Kéren Saint-Hilaire

dblp:313/3100 · DBLP profile ↗
← Back
5ranked-venue papers
5as first author
5since 2021 · last 2026
0009-0003-8139-3992ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 5 · 5 first-author · 5 since 2021
YearPublicationVenuePosition
2026 Playbook Generation for Process Anomalies in Insider Threat Scenarios
Kéren Saint-Hilaire, Nora Cuppens, Frédéric Cuppens
SECRYPT (2)1
2025 A real-time automated attack-defense graph generation approach
abstract
With the increase in cyberattacks, developing appropriate strategies to mitigate and prevent them is essential. In the literature, tools exist that either help prevent or mitigate them. Attack graphs help define mitigation strategies because they help represent and visualize the attacker’s position on a system. However, the mitigation actions are not instantiated on the attack graph. This paper proposes an approach to generate an automated attack-defense graph based on real-time monitored system alerts and an extensive and comprehensive state-of-the-art review. We propose to enrich logical attack graphs generated by a logical reasoner. The enrichment process is possible thanks to a vulnerability ontology that infers additional impacts for an exploited vulnerability. We propose a countermeasure selection approach based on graph matching to generate an optimal Incident Response (IR) playbook. We propose instantiating the generated playbook’s IR actions to get an attack-defense graph in real-time. This instantiation is done thanks to anti-correlation. The anti-correlation ensures that the countermeasures are instantiated on the appropriate attack graph nodes. Only the IR actions whose execution can be launched automatically are applied. We validate our approach using two use-case scenarios that target critical industrial infrastructures. We analyze the countermeasures instantiated on the attack graphs for the scenarios that can achieve the attack goal. We evaluated the approach concerning the security relevance of instantiated countermeasures in attack graphs for several attack paths. The countermeasures instantiated on a node are always relevant to the attacker’s action represented by this node. We also evaluate the approach regarding time performance, considering several situations for the use-case scenarios. The generation time depends on the number of vulnerabilities involved in the scenario. The generation time is on average 0.161 s when the playbook has been generated before the attack defense graph generation process.
Kéren Saint-Hilaire, Christopher Neal, Frédéric Cuppens, Nora Cuppens, Francesca Bassi, Makhlouf Hadji
J. Inf. Secur. Appl.1
2024 Optimal Automated Generation of Playbooks
Kéren Saint-Hilaire, Christopher Neal, Frédéric Cuppens, Nora Cuppens, Makhlouf Hadji
DBSec1
2024 Attack-Defense Graph Generation: Instantiating Incident Response Actions on Attack Graphs
abstract
Cyber-attacks are increasing; it is more urgent for organizations to automate their Incident Response (IR) plan process. Attack Graphs (AGs) are used to represent actions followed by an adversary to reach a goal. However, an expert should analyze each possible action and their impact to decide which mitigation actions should be applied to block the attack fulfillment. This paper proposes an approach to generate Attack-Defense Graphs in real-time by instantiating IR actions on a logical AG. The system’s real-time monitoring enables the detection of malicious actions, which leads to the generation of alerts mapped with the AG to deduce the attacker’s location on the system. Our solution can decide where to apply IR actions to mitigate the attack impact. These IR actions are part of playbooks that are generated automatically for the attack. We propose correlating IR actions with the AG fact nodes to choose which IR actions to instantiate on the AG. Therefore, we propose generating predicates for the mitigation actions, which are mapped with the AG predicates. We validate our approach with an industrial use case. An asset is vulnerable to Remote Code Execution (RCE) requiring user credentials that can be obtained through a brute force attack. We show how our approach helps anticipate an adversary’s next step. The countermeasures predicates are instantiated on the AG to prevent the attacker from going further on the system.
Kéren Saint-Hilaire, Christopher Neal, Frédéric Cuppens, Nora Cuppens, Francesca Bassi
TrustCom1
2023 Automated Enrichment of Logical Attack Graphs via Formal Ontologies
Kéren Saint-Hilaire, Frédéric Cuppens, Nora Cuppens, Joaquín García 0001
SEC1