Nicolas Bailluet

dblp:294/4609 · DBLP profile ↗
← Back
3ranked-venue papers
2as first author
3since 2021 · last 2025
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 3 · 2 first-author · 3 since 2021
YearPublicationVenuePosition
2025 Nothing is Unreachable: Automated Synthesis of Robust Code-Reuse Gadget Chains for Arbitrary Exploitation Primitives
Nicolas Bailluet, Emmanuel Fleury, Isabelle Puaut, Erven Rohou
USENIX Security Symposium1
2022 The Closer You Look, The More You Learn: A Grey-box Approach to Protocol State Machine Learning
abstract
We propose a new approach to infer state machine models from protocol implementations. Our new tool, StateInspector, learns protocol states by using novel program analyses to combine observations of run-time memory and I/O. It requires no access to source code and only lightweight execution monitoring of the implementation under test. We demonstrate and evaluate StateInspector's effectiveness on numerous TLS and WPA/2 implementations. In the process, we show StateInspector enables deeper state discovery, increased learning efficiency, and more insight compared to existing approaches. Our method led us to discover several concerning deviations from the standards and vulnerabilities in IWD and WolfSSL, both of which were assigned CVEs.
Chris McMahon Stone, Sam L. Thomas, Mathy Vanhoef, Nicolas Bailluet, Tom Chothia
CCS5
2021 Ransomware Detection using Markov Chain Models over File Headers
abstract
This version is a long version of the paper presented to SECRYPT
Nicolas Bailluet, Hélène Le Bouder, David Lubicz
SECRYPT1