EDBT 2026 Demo / reviewers in the wild / expert
Isabelle Chrisment
dblp:66/2464
· DBLP profile ↗
43ranked-venue papers
1as first author
13since 2021 · last 2025
0000-0002-8474-0019ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 19 · 1 first-author · 5 since 2021Security and privacy · 5 · 3 since 2021Systems, architecture and hardware · 2 · 1 since 2021Software engineering, systems software and programming languages · 2
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | TATA: Benchmark NIDS Test Sets Assessment and Targeted Augmentation
Omar Anser, Jérôme François, Isabelle Chrisment, Daishi Kondo |
ESORICS (1) | 3 |
| 2025 | Demo: SweetsPot: A Distributed Honeypot Federation PlatformabstractNetworks of honeypots, similar to network telescopes, enable the monitoring of Internet threat activity. Honeypots can collect service-specific information about threat behavior and capabilities, depending on their configuration. This demonstration paper presents SweetsPot, a distributed honeypot data collection system. SweetsPot aims to facilitate threat research to model attacker behavior and characterize emerging threats. Additionally, SweetsPot supports live-streaming of event data, enabling rapid analysis, visualization, and timely threat response. Tillmann Angeli, Frédéric Beck, Daishi Kondo, Isabelle Chrisment, Hideki Tode, Hans D. Schotten |
LCN | 4 |
| 2025 | Scalable and Generalizable RL Agents for Attack Path Discovery via Continuous Invariant SpacesabstractIdentifying critical attack paths in a net-work-sequences of vulnerabilities an attacker can chain to achieve a specific threat model-is crucial for pinpointing vulnerable areas where defensive measures should be focused. Recently, Reinforcement Learning (RL) has gained traction for training agents in identifying these critical paths. However, current solutions typically train RL agents tailored to a specific environment-defined by a fixed network structure and vulnerability set-requiring costly retraining whenever either changes. This limitation arises from optimizing the agent to map between discrete input and output spaces, treating network nodes and vulnerabilities as atomic discrete elements. In this paper, we propose a method for constructing continuous and invariant input and output spaces for RL agents, enabling them to learn transferable policies that generalize across diverse network configurations and vulnerability sets. We also release Continuous CyberBattleSim (C-CyberBattleSim), an enhanced version of Microsoft CyberBattleSim designed to train agents with the novel continuous spaces. The tool is further extended to integrate realworld vulnerability data and a new scenario generation pipeline to improve the realism of training and testing environments. Agents trained in continuous spaces are assessed in 800 scenarios with varying sizes and various allocations of 829 real-world vulnerabilities, demonstrating an average improvement of 9.3x in scalability against agents trained in discrete spaces, as well as an average generalization score of $89 \%$ to more complex scenarios when trained in simpler scenarios. A final study evaluates whether continuous agents trained in simulation can adapt to real-world and emulated scans. On average, agents achieve $75 \%$ of the score they would have if trained directly on the scans, demonstrating effective knowledge transfer. Franco Terranova, Abdelkader Lahmadi, Isabelle Chrisment |
RAID | 3 |
| 2024 | Automated Machine Learning Configuration to Learn Intrusion Detectors on Attack-Free DatasetsabstractIntrusion detection systems have benefited from Machine Learning (ML) to alleviate the problem of building and maintaining accurate signatures. Nevertheless, ML solutions face issues like overfitting or insufficient training data, which may necessitate retraining or adjustments to maintain long-term efficiency. From data collection to model training, all efforts are crucial for deploying a robust ML-based intrusion detector. Among these efforts, optimizing model hyperparameters, a time-consuming task, can be automated by existing methods.Yet, such methods require a validation set, making them unsuitable for training a detector on an attack-free dataset, as in anomaly-based intrusion detection. Additionally, setting the anomaly detectors’ threshold, usually beyond hyperparameters configuration, requires knowledge of attacks. To overcome these challenges, this paper presents an automated solution to infer the hyperparameters and the threshold jointly from an attack-free training dataset. Pre-learned optimal configurations are transferred and fine-tuned across datasets.Our method minimally impacts model accuracy detection performance (4% degradation), while dramatically reducing configuration time by a factor of 160 across the IDS2017 and IDS2018 datasets. Omar Anser, Jérôme François, Isabelle Chrisment |
LCN | 3 |
| 2024 | SDN-based Mitigation of Synchronization Attacks on Distributed and Cooperative Controls in MicrogridabstractThe power grid has recently evolved through the integration of Information and Communication Technologies (ICT), leading to the emergence of the smart grid. A key component of the smart grid is the microgrid, a small-scale electrical network made of Distributed Generators (DGs) that nowadays use distributed and cooperative control systems to ensure the reliability of its operations. However, the communication networks employed to control data exchange between DGs are subject to synchronization attacks that can disrupt grid operations. These existing communication infrastructures often lack the flexibility to deploy efficient mitigation and security measures against attacks. Software-Defined Networking (SDN) emerges as a promising solution, providing a dynamic and resilient approach to mitigate synchronization attacks. In this work, we build an SDN-enabled microgrid hardware platform comprising DGs, Open vSwitches (OVSs) installed on Raspberry Pi devices, and a POX controller running on a laptop. In the demo, we will show two methods of mitigating Man-in-the-Middle (MitM) attacks to demonstrate the effectiveness of SDN in limiting their impact on the microgrid. Aurélie Kpoze, Abdelkader Lahmadi, Isabelle Chrisment, Jules R. Dégila |
NOMS | 3 |
| 2024 | Leveraging Deep Reinforcement Learning for Cyber-Attack Paths Prediction: Formulation, Generalization, and EvaluationabstractAttack paths represent the sequences of network nodes compromised by attackers while exploiting their respective vulnerabilities. Current methods for predicting such attack paths largely depend on existing human expertise or established heuristics. These traditional methods are time-consuming and require highly skilled threat-hunting analysts to identify these attack paths and proactively apply security measures. However, the task becomes challenging when facing large-scale and highly vulnerable networks. In this paper, we propose an alternative approach leveraging Deep Reinforcement Learning (DRL) techniques aiming to approximate the decision-making of attackers. Our approach embodies the attacker’s perspective and tactics to leverage discovered paths for proactive security analysis and establish defense strategies. We introduce a novel re-formulation of the problem with a local view for the DRL agent, representing the source and target node of the attack at each timestep. Additionally, our training methodology involves a diverse set of network topologies of different sizes and exploitable vulnerabilities, demonstrating the ability of DRL algorithms to navigate topologies, identify attack paths, and compromise nodes. Results highlight the capability of the learned policies to generalize within entirely new topologies, arriving to discover 80% ± 0.08% of the attack paths in 1500 steps. Franco Terranova, Abdelkader Lahmadi, Isabelle Chrisment |
RAID | 3 |
| 2023 | Auto-tuning of Hyper-parameters for Detecting Network Intrusions via Meta-learningabstractIn recent years, machine learning-based Network Intrusion Detection Systems have been widely investigated to detect network attacks. The performance of such systems is strongly affected by their configuration, i.e. the setting of the hyper-parameters, usually based on human expertise. Few efforts have been made towards automatic methods except using a long process of trials. Besides, the resulting configuration is specific to the network where the system is deployed or the type of attacks to detect. To address these issues, we define a method using metalearning which learns from the past experiences. By extracting useful information from the previous optimized tuning tasks, a model is trained in order to quickly infer a new configuration. In comparison with Bayesian optimization, our evaluation based on the CSE CIC IDS2018 and CIC IDS2017 datasets demonstrates that our lightweight technique does not degrade attack detection accuracy in 88% of cases but is on average 9 times faster. Omar Anser, Jérôme François, Isabelle Chrisment |
NOMS | 3 |
| 2022 | Detecting Multi-Step Attacks: A Modular Approach for Programmable Data PlaneabstractThe increasing sophistication of attacks over the last years such as the proliferation of complex multi-steps attacks, calls for new monitoring models and methods for diagnosing the attacks’ severity and mitigating them in a timely manner. In this paper, we propose an in-network monitoring approach capable of detecting a set of composed behaviors and consequently triggering different levels of alerts and reactions. Our approach is based on a Petri Net model capable of aggregating individual attacks into a multi-step composition. To this end, we propose a method for deriving a Match-Action Table (MAT) abstraction from a Petri net model. MATs can be then deployed on a P4 programmable data plane, enabling flexible re-composition of attack detection steps at runtime. We demonstrate the feasibility of our proposal by modeling the detection of a multi-step DNS cache poisoning attack and implementing the model on a P4 programmable data plane. Abir Laraba, Jérôme François, Isabelle Chrisment, Shihabur Rahman Chowdhury, Raouf Boutaba |
NOMS | 3 |
| 2022 | Monitoring Network Telescopes and Inferring Anomalous Traffic Through the Prediction of Probing RatesabstractNetwork reconnaissance is the first step preceding a cyber-attack. Hence, monitoring the probing activities is imperative to help security practitioners enhancing their awareness about Internet’s large-scale events or peculiar events targeting their network. In this paper, we present a framework for an improved and efficient monitoring of the probing activities targeting network telescopes. Particularly, we model the probing rates which are a good indicator for measuring the cyber-security risk targeting network services. The approach consists of first inferring groups of network ports sharing similar probing characteristics through a new affinity metric capturing both temporal and semantic similarities between ports. Then, sequences of probing rates targeting similar ports are used as inputs to stacked Long Short-Term Memory (LSTM) neural networks to predict probing rates 1 hour and 1 day in advance. Finally, we describe two monitoring indicators that use the prediction models to infer anomalous probing traffic and to raise early threat warnings. We show that LSTM networks can accurately predict probing rates, outperforming the non-stationary autoregressive model, and we demonstrate that the monitoring indicators are efficient in assessing the cyber-security risk related to vulnerability disclosure. Mehdi Zakroum, Jérôme François, Isabelle Chrisment, Mounir Ghogho |
IEEE Trans. Netw. Serv. Manag. | 3 |
| 2021 | An Ensemble Learning-Based Architecture for Security Detection in IoT InfrastructuresabstractThe Internet of Things has known an important development. However, security management is still a key challenge in particular for deploying complex IoT systems that provide sophisticated services. In this paper, we design an ensemble learning-based architecture to support early security detection in the context of multi-step attacks, by leveraging the performance of different detection techniques. The architecture relies on a total of five major methods, including process mining, elliptic envelope, one class support vector machine, local outlier factor and isolation forest. We describe the main components of this architecture and their interactions, from the data preprocessing to the generation of alerts, through the calculation of scores. The different detection methods are executed in parallel, and their results are combined by an ensemble learning strategy in order to improve the overall detection performance. We develop a proof-of-concept prototype and perform a large set of experiments to quantify the benefits and limits of this approach based on industrial datasets. Adrien Hemmer, Mohamed Abderrahim 0002, Rémi Badonnel, Isabelle Chrisment |
CNSM | 4 |
| 2021 | Empowering mobile crowdsourcing apps with user privacy control
Lakhdar Meftah, Romain Rouvoy, Isabelle Chrisment |
J. Parallel Distributed Comput. | 3 |
| 2021 | Comparative Assessment of Process Mining for Supporting IoT Predictive SecurityabstractThe growth of the Internet-of-Things (IoT) has been characterized by the large-scale deployment of sensors and connected objects. These ones are integrated with other Internet resources in order to elaborate more complex systems and applications. Security management is a major challenge for these systems due to their complexity, their heterogeneity and the limited resources of their devices. In this article we evaluate the exploitability and performance of a process mining approach for detecting misbehaviors in such systems. We describe the considered architecture and detail its operation, from the generation of behavioral models to the detection of potential attacks. We formalize several alternative commonly-used detection methods, including elliptic envelope, support-vector machine, local outlier factor, and isolation forest techniques. After presenting a proof-of-concept prototype, we quantify comparatively the benefits and limits of our process mining solution combined with data pre-processing, through extensive experiments based on different industrial datasets. Adrien Hemmer, Mohamed Abderrahim 0002, Rémi Badonnel, Jérôme François, Isabelle Chrisment |
IEEE Trans. Netw. Serv. Manag. | 5 |
| 2021 | Mitigating TCP Protocol Misuse With Programmable Data PlanesabstractThis article proposes a new approach for detecting and mitigating the impact of misbehaving TCP end-hosts, specifically the Optimistic ACK attack, and Explicit Congestion Notification (ECN) abuse. In contrast to the state-of-the-art, we show that it is possible to mitigate such misbehavior leveraging emerging programmable data planes while not requiring any end-host or protocol modifications. A key challenge in doing so is to implement expressive, complex and stateful functions in the data plane within its restricted programming model. In this regard, we propose a security monitoring function that uses Extended Finite State Machine (EFSM) abstraction for monitoring stateful protocols in the data plane. We also design a mechanism for mapping a protocol's EFSM to programmable data plane primitives. Our evaluation results demonstrate that our approach can fully or partially restore the throughput loss caused by misbehaving end-hosts that manipulate TCP congestion control through misinformation. Abir Laraba, Jérôme François, Shihabur Rahman Chowdhury, Isabelle Chrisment, Raouf Boutaba |
IEEE Trans. Netw. Serv. Manag. | 4 |
| 2020 | Capturing Privacy-Preserving User Contexts with IndoorHash
Lakhdar Meftah, Romain Rouvoy, Isabelle Chrisment |
DAIS | 3 |
| 2020 | Defeating Protocol Abuse with P4: Application to Explicit Congestion Notification
Abir Laraba, Jérôme François, Isabelle Chrisment, Shihabur Rahman Chowdhury, Raouf Boutaba |
Networking | 3 |
| 2020 | A Process Mining Approach for Supporting IoT Predictive SecurityabstractThe growing interest for the Internet-of-Things (IoT) is supported by the large-scale deployment of sensors and connected objects. These ones are integrated with other Internet resources in order to elaborate more complex and value-added systems and applications. While important efforts have been done for their protection, security management is a major challenge for these systems, due to their complexity, their heterogeneity and the limited resources of their devices. In this paper we introduce a process mining approach for detecting misbehaviors in such systems. It permits to characterize the behavioral models of IoT-based systems and to detect potential attacks, even in the case of heterogenous protocols and platforms. We then describe and formalize its underlying architecture and components, and detail a proof-of-concept prototype. Finally, we evaluate the performance of this solution through extensive experiments based on real industrial datasets. Adrien Hemmer, Rémi Badonnel, Isabelle Chrisment |
NOMS | 3 |
| 2020 | A Process Mining Tool for Supporting IoT SecurityabstractThe development of the Internet has been characterized by a growing interest for the Internet-of-Things (IoT). In particular, connected devices are integrated to other Internet resources (such as cloud resources) to elaboratevalue-added services. However, they pose important challenges with respect to security management due to their heterogeneity, their distribution, and their limited resources. In this demonstration, we present a process mining toool for supporting IoT security. This tool is capable to automate the detection of misbehaviours and attacks in large and heterogeneous IoT infrastructures, based on process mining techniques combined with normalization and clustering data pre-processing. We detail the different building blocks of this tool provided into a docker container, and illustrate its operations with different scenarios. Adrien Hemmer, Rémi Badonnel, Jérôme François, Isabelle Chrisment |
NOMS | 4 |
| 2019 | FOUGERE: User-Centric Location Privacy in Mobile Crowdsourcing Apps
Lakhdar Meftah, Romain Rouvoy, Isabelle Chrisment |
DAIS | 3 |
| 2019 | Demonstration of Synchronization Attacks on Distributed and Cooperative Control in Microgrids
Abdelkader Lahmadi, Isabelle Chrisment |
IM | 3 |
| 2019 | Transparent and Service-Agnostic Monitoring of Encrypted Web TrafficabstractNowadays, most of Web services are accessed through HTTPS. While preserving user privacy is important, it is also mandatory to monitor and detect specific users' actions, for instance, according to a security policy. This paper presents a solution to monitor HTTP/2 traffic over TLS. It highly differs from HTTP/1.1 over TLS traffic what makes existing monitoring techniques obsolete. Our solution, H2Classifier, aims at detecting if a user performs an action that has been previously defined over a monitored Web service, but without using any decryption. It is thus only based on passive traffic analysis and relies on random forest classifier. A challenge is to extract representative values of the loaded content associated to a Web page, which is actually customized based on the user action. Extensive evaluations with five top used Web services demonstrate the viability of our technique with an accuracy between 94% and 99%. Pierre-Olivier Brissaud, Jérôme François, Isabelle Chrisment, Thibault Cholez, Olivier Bettan |
IEEE Trans. Netw. Serv. Manag. | 3 |
| 2018 | Passive Monitoring of HTTPS Service Use
Pierre-Olivier Brissaud, Jérôme François, Isabelle Chrisment, Thibault Cholez, Olivier Bettan |
CNSM | 3 |
| 2017 | Implementation and Evaluation of a Controller-Based Forwarding Scheme for NDNabstractNamed-Data Networking (NDN) is a novel cleanslate architecture for Future Internet. It has been designed to take into account a new use of the Internet and especially accessing content for a large number of users, and it integrates several features such as in-network caching, security or multipath. As NDN relies on content names instead of host address, it cannot rely on traditional Internet routing, and it is therefore essential to propose a routing scheme adapted for NDN. To this end, in this paper, we present SRSC, our SDN-based Routing Scheme for CCN/NDN and its implementation. SRSC relies on the SDN paradigm.A controller is responsible to forward decisions and to set up rules into NDN nodes. We implement SRSC into NDNx and we also deploy an NDN testbed within a virtual environment and real ISP topology in order to evaluate the performances of our proposal with real-world experiments. We demonstrate the feasibility of SRSC and its ability to forward Interest messages in a fully deployed NDN environment, while keeping low overhead and computation time and high caching performances. Elian Aubry, Thomas Silverston, Isabelle Chrisment |
AINA | 3 |
| 2017 | ANDROFLEET: testing WiFi peer-to-peer mobile apps in the largeabstractWiFi P2P allows mobile apps to connect to each other via WiFi without an intermediate access point. This communication mode is widely used by mobile apps to support interactions with one or more devices simultaneously. However, testing such P2P apps remains a challenge for app developers as i) existing testing frameworks lack support for WiFi P2P, and ii) WiFi P2P testing fails to scale when considering a deployment on more than two devices. In this paper, we therefore propose an acceptance testing framework, named Androfleet, to automate testing of WiFi P2P mobile apps at scale. Beyond the capability of testing point-to-point interactions under various conditions, An-drofleet supports the deployment and the emulation of a fleet of mobile devices as part of an alpha testing phase in order to assess the robustness of a WiFi P2P app once deployed in the field. To validate Androfleet, we demonstrate the detection of failing black-box acceptance tests for WiFi P2P apps and we capture the conditions under which such a mobile app can correctly work in the field. The demo video of Androfleet is made available from https://youtu.be/gJ5_Ed7XL04. Lakhdar Meftah, María Gómez 0001, Romain Rouvoy, Isabelle Chrisment |
ASE | 4 |
| 2017 | A Distributed Monitoring Strategy for Detecting Version Number Attacks in RPL-Based NetworksabstractThe Internet of Things is characterized by the large-scale deployment of low power and lossy networks (LLN), interconnecting pervasive objects. The routing protocol for LLN (RPL) protocol has been standardized by IETF to enable a lightweight and robust routing in these constrained networks. A versioning mechanism is incorporated into RPL in order to maintain an optimized topology. However, an attacker can exploit this mechanism to significantly damage the network and reduce its lifetime. After analyzing and comparing existing work, we propose in this paper a monitoring strategy with dedicated algorithms for detecting such attacks and identifying the involved malicious nodes. The performance of this solution is evaluated through extensive experiments, and its scalability is quantified with the support of a monitoring node placement optimization method. Anthéa Mayzaud, Rémi Badonnel, Isabelle Chrisment |
IEEE Trans. Netw. Serv. Manag. | 3 |
| 2016 | Detecting version number attacks in RPL-based networks using a distributed monitoring architectureabstractThe concept of Internet of Things involves the deployment of Low power and Lossy Networks (LLN) allowing communications among pervasive devices such as embedded sensors. The IETF designed the Routing Protocol for Low power and Lossy Networks (RPL) for supporting these constrained networks. Keeping in mind the different requirements of such networks, the protocol supports multiple routing topologies, called DODAGs, built using different objective functions, so as to optimize routing based on several metrics. A DODAG versioning system is incorporated into RPL in order to ensure an optimized topology. However, an attacker can exploit this mechanism to damage the network and reduce its lifetime. In this paper we propose a detection strategy based on a distributed monitoring architecture with dedicated algorithms that is able to identify malicious nodes performing such attacks in RPL-based environments. The performance of this solution is evaluated through extensive experiments and its scalability is quantified considering a monitoring node placement method. Anthéa Mayzaud, Rémi Badonnel, Isabelle Chrisment |
CNSM | 3 |
| 2016 | Green growth in NDN: Deployment of content storesabstractNamed-Data Networking architecture relies on cache networks, where nodes store the data for further requests. However, the memory needed at each node called Content Store represents the most significant part of the entire cost of the infrastructure that has to be supported by network providers, making difficult the change from the current Internet infrastructure to a Future Internet based on NDN. Thus, a legitimate question would be: “are all these Content Stores useful in a large-scale NDN network?” In this paper, we investigate the impact of Content Stores in NDN network, and we evaluate the performances of the NDN architecture according to the number of Content Stores effectively deployed in the network. We show through extensive simulation experiments in NS-3 that only about 50% of nodes with Content Stores is enough to achieve higher level of performances than a fully-deployed NDN network. This result is very important for the deployment of NDN architecture as it shows that the infrastructure cost can be drastically reduced and it is an incentive for network providers that benefits directly from this result. Elian Aubry, Thomas Silverston, Isabelle Chrisment |
LANMAN | 3 |
| 2016 | Using the RPL protocol for supporting passive monitoring in the Internet of ThingsabstractMost devices deployed in the Internet of Things (IoT) are expected to suffer from resource constraints. Using specialized tools on such devices for monitoring IoT networks would take away precious resources that could otherwise be dedicated towards their primary task. In many IoT applications such as Advanced Metering Infrastructure (AMI) networks, higher order devices are expected to form the backbone infrastructure, to which the constrained nodes would connect. It would, as such, make sense to exploit the capabilities of these higher order devices to perform network monitoring tasks. We propose in this paper a distributed monitoring architecture that takes benefits from specificities of the IoT routing protocol RPL to passively monitor events and network flows without having impact upon the resource constrained nodes. We describe the underlying mechanisms of this architecture, quantify its performances through a set of experiments using the Cooja environment. We also evaluate its benefits and limits through a use case scenario dedicated to anomaly detection. Anthéa Mayzaud, Anuj Sehgal, Rémi Badonnel, Isabelle Chrisment, Jürgen Schönwälder |
NOMS | 4 |
| 2016 | A multi-level framework to identify HTTPS servicesabstractThe development of TLS-based encrypted traffic comes with new challenges related to the management and security analysis of encrypted traffic. There is an essential need for new methods to investigate, with a proper level of identification, the increasing number of HTTPS traffic that may hold security breaches. In fact, although many approaches detect the type of an application (Web, P2P, SSH, etc.) running in secure tunnels, and others identify a couple of specific encrypted web pages through website fingerprinting, this paper proposes a robust technique to precisely identify the services run within HTTPS connections, i.e. to name the services, without relying on specific header fields that can be easily altered. We have defined dedicated features for HTTPS traffic that are used as input for a multi-level identification framework based on machine learning algorithms. Our evaluation based on real traffic shows that we can identify encrypted web services with a high accuracy. Wazen M. Shbair, Thibault Cholez, Jérôme François, Isabelle Chrisment |
NOMS | 4 |
| 2015 | Evaluation of the Anonymous I2P Network's Design Choices Against Performance and SecurityabstractInternational audience Juan Pablo Timpanaro, Thibault Cholez, Isabelle Chrisment, Olivier Festor |
ICISSP | 3 |
| 2015 | Efficiently bypassing SNI-based HTTPS filteringabstractEncrypted Internet traffic is an essential element to enable security and privacy in the Internet. Surveys show that websites are more and more being served over HTTPS. They highlight an increase of 48% of sites using TLS over the past year, justifying the tendency that the Web is going to be encrypted. This motivates the development of new tools and methods to monitor and filter HTTPS traffic. This paper handles the latest technique for HTTPS traffic filtering that is based on the Server Name Indication (SNI) field of TLS and which has been recently implemented in many firewall solutions. Our main contribution is an evaluation of the reliability of this SNI extension for properly identifying and filtering HTTPS traffic. We show that SNI has two weaknesses, regarding (1) backward compatibility and (2) multiple services using a single certificate. We demonstrate thanks to a web browser plug-in called “Escape” that we designed and implemented, how these weaknesses can be practically used to bypass firewalls and monitoring systems relying on SNI. The results show positive evaluation (firewall's rules successfully bypassed) for all tested websites. Wazen M. Shbair, Thibault Cholez, Antoine Goichot, Isabelle Chrisment |
IM | 4 |
| 2015 | SRSC: SDN-based routing scheme for CCNabstractContent delivery such as P2P or video streaming generates the main part of the Internet traffic and Content Centric Network (CCN) appears as an appropriate architecture to satisfy the user needs. However, the lack of scalable routing scheme is one of the main obstacles that slows down a large deployment of CCN at an Internet-scale. In this paper we propose to use the Software-Defined Networking (SDN) paradigm to decouple data plane and control plane and present SRSC, a new routing scheme for CCN. Our solution is a clean-slate approach using only CCN messages and the SDN paradigm. We implemented our solution into the NS-3 simulator and perform simulations of our proposal. SRSC shows better performances than the flooding scheme used by default in CCN: it reduces the number of messages, while still improves CCN caching performances. Elian Aubry, Thomas Silverston, Isabelle Chrisment |
NetSoft | 3 |
| 2013 | Monitoring anonymous P2P file-sharing systemsabstractAnonymous communications have been exponentially growing, where more and more users are shifting to a privacy-preserving Internet and anonymising their peer-to-peer communications. Anonymous systems allow users to access different services while preserving their anonymity. We aim to characterise these anonymous systems, with a special focus in the I2P network. Current statistics service for the I2P network do not provide values about the type of applications deployed in the network nor the geographical localisation of users. Our objective is to determine the number of users in the network, the number of anonymous applications, and the type of those applications. We also explore the possibility of inferring which group of users is responsible for the activity of an anonymous application. Thus, we improve the current I2P statistics and get better insights of the network. Juan Pablo Timpanaro, Isabelle Chrisment, Olivier Festor |
P2P | 2 |
| 2013 | Detection and mitigation of localized attacks in a widely deployed P2P network
Thibault Cholez, Isabelle Chrisment, Olivier Festor, Guillaume Doyen |
Peer-to-Peer Netw. Appl. | 2 |
| 2012 | A Bird's Eye View on the I2P Anonymous File-Sharing Environment
Juan Pablo Timpanaro, Isabelle Chrisment, Olivier Festor |
NSS | 2 |
| 2011 | Content pollution quantification in large P2P networks : A measurement study on KADabstractContent pollution is one of the major issues affecting P2P file sharing networks. However, since early studies on FastTrack and Overnet, no recent investigation has reported its impact on current P2P networks. In this paper, we present a method and the supporting architecture to quantify the pollution of contents in the KAD network. We first collect information on many popular files shared in this network. Then, we propose a new way to detect content pollution by analyzing all filenames linked to a content with a metric based on the Tversky index and which gives very low error rates. By analyzing a large number of popular files, we show that 2/3 of the contents are polluted, one part by index poisoning but the majority by a new, more dangerous, form of pollution that we call index falsification. Guillaume Montassier, Thibault Cholez, Guillaume Doyen, Rida Khatoun, Isabelle Chrisment, Olivier Festor |
Peer-to-Peer Computing | 5 |
| 2010 | Automated and secure IPv6 configuration in enterprise networksabstractOver the last decade, IPv6 has established itself as the most mature network protocol for the future Internet. Its recent deployment in core networks of operators, its availability to end customers of multiple ISPs together with the availability of native access to large services like Google assess the increasing penetration of IPv6. While its deployment from the inside of the network leading to the edges is successful, the transition remains an issue today for many enterprises which see it as a tedious and error prone task for network administrators. To fill this gap, we present the necessary algorithms and provide the supporting tools to enable this transition to become automatic. Based on a model of an IPv4 network, we describe the algorithms to build an optimized IPv6 adressing scheme and to automatically generate the adequate security plan as well as the corresponding configurations for the different devices in the network. Frédéric Beck, Olivier Festor, Isabelle Chrisment, Ralph E. Droms |
CNSM | 3 |
| 2010 | Monitoring and Controlling Content Access in KADabstractWe propose a new distributed architecture that aims to investigate and control the spread of contents in the KAD P2P network through the indexation of keywords and files. Our solution can control the DHT at a local level with a new strategy bypassing the Sybil attack protections inserted in KAD. For the targeted DHT entries, we can monitor all requests emitted by the peers, from the initial content publication or search, to the final download request of fake files, assessing accurately peers interest to access it. We demonstrate the efficiency of our approach through experiments performed on the worldwide KAD network. Thibault Cholez, Isabelle Chrisment, Olivier Festor |
ICC | 2 |
| 2007 | Assessing the security of VoIP ServicesabstractVoIP networks are in a major deployment phase and are becoming widely spread out due to their extended functionality and cast efficiency. Meanwhile, as VoIP traffic is transported over the Internet, it is the target of a range of attacks that can jeopardize its proper functionality. In this paper we describe our work in a VoIP specific security assessment framework. Such an assessment is automated with integrated discovery actions, data management and security attacks allowing to perform VoIP specific penetration tests. These tests are important because they permit to search and detect existing vulnerabilities or misconflgured devices and services. Our main contributions consist in an elaborated network information model capable to be used in VoIP assessment, an extensible assessment architecture and its implementation, as well as in a comprehensive framework for defining and composing VoIP specific attacks. Humberto J. Abdelnur, Radu State, Isabelle Chrisment, C. Popi |
Integrated Network Management | 3 |
| 2005 | Efficient Clustering for Multicast Key Distribution in MANETs
Mohamed Salah Bouassida, Isabelle Chrisment, Olivier Festor |
NETWORKING | 2 |
| 2004 | An Enhanced Hybrid Key Management Protocol for Secure Multicast in Ad Hoc Networks
Mohamed Salah Bouassida, Isabelle Chrisment, Olivier Festor |
NETWORKING | 2 |
| 2001 | Dynamic Group Communication SecurityabstractIf multicast communication appears as the most efficient way to send data to a group of participants, it presents also more vulnerabilities to attacks and requires services such as authentication, integrity and confidentiality to transport data securely. We present the protocol, Baal, as a scalable solution to group key management problems and show how Baal resolves the user's revocation problem. This protocol is based on decentralized group key management with only one key shared among group members. We use then Network Simulator ns-2, in order to evaluate the performance of our protocol in the case of group initialization, and compare it with single key distribution center (SKDC) approaches. Ghassan Chaddoud, Isabelle Chrisment, André Schaff |
ISCC | 2 |
| 1998 | An ALF communication architecture: design and automated implementationabstractThe application level framing (ALF) principle states that information should be packetized by the application into application data units (ADUs), each of which should be at the same time a unit of transmission, a unit of control, and a unit of processing. This paper describes a communication system architecture based on the ALF principle, which then attempts to maximize what might be gained from using ADUs. In this architecture, protocols are tailored to application requirements, i.e., to ADU types. In a first approximation, we consider three specific requirements, namely, in-order delivery, reliable delivery, and real-time delivery. ALF-based systems promise performance gains; however, implementing them in practice might be a complex task. Therefore, we have developed a compiler that automatically generates ALF-based communication systems starting from formal specification of applications. We have used this compiler to generate protocols tailored to three specific applications. Experimental results show that the gains are linked to application "complexity". Isabelle Chrisment, Delphine Kaplan, Christophe Diot |
IEEE J. Sel. Areas Commun. | 1 |
| 1996 | ALFred, a Protocol Compiler for the Automated Implementation of Distributed ApplicationsabstractThis paper describes the design and the prototyping of a compiling tool for the automated implementation of distributed applications: ALFred. This compiler starts from the formal specification of an application written in ESTEREL and then integrates end-to-end communication functions tailored to the application characteristics (described in the specification); it finally produces a high performance implementation. The paper describes the communication architecture associated with the approach. The compiler consists of a control compiler, also called ALF compiler, and a data manipulation compiler (the ILP compiler) that combines data manipulation functions in an efficient way (the ILP loop). The ALFred compiler has been designed to allow the development and the analysis of non-layered high performance communication architectures based on ALF and ILP. Torsten Braun, Isabelle Chrisment, Christophe Diot, François Gagnon, Laurent Gautier |
HPDC | 2 |