EDBT 2026 Demo / reviewers in the wild / expert
Gilles Guette
dblp:15/2356
· DBLP profile ↗
15ranked-venue papers
3as first author
7since 2021 · last 2025
0000-0002-8051-0013ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 7 · 2 first-author · 4 since 2021Computer networks · 5 · 1 first-author · 2 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Overlapping Data in Network Protocols: Bridging OS and NIDS Reassembly Gap
Lucas Aubard, Johan Mazel, Gilles Guette, Pierre Chifflier |
DIMVA (2) | 3 |
| 2025 | Overlapping IPv4, IPv6, and TCP data: exploring errors, test case context, and multiple overlaps inside network stacks and NIDSes with PyrolyseabstractIP fragmentation and TCP segmentation allow for splitting large data packets into smaller ones, e.g., for transmission across network links of limited capacity. These mechanisms permit complete or partial overlaps with different data on the overlapping portions. IPv4, IPv6, and TCP reassembly policies, i.e., the data chunk preferences that depend on the overlap types, differ across protocol implementations. This leads to vulnerabilities, as NIDSes may interpret the packet differently from the monitored host OSes. Some NIDSes, such as Suricata or Snort, can be configured so that their policies are consistent with the monitored OSes. The first contribution of the paper is pyrolyse, an audit tool that exhaustively tests and describes the reassembly policies of various IP and TCP implementation types. This tool ensures that implementations reassemble overlapping chunk sequences without errors. The second contribution is the analysis of pyrolyse artifacts. We first show that the reassembly policies are much more diverse than previously thought. Indeed, by testing all the overlap possibilities for $n \leq 3$ test case chunks and different testing scenarios, we observe 15 different behaviors out of 23 tested implementations depending on the protocol. Second, we report eight errors impacting one OS, two NIDSes, and two embedded stacks, which can lead to security issues such as NIDS pattern-matching bypass or DoS attacks. A CVE [1] was assigned to a NIDS error. Finally, we show that implemented IP and TCP policies obtained through chunk pair testing are usually inconsistent with the observed triplet reassemblies. Therefore, contrary to what they currently do, NIDSes or other network traffic analysis tools should not apply $n=2$ pair policies when the number of overlapping chunks exceeds two. Lucas Aubard, Johan Mazel, Gilles Guette, Pierre Chifflier |
RAID | 3 |
| 2024 | SCWAD: Automated Pentesting of Web ApplicationsabstractInternational audience Natan Talon, Valérie Viet Triem Tong, Gilles Guette, Yufei Han 0001, Youssef Laarouchi |
SECRYPT | 3 |
| 2023 | CVE representation to build attack positions graphsabstractIn cybersecurity, CVEs (Common Vulnerabilities and Exposures) are publicly disclosed hardware or software vulnerabilities. These vulnerabilities are documented and listed in the NVD database maintained by the NIST. Knowledge of the CVEs impacting an information system provides a measure of its level of security. This article points out that these vulnerabilities should be described in greater detail to understand how they could be chained together in a complete attack scenario. This article presents the first proposal for the CAPG format, which is a method for representing a CVE vulnerability, a corresponding exploit, and associated attack positions. Manuel Poisson, Valérie Viet Triem Tong, Gilles Guette, Frédéric Guihéry, Damien Crémilleux |
IEEE Big Data | 3 |
| 2022 | PWNJUTSU: A Dataset and a Semantics-Driven Approach to Retrace Attack CampaignsabstractIdentifying patterns in the modus operandi of attackers is an essential requirement in the study of Advanced Persistent Threats. Previous studies have been hampered by the lack of accurate, relevant, and representative datasets of current threats. System logs and network traffic captured during attacks on real companies’ information systems are the best data sources to build such datasets. Unfortunately, for apparent reasons of companies’ reputation, privacy, and security, such data is seldom available. This article proposes an alternative approach to such issues involved with collecting data. It first presents a formal model of an attacker’s tactical progression during their network propagation phase. Such a progression is expressed according to the attacker’s state, called muSE, which specifies their propagation area, collected secrets, and knowledge of the environment. The new model wields the operational semantics of attack techniques proposed in this article. The semantics formally define a transition relation between attackers’ states. Hence, it can be used to describe an entire attack scenario. This formalization allows the ability to describe the PWNJUTSU experiment unequivocally. In this experiment, 22 Red Teamers attacked the vulnerable infrastructure to compromise machines and steal secret flags. Each Red Teamer operated on a dedicated instance. Sensors captured system logs and network traffic on each of these instances. This article’s second contribution is the public release of the PWNJUTSU dataset. Aimad Berady, Mathieu Jaume, Valérie Viet Triem Tong, Gilles Guette |
IEEE Trans. Netw. Serv. Manag. | 4 |
| 2021 | Accurate Measurement of the Energy Consumption of Security Functions
Benoît Fournier, Valérie Viet Triem Tong, Gilles Guette |
SECRYPT | 3 |
| 2021 | From TTP to IoC: Advanced Persistent Graphs for Threat HuntingabstractDefenders fighting against Advanced Persistent Threats need to discover the propagation area of an adversary as quickly as possible. This discovery takes place through a phase of an incident response operation called Threat Hunting, where defenders track down attackers within the compromised network. In this article, we propose a formal model that dissects and abstracts elements of an attack, from both attacker and defender perspectives. This model leads to the construction of two persistent graphs on a common set of objects and components allowing for (1) an omniscient actor to compare, for both defender and attacker, the gap in knowledge and perceptions; (2) the attacker to become aware of the traces left on the targeted network; (3) the defender to improve the quality of Threat Hunting by identifying false-positives and adapting logging policy to be oriented for investigations. In this article, we challenge this model using an attack campaign mimicking APT29, a real-world threat, in a scenario designed by the MITRE Corporation. We measure the quality of the defensive architecture experimentally and then determine the most effective strategy to exploit data collected by the defender in order to extract actionable Cyber Threat Intelligence, and finally unveil the attacker. Aimad Berady, Mathieu Jaume, Valérie Viet Triem Tong, Gilles Guette |
IEEE Trans. Netw. Serv. Manag. | 4 |
| 2019 | SEER4US, Secured Energy Efficient Routing for UAV SwarmsabstractThis article introduces SEER4US a secured routing protocol designed for UAV swarm networks. SEER4US is the first protocol providing integrity of routing messages and authentication of their sender with low energy consumption for battery preservation. SEER4US prevents the UAV swarms from usual routing attacks enabled when routing messages are modified or replayed by nodes external to the swarm. SEER4US is an extension of the pro-active routing protocol OLSR designed for mobile ad-hoc networks. SEER4US is also inspired from TESLA, a protocol designed for stream signature allowing authentication of stream messages sender. After specifying SEER4US, we evaluate here the energy requirements of this protocol and we show that the use of lightweight cryptography allows a significant energy saving compared to traditional cryptographic schemes. Benoît Fournier, Gilles Guette, Valérie Viet Triem Tong, Jean-Louis Lanet |
WiMob | 2 |
| 2018 | Alternatives to Binary Routing Policies Applied to a Military MANET CoalitionabstractNew generation radio equipment, used by soldiers and vehicles on the battlefield, form ad hoc networks and specifically, Mobile Ad hoc NETworks (MANET). The battlefields where these equipment are deployed include a majority of coalition communication. Each group on the battleground may communicate with other members of the coalition and establish inter-MANET links. These interMANET links are governed by routing policies that can be summarized as Allowed or Denied link. However, if more than two groups form a coalition, blocked multihop communications and non-desired transmissions due to these restrictive policies would appear. In this paper, we present these blocking cases and theoretically evaluate their apparition frequency. Then, we present two alternatives to extend the binary policies and decrease the number of blocking cases. Finally, we describe an experimental scenario containing a blocking case and evaluate our propositions and their performance. Florian Grandhomme, Gilles Guette, Adlen Ksentini, Thierry Plesse |
IWCMC | 2 |
| 2016 | Comparing inter-domain routing protocol assessment tools for MANETabstractNew generation military equipment, soldiers and vehicles, use wireless technology to communicate on the battlefield. During missions, they form an ad hoc network, namely Mobile Ad hoc NETwork (MANET). Since the battlefield includes coalition, each group may communicate with another group, and inter-MANET communication may be established. Inter-MANET (or interdomain MANET) communication should allow communication, but maintain a control on the exchanged information. Several protocols have been proposed in order to handle inter-domain routing for tactical MANETs. In this paper, we review these protocols and highlight the general issues they solve. Then, we compare the behavior of a simulator (NS3), an emulator (CORE) and a real platform (using laptops) on simple network characteristics at Network and Data Link layers level. We show that there are behavioral differences among these three validation tools, and particularly those based on softwares (NS3 and CORE), which create problems that does not exist in reality. Consequently, most existing protocols are more complex than they should be. Based on this analysis and real behavior, we propose some preconization to design Inter-domain protocols for MANET. Florian Grandhomme, Gilles Guette, Adlen Ksentini, Thierry Plesse |
ICC | 2 |
| 2013 | A privacy preserving distributed reputation mechanismabstractReputation systems allow to estimate the trustworthiness of entities based on their past behavior. Electronic commerce, peer-to-peer routing and collaborative environments, just to cite a few, highly benefit from using reputation systems. To guarantee an accurate estimation, reputation systems typically rely on a central authority, on the identification and authentication of all the participants, or both. In this paper, we go a step further by presenting a distributed reputation mechanism which is robust against malicious behaviors and that preserves the privacy of its clients. Guaranteed error bounds on the estimation are provided. Emmanuelle Anceaume, Gilles Guette, Paul Lajoie-Mazenc, Nicolas Prigent, Valérie Viet Triem Tong |
ICC | 2 |
| 2009 | On the Unobservability of a Trust Relation in Mobile Ad Hoc Networks
Olivier Heen, Gilles Guette, Thomas Genet |
WISTP | 2 |
| 2009 | Automating trusted key rollover in DNSSECabstractThe Domain Name System (DNS) is a distributed tree-based database largely used to translate a human readable machine name into an IP address. The DNS security extensions (DNSSEC) has been designed to protect the DNS protocol using public key cryptogr Gilles Guette |
J. Comput. Secur. | 1 |
| 2008 | Using TPMs to Secure Vehicular Ad-Hoc Networks (VANETs)
Gilles Guette, Ciarán Bryce |
WISTP | 1 |
| 2007 | On the Sybil attack detection in VANETabstractSince few years, Vehicular Ad hoc Networks deserve much attention. The development of wireless communication in VANET implies to take into account the need of security. In VANET, many attacks rely on having the attacker generate multiple identities to simulate multiple nodes: this is called the Sybil attack. In this paper, we propose a precise quantification of the effects of various assumptions (type of antenna, transmission signal strength) on the effectiveness of a Sybil attack. Gilles Guette, Bertrand Ducourthial |
MASS | 1 |