EDBT 2026 Demo / reviewers in the wild / expert
Pierre Chifflier
dblp:189/1071
· DBLP profile ↗
7ranked-venue papers
0as first author
4since 2021 · last 2025
—ORCID · none
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 4 · 3 since 2021Theory of computation · 3 · 1 since 2021Software engineering, systems software and programming languages · 2
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Striking Back at Cobalt: Using Network Traffic Metadata to Detect Cobalt Strike Masquerading Command and Control Channels
Clément Parssegny, Johan Mazel, Olivier Levillain, Pierre Chifflier |
ARES (1) | 4 |
| 2025 | Overlapping Data in Network Protocols: Bridging OS and NIDS Reassembly Gap
Lucas Aubard, Johan Mazel, Gilles Guette, Pierre Chifflier |
DIMVA (2) | 4 |
| 2025 | Overlapping IPv4, IPv6, and TCP data: exploring errors, test case context, and multiple overlaps inside network stacks and NIDSes with PyrolyseabstractIP fragmentation and TCP segmentation allow for splitting large data packets into smaller ones, e.g., for transmission across network links of limited capacity. These mechanisms permit complete or partial overlaps with different data on the overlapping portions. IPv4, IPv6, and TCP reassembly policies, i.e., the data chunk preferences that depend on the overlap types, differ across protocol implementations. This leads to vulnerabilities, as NIDSes may interpret the packet differently from the monitored host OSes. Some NIDSes, such as Suricata or Snort, can be configured so that their policies are consistent with the monitored OSes. The first contribution of the paper is pyrolyse, an audit tool that exhaustively tests and describes the reassembly policies of various IP and TCP implementation types. This tool ensures that implementations reassemble overlapping chunk sequences without errors. The second contribution is the analysis of pyrolyse artifacts. We first show that the reassembly policies are much more diverse than previously thought. Indeed, by testing all the overlap possibilities for $n \leq 3$ test case chunks and different testing scenarios, we observe 15 different behaviors out of 23 tested implementations depending on the protocol. Second, we report eight errors impacting one OS, two NIDSes, and two embedded stacks, which can lead to security issues such as NIDS pattern-matching bypass or DoS attacks. A CVE [1] was assigned to a NIDS error. Finally, we show that implemented IP and TCP policies obtained through chunk pair testing are usually inconsistent with the observed triplet reassemblies. Therefore, contrary to what they currently do, NIDSes or other network traffic analysis tools should not apply $n=2$ pair policies when the number of overlapping chunks exceeds two. Lucas Aubard, Johan Mazel, Gilles Guette, Pierre Chifflier |
RAID | 4 |
| 2021 | Modular verification of programs with effects and effects handlersabstractAbstract Modern computing systems have grown in complexity, and even though system components are generally carefully designed and even verified by different groups of people, thecompositionof these components is often regarded with less attention. Inconsistencies between components’ assumptions on the rest of the system can have significant repercussions on this system, and may ultimately lead to safety or security issues. In this article, we introduce FreeSpec, a formalismbuilt upon the key idea that components can bemodeled as programs with algebraic effects to be realized by other components. FreeSpec allows for the modular modeling of a complex system, by defining idealized components connected together, and the modular verification of the properties of their composition. In addition, we have implemented a framework for the Coq proof assistant based on FreeSpec. Thomas Letan, Yann Régis-Gianas, Pierre Chifflier, Guillaume Hiet |
Formal Aspects Comput. | 3 |
| 2018 | Modular Verification of Programs with Effects and Effect Handlers in Coq
Thomas Letan, Yann Régis-Gianas, Pierre Chifflier, Guillaume Hiet |
FM | 3 |
| 2017 | ILAB: An Interactive Labelling Strategy for Intrusion Detection
Anaël Beaugnon, Pierre Chifflier, Francis R. Bach |
RAID | 2 |
| 2016 | SpecCert: Specifying and Verifying Hardware-Based Security Enforcement
Thomas Letan, Pierre Chifflier, Guillaume Hiet, Pierre Néron, Benjamin Morin |
FM | 2 |