grained manner. Hosts store and exchange security labels in a peer to peer fashion, and there is no central monitor. Our IDS is implemented in the Linux kernel as a Linux Security Module (LSM) and runs standard software on commodity hardware with no required modification. The only trusted code is our modified operating system kernel. We finally present a scenario of intrusion in a web service running on multiple hosts, and show how our distributed IDS is able to report security violations at each host level. Christophe Hauser, Frédéric Tronel, Colin J. Fidge, Ludovic Mé |
ICC | 4 |
| 2009 | An Efficient Distributed PKI for Structured P2P NetworksabstractIn decentralized P2P networks, many security mechanisms still rely on a central authority. This centralization creates a single point of failure and does not comply with the P2P principles. We previously proposed a distributed PKI for P2P networks which allows to push security mechanisms to the edges of the network but relies on unaffordable maintenance operations using byzantine agreements. In this paper, we address this shortcoming and propose efficient maintenance operations without any agreements. Our improvements allow a real deployment of this P2P PKI. François Lesueur, Ludovic Mé, Valérie Viet Triem Tong |
Peer-to-Peer Computing | 2 |
| 2009 | Blare Tools: A Policy-Based Intrusion Detection System Automatically Set by the Security Policy
Laurent George 0002, Valérie Viet Triem Tong, Ludovic Mé |
RAID | 3 |
| 2009 | Policy-based intrusion detection in web applications by monitoring Java information flowsabstractThis article focuses on intrusion detection in systems using Web applications and COTS. We present a solution that combines policy-based intrusion detection and information flow control. We describe JBlare, an inline Java monitor that tracks inter-method flows in Java applications. This monitor collaborates with Blare, a monitor that tracks information flow in the whole system at the OS-level. The combination of these two detectors constitutes a policy-based Intrusion Detection System that can address a wide range of attacks. Guillaume Hiet, Valérie Viet Triem Tong, Ludovic Mé, Benjamin Morin |
Int. J. Inf. Comput. Secur. | 3 |
| 2008 | Policy-based intrusion detection in Web applications by monitoring Java information flowsabstractThis article focuses on intrusion detection in systems using Web applications and COTS. We present a solution that combines policy-based intrusion detection and information flow control. We describe JBlare, an inline Java monitor that tracks inter-method flows in Java applications. This monitor collaborates with Blare, a monitor that tracks information flow in the whole system at the OS-level. The combination of these two detectors constitutes a policy-based Intrusion Detection System that can address a wide range of attacks. Guillaume Hiet, Valérie Viet Triem Tong, Ludovic Mé, Benjamin Morin |
CRiSIS | 3 |
| 2008 | A sybilproof distributed identity management for P2P networksabstractStructured P2P networks are vulnerable to the sybil attack. In this attack, a misbehaving person generates a huge number of node identifiers and possibly chooses some of them in order to disrupt availability or integrity in the P2P network. In order to circumvent this attack, one person should be able to obtain only a limited set of identifiers and should not be able to choose them. Moreover, due to the distributed architecture of P2P networks, this limitation should not be managed by a centralized system. In this paper, we propose such a sybilproof distributed identity management system which is based on invitations, and thus rely on social relationships between users. François Lesueur, Ludovic Mé, Valérie Viet Triem Tong |
ISCC | 2 |
| 2008 | Anomaly Detection with Diagnosis in Diversified Systems using Information Flow Graphs
Frédéric Majorczyk, Eric Totel, Ludovic Mé, Ayda Saïdane |
SEC | 3 |
| 2006 | Time series modeling for IDS alert managementabstractIntrusion detection systems create large amounts of alerts. Significant part of these alerts can be seen as background noise of an operational information system, and its quantity typically overwhelms the user. In this paper we have three points to make. First, we present our findings regarding the causes of this noise. Second, we provide some reasoning why one would like to keep an eye on the noise despite the large number of alerts. Finally, one approach for monitoring the noise with reasonable user load is proposed. The approach is based on modeling regularities in alert flows with classical time series methods. We present experimentations and results obtained using real world data. Jouni Viinikka, Hervé Debar, Ludovic Mé, Renaud Séguier |
AsiaCCS | 3 |
| 2006 | A Dependable Intrusion Detection Architecture Based on Agreement Services
Michel Hurfin, Jean-Pierre Le Narzul, Frédéric Majorczyk, Ludovic Mé, Ayda Saïdane, Eric Totel, Frédéric Tronel |
SSS | 4 |
| 2005 | COTS Diversity Based Intrusion Detection and Application to Web Servers
Eric Totel, Frédéric Majorczyk, Ludovic Mé |
RAID | 3 |
| 2004 | A Serial Combination of Anomaly and Misuse IDSes Applied to HTTP TrafficabstractCombining an "anomaly" and a "misuse" IDSes offers the advantage of separating the monitored events between normal, intrusive or unqualified classes (i.e. not known as an attack, but not recognize as safe either). In this article, we provide a framework to systematically reason about the combination of anomaly and misuse components. This framework applied to Web servers lead us to propose a serial architecture, using a drastic anomaly component with a sensitive misuse component. This architecture provides the operator with better qualification of the detection results, raises lower amount of false alarms and unqualified events. Elvis Tombini, Hervé Debar, Ludovic Mé, Mireille Ducassé |
ACSAC | 3 |
| 2004 | A fully distributed IDS for MANETabstractIn This work we propose a new distributed intrusion detection system (IDS) designed for mobile ad hoc network (MANET) environments. The complete distribution of the intrusion detection process is the salient feature of our proposition: distribution is not restricted to data collection but also applied to execution of the detection algorithm and alert correlation. Each node in the MANET runs a local IDS (LIDS) that cooperates with others LIDS. A mobile agent framework is used to preserve the autonomy of each LIDS while providing a flexible technique for exploring the natural redundancies in MANET to compensate for the dynamic state of wireless links between high mobility nodes. The proposed solution has been validated by actual implementation, which is described in the paper. Three attacks are presented as illustrative examples of the IDS mechanisms. Attack detection is formally described by specification of data collection, attack signatures associated with such data and alerts generation and correlation. Experiments exhibit fairly good results, the attacks being collaboratively detected in real-time. Ricardo Staciarini Puttini, Jean-Marc Percher, Ludovic Mé, Rafael Timóteo de Sousa Júnior |
ISCC | 3 |
| 2004 | A Language Driven IDS for Event and Alert Correlation
Eric Totel, Bernard Vivinis, Ludovic Mé |
SEC | 3 |
| 2003 | Experimenting with a Policy-Based HIDS Based on an Information Flow Control ModelabstractIn 2002 we proposed a model for policy-based intrusion detection, based on information flow control. In the present paper, we show its applicability and effectiveness on a standard OS. We present results of two set of experiments, one carried out in a completely controlled environment, the other on an operational server with real network traffic. Our results show that the model fulfills its goals and serves as a successful runtime policy-based intrusion detector. Jacob Zimmermann, Ludovic Mé, Christophe Bidan |
ACSAC | 2 |
| 2003 | An Improved Reference Flow Control Model for Policy-Based Intrusion Detection
Jacob Zimmermann, Ludovic Mé, Christophe Bidan |
ESORICS | 2 |
| 2003 | A Modular Architecture for Distributed IDS in MANET
Ricardo Staciarini Puttini, Jean-Marc Percher, Ludovic Mé, Olivier Camp, Rafael Timóteo de Sousa Júnior, Cláudia Jacy Barenco Abbas, Luis Javier García Villalba |
ICCSA (3) | 3 |
| 2003 | Fast Multipattern Search Algorithms for Intrusion Detection
Josué Kuri, Gonzalo Navarro 0001, Ludovic Mé |
Fundam. Informaticae | 3 |
| 2002 | M2D2: A Formal Data Model for IDS Alert Correlation
Benjamin Morin, Ludovic Mé, Hervé Debar, Mireille Ducassé |
RAID | 2 |
| 2002 | Introducing Reference Flow Control for Detecting Intrusion Symptoms at the OS Level
Jacob Zimmermann, Ludovic Mé, Christophe Bidan |
RAID | 2 |
| 2001 | ADeLe: An Attack Description Language for Knowledge-Based Intrusion Detection
Cédric Michel, Ludovic Mé |
SEC | 2 |
| 2000 | A Pattern Matching Based Filter for Audit Reduction and Fast Detection of Potential Intrusions
Josué Kuri, Gonzalo Navarro 0001, Ludovic Mé, Laurent Heye |
Recent Advances in Intrusion Detection | 3 |
| 2000 | Flexible Intrusion Detection Using Variable-Length Behavior Modeling in Distributed Environment: Application to CORBA Objects
Zakia Marrakchi, Ludovic Mé, Bernard Vivinis, Benjamin Morin |
Recent Advances in Intrusion Detection | 2 |
| 1993 | Security Audit Trail Analysis Using Genetic Algorithms
Ludovic Mé |
SAFECOMP | 1 |