Florent Galtier

dblp:283/8977 · DBLP profile ↗
← Back
7ranked-venue papers
2as first author
6since 2021 · last 2025
0000-0002-4444-3837ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 7 · 2 first-author · 6 since 2021Systems, architecture and hardware · 2 · 2 since 2021Software engineering, systems software and programming languages · 2 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2025 SIROCCO: A Dry Wind to Warn you from Bluetooth Attacks
abstract
Bluetooth Low Energy (BLE) has become ubiquitous in Internet of Things (IoT) devices, yet it remains vulnerable to sophisticated over-the-air attacks that can compromise data security. This paper introduces Sirocco, a novel host-based intrusion detection system that leverages the open source Zephyr RTOS to address critical security challenges in BLE communications. Sirocco provides a flexible and lightweight detection framework that integrates with the BLE protocol stack. It targets sophisticated and low-level attacks such as spoofing, signal injection, and key sharing vulnerabilities. By inserting lightweight metric collection functions directly into the BLE stack's interrupt service routines and employing a dedicated kernel thread for analysis, Sirocco minimizes performance overhead while maintaining real-time attack detection capabilities across different device roles. Experimental evaluation demonstrates the system's effectiveness, with the framework introducing minimal performance and power consumption overhead.
Paul L. R. Olivier, Florent Galtier, Guillaume Auriol, Vincent Nicomette, Romain Cayre
PRDC2
2024 Wireless Modulation Identification: Filling the Gap in IoT Networks Security Audit
Florent Galtier, Guillaume Auriol, Vincent Nicomette, Paul L. R. Olivier, Romain Cayre, Mohamed Kaâniche
DIMVA1
2021 WazaBee: attacking Zigbee networks by diverting Bluetooth Low Energy chips
abstract
This paper discusses the security of wireless communication protocols of the Internet of Things (IoT) and presents a new attack targeting these protocols, called WazaBee, which could have a critical impact and be difficult to detect. Specifically, WazaBee is a pivotal attack aimed at hijacking BLE devices, commonly used in IoT networks, in order to communicate with and possibly attack through a different wireless network technology, considering protocols based on 802.15.4, in particular Zigbee. We present the key principles of the attack and describe some real-world experiments that allowed us to demonstrate its practical feasibility. The attack takes advantage of the compatibility that exists between the two modulation techniques used by these two protocols. Finally, the paper briefly discusses possible countermeasures to mitigate the impact of this attack.
Romain Cayre, Florent Galtier, Guillaume Auriol, Vincent Nicomette, Mohamed Kaâniche, Géraldine Vache Marconato
DSN2
2021 InjectaBLE: Injecting malicious traffic into established Bluetooth Low Energy connections
abstract
Bluetooth Low Energy (BLE) is nowadays one of the most popular wireless communication protocols for Internet of Things (IoT) devices. As a result, several attacks have targeted this protocol or its implementations in recent years, illustrating the growing interest for this technology. However, some major challenges remain from an offensive perspective, such as injecting arbitrary frames, hijacking the Slave role or performing a Manin-The-Middle in an already established connection. In this paper, we describe a novel attack called InjectaBLE, allowing to inject malicious traffic into an existing connection. This attack is highly critical as the vulnerability exploited is inherent to the BLE specification itself, which means that any BLE connection can be possibly vulnerable, regardless of the BLE devices involved in the connection. We describe the theoretical foundations of the attack, how to implement it in practice, and we explore four critical attack scenarios allowing to maliciously trigger a specific feature of the target device, hijack the Slave and Master role or to perform a Man-in-the-Middle attack. Finally, we discuss the impact of this attack and outline some mitigation measures.
Romain Cayre, Florent Galtier, Guillaume Auriol, Vincent Nicomette, Mohamed Kaâniche, Géraldine Vache Marconato
DSN2
2021 A defensive man-in-middle approach to filter BLE packets
abstract
In this paper, we propose an original defensive strategy in which we benefit from the use of Man-in-The-Middle attacks in order to protect some vulnerable BLE devices. More precisely, we describe a tool that uses a Man-in-The-Middle attack to implement a wireless firewall for BLE communications, that is able to block specific commands, make some services invisible on BLE devices, or to force out weak pairing mechanisms.
Ahmed Aboukora, Guillaume Bonnet, Florent Galtier, Romain Cayre, Vincent Nicomette, Guillaume Auriol
WISEC3
2021 Cross-protocol attacks: weaponizing a smartphone by diverting its bluetooth controller
abstract
In this paper, we focus on a new type of wireless attacks, named cross-technology pivoting attacks. The main objective of these attacks is to divert the transceivers of compromised devices dedicated to a given protocol to allow them to communicate through another protocol, taking advantage of some similarities in their modulation schemes. The main contribution of this work consists in demonstrating the practical feasibility of pivoting attacks from off-the-shelf devices implementing the Bluetooth 5.0 specification. To our knowledge, this attack has not been explored so far in the state of the art.
Romain Cayre, Géraldine Vache Marconato, Florent Galtier, Mohamed Kaâniche, Vincent Nicomette, Guillaume Auriol
WISEC3
2020 A PSD-based fingerprinting approach to detect IoT device spoofing
abstract
Spoofing attacks are generally difficult to detect and can have potentially harmful consequences on computer networks and applications. Wireless IoT networks, in the context of smart buildings or smart factories, are particularly vulnerable to these attacks. In this paper, we present a new physical device fingerprinting approach aiming at detecting spoofing attacks in wireless IoT environments. The proposed approach is based on the analysis of some properties of the physical signals emitted by connected devices, using their Power Spectral Density (PSD) to extract a frequency profile of their communications. This approach does not require any expensive equipment, is easy to deploy, and is resilient to non predictable phenomena in transmissions. The detection of spoofing attacks consists in comparing the fingerprint of a transmitting device with previously stored fingerprints of legitimate devices, by measuring the similarity of the corresponding PSDs and applying a community detection algorithm. The efficiency of this approach has been successfully tested using various experimental setups with connected devices supporting different wireless protocols (BLE, Zigbee). We also discuss the practical applicability of our approach, e.g. in an industrial environment by analysing its scalability and proposing solutions to tune and optimize its deployment at a large scale.
Florent Galtier, Romain Cayre, Guillaume Auriol, Mohamed Kaâniche, Vincent Nicomette
PRDC1