Hugo Kermabon-Bobinnec

dblp:318/4217 · DBLP profile ↗
← Back
8ranked-venue papers
3as first author
8since 2021 · last 2025
0000-0003-0044-2178ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 7 · 3 first-author · 7 since 2021Computer networks · 1 · 1 since 2021
YearPublicationVenuePosition
2025 CapMan: Detecting and Mitigating Linux Capability Abuses at Runtime to Secure Privileged Containers
Alireza Moghaddas Borhan, Hugo Kermabon-Bobinnec, Lingyu Wang 0001, Yosr Jarraya, Suryadipta Majumdar
ESORICS (3)2
2025 Connecting the Extra Dots (Contexts): Correlating External Information about Point of Interest for Attack Investigation
abstract
Provenance analysis is one of the go-to solutions today for human analysts to investigate security incidents. To assist analysts in managing the sheer size of provenance graphs, many pruning solutions have been proposed. Such solutions rely on graph-theory features, anomaly detection, and other techniques to identify nodes and edges that are irrelevant to the detected incident. Despite differences in their methodologies, those solutions typically share a common approach when it comes to the detected incident, i.e., they merely regard the incident as an abstract starting point, without tapping into it further. However, we observe that this may lead to missed opportunities for pruning, since the incident is typically associated with external information, e.g., knowledge about the exploit or the vulnerability, which may provide extra contextual insights for effective pruning. Based on such an observation, we propose Contexts, a solution that complements existing pruning approaches by leveraging external information about the incident. Specifically, the solution extracts contextual information from external sources, maps such information to provenance graph nodes, and then correlates those nodes to form a subgraph relevant to the incident. Our implementation and experiments based on real-world attacks demonstrate its effectiveness, e.g., working as the pre-processor of an existing pruning approach, it helps to reduce the false positives from more than 150k to less than ten, and as a standalone pruning solution, Contextsachieves 100% TPR for 19 out of 20 attacks, with an FPR below 0.6% for 16 out of 20 attacks. Finally, its real-world practicality is illustrated through a user study where 94.4% of participants agreed with its usefulness in attack investigation.
Sareh Mohammadi, Hugo Kermabon-Bobinnec, Azadeh Tabiban, Lingyu Wang 0001, Tomás Navarro Múnera, Yosr Jarraya
SP2
2025 PerfSPEC: Performance Profiling-Based Proactive Security Policy Enforcement for Containers
abstract
Container environments provide cloud native applications with scalability, flexibility, and portable support. As a popular container orchestrator, Kubernetes facilitates automatic deployment and maintenance of a large number of containerized applications. However, potential misconfigurations, vulnerabilities, or implementation flaws may empower attackers to exploit the Kubernetes cluster. Although existing solutions such as runtime security policy enforcement may prevent an attack, they can be inefficient in large scale container environments. In this paper, we propose a performance profiling-based proactive security policy enforcement solution, namely, PerfSPEC. First, we accelerate the proactivization of policies (which typically requires significant manual effort) by proposing to profile and rank existing policies according to their induced overhead. This allows us to better focus our efforts and greatly improve the overall response time (e.g., by 98% in contrast to less than 49%). Then, we address the performance limitations of existing solutions by leveraging learning-based approaches to predict future events and compute their verification results in advance. As a result, PerfSPEC achieves a viable response time (e.g., less than 10 ms in contrast to 600 ms with one of the most popular existing approaches) even for large container environments (up to 800 Pods).
Hugo Kermabon-Bobinnec, Sima Bagheri, Mahmood Gholipourchoubeh, Suryadipta Majumdar, Yosr Jarraya, Lingyu Wang 0001, Makan Pourzandi
IEEE Trans. Dependable Secur. Comput.1
2024 CCSM: Building Cross-Cluster Security Models for Edge-Core Environments Involving Multiple Kubernetes Clusters
abstract
With the emergence of 5G networks and their large scale applications such as IoT and autonomous vehicles, telecom operators are increasingly offloading the computation closer to customers (i.e., on the edge). Such edge-core environments usually involve multiple Kubernetes clusters potentially owned by different providers. Confidentiality concerns could prevent those providers from sharing data freely with each other, which makes it challenging to perform common security tasks such as security verification across different clusters. In this work, we propose a solution for building cross-cluster security models to enable various security analyses, while preserving confidentiality for each cluster. We design a six-step methodology to model both the cross-cluster communication and cross-cluster event dependency, and we apply those models to different security use cases. We implement our solution based on a 5G edge-core environment that involves multiple Kubernetes clusters, and our experimental results demonstrate its efficiency (e.g., less than 8 seconds of processing time for a model with 3,600 edges and nodes) and accuracy (e.g., more than 96% for cross-cluster event prediction).
Mahmood Gholipourchoubeh, Hugo Kermabon-Bobinnec, Suryadipta Majumdar, Yosr Jarraya, Lingyu Wang 0001, Boubakr Nour, Makan Pourzandi
CODASPY2
2024 Phoenix: Surviving Unpatched Vulnerabilities via Accurate and Efficient Filtering of Syscall Sequences
Hugo Kermabon-Bobinnec, Yosr Jarraya, Lingyu Wang 0001, Suryadipta Majumdar, Makan Pourzandi
NDSS1
2024 ACE-WARP: A Cost-Effective Approach to Proactive and Non-Disruptive Incident Response in Kubernetes Clusters
abstract
A large-scale cluster of containers managed with an orchestrator like Kubernetes are behind many cloud-native applications today. However, the weaker isolation provided by containers means attackers can potentially exploit a vulnerable container and then escape its isolation to cause more severe damages to the underlying infrastructure and its hosted applications. Defending against such an attack using existing attack detection solutions can be challenging. Due to the well known high false positive rate of such solutions, taking aggressive actions upon every alert can lead to unacceptable service disruption. On the other hand, waiting for security administrators to perform in-depth analysis and validation could render the mitigation too late to prevent irreversible damages. In this paper, we propose ACE-WARP, a cost-effective proactive and non-disruptive incident response to address such security challenges for Kubernetes clusters. First, our approach is proactive in the sense that it performs mitigation based on predicted (instead of real) attacks, which prevents irreversible damages. Second, our approach is also non-disruptive since the mitigation is achieved through live migration of containers, which causes no service disruption even in the case of false positives. Finally, to realize the full potential of this approach in containers migration, we formulate the inherent trade-off between security and cost (delay) as a multi-objective optimization problem. Our evaluation results show that ACE-WARP can successfully mitigate up to 81% of the attacks, and our optimization algorithm achieves up to 30% more threat reduction and 7% less delay while being 37 times faster compared to a standard optimization solution.
Sima Bagheri, Hugo Kermabon-Bobinnec, Mohammad Ekramul Kabir, Suryadipta Majumdar, Lingyu Wang 0001, Yosr Jarraya, Boubakr Nour, Makan Pourzandi
IEEE Trans. Inf. Forensics Secur.2
2023 Warping the Defence Timeline: Non-Disruptive Proactive Attack Mitigation for Kubernetes Clusters
abstract
In spite of being the de-facto standard of container orchestrators, Kubernetes reportedly suffers from security vulnerabilities and misconfigurations which may lead to severe security threats to the containerized environments it manages. Mitigating such threats based on alerts raised by existing security monitoring solutions (e.g., Falco) can be challenging. First, taking actions upon every alert can cause unacceptable service disruption, as many such alerts may turn out to be false positives. Second, validating each alert by administrators before taking actions may render the mitigation too late to prevent irreversible damages, e.g., denial of service. In this paper, we propose a non-disruptive proactive mitigation approach to address those limitations. Our main idea is to proactively trigger mitigation ahead of an attack to prevent irreversible damages, while designing the mitigation actions to be non-disruptive to avoid any service disruption caused by false alerts. We implement and integrate our approach with Kubernetes, and show its effectiveness and efficiency.
Sima Bagheri, Hugo Kermabon-Bobinnec, Suryadipta Majumdar, Yosr Jarraya, Lingyu Wang 0001, Makan Pourzandi
ICC2
2022 ProSPEC: Proactive Security Policy Enforcement for Containers
abstract
By providing lightweight and portable support for cloud native applications, container environments have gained significant momentum lately. A container orchestrator such as Kubernetes can enable the automatic deployment and maintenance of a large number of containerized applications. However, due to its critical role, a container orchestrator also attracts a wide range of security threats exploiting misconfigurations or implementation flaws. Moreover, enforcing security policies at runtime against such security threats becomes far more challenging, as the large scale of container environments implies high complexity, while the high dynamicity demands a short response time. In this paper, we tackle this key security challenge to container environments through a proactive approach, namely, ProSPEC. Our approach leverages learning-based prediction to conduct the computationally intensive steps (e.g., security verification) in advance, while keeping the runtime steps (e.g., policy enforcement) lightweight. Consequently, ProSPEC can ensure a practical response time (e.g., less than 10 ms in contrast to 600 ms with one of the most popular existing approaches) for large container environments (up to 800 Pods).
Hugo Kermabon-Bobinnec, Mahmood Gholipourchoubeh, Sima Bagheri, Suryadipta Majumdar, Yosr Jarraya, Makan Pourzandi, Lingyu Wang 0001
CODASPY1