Jérôme François

dblp:29/6239 · DBLP profile ↗
← Back
68ranked-venue papers
10as first author
27since 2021 · last 2026
0000-0002-7457-458XORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 30 · 5 first-author · 11 since 2021Software engineering, systems software and programming languages · 7 · 6 since 2021Security and privacy · 6 · 1 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 3 since 2021Systems, architecture and hardware · 2 · 1 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021
YearPublicationVenuePosition
2026 NegBLEURT Forest: Leveraging Inconsistencies for Detecting Jailbreak Attacks
abstract
Jailbreak attacks designed to bypass safety mechanisms pose a serious threat by prompting LLMs to generate harmful or inappropriate content, despite alignment with ethical guidelines. Crafting universal filtering rules remains difficult due to their inherent dependence on specific contexts. To address these challenges without relying on threshold calibration or model fine-tuning, this work introduces a semantic consistency analysis between successful and unsuccessful responses, demonstrating that a negation-aware scoring approach captures meaningful patterns. Building on this insight, a novel detection framework called NegBLEURT Forest is proposed to evaluate the degree of alignment between outputs elicited by adversarial prompts and expected safe behaviors. It identifies anomalous responses using the Isolation Forest algorithm, enabling reliable jailbreak detection. Experimental results show that the proposed method consistently achieves top-tier performance, ranking first or second in accuracy across diverse models using the crafted dataset, while competing approaches exhibit notable sensitivity to model and data variations1.
Lama Sleem, Jérôme François, Nathan Foucher, Niccolò Gentile, Radu State
CCNC2
2026 PRISM: A Lightweight Method for Jailbreak Detection via Prompt-Response Semantic Coherence Scoring in LLMs
Costabile Di Gregorio, Lama Sleem, Jérôme François, Radu State
COMPSAC3
2026 Key-Parametrized Embeddings for Access Control in Retrieval-Augmented Generation
Théo Thuillier, Léo Lavaur, Jérôme François, Radu State, William Ferguson
COMPSAC3
2026 Investigating Neuro-Symbolic AI for Context-Aware Process Classification with MITRE ATT&CK® Techniques
abstract
System logs contain rich information about system activity, but correctly identifying malicious events is difficult without contextual information. While sequential models like Transformers or LSTMs can process sequences of events and extract information from that context, they are neither interpretable nor explicit. In this paper, we use a neural-symbolic framework to classify process-level auditd events into the appropriate techniques of the MITRE ATT&CK® framework. We apply our approach to multiple model architectures and show that contextual logic can improve the overall F1-score, while providing interpretable per-technique corrections.
Omar Anser, Léo Lavaur, Jérôme François
SIGCOMM3
2025 Leveraging Large Language Models to Build Computationally Efficient Models for Sustainable Finance Investment Decision Support
abstract
peer reviewed
Loris Bergeron, Jérôme François, Radu State, Jean Hilger
IEEE Big Data2
2025 TATA: Benchmark NIDS Test Sets Assessment and Targeted Augmentation
Omar Anser, Jérôme François, Isabelle Chrisment, Daishi Kondo
ESORICS (1)2
2024 Automated Machine Learning Configuration to Learn Intrusion Detectors on Attack-Free Datasets
abstract
Intrusion detection systems have benefited from Machine Learning (ML) to alleviate the problem of building and maintaining accurate signatures. Nevertheless, ML solutions face issues like overfitting or insufficient training data, which may necessitate retraining or adjustments to maintain long-term efficiency. From data collection to model training, all efforts are crucial for deploying a robust ML-based intrusion detector. Among these efforts, optimizing model hyperparameters, a time-consuming task, can be automated by existing methods.Yet, such methods require a validation set, making them unsuitable for training a detector on an attack-free dataset, as in anomaly-based intrusion detection. Additionally, setting the anomaly detectors’ threshold, usually beyond hyperparameters configuration, requires knowledge of attacks. To overcome these challenges, this paper presents an automated solution to infer the hyperparameters and the threshold jointly from an attack-free training dataset. Pre-learned optimal configurations are transferred and fine-tuned across datasets.Our method minimally impacts model accuracy detection performance (4% degradation), while dramatically reducing configuration time by a factor of 160 across the IDS2017 and IDS2018 datasets.
Omar Anser, Jérôme François, Isabelle Chrisment
LCN2
2024 Intent-Based Attack Mitigation through Opportunistic Synchronization of Micro-Services
abstract
The escalating number of cyberattacks poses a significant threat to digital infrastructures. Defining and deploying accurate countermeasures is challenging because of (1) the variety of threats and their possible evolution over time and (2) the need to enforce them as fast as possible, especially for fast-propagating attacks. Intent-Based Networking (IBN) stands for a promising solution for security management, especially to mitigate attacks through the specification of reaction intents, saving time and avoiding error-prone tasks. Nevertheless, most current IBN solutions rely on centralized architectures performing time-consuming operations, which makes them inappropriate to timely deploy countermeasures, especially in the case of fast-propagating attacks spreading large-scale systems. As a solution to shorten the reaction time while supporting scalability, we first consider fast micro-services technologies (e.g., Unikernels) as the substrate of security functions acting as Policy Enforcement Points (PEP). Second, we propose to enable an opportunistic synchronization of those PEPs to react, at least partially but autonomously, against the ongoing attacks in a decentralized fashion. Such a solution raises challenges related to the consistency and performance of the overall enforced reaction policies. This paper presents the early stage of the PhD, outlining the specific challenges, limitations, and research required to leverage decentralized reaction using opportunistic synchronization of micro-services in an IBN framework for security.
Do Duc Anh Nguyen, Pierre Alain, Fabien Autrel, Ahmed Bouabdallah, Jérôme François
NetSoft5
2024 How Fast Does Malware Leveraging EternalBlue Propagate? The case of WannaCry and NotPetya
abstract
Malware attacks pose a critical threat to digital infrastructures particularly given their potential for widespread and fast propagation. Mitigating them involves limiting their expansion, which requires a thorough understanding of their propagation mechanisms. However, few studies have been conducted on their propagation behaviors in large-scale networks. In this paper, we present the results of an empirical study focusing on the propagation strategy of WannaCry and NotPetya, two malware instances leveraging EternalBlue, an exploit developed by the NSA and stolen by The Shadow Brokers hacker group, which has been used to implement rapid spreading in some mal-ware instances. Our experiments qualify the speed of infection, epidemic behavior, and spreading strategies in a local network of 50 VMs. We have especially measured for WannyCry that (1) nearly 20% of infections are processed in less than 50 seconds, and (2) up to 16 hosts are infected in a 100-second period. Our results provide meaningful insights on malware propagation to support the design of effective countermeasures.
Do Duc Anh Nguyen, Pierre Alain, Fabien Autrel, Ahmed Bouabdallah, Jérôme François, Guillaume Doyen
NetSoft5
2024 Vulnet: Learning Navigation in an Attack Graph
abstract
Nowadays, new flaws or vulnerabilities are frequently discovered. Analyzing how these vulnerabilities can be used by attackers to gain access to different parts of a network allows to provide better protection and defense. Amongst the diverse analysis techniques, simulations do not necessitate a full infrastructure deployment and recently benefited from advances in reinforcement learning to better mimic an attacker’s behavior. However, such simulations are resource consuming. By representing the interconnected hosts of a network and their vulnerabilities as attack graphs and leveraging machine learning, our method, Vulnet, is capable to generalize knowledge generated by simulation and gives insight about attacker capabilities. It can predict instantaneously the overall performance of an attacker to compromise a system with a mean error of 0.07.
Enzo d'Andréa, Jérôme François, Abdelkader Lahmadi, Olivier Festor
NetSoft2
2024 To Squelch or not to Squelch: Enabling Improved Message Dissemination on the XRP Ledger
abstract
With the large increase in the adoption of blockchain technologies, their underlying peer-to-peer networks must also scale with the demand. In this context, previous works highlighted the importance of ensuring efficient and resilient communication for the underlying consensus and replication mechanisms. However, they were mainly focused on mainstream, Proof-of-Work-based Distributed Ledger Technologies like Bitcoin or Ethereum.In this paper, the problem is investigated in the context of consensus-validation based blockchains, like the XRP Ledger. The latter relies on a Federated Byzantine Agreement (FBA) consensus mechanism which is proven to have a good scalability in regards to transaction throughput. However, it is known that significant increases in the size of the XRP Ledger network would be challenging to achieve. The main reason is the flooding mechanism used to disseminate the messages related to the consensus protocol, which creates many duplicates in the network. Squelching is a recent solution proposed for limiting this duplication, however, it was never evaluated quantitatively in real-life scenarios involving the XRPL production network. In this paper, our aim is to assess this mechanism using a real-life controllable testbed and the XRPL production network, to assess its benefit and compare it to alternative solutions relying on Named Data Networking and on a gossip-based approach.
Lucian Trestioreanu, Flaviene Scheidt de Cristo, Wazen M. Shbair, Jérôme François, Damien Magoni, Radu State
NOMS4
2023 Auto-tuning of Hyper-parameters for Detecting Network Intrusions via Meta-learning
abstract
In recent years, machine learning-based Network Intrusion Detection Systems have been widely investigated to detect network attacks. The performance of such systems is strongly affected by their configuration, i.e. the setting of the hyper-parameters, usually based on human expertise. Few efforts have been made towards automatic methods except using a long process of trials. Besides, the resulting configuration is specific to the network where the system is deployed or the type of attacks to detect. To address these issues, we define a method using metalearning which learns from the past experiences. By extracting useful information from the previous optimized tuning tasks, a model is trained in order to quickly infer a new configuration. In comparison with Bayesian optimization, our evaluation based on the CSE CIC IDS2018 and CIC IDS2017 datasets demonstrates that our lightweight technique does not degrade attack detection accuracy in 88% of cases but is on average 9 times faster.
Omar Anser, Jérôme François, Isabelle Chrisment
NOMS2
2023 HiFiPot: a High-Fidelity Emulation Framework for Internet of Things Honeypots
abstract
Internet of Things (IoT) devices are easy targets for attackers. Preventing and counter-fighting this threat impose to capture and analyze attackers’ behaviors. Several IoT-oriented honeypots have been proposed recently while, in parallel, emulation techniques for IoT devices have been improved to allow firmware analysis of this type of devices.In this paper, our objective is to consolidate these two facets in a single framework called HiFiPot. It is capable of creating a high-interaction honeypot on-the-fly with a high fidelity, i.e. from a firmware image. Our technique improves the most recent stateof-the-art solution to emulate an IoT device without scarifying the furtiveness. It is based on an iterative learning procedure to automatically correct emulation errors and to ensure Internet connectivity while maintaining these corrections invisible to the attackers. Out of the 1,000 firmware images tested, 443 (44,3%) can be deployed as honeypot. More than 500 instances of HiFiPot were deployed in the wild, and received about 1,900 HTTP traversal attacks, and downloaded 31 distinct malware binaries (out of 909) among which eight were unknown.
Pierre-Marie Junges, Jérôme François, Olivier Festor
NOMS2
2023 Multi-label Classification of Hosts Observed through a Darknet
abstract
To observe compromised hosts at Internet-scale, a darknet or network telescope collects Internet background radiation that includes large-scale phenomena like DDoS (Distributed Denial-of-Service) or scanning. Gathered data is however very partial and labeling such traffic to precise activities thanks to external databases is far from being satisfactory (8.4% of IP addresses in our case). In addition, as compromised hosts are used for multiple malicious activities, they cannot be classified in a unique category. We propose in this paper a new multi-label classification method by representing traffic generated by a host as a graph and leveraging machine learning algorithms (Node embedding and Graph Convolutional Networks). From partial information about IP addresses, our method can label addresses with a precision of 0.80 and recall of 0.81.
Enzo d'Andréa, Jérôme François, Olivier Festor, Mehdi Zakroum
NOMS2
2023 Stateful InREC: Stateful In-Network Real Number Computation With Recursive Functions
abstract
The current generation of Reconfigurable Match-Action Tables switches are highly programmable, able to support stateful operations and pipeline specifications using languages like P4. Nevertheless, these switches do not offer primitives to support real-valued operations on the data plane, thus requiring support from external servers or middle boxes to perform advanced operations. We introduce Stateful InREC, a system that extends the capabilities of programmable switches to support in-network real-valued operations using the IEEE half-precision floating point representation. Stateful InREC relies on decomposing real-valued functions into lookup tables taking into account the RMT model constraints to reach the right trade-off between accuracy and resource usage. It also supports state management for the computation of recursive function over time series. Stateful InREC prototype on Barefoot Tofino switches demonstrates the efficiency of Stateful InREC for in-network computation of different types of operations and its application for in-network logistic regression models used for classification problems. We also demonstrate the use of Stateful InREC to implement an ARIMA model on a Tofino switch for DDoS detection. Our evaluation of Stateful InREC shows that it is possible to implement complex in-network applications with high accuracy and low latency.
Matthews Jose, Kahina Lazri, Jérôme François, Olivier Festor
IEEE Trans. Netw. Serv. Manag.3
2022 NetREC: Network-wide in-network REal-value Computation
abstract
The current generation of networks empowers the use of programmable switches whose behaviour can be defined using languages like P4. Nevertheless, these languages do not support network-wide deployment of stateful real-value functions. This paper presents NetREC, an extension of RMT programmable data planes designed to enable stateful real-value functions computation across multiple switches. NetREC first decomposes the real-value functions into a dependency graph of elementary operations that are distributed among the network. This distribution is carried out by dynamically generating and solving an integer linear program. We deploy a prototype of NetREC on a network of Tofino switches and demonstrate its capability of computing recursive real-value functions like exponential weighted moving average.
Matthews Jose, Kahina Lazri, Jérôme François, Olivier Festor
NetSoft3
2022 Detecting Multi-Step Attacks: A Modular Approach for Programmable Data Plane
abstract
The increasing sophistication of attacks over the last years such as the proliferation of complex multi-steps attacks, calls for new monitoring models and methods for diagnosing the attacks’ severity and mitigating them in a timely manner. In this paper, we propose an in-network monitoring approach capable of detecting a set of composed behaviors and consequently triggering different levels of alerts and reactions. Our approach is based on a Petri Net model capable of aggregating individual attacks into a multi-step composition. To this end, we propose a method for deriving a Match-Action Table (MAT) abstraction from a Petri net model. MATs can be then deployed on a P4 programmable data plane, enabling flexible re-composition of attack detection steps at runtime. We demonstrate the feasibility of our proposal by modeling the detection of a multi-step DNS cache poisoning attack and implementing the model on a P4 programmable data plane.
Abir Laraba, Jérôme François, Isabelle Chrisment, Shihabur Rahman Chowdhury, Raouf Boutaba
NOMS2
2022 Non-Intrusive and Workflow-Aware Virtual Network Function Scheduling in User-Space
abstract
The simple programming model and very low-overhead I/O capabilities of emerging packet processing techniques leveraging kernel-bypass I/O and poll-mode processing is gaining significant popularity for building high performance softwaremiddleboxes(akaVirtual Network Functions (VNFs)). However, existing OS schedulers fall short in rightsizing CPU allocation to poll-mode VNFs due to the schedulers’ shortcoming in capturing the actual processing cost of these VNFs. This issue is further exacerbated by their inability to consider VNF processing order when VNFs are chained to form Service Function Chains (SFCs). The state-of-the-art VNF schedulers proposed as an alternative to OS schedulers areintrusive, requiring the VNFs to be built with scheduler specific libraries or having carefully selected scheduling checkpoints. This highly restricts the VNFs that can properly work with these schedulers. In this article, we presentUNiS, aUser-spaceNon-intrusive work-flow aware VNFScheduler. Unlike existing approaches, UNiS is non-intrusive, i.e., does not require VNF modifications and treats poll-mode VNFs as black boxes. UNiS is also workflow-aware, i.e., takes SFC processing order into account while scheduling VNFs. Testbed experiments show thatUNiSis able to achieve a throughput within 90 and 98 percent of that achievable using an intrusive co-operative scheduler for synthetic and real data center traffic, respectively.
Anthony, Shihabur Rahman Chowdhury, Tim Bai, Raouf Boutaba, Jérôme François
IEEE Trans. Cloud Comput.5
2022 Monitoring Network Telescopes and Inferring Anomalous Traffic Through the Prediction of Probing Rates
abstract
Network reconnaissance is the first step preceding a cyber-attack. Hence, monitoring the probing activities is imperative to help security practitioners enhancing their awareness about Internet’s large-scale events or peculiar events targeting their network. In this paper, we present a framework for an improved and efficient monitoring of the probing activities targeting network telescopes. Particularly, we model the probing rates which are a good indicator for measuring the cyber-security risk targeting network services. The approach consists of first inferring groups of network ports sharing similar probing characteristics through a new affinity metric capturing both temporal and semantic similarities between ports. Then, sequences of probing rates targeting similar ports are used as inputs to stacked Long Short-Term Memory (LSTM) neural networks to predict probing rates 1 hour and 1 day in advance. Finally, we describe two monitoring indicators that use the prediction models to infer anomalous probing traffic and to raise early threat warnings. We show that LSTM networks can accurately predict probing rates, outperforming the non-stationary autoregressive model, and we demonstrate that the monitoring indicators are efficient in assessing the cyber-security risk related to vulnerability disclosure.
Mehdi Zakroum, Jérôme François, Isabelle Chrisment, Mounir Ghogho
IEEE Trans. Netw. Serv. Manag.2
2021 Inferring Software Composition and Credentials of Embedded Devices from Partial Knowledge
abstract
Internet-of-Things (IoT) devices or more generally embedded devices are nowadays commonly deployed in public, personal or work spaces despite suffering from security issues often related to their bad design and/or configuration. For instance, IoT botnets such as Mirai successfully compromised thousands of devices using a bruteforce method on a set of known credentials. Although brute-force attacks against a particular service (e.g. SSH, telnet) generate many packets which can be easily detected and mitigated, attackers can easily rely on TCP scans to assess the services present on a device while maintaining a high level of stealthiness. In this paper, we present a method to reconstruct precise information about an IoT device configuration (brand name, usernames, passwords, software components) from partial knowledge such as open ports revealed by a TCP scan. It relies on constituting a knowledge base from a large dataset of publicly accessible firmware serving as training multiple Random Forest (RF) classifiers. Using a dataset of 6935 embedded devices, the HTTP, SSH or DNS software names can be predicted with a precision higher than 80% with a limited knowledge. The correct HTTP, SSH or DNS versions can be inferred in more than 95% of cases after 1.4 trials on average. Similarly, our technique also predicts the password of at least one valid user in more than 97% of the cases after 1.15 trials on average.
Pierre-Marie Junges, Jérôme François, Olivier Festor
CNSM2
2021 HSL: a Cyber Security Research Facility for Sensitive Data Experiments
Frédéric Beck, Abdelkader Lahmadi, Jérôme François
IM3
2021 LINT: Accuracy-adaptive and Lightweight In-band Network Telemetry
Shihabur Rahman Chowdhury, Raouf Boutaba, Jérôme François
IM3
2021 InREC: In-network REal Number Computation
Matthews Jose, Kahina Lazri, Jérôme François, Olivier Festor
IM3
2021 Leveraging in-network real-value computation for home network device recognition
Matthews Jose, Kahina Lazri, Jérôme François, Olivier Festor
IM3
2021 Software-based Analysis of the Security by Design in Embedded Devices
Pierre-Marie Junges, Jérôme François, Olivier Festor
IM2
2021 Comparative Assessment of Process Mining for Supporting IoT Predictive Security
abstract
The growth of the Internet-of-Things (IoT) has been characterized by the large-scale deployment of sensors and connected objects. These ones are integrated with other Internet resources in order to elaborate more complex systems and applications. Security management is a major challenge for these systems due to their complexity, their heterogeneity and the limited resources of their devices. In this article we evaluate the exploitability and performance of a process mining approach for detecting misbehaviors in such systems. We describe the considered architecture and detail its operation, from the generation of behavioral models to the detection of potential attacks. We formalize several alternative commonly-used detection methods, including elliptic envelope, support-vector machine, local outlier factor, and isolation forest techniques. After presenting a proof-of-concept prototype, we quantify comparatively the benefits and limits of our process mining solution combined with data pre-processing, through extensive experiments based on different industrial datasets.
Adrien Hemmer, Mohamed Abderrahim 0002, Rémi Badonnel, Jérôme François, Isabelle Chrisment
IEEE Trans. Netw. Serv. Manag.4
2021 Mitigating TCP Protocol Misuse With Programmable Data Planes
abstract
This article proposes a new approach for detecting and mitigating the impact of misbehaving TCP end-hosts, specifically the Optimistic ACK attack, and Explicit Congestion Notification (ECN) abuse. In contrast to the state-of-the-art, we show that it is possible to mitigate such misbehavior leveraging emerging programmable data planes while not requiring any end-host or protocol modifications. A key challenge in doing so is to implement expressive, complex and stateful functions in the data plane within its restricted programming model. In this regard, we propose a security monitoring function that uses Extended Finite State Machine (EFSM) abstraction for monitoring stateful protocols in the data plane. We also design a mechanism for mapping a protocol's EFSM to programmable data plane primitives. Our evaluation results demonstrate that our approach can fully or partially restore the throughput loss caused by misbehaving end-hosts that manipulate TCP congestion control through misinformation.
Abir Laraba, Jérôme François, Shihabur Rahman Chowdhury, Isabelle Chrisment, Raouf Boutaba
IEEE Trans. Netw. Serv. Manag.2
2020 BPP over P4: Exploring Frontiers and Limits in Programmable Packet Processing
abstract
This paper describes experiences gained during the development of a Proof-of-Concept implementation of NewIP/BPP, the protocol at the core of a novel packet-programmable networking framework, using P4, a popular SDN technology for the implementation of networking protocols using protocol-independent packet processors. NewIP/BPP introduces a number of novel requirements whose implementation encountered a number of P4 limitations that proved very challenging to overcome. We hope that the resulting insights will be useful for future implementations of NewIP/BPP as well as for its and P4's evolution.
Jérôme François, Alexander Clemm, Vivien Maintenant, Sébastien Tabor
GLOBECOM1
2020 Defeating Protocol Abuse with P4: Application to Explicit Congestion Notification
Abir Laraba, Jérôme François, Isabelle Chrisment, Shihabur Rahman Chowdhury, Raouf Boutaba
Networking2
2020 A Process Mining Tool for Supporting IoT Security
abstract
The development of the Internet has been characterized by a growing interest for the Internet-of-Things (IoT). In particular, connected devices are integrated to other Internet resources (such as cloud resources) to elaboratevalue-added services. However, they pose important challenges with respect to security management due to their heterogeneity, their distribution, and their limited resources. In this demonstration, we present a process mining toool for supporting IoT security. This tool is capable to automate the detection of misbehaviours and attacks in large and heterogeneous IoT infrastructures, based on process mining techniques combined with normalization and clustering data pre-processing. We detail the different building blocks of this tool provided into a docker container, and illustrate its operations with different scenarios.
Adrien Hemmer, Rémi Badonnel, Jérôme François, Isabelle Chrisment
NOMS3
2019 Attacker Behavior-Based Metric for Security Monitoring Applied to Darknet Analysis
Laurent Evrard, Jérôme François, Jean-Noël Colin
IM2
2019 port2dist: Semantic Port Distances for Network Analytics
Laurent Evrard, Jérôme François, Jean-Noël Colin, Frédéric Beck
IM2
2019 Passive Inference of User Actions through IoT Gateway Encrypted Traffic Analysis
Pierre-Marie Junges, Jérôme François, Olivier Festor
IM2
2019 SPONGE: Software-Defined Traffic Engineering to Absorb Influx of Network Traffic
abstract
Existing shortest path-based routing in wide area networks or equal cost multi-path routing in data center networks do not consider the load on the links while taking routing decisions. As a consequence, an influx of network traffic stemming from events such as distributed link flooding attacks and data shuffle during large scale analytics can congest network links despite the network having sufficient capacity on alternate paths to absorb the traffic. This can have several negative consequences such as service unavailability, delayed flow completion, packet losses, among others. In this regard, we propose SPONGE, a traffic engineering mechanism for handling sudden influx of network traffic. SPONGE models the network as a stochastic process, takes the switch queue occupancy and traffic rate as inputs, and leverages the multiple available paths in the network to route traffic in a way that minimizes the overall packet loss in the network. We demonstrate the practicality of SPONGE through an OpenFlow based implementation, where we periodically and pro-actively re-route network traffic to the routes computed by SPONGE. Mininet emulations using real network topologies show that SPONGE is capable of reducing packet drops by 20% on average even when the network is highly loaded because of an ongoing link flooding attack.
Benoît Henry, Shihabur Rahman Chowdhury, Abdelkader Lahmadi, Romain Azaïs, Jérôme François, Raouf Boutaba
LCN5
2019 Efficient Resource Allocation for Multi-Tenant Monitoring of Edge Infrastructures
abstract
By relying on small sized and massively distributed infrastructures, the Edge computing paradigm aims at supporting the low latency and high bandwidth requirements of the next generation services that will leverage IoT devices (e.g., video cameras, sensors). To favor the advent of this paradigm, management services, similar to the ones that made the success of Cloud computing platforms, should be proposed. However, they should be designed in order to cope with the limited capabilities of the resources that are located at the edge. In that sense, they should mitigate as much as possible their footprint. Among the different management services that need to be revisited, we investigate in this paper the monitoring one. Monitoring functions tend to become compute-, storage- and network-intensive, in particular because they will be used by a large part of applications that rely on real-time data. To reduce as much as possible the footprint of the whole monitoring service, we propose to mutualize identical processing functions among different tenants while ensuring their quality-of-service (QoS) expectations. We formalize our approach as a constraint satisfaction problem and show through micro-benchmarks its relevance to mitigate compute and network footprints.
Mohamed Abderrahim 0002, Meryem Ouzzif, Karine Guillouard, Jérôme François, Adrien Lèbre, Charles Prud'homme, Xavier Lorca
PDP4
2019 Transparent and Service-Agnostic Monitoring of Encrypted Web Traffic
abstract
Nowadays, most of Web services are accessed through HTTPS. While preserving user privacy is important, it is also mandatory to monitor and detect specific users' actions, for instance, according to a security policy. This paper presents a solution to monitor HTTP/2 traffic over TLS. It highly differs from HTTP/1.1 over TLS traffic what makes existing monitoring techniques obsolete. Our solution, H2Classifier, aims at detecting if a user performs an action that has been previously defined over a monitored Web service, but without using any decryption. It is thus only based on passive traffic analysis and relies on random forest classifier. A challenge is to extract representative values of the loaded content associated to a Web page, which is actually customized based on the user action. Extensive evaluations with five top used Web services demonstrate the viability of our technique with an accuracy between 94% and 99%.
Pierre-Olivier Brissaud, Jérôme François, Isabelle Chrisment, Thibault Cholez, Olivier Bettan
IEEE Trans. Netw. Serv. Manag.2
2018 UNiS: A User-space Non-intrusive Workflow-aware Virtual Network Function Scheduler
Anthony, Shihabur Rahman Chowdhury, Tim Bai, Raouf Boutaba, Jérôme François
CNSM5
2018 Passive Monitoring of HTTPS Service Use
Pierre-Olivier Brissaud, Jérôme François, Isabelle Chrisment, Thibault Cholez, Olivier Bettan
CNSM2
2018 Exploratory Data Analysis of a Network Telescope Traffic and Prediction of Port Probing Rates
abstract
Understanding the properties exhibited by large scale network probing traffic would improve cyber threat intelligence. In addition, the prediction of probing rates is a key feature for security practitioners in their endeavors for making better operational decisions and for enhancing their defense strategy skills. In this work, we study different aspects of the traffic captured by a /20 network telescope. First, we perform an exploratory data analysis of the collected probing activities. The investigation includes probing rates at the port level, services interesting top network probers and the distribution of probing rates by geolocation. Second, we extract the network probers exploration patterns. We model these behaviors using transition graphs decorated with probabilities of switching from a port to another. Finally, we assess the capacity of Non-stationary Autoregressive and Vector Autoregressive models in predicting port probing rates as a first step towards using more robust models for better forecasting performance.
Mehdi Zakroum, Abdellah Houmz, Mounir Ghogho, Ghita Mezzour, Abdelkader Lahmadi, Jérôme François, Mohammed Elkoutbi
ISI6
2018 Towards a management plane for smart contracts: Ethereum case study
abstract
Blockchain is an emerging foundational technology with the potential to create a novel economic and social system. The complexity of the technology poses many challenges and foremost amongst these are monitoring and management of blockchain-based decentralized applications. In this paper, we design, implement and evaluate a novel system to enable management operations in smart contracts. A key aspect of our system is that it facilitates the integration of these operations through dedicated 'managing' smart contracts to provide data filtering as per the role of the smart contract-based application user. We evaluate the overhead costs of such data filtering operations after post-deployment analyses of five categories of smart contracts on the Ethereum public testnet, Rinkeby. We also build a monitoring tool to display public blockchain data using a dashboard coupled with a notification mechanism of any changes in private data to the administrator of the monitored decentralized application.
Nida Khan, Abdelkader Lahmadi, Jérôme François, Radu State
NOMS3
2018 Blockchain orchestration and experimentation framework: A case study of KYC
abstract
Conducting experiments to evaluate blockchain applications is a challenging task for developers, because there is a range of configuration parameters that control blockchain environment. Many public testnets (e.g. Rinkeby Ethereum) can be used for testing, however, we cannot adjust their parameters (e.g. Gas limit, Mining difficulty) to further the understanding of the application in question and of the employed blockchain. This paper proposes an easy to use orchestration framework over the Grid'5000 platform. Grid'5000 is a highly reconfigurable and controllable large-scale testbed. We developed a tool that facilitates nodes reservation, deployment and blockchain configuration over the Grid'5000 platform. In addition, our tool can fine-tune blockchain and network parameters before and between experiments. The proposed framework offers insights for private and consortium blockchain developers to identify performance bottlenecks and to assess the behavior of their applications in different circumstances.
Wazen M. Shbair, Mathis Steichen, Jérôme François, Radu State
NOMS3
2017 Knowledge discovery of port scans from darknet
abstract
Port scanning is widely used in Internet prior for attacks in order to identify accessible and potentially vulnerable hosts. In this work, we propose an approach that allows to discover port scanning behavior patterns and group properties of port scans. This approach is based on graph modelling and graph mining. It provides to security analysts relevant information of what services are jointly targeted, and the relationship of the scanned ports. This is helpful to assess the skills and strategy of the attacker. We applied our method to data collected from a large darknet data, i.e. a full /20 network where no machines or services are or have been hosted to study scanning activities.
Sofiane Lagraa, Jérôme François
IM2
2017 Advanced interest flooding attacks in named-data networking
abstract
The Named-Data Networking (NDN) has emerged as a clean-slate Internet proposal on the wave of Information-Centric Networking. Although the NDN's data-plane seems to offer many advantages, e.g., native support for multicast communications and flow balance, it also makes the network infrastructure vulnerable to a specific DDoS attack, the Interest Flooding Attack (IFA). In IFAs, a botnet issuing unsatisfiable content requests can be set up effortlessly to exhaust routers' resources and cause a severe performance drop to legitimate users. So far several countermeasures have addressed this security threat, however, their efficacy was proved by means of simplistic assumptions on the attack model. Therefore, we propose a more complete attack model and design an advanced IFA. We show the efficiency of our novel attack scheme by extensively assessing some of the state-of-the-art countermeasures. Further, we release the software to perform this attack as open source tool to help design future more robust defense mechanisms.
Salvatore Signorello, Samuel Marchal, Jérôme François, Olivier Festor, Radu State
NCA3
2017 Understanding disruptive monitoring capabilities of programmable networks
abstract
The design shift proposed by OpenFlow, with its simple stateless dataplane, initially contributed to the success of Software-Defined Networks. Its lack of state, however, prevents the implementation of many dataplane algorithms. Network applications must therefore offload stateful operations to the control plane, thereby increasing latency and limiting network scalability. Thus, recent research efforts centered on the addition of stateful properties to switches. In this paper, we discuss the impact of emerging programmable dataplane abstractions on network monitoring. In particular, we investigate the need for dataplane states in the design of scalable monitoring applications. We argue that these abstractions are ill-suited for software switches as they retain hardware-specific limitations. Furthermore, we analyse the impact of stateful dataplane designs on the control plane visibility of the network. Finally, we identify opportunities for improvement in the design of stateful software switches.
Paul Chaignon, Kahina Lazri, Jérôme François, Olivier Festor
NetSoft3
2016 Optimizing internet scanning for assessing industrial systems exposure
abstract
Industrial systems are composed of multiple components whose security has not been addressed for a while. Even if recent propositions target to improve it, they are still often exposed to vulnerabilities, since their components are hard to update or replace. In parallel, they tend to be more and more exposed in the public Internet for convenience. Although awareness of such a problem has been raised, there is no precise evaluation of such a risk. In this paper, we define a methodology to measure the exposure of industrial systems through Internet. In particular, a carefully designed scanning approach, named WiScan, is proposed with a low footprint due to the high sensitivity and low resources of targeted systems. It has been applied on the entire IPv4 address space, by targeting specific SCADA ports.
Jérôme François, Abdelkader Lahmadi, Valentín Giannini, Damien Cupif, Frédéric Beck, Bertrand Wallrich
IWCMC1
2016 A multi-level framework to identify HTTPS services
abstract
The development of TLS-based encrypted traffic comes with new challenges related to the management and security analysis of encrypted traffic. There is an essential need for new methods to investigate, with a proper level of identification, the increasing number of HTTPS traffic that may hold security breaches. In fact, although many approaches detect the type of an application (Web, P2P, SSH, etc.) running in secure tunnels, and others identify a couple of specific encrypted web pages through website fingerprinting, this paper proposes a robust technique to precisely identify the services run within HTTPS connections, i.e. to name the services, without relying on specific header fields that can be easily altered. We have defined dedicated features for HTTPS traffic that are used as input for a multi-level identification framework based on machine learning algorithms. Our evaluation based on real traffic shows that we can identify encrypted web services with a high accuracy.
Wazen M. Shbair, Thibault Cholez, Jérôme François, Isabelle Chrisment
NOMS3
2014 Tracking spoofed locations in crowdsourced vehicular applications
abstract
Position information is essential for many vehicular applications like traffic information and route planning but also for enabling vital network routing services. However, the accuracy of the latter is highly dependent of a precise location service which might be altered by attackers forging falsified position data. In this paper, we propose a new method for tracking and removing location spoofing anomalies in large scale position based services assuming neither control of the communication infrastructure or additional hardware nor software at the client side. Our system uses aggregation of location information to compute relevant stability metrics which may reveal anomalous events.
Lautaro Dolberg, Jérôme François, Thomas Engel 0001
NOMS2
2014 RAMSES: Revealing Android Malware Through String Extraction and Selection
Lautaro Dolberg, Quentin Jérôme, Jérôme François, Radu State, Thomas Engel 0001
SecureComm (1)3
2014 PhishStorm: Detecting Phishing With Streaming Analytics
abstract
Despite the growth of prevention techniques, phishing remains an important threat since the principal countermeasures in use are still based on reactive URL blacklisting. This technique is inefficient due to the short lifetime of phishing Web sites, making recent approaches relying on real-time or proactive phishing URL detection techniques more appropriate. In this paper, we introduce PhishStorm, an automated phishing detection system that can analyze in real time any URL in order to identify potential phishing sites. PhishStorm can interface with any email server or HTTP proxy. We argue that phishing URLs usually have few relationships between the part of the URL that must be registered (low-level domain) and the remaining part of the URL (upper-level domain, path, query). We show in this paper that experimental evidence supports this observation and can be used to detect phishing sites. For this purpose, we define the new concept of intra-URL relatedness and evaluate it using features extracted from words that compose a URL based on query data from Google and Yahoo search engines. These features are then used in machine-learning-based classification to detect phishing URLs from a real dataset. Our technique is assessed on 96 018 phishing and legitimate URLs that result in a correct classification rate of 94.91% with only 1.44% false positives. An extension for a URL phishingness rating system exhibiting high confidence rate ( $>$ 99%) is proposed. We discuss in this paper efficient implementation patterns that allow real-time analytics using Big Data architectures such as STORM and advanced data structures based on the Bloom filter.
Samuel Marchal, Jérôme François, Radu State, Thomas Engel 0001
IEEE Trans. Netw. Serv. Manag.2
2013 A semantic firewall for Content-Centric Networking
David Goergen, Thibault Cholez, Jérôme François, Thomas Engel 0001
IM3
2013 ASMATRA: Ranking ASs providing transit service to malware hosters
Cynthia Wagner, Jérôme François, Radu State, Alexandre Dulaunoy, Thomas Engel 0001, Gilles Massen
IM2
2013 Multi-dimensional aggregation for DNS monitoring
abstract
DNS is an essential service in the Internet as it allows to translate human language based domain names into IP addresses. DNS traffic reflects the user activities and behaviors. It is thus a helpful source of information in the context of large scale network monitoring. In particular, passive DNS monitoring garnered much interest for the security perspectives by highlighting the services the machines want to access. In this paper, we propose a new method for assessing the dynamics of the match between DNS names and IP subnetworks using an efficient aggregating scheme combined with relevant steadiness metrics. The evaluation relies on real data collected over several months and is able to detect anomalies related to malicious domains.
Lautaro Dolberg, Jérôme François, Thomas Engel 0001
LCN2
2012 Efficient Multidimensional Aggregation for Large Scale Monitoring
Lautaro Dolberg, Jérôme François, Thomas Engel 0001
LISA2
2012 Semantic Exploration of DNS
Samuel Marchal, Jérôme François, Cynthia Wagner, Thomas Engel 0001
Networking (1)2
2012 SAFEM: Scalable analysis of flows with entropic measures and SVM
abstract
This paper describes a new approach for the detection of large-scale anomalies or malicious events in Netflow records. This approach allows Internet operators, to whom botnets and spam are major threats, to detect large-scale distributed attacks. The prototype SAFEM (Scalable Analysis of Flows with Entropic Measures) uses spatial-temporal Netflow record aggregation and applies entropic measures to traffic. The aggregation scheme highly reduces data storage leading to the viability of using such an approach in an Internet Service Provider network.
Jérôme François, Cynthia Wagner, Radu State, Thomas Engel 0001
NOMS1
2012 DNSSM: A large scale passive DNS security monitoring framework
abstract
We present a monitoring approach and the supporting software architecture for passive DNS traffic. Monitoring DNS traffic can reveal essential network and system level activity profiles. Worm infected and botnet participating hosts can be identified and malicious backdoor communications can be detected. Any passive DNS monitoring solution needs to address several challenges that range from architectural approaches for dealing with large volumes of data up to specific Data Mining approaches for this purpose. We describe a framework that leverages state of the art distributed processing facilities with clustering techniques in order to detect anomalies in both online and offline DNS traffic. This framework entitled DNSSM is implemented and operational on several networks. We validate the framework against two large trace sets.
Samuel Marchal, Jérôme François, Cynthia Wagner, Radu State, Alexandre Dulaunoy, Thomas Engel 0001, Olivier Festor
NOMS2
2012 SDBF: Smart DNS brute-forcer
abstract
The structure of the domain name is highly relevant for providing insights into the management, organization and operation of a given enterprise. Security assessment and network penetration testing are using information sourced from the DNS service in order to map the network, perform reconnaissance tasks, identify services and target individual hosts. Tracking the domain names used by popular Botnets is another major application that needs to undercover their underlying DNS structure. Current approaches for this purpose are limited to simplistic brute force scanning or reverse DNS, but these are unreliable. Brute force attacks depend of a huge list of known words and thus, will not work against unknown names, while reverse DNS is not always setup or properly configured. In this paper, we address the issue of fast and efficient generation of DNS names and describe practical experiences against real world large scale DNS names. Our approach is based on techniques derived from natural language modeling and leverage Markov Chain Models in order to build the first DNS scanner (SDBF) that is leveraging both, training and advanced language modeling approaches.
Cynthia Wagner, Jérôme François, Radu State, Thomas Engel 0001, Gérard Wagener, Alexandre Dulaunoy
NOMS2
2012 Proactive Discovery of Phishing Related Domain Names
Samuel Marchal, Jérôme François, Radu State, Thomas Engel 0001
RAID2
2012 FireCol: a collaborative protection network for the detection of flooding DDoS attacks
abstract
Distributed denial-of-service (DDoS) attacks remain a major security problem, the mitigation of which is very hard especially when it comes to highly distributed botnet-based attacks. The early discovery of these attacks, although challenging, is necessary to protect end-users as well as the expensive network infrastructure resources. In this paper, we address the problem of DDoS attacks and present the theoretical foundation, architecture, and algorithms of FireCol. The core of FireCol is composed of intrusion prevention systems (IPSs) located at the Internet service providers (ISPs) level. The IPSs form virtual protection rings around the hosts to defend and collaborate by exchanging selected traffic information. The evaluation of FireCol using extensive simulations and a real dataset is presented, showing FireCol effectiveness and low overhead, as well as its support for incremental deployment in real networks.
Jérôme François, Issam Aib, Raouf Boutaba
IEEE/ACM Trans. Netw.1
2011 Enforcing security with behavioral fingerprinting
Jérôme François, Radu State, Thomas Engel 0001, Olivier Festor
CNSM1
2011 PTF: Passive Temporal Fingerprinting
abstract
We describe in this paper a tool named PTF (Passive and Temporal Fingerprinting) for fingerprinting network devices. The objective of device fingerprinting is to uniquely identify device types by looking at captured traffic from devices implementing that protocol. The main novelty of our approach consists in leveraging both temporal and behavioral features for this purpose. The key contribution is a fingerprinting scheme, where individual fingerprints are represented by tree-based temporal finite state machines. We have developed a fingerprinting scheme that leverages supervised learning approaches based on support vector machines for this purpose.
Jérôme François, Humberto J. Abdelnur, Radu State, Olivier Festor
Integrated Network Management1
2011 BotTrack: Tracking Botnets Using NetFlow and PageRank
Jérôme François, Shaonan Wang, Radu State, Thomas Engel 0001
Networking (1)1
2011 Machine Learning Approach for IP-Flow Record Anomaly Detection
Cynthia Wagner, Jérôme François, Radu State, Thomas Engel 0001
Networking (1)2
2011 DANAK: Finding the odd!
abstract
With the growth of network connectivity and network sizes, the interest in traffic classification respectively attack and anomaly detection in network monitoring and security related activities have become very strong. In this paper, a new tool called DANAK has been developed for the detection of anomalies in Netflow records by referring to spatial and temporal information aggregation in combination with Machine Learning techniques. Spatially aggregated Netflow records are fed in a new designed kernel function in order to analyze Netflow records on context and quantitative information. To strengthen the analysis of large volumes of Netflow records, Phase Space Embedding and Machine Learning are applied. The proposed method has been validated by extensive experimentation on real data sets, including numerous attack strategies of different roots.
Cynthia Wagner, Jérôme François, Radu State, Thomas Engel 0001
NSS2
2010 Machine Learning Techniques for Passive Network Inventory
abstract
Being able to fingerprint devices and services, i.e., remotely identify running code, is a powerful service for both security assessment and inventory management. This paper describes two novel fingerprinting techniques supported by isomorphic based distances which are adapted for measuring the similarity between two syntactic trees. The first method leverages the support vector machines paradigm and requires a learning stage. The second method operates in an unsupervised manner thanks to a new classification algorithm derived from the ROCK and QROCK algorithms. It provides an efficient and accurate classification. We highlight the use of such classification techniques for identifying the remote running applications. The approaches are validated through extensive experimentations on SIP (Session Initiation Protocol) for evaluating the impact of the different parameters and identifying the best configuration before applying the techniques to network traces collected by a real operator.
Jérôme François, Humberto J. Abdelnur, Radu State, Olivier Festor
IEEE Trans. Netw. Serv. Manag.1
2009 Policy-Based Security Configuration Management, Application to Intrusion Detection and Prevention
abstract
Intrusion detection and/or prevention systems (IDPS) represent an important line of defense against the variety of attacks that can compromise the security and well functioning of an enterprise information system. IDPSes can be network or host-based and can collaborate in order to provide better detections of malicious traffic. Although several IDPS systems have been proposed, their appropriate configuration and control for effective detection and prevention of attacks has always been far from trivial. Another concern is related to the slowing down of system performance when maximum security is applied, hence the need to trade off between security enforcement levels and the performance and usability of an enterprise information system. In this paper we motivate the need for and present a policy-based framework for the configuration and control of the security enforcement mechanisms of an enterprise information system. The approach is based on dynamic adaptation of security measures based on the assessment of system vulnerability and threat prediction and provides several levels of attack containment. As an application, we have implemented a dynamic policy-based adaptation mechanism between the Snort signature-based IDPS and the light weight anomaly-based FireCollaborator IDS. Experiments conducted over the DARPA 2000 and 1999 intrusion detection evaluation datasets show the viability of our framework.
Khalid Alsubhi, Issam Aib, Jérôme François, Raouf Boutaba
ICC3
2009 Automated Behavioral Fingerprinting
Jérôme François, Humberto J. Abdelnur, Radu State, Olivier Festor
RAID1
2008 Towards malware inspired management frameworks
abstract
Scalability is a real challenge for network management due to the increase of the devices to be managed and their various locations. A potential solution is based on botnets basically used by attackers. To prove the efficiency of such a system, a model is needed. Since in a previous paper we propose an IRC botnet model, in this paper we introduce two kinds of P2P models, evaluate them and compare the three different models to determine a practicable solution for network management.
Jérôme François, Radu State, Olivier Festor
NOMS1