Alexis Olivereau

dblp:35/10474 · DBLP profile ↗
← Back
17ranked-venue papers
0as first author
4since 2021 · last 2024
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 7 · 2 since 2021Computer networks · 5Systems, architecture and hardware · 1 · 1 since 2021
YearPublicationVenuePosition
2024 Addressing the Scalability of Network Digital Twins: A Network Sampling Approach
abstract
With the increasing complexity of mobile communication networks like 5G/6G networks, characterized by the diversity of network devices, technologies, and applications, advanced network management solutions are needed to ensure real-time network optimization with risk-free decision making operations (e.g., safe network reconfiguration). To achieve this objective, a Network Digital Twin (NDT) paradigm represents an attractive perspective, enabling the manipulation of the virtual counterpart of a real communication network. Nonetheless, generating a Digital Twin of a complex network, comprising thousands of heterogeneous devices and highly dynamic network characteristics (resource usage, network topology, link quality, etc.) poses a serious scalability problem. This paper aims at addressing the scalability problem for the generation of a Digital Twin of a complex network like a 5G/6G network. In particular, the paper proposes a sampling approach in conjunction with a structured network information representation, as well as zoom-in/out operations to enable a modular generation of the NDT.
Mounir Kellil, Siwar Ben Hadj Said, Minh-Thuyen Thi, Christophe Janneteau, Alexis Olivereau
CNSM5
2023 Efficient Network Representation for GNN-Based Intrusion Detection
Hamdi Friji, Alexis Olivereau, Mireille Sarkiss
ACNS (1)2
2023 On the Management of TSN Networks in 6G: A Network Digital Twin Approach
abstract
Emerging latency-sensitive applications (e.g. factory automation control, industrial metaverse, digital twin-enabled smart manufacturing) require that the networks ensure data delivery with a guaranteed low and bounded latency. Time-Sensitive Networking (TSN) mechanisms have been developed to enable deterministic features in standard Ethernet. 5G and 6G networks are looking forward to integrate TSN and benefit from its ability to ensure determinism. Accommodating the complexity of TSN networks in 6G is not straightforward. In particular, conventional rule-based heuristic algorithms are not optimized for such environments. Therefore, the TSN network management framework should be equipped with the right tools allowing to compute at runtime new TSN configuration for each event (e.g. change in topology, new application, new device, etc.). To address this problem, recent standardization initiatives (IETF and ITU-T) have investigated the opportunities to use Network Digital Twin (NDT) paradigm for these use cases of 6G networks.This paper proposes a framework that puts together the key enablers to support NDT deployment for TSN-based public or private 6G network and to cope with the relevant challenges. In particular, we define a modular and self-learner NDT framework. To construct the DT model, the framework can rely on open source simulators/emulators with predefined models, or in other cases, it may learn the DT model from real infrastructure using Artificial Intelligence (AI)/Machine Learning (ML) techniques trained over collected data. The paper also showcases how NDT, Software-Defined Network (SDN) and deterministic networks (TSN and DetNet) are key enablers for 6G network architecture.
Siwar Ben Hadj Said, Minh-Thuyen Thi, Mounir Kellil, Alexis Olivereau
ETFA4
2023 Multi-stage Attack Detection and Prediction Using Graph Neural Networks: An IoT Feasibility Study
abstract
With the ever-increasing reliance on digital networks for various aspects of modern life, ensuring their security has become a critical challenge. Intrusion Detection Systems play a crucial role in ensuring network security, actively identifying and mitigating malicious behaviours. However, the relentless advancement of cyber-threats has rendered traditional/classical approaches insufficient in addressing the sophistication and complexity of attacks. This paper proposes a novel 3-stage intrusion detection system inspired by a simplified version of the Lockheed Martin cyber kill chain to detect advanced multi-step attacks. The proposed approach consists of three models, each responsible for detecting a group of attacks with common characteristics. The detection outcome of the first two stages is used to conduct a feasibility study on the possibility of predicting attacks in the third stage. Using the ToN IoT dataset, we achieved an average of 94% F1-Score among different stages, outperforming the benchmark approaches based on Random-forest model. Finally, we comment on the feasibility of this approach to be integrated in a real-world system and propose various possible future work.
Hamdi Friji, Ioannis Mavromatis, Adrián Sánchez-Mompó, Pietro Edoardo Carnelli, Alexis Olivereau, Aftab Khan 0001
TrustCom5
2019 A Cascade-structured Meta-Specialists Approach for Neural Network-based Intrusion Detection
abstract
An ensemble learning approach for classification in intrusion detection is proposed. Its application to the KDD Cup 99 and NSL-KDD datasets consistently increases the classification accuracy compared to previous techniques. The cascade-structured meta-specialists architecture is based on a three-step optimization method: data augmentation, hyperparameters optimization and ensemble learning. Classifiers are first created with a strong specialization in each specific class. These specialists are then combined to form meta-specialists, more accurate than the best classifiers that compose them. Finally, meta-specialists are arranged in a cascading architecture where each classifier is successively given the opportunity to recognize its own class. This method is particularly useful for datasets where training and test sets differ greatly, as in this case. The cascade-structured meta-specialists approach achieved a very high classification accuracy (94.44% on KDD Cup 99 test set and 88.39% on NSL-KDD test set) with a low false positive rate (0.33% and 1.94% respectively).
Maxime Labonne, Alexis Olivereau, Baptiste Polvé, Djamal Zeghlache
CCNC2
2019 Autonomous Detection of Synchronization Attacks in the Industrial Internet Of Things
abstract
Time Synchronization is an essential communication component for Industrial Wireless Sensor Networks (IWSNs). An IWSN is composed of multiple distributed resource-constrained sensor nodes, which require their local clocks to be synchronized with each other to exchange packets in a precisely real time ordered schedule. Time synchronization protocols are not outlined with security support. As a consequence, a new generation of attacks arose, explicitly targeting the corresponding protocols. Recent research studies [1, 2, 3] prove that synchronization attacks are severe and practical. Without detection mechanisms, synchronization attacks bypass security defenses. A methodology for the detection of synchronization attacks based on characteristics of the synchronization protocol is proposed in this paper. Thus, we propose a novel method based on machine learning algorithms for detecting IIoT synchronization attacks. Applying such strategies for cyber-security in IIoT requires the availability of substantial synchronization IIoT attack data. In our research, the real-life equivalent simulations using the open source OpenWSN simulator has been utilized for generation of high fidelity attack area, within the 6TiSCH industrial network. We believe that the IIoT attack dataset generated in this work can be used for further research and for detecting high layer attacks too. Experimentation was carried out using six learning algorithms to detect the attack and classify them from legitimate behavior.
Meriem Smache, Alexis Olivereau, Thibault Franco-Rondisson, Assia Tria
IPCCC2
2019 Time Synchronization Attack Scenarios and Analysis of Effective Self-Detection Parameters in a Distributed Industrial Wireless Sensor Network
abstract
Time Synchronization is an essential communication component for Industrial Wireless Sensor Networks (IWSNs). An IWSN is composed of multiple distributed resource-constrained sensor nodes, which require their local clocks to be synchronized with each other in order to exchange packets in real time precisely ordered schedule. Time synchronization strategies are not designed with security support. As a consequence, a new generation of attacks arose, specifically targeting the corresponding protocols. Recent research studies prove that some attacks are practical and severe. At the same time, the set of detection parameters proposed in emerging attack detection techniques are not sufficient to catch up on the attacks. In this paper, we analyze in depth some attack strategies and develop new useful detection parameters. The key concept behind our mechanism is to use the MAC layer protocol characteristics to figure out novel metrics as inputs for a self-detection of time synchronization attacks.
Meriem Smache, Alexis Olivereau, Thibault Franco-Rondisson, Assia Tria
PST2
2018 Anomaly Detection in Vehicle-to-Infrastructure Communications
abstract
This paper presents a neural network-based anomaly detection system for vehicular communications. The proposed system is able to detect in-vehicle data tampering in order to avoid the transmission of bogus or harmful information. We investigate the use of Long Short-term Memory (LSTM) and Multilayer Perceptron (MLP) neural networks to build two prediction models. For each model, an efficient architecture is designed based on appropriate hardware requirements. Then, a comparative performance analysis is provided to recommend the most efficient neural network model. Finally, a set of metrics are selected to show the accuracy of the proposed detection system under several types of security attacks.
Michele Russo, Maxime Labonne, Alexis Olivereau, Mohammad Rmayti
VTC Spring3
2014 Lightweight collaborative key establishment scheme for the Internet of Things
Yosra Ben Saied, Alexis Olivereau, Djamal Zeghlache, Maryline Laurent
Comput. Networks2
2014 A survey of collaborative services and security-related issues in modern wireless Ad-Hoc communications
Yosra Ben Saied, Alexis Olivereau, Djamal Zeghlache, Maryline Laurent
J. Netw. Comput. Appl.2
2013 COACH: A context aware and multi-service trust model for Cooperation management in heterogeneous wireless networks
abstract
The wide majority of existing trust-based systems in wireless networks are today bound to a single service. As such, they cannot use past experiences related to other services. Even those that support multiple services hide this heterogeneity by regrouping all past experiences and contexts into a single metric, which strongly degrades the quality of results. To go beyond these restrictions, we designed a novel context-aware and multi-service trust model for heterogeneous wireless networks that involve nodes with different resources capabilities. Simulation results prove the proper functioning of the proposed system and its effectiveness against common attacks hindering trust models.
Yosra Ben Saied, Alexis Olivereau, Radhouene Azzabi
IWCMC2
2013 Pseudonymous communications in secure industrial wireless sensor networks
abstract
Wireless sensor networks are becoming widely deployed in the industry. They are used to provide contextual information about the industrial environment being surveyed, to control and monitor the industrial processes, and even for workers who can be augmented with sensors. In these wireless networks, an adversary can easily eavesdrop communications with the aim to collect private information about sensors, because of the open nature of the wireless medium. A usual solution to prevent privacy violation relies on the use of pseudonyms as sensor identities; however, pseudonyms may deter authentication and access control enforcement in the network. This paper introduces an efficient pseudonym-based scheme that provides privacy protection to sensors without compromising network access security.
Nouha Oualha, Alexis Olivereau, Aymen Boudguiga
PST2
2013 Trust management system design for the Internet of Things: A context-aware and multi-service approach
Yosra Ben Saied, Alexis Olivereau, Djamal Zeghlache, Maryline Laurent
Comput. Secur.2
2012 Challenges and Current Results of the TWISNet FP7 Project - (Extended Abstract)
Markus Wehner, Sven Zeisberg, Nouha Oualha, Alexis Olivereau, Mike Ludwig, Dan Tudose, Laura Gheorghe, Emil Slusanschi, Basil Hess, Felix von Reischach, David Bateman
TrustBus4
2012 Trustworthy Infrastructure Services for a Secure and Privacy-Respecting Internet of Things
abstract
Security is an important cornerstone for the Internet of Things (IoT). Due to the expected pervasion of IoT and its relevance in all fields of human activity, it will likely become a critical asset. Thus, the integrity of data and trust in the services offering the data is crucial. Further, to protect important data and user interests, confidentiality of data and privacy of users must be ensured. Moreover, each request and response in the frame of IoT has to be authenticated in a proper and secure way to ensure accountability and proper operation. Finally, with the usage of IoT for vital functionalities, availability becomes increasingly important, although availability is out of the scope of this document. The resolution infrastructure introduced in this work is a crucial component of the overall IoT architecture and most security goals are anchored here. Our suggested architecture ensures privacy and security for the resolution functions and offers as well a basis for other security functionalities needed outside the resolution infrastructure.
Dennis Gessner, Alexis Olivereau, Alexander Salinas Segura, Alexandru Serbanati
TrustCom2
2012 Secure communication for smart IoT objects: Protocol stacks, use cases and practical examples
abstract
In this paper we discuss security procedures for constrained IoT devices. We start with the description of a general security architecture along with its basic procedures, then discuss how its elements interact with the constrained communication stack and explore pros and cons of popular security approaches at various layers of the ISO/OSI model. We also discuss a practical example for the establishment of end-to-end secure channels between constrained and unconstrained devices. The proposed method is lightweight and allows the protection of IoT devices through strong encryption and authentication means, so that constrained devices can benefit from the same security functionalities that are typical of unconstrained domains, without however having to execute computationally intensive operations. To make this possible, we advocate using trusted unconstrained nodes for the offloading of computationally intensive tasks. Moreover, our design does not require any modifications to the protocol stacks of unconstrained nodes.
Riccardo Bonetto, Nicola Bui, Vishwas Lakkundi, Alexis Olivereau, Alexandru Serbanati, Michele Rossi
WOWMOM4
2012 D-HIP: A distributed key exchange scheme for HIP-based Internet of Things
abstract
Host Identity Protocol (HIP) emerges as the most suitable identification protocol for the Internet of Things. HIP not only provides identifier/locator split but also a key agreement procedure named HIP Base Exchange, which allows secure connections between HIP peers. However, the heterogeneous and decentralized nature of IoT architecture, coupling resource-constrained networks with powerful Internet, impedes the use of HIP on small devices due to its computationally expensive cryptographic operations. In this paper, we propose a distributed lightweight key exchange protocol designed to reduce the requirements of HIP Base Exchange, in order to be supported by resource-constrained nodes.
Yosra Ben Saied, Alexis Olivereau
WOWMOM2