Christopher Neal

dblp:29/7507 · DBLP profile ↗
← Back
12ranked-venue papers
0as first author
11since 2021 · last 2025
0000-0002-6953-8728ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 11 · 11 since 2021Software engineering, systems software and programming languages · 1Databases, data management, data science and information retrieval · 1
YearPublicationVenuePosition
2025 Federated Intrusion Detection System Based on Unsupervised Machine Learning
Maxime Gourceyraud, Rim Ben Salem, Christopher Neal, Frédéric Cuppens, Nora Cuppens
CRiSIS3
2025 Semantic and Graph-Based Unsupervised Learning for Insider Threat Detection Using User Activity Sequences
abstract
Insider threats, where legitimate users misuse their access for malicious purposes, remain challenging to detect due to their contextual and behavioral subtleties. This paper presents a novel machine learning framework that captures user activity sequences through a user-centric representation named the User Daily Activity Sentence (UDAS). Unlike prior work that informally uses daily sequences, we formalize UDAS as a behavioral encoding technique using Word2Vec embeddings and extensively evaluate it across multiple unsupervised anomaly detection methods.To enrich this representation with relational context, we propose a graph-based extension that constructs a user interaction graph based on co-device usage and domain access. A Graph Convolutional Network (GCN) is applied to enhance semantic user embeddings, and anomaly detection is performed using Kmeans clustering.To the best of our knowledge, this is the first work to systematically combine semantic sequence embeddings with graph-based relational learning for insider threat detection. Experiments on the CERT Insider Threat v4.2 dataset show that our method outperforms prior unsupervised models in accuracy and robustness. The proposed framework requires no feature engineering or labeled data, making it applicable to real-world monitoring environments.
Neda Baghalizadeh-Moghadam, Christopher Neal, Sara Imene Boucetta, Frédéric Cuppens, Nora Cuppens
PST2
2025 A real-time automated attack-defense graph generation approach
abstract
With the increase in cyberattacks, developing appropriate strategies to mitigate and prevent them is essential. In the literature, tools exist that either help prevent or mitigate them. Attack graphs help define mitigation strategies because they help represent and visualize the attacker’s position on a system. However, the mitigation actions are not instantiated on the attack graph. This paper proposes an approach to generate an automated attack-defense graph based on real-time monitored system alerts and an extensive and comprehensive state-of-the-art review. We propose to enrich logical attack graphs generated by a logical reasoner. The enrichment process is possible thanks to a vulnerability ontology that infers additional impacts for an exploited vulnerability. We propose a countermeasure selection approach based on graph matching to generate an optimal Incident Response (IR) playbook. We propose instantiating the generated playbook’s IR actions to get an attack-defense graph in real-time. This instantiation is done thanks to anti-correlation. The anti-correlation ensures that the countermeasures are instantiated on the appropriate attack graph nodes. Only the IR actions whose execution can be launched automatically are applied. We validate our approach using two use-case scenarios that target critical industrial infrastructures. We analyze the countermeasures instantiated on the attack graphs for the scenarios that can achieve the attack goal. We evaluated the approach concerning the security relevance of instantiated countermeasures in attack graphs for several attack paths. The countermeasures instantiated on a node are always relevant to the attacker’s action represented by this node. We also evaluate the approach regarding time performance, considering several situations for the use-case scenarios. The generation time depends on the number of vulnerabilities involved in the scenario. The generation time is on average 0.161 s when the playbook has been generated before the attack defense graph generation process.
Kéren Saint-Hilaire, Christopher Neal, Frédéric Cuppens, Nora Cuppens, Francesca Bassi, Makhlouf Hadji
J. Inf. Secur. Appl.2
2024 Classifying Insider Threat Scenarios Through Explainable Articial Intelligence
Rémi Grzeczkowicz, Christopher Neal, Neda Baghalizadeh-Moghadam, Nora Cuppens, Frédéric Cuppens
CRiSIS2
2024 Optimal Automated Generation of Playbooks
Kéren Saint-Hilaire, Christopher Neal, Frédéric Cuppens, Nora Cuppens, Makhlouf Hadji
DBSec2
2024 How to Better Fit Reinforcement Learning for Pentesting: A New Hierarchical Approach
Marc-Antoine Faillon, Baptiste Bout, Julien Francq, Christopher Neal, Nora Cuppens, Frédéric Cuppens, Reda Yaich
ESORICS (4)4
2024 NLP and Neural Networks for Insider Threat Detection
abstract
Insider threats in cybersecurity are notoriously difficult to detect due to their covert nature, often evading traditional security measures. In this paper, we propose an unsupervised method for insider threat detection, where we leverage advanced Natural Language Processing (NLP) techniques to enhance the detection of abnormal user activities indicative of insider threats. We represent user behaviors in a vector space using Word2Vec, which in turn are analyzed using state-of-the-art NLP models, including BERT, SciBERT, RoBERTa, GPT-2, and LLaMA. These models are integrated with Long Short-Term Memory (LSTM) and Gated Recurrent Unit (GRU) networks to analyze the temporal behavior of user actions. We evaluate the proposed method using the CMU-CERT dataset version 4.2. Our implemented approaches based on NLP achieve better results than previous state-of-the-art approaches that use traditional unsupervised learning.
Neda Baghalizadeh-Moghadam, Christopher Neal, Frédéric Cuppens, Nora Cuppens
TrustCom2
2024 Attack-Defense Graph Generation: Instantiating Incident Response Actions on Attack Graphs
abstract
Cyber-attacks are increasing; it is more urgent for organizations to automate their Incident Response (IR) plan process. Attack Graphs (AGs) are used to represent actions followed by an adversary to reach a goal. However, an expert should analyze each possible action and their impact to decide which mitigation actions should be applied to block the attack fulfillment. This paper proposes an approach to generate Attack-Defense Graphs in real-time by instantiating IR actions on a logical AG. The system’s real-time monitoring enables the detection of malicious actions, which leads to the generation of alerts mapped with the AG to deduce the attacker’s location on the system. Our solution can decide where to apply IR actions to mitigate the attack impact. These IR actions are part of playbooks that are generated automatically for the attack. We propose correlating IR actions with the AG fact nodes to choose which IR actions to instantiate on the AG. Therefore, we propose generating predicates for the mitigation actions, which are mapped with the AG predicates. We validate our approach with an industrial use case. An asset is vulnerable to Remote Code Execution (RCE) requiring user credentials that can be obtained through a brute force attack. We show how our approach helps anticipate an adversary’s next step. The countermeasures predicates are instantiated on the AG to prevent the attacker from going further on the system.
Kéren Saint-Hilaire, Christopher Neal, Frédéric Cuppens, Nora Cuppens, Francesca Bassi
TrustCom2
2023 Real-Time Defensive Strategy Selection via Deep Reinforcement Learning
abstract
As computer networks face increasingly sophisticated attacks there is a need to create adaptive defensive systems that can select appropriate countermeasures to thwart attacks. The use of Deep Reinforcement Learning to train defensive agents is an avenue to study to meet this demand. In this paper we describe a simulated computer network environment wherein we conduct attacks and train defensive agents that employ Moving Target Defense and Deception strategies. We train an attacking agent, using Proximal Policy Optimization, to learn a policy to extract sensitive network data as quickly as possible from the environment. We then train a defending agent to prevent the attacker from reaching its objective. Our results demonstrate how the defender is able to learn a policy to inhibit the attacker.
Axel Charpentier, Christopher Neal, Nora Cuppens, Frédéric Cuppens, Reda Yaich
ARES2
2022 Evading Deep Reinforcement Learning-based Network Intrusion Detection with Adversarial Attacks
abstract
An Intrusion Detection System (IDS) aims to detect attacks conducted over computer networks by analyzing traffic data. Deep Reinforcement Learning (Deep-RL) is a promising lead in IDS research, due to its lightness and adaptability. However, the neural networks on which Deep-RL is based can be vulnerable to adversarial attacks. By applying a well-computed modification to malicious traffic, adversarial examples can evade detection. In this paper, we test the performance of a state-of-the-art Deep-RL IDS agent against the Fast Gradient Sign Method (FGSM) and Basic Iterative Method (BIM) adversarial attacks. We demonstrate that the performance of the Deep-RL detection agent is compromised in the face of adversarial examples and highlight the need for future Deep-RL IDS work to consider mechanisms for coping with adversarial examples.
Mohamed Amine Merzouk, Joséphine Delas, Christopher Neal, Frédéric Cuppens, Nora Cuppens, Reda Yaich
ARES3
2022 Attacker Attribution via Characteristics Inference Using Honeypot Data
Pierre Crochelet, Christopher Neal, Nora Cuppens, Frédéric Cuppens
NSS2
2012 A Linked Data platform for mining software repositories
abstract
The mining of software repositories involves the extraction of both basic and value-added information from existing software repositories. The repositories will be mined to extract facts by different stakeholders (e.g. researchers, managers) and for various purposes. To avoid unnecessary pre-processing and analysis steps, sharing and integration of both basic and value-added facts are needed. In this research, we introduce SeCold, an open and collaborative platform for sharing software datasets. SeCold provides the first online software ecosystem Linked Data platform that supports data extraction and on-the-fly inter-dataset integration from major version control, issue tracking, and quality evaluation systems. In its first release, the dataset contains about two billion facts, such as source code statements, software licenses, and code clones from 18 000 software projects. In its second release the SeCold project will contain additional facts mined from issue trackers and versioning systems. Our approach is based on the same fundamental principle as Wikipedia: researchers and tool developers share analysis results obtained from their tools by publishing them as part of the SeCold portal and therefore make them an integrated part of the global knowledge domain. The SeCold project is an official member of the Linked Data dataset cloud and is currently the eighth largest online dataset available on the Web.
Iman Keivanloo, Christopher Forbes, Aseel Hmood, Mostafa Erfani, Christopher Neal, George Peristerakis, Juergen Rilling
MSR5