EDBT 2026 Demo / reviewers in the wild / expert
Wissam Mallouli
dblp:74/4777
· DBLP profile ↗
50ranked-venue papers
5as first author
22since 2021 · last 2026
0000-0003-2548-6628ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 18 · 1 first-author · 12 since 2021Software engineering, systems software and programming languages · 16 · 2 first-author · 6 since 2021Computer networks · 3 · 1 first-author · 1 since 2021Human-computer interaction and ubiquitous computing · 3 · 1 first-authorArtificial intelligence and machine learning · 2 · 1 first-authorApplied, interdisciplinary, general and emerging computing · 2Systems, architecture and hardware · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Cybersecurity in IoT-to-Cloud Applications Using Service-Oriented Digital Twin Approach and Toolboxabstract584 Sonika Gogineni, Ilinca Burdulea, Wissam Mallouli, Bruno Vidalenc, Alexandros Valantasis, Pascal Lünnemann |
NetSoft | 3 |
| 2024 | AI-Powered Penetration Testing using Shennina: From Simulation to ValidationabstractArtificial intelligence has been greatly improved nowadays, providing innovative approaches in cybersecurity both on offensive and defensive tactics. AI can be specifically utilized to automate and conduct penetration testing, a task that is usually time-intensive, involves high-costs, and requires cybersecurity professionals of high expertise. In this research paper, we utilize an AI penetration testing framework to validate, discover and analyze the techniques that were used. To this end, we conducted a validation process in a realistic environment and to collect the relevant datasets from the execution of the cyberattacks. Finally, the behavior of the AI penetration testing was analyzed in order to adapt and upgrade further. Overall, the research paper provides contributions to dataset generation and a methodology to understand the details of the attack simulation. Stylianos Karagiannis, Camilla Fusco, Leonidas Agathos, Wissam Mallouli, Valentina Casola, Christoforos Ntantogian, Emmanouil Magkos |
ARES | 4 |
| 2024 | NERO: Advanced Cybersecurity Awareness Ecosystem for SMEsabstractNERO represents a sophisticated Cybersecurity Ecosystem comprising five interconnected frameworks designed to deliver a Cybersecurity Awareness initiative, as advocated by ENISA as the optimal method for cultivating a security-centric mindset among employees to mitigate the impact of cyber threats. It integrates activities, resources, and training to nurture a culture of cybersecurity. NERO primarily equips SMEs with a repository of Cyber Immunity Toolkits, a Cyber Resilience Program, and Gamified Cyber Awareness Training, all accessible through a user-friendly Marketplace. The efficacy and performance of this concept will be affirmed through three distinct use case demonstrations across various sectors: Improving Patient Data Security in Healthcare with Cybersecurity Tools, Enhancing Supply Chain Resilience in the Transportation and Logistics Industry through Cybersecurity Awareness, and Elevating Financial Security via Enhanced Cybersecurity Awareness and Tools. Charalambos Klitis, Ioannis Makris, Pavlos S. Bouzinis, Dimitrios Christos Asimopoulos, Wissam Mallouli, Kitty Kioskli, Eleni Seralidou, Christos Douligeris, Loizos Christofi |
ARES | 5 |
| 2024 | AI4SOAR: A Security Intelligence Tool for Automated Incident ResponseabstractThe cybersecurity landscape is fraught with challenges stemming from the increasing volume and complexity of security alerts. Traditional manual or semi-automated approaches to threat analysis and incident response often result in significant delays in identifying and mitigating security threats. In this paper, we address these challenges by proposing AI4SOAR, a security intelligence tool for automated incident response. AI4SOAR leverages similarity learning techniques and integrates seamlessly with the open-source SOAR platform Shuffle. We conduct a comprehensive survey of existing open-source SOAR platforms, highlighting their strengths and weaknesses. Additionally, we present a similarity-based learning approach to quickly identify suitable playbooks for incoming alerts. We implement AI4SOAR and demonstrate its application through a use case for automated incident response against SSH brute-force attacks. Manh-Dung Nguyen, Wissam Mallouli, Ana R. Cavalli, Edgardo Montes de Oca |
ARES | 2 |
| 2024 | Diagnosis Automation Using Similarity Analysis: Application to Industrial SystemsabstractInternational audience Ivan Orefice, Wissam Mallouli, Ana R. Cavalli, Filip Sebek, Alberto Lizarduy |
ICSOFT | 2 |
| 2023 | HTTP/2 Attacks Generation using 5Greplayabstract5G networks become increasingly pervasive, ensuring the robustness and integrity of network functions. The adoption of HTTP/2 in 5G core functions brings notable performance benefits but also introduces potential security risks. By analyzing HTTP/2 related threats, this research aims to shed light on the security challenges faced by 5G networks. The paper proposes effective security testing methodologies using an open-source solution called 5Greplay to detect these security breaches, enabling network operators to protect against potential attacks, safeguard user privacy, and ensure uninterrupted service continuity. By addressing the specific concerns of HTTP/2 related threats, this research contributes to the overall security posture of 5G network functions and provides valuable insights for the secure deployment of 5G networks in an evolving threat landscape. Francesco G. Caccavale, Huu Nghia Nguyen, Ana R. Cavalli, Edgardo Montes de Oca, Wissam Mallouli |
ARES | 5 |
| 2023 | VeriDevOps Software Methodology: Security Verification and Validation for DevOps PracticesabstractVeriDevOps offers a methodology and a set of integrated mechanisms that significantly improve automation in DevOps to protect systems at operations time and prevent security issues at development time by (1) specifying security requirements, (2) generating trace monitors, (3) locating root causes of vulnerabilities, and (4) identifying security flaws in code and designs. This paper presents a methodology that enhances productivity and enables the continuous integration/delivery of trustworthy systems. We outline the methodology, its application to relevant scenarios, and offer recommendations for engineers and managers adopting the VeriDevOps approach. Practitioners applying the VeriDevOps methodology should include security modeling in the DevOps process, integrate security verification throughout all stages, utilize automated test generation tools for security requirements, and implement a comprehensive security monitoring system, with regular review and update procedures to maintain relevance and effectiveness. Eduard Paul Enoiu, Dragos Truscan, Andrey Sadovykh, Wissam Mallouli |
ARES | 4 |
| 2023 | A deep learning anomaly detection framework with explainability and robustnessabstractThe prevalence of encrypted Internet traffic has resulted in a pressing need for advanced analysis techniques for traffic analysis and classification. Traditional rule-based and signature-based approaches have been hindered by the introduction of network encryption methods. With the emergence of machine learning (ML) and deep learning (DL), several preliminary works have been developed for anomaly detection in encrypted network traffic. However, complex Artificial Intelligence (AI) models like neural networks lack explainability, limiting the understanding of their predictions. To address this limitation, eXplainable Artificial Intelligence (XAI) has emerged, aiming to provide users with a rationale for understanding AI system outputs and fostering trust. However, existing explainable frameworks still lack comprehensive support for adversarial attacks and defenses. Manh-Dung Nguyen, Anis Bouaziz, Valeria Valdés Ríos, Ana R. Cavalli, Wissam Mallouli, Edgardo Montes de Oca |
ARES | 5 |
| 2023 | The DYNABIC approach to resilience of critical infrastructuresabstractWith increasing interdependencies and evolving threats, maintaining operational continuity in critical systems has become a significant challenge. This paper presents the DYNABIC (Dynamic business continuity of critical infrastructures on top of adaptive multi-level cybersecurity) approach as a comprehensive framework to enhance the resilience of critical infrastructures. The DYNABIC approach provides the resilience enhancement through dynamic adaptation, automated response, collaboration, risk assessment, and continuous improvement. By fostering a proactive and collaborative approach to resilience, the DYNABIC framework empowers critical infrastructure sectors to effectively mitigate disruptions and recover from incidents. The paper explores the key components and architecture of the DYNABIC approach and highlights its potential to strengthen the resilience of critical infrastructures using the concept of Digital Twins in the face of evolving threats and complex operating environments involving cascading effects. Erkuden Rios, Eider Iturbe, Angel Rego, Nicolas Ferry 0001, Jean-Yves Tigli, Stéphane Lavirotte, Gérald Rocher, Phu Hong Nguyen, Rustem Dautov, Wissam Mallouli, Ana R. Cavalli |
ARES | 11 |
| 2023 | 5G SUCI Catcher: Attack and DetectionabstractThe deployment of 5G networks opens up new possibilities for communication and connectivity. However, it also introduces new security threats. This paper explores one cyber threat: 5G SUCI Catcher attack. The 5G SUCI Catcher attack is a proof of concept involving monitoring from nearby mobile devices in the 5G paradigm. SUCI Catchers act as fake base stations by exploiting weaknesses of the 5G authentication and encryption protocol. In this paper, SUCI Catcher attack and detection rules are implemented in a 5G experimental environment. The detection solution demonstrates practically the capability to efficiently mitigate the risks associated with this 5G attack. Lorens Barraud, Francesco G. Caccavale, Jean-Baptiste Peyrat, Wissam Mallouli, Véronique Capdevielle, Hicham Khalife, Ana R. Cavalli |
CloudCom | 4 |
| 2023 | Towards Smarter Security Orchestration and Automatic Response for CPS and IoTabstractCurrent security orchestration and response (SOAR) approaches have primarily focused on specific layers of systems, such as Intrusion Detection Systems, the network layer, or the application layer. We aim to find the gaps in the existing SOAR approaches for IoT/CPS-based systems, especially critical infrastructures, and propose some directions to fill in these gaps. This paper presents a literature survey and future research directions for advancing SOAR towards increased automation and more holistic operation, especially for the cyber-physical security of critical infrastructures. We have found 14 primary SOAR studies and discussed the gaps in general. There is a significant gap when it comes to a comprehensive and systematic approach to SOAR for multi-layered systems using IoT/CPS and considering the computing continuum perspective. To address the gap, we present our on-going work on a framework of multi-layer SOAR decision-making methods and orchestration tools that leverage Reinforcement Learning (RL)-based adaptation intelligence, virtual reality, avatar-human interaction and advanced Cyber Threat Intelligence (CTI) tools. Phu Hong Nguyen, Rustem Dautov, Angel Rego, Eider Iturbe, Erkuden Rios, Diego Sagasti, Gonzalo Nicolas, Valeria Valdés Ríos, Wissam Mallouli, Ana R. Cavalli, Nicolas Ferry 0001 |
CloudCom | 10 |
| 2023 | Testing techniques to assess impact and cascading effectsabstractThe rapid evolution of digital environments and their integration into critical operations of our society have led to substantial challenges in advancing cybersecurity to ensure the proper functioning of these systems . In the face of over-evolving cyber threats and attacks, systems must be equipped with robust mechanisms for protection. In this context, resilience techniques aim to mitigate such treats. However, the evaluation of these techniques is a crucial process, enabling informed decision-making and proactive threat mitigation. This article introduces a methodology based on regression testing for evaluating the impact and cascading effects of resilience strategies. It delves into the methodology’s adaptability across different scenarios and provides insights about the evaluation process. Valeria Valdés Ríos, Ana R. Cavalli, Fatiha Zaïdi, Wissam Mallouli |
CloudCom | 4 |
| 2023 | Study on Adversarial Attacks Techniques, Learning Methods and Countermeasures: Application to Anomaly DetectionabstractInternational audience Anis Bouaziz, Manh-Dung Nguyen, Valeria Valdés Ríos, Ana R. Cavalli, Wissam Mallouli |
ICSOFT | 5 |
| 2023 | Novel modeling and optimization for joint Cybersecurity-vs-QoS Intrusion Detection Mechanisms in 5G networksabstractThe rapid emergence of 5G technology brings new cybersecurity challenges that hold significant implications for our economy, society, and environment. Among these challenges, ensuring the effectiveness of Intrusion Detection Mechanisms (IDMs) in monitoring networks and detecting 5G-related cyberattacks is of utmost importance. However, optimizing cybersecurity levels and selecting appropriate IDMs remain as critical and ongoing challenges. This work considers multiple pre-deployed distributed Security Agents (SAs) across the network, each capable of running various IDMs, where they differ by their effectiveness in detecting the attacks (referred to as security term) and the consumption of resources (referred to as Quality of Service (QoS) costs). We formulate a joint security and QoS utility function leveraging the Cobb–Douglas production utility function. There are several parameters that impact the joint objective problem, including the set of elasticity parameters, that reflect the importance of the two objectives. We derive an optimal set of elasticity parameters in closed form to identify the balancing point where both objectives have equal utility values. Through comprehensive simulations, we demonstrate that increasing the detection level of SAs enhances the security utility while simultaneously diminishing the QoS utility, as more computational, bandwidth, and monetary resources are utilized for IDM processing. After optimization, our mechanism can strike an effective balance between cybersecurity and QoS overhead while demonstrating the importance of different parameters in the joint problem. Arash Bozorgchenani, Charilaos C. Zarakovitis, Su Fong Chien, Tiew On Ting, Qiang Ni, Wissam Mallouli |
Comput. Networks | 6 |
| 2022 | Joint Security-vs-QoS Framework: Optimizing the Selection of Intrusion Detection Mechanisms in 5G networksabstractThe advent of 5G technology introduces new - and potentially undiscovered - cybersecurity challenges, with unforeseen impacts on our economy, society, and environment. Interestingly, Intrusion Detection Mechanisms (IDMs) can provide the necessary network monitoring to ensure - to a big extent - the detection of 5G-related cyberattacks. Yet, how to realize the attack surface of 5G networks with respect to the detected risks, and, consequently, how to optimize the cybersecurity levels of the network, remains an open critical challenge. In respect, this work focuses on deploying multiple distributed Security Agents (SAs) that can run different IDMs over various network components and proposes a cybersecurity mechanism for optimizing the network’s attack surface with respect to the Quality of Service (QoS). The proposed approach relies on a new closed-form utility function to describe the trade-off between cybersecurity and QoS and uses multi-objective optimization to improve the selection of each SA detection level. We demonstrate via simulations that before optimization, an increase in the detection level of SAs brings a direct decrease in QoS as more computational, bandwidth and monetary resources are utilized for IDM processing. Thereby, after optimization, we demonstrate that our mechanism can strike a balance between cybersecurity and QoS while showcasing the impact of the importance of different objectives of the joint optimization. Arash Bozorgchenani, Charilaos C. Zarakovitis, Su Fong Chien, Heng Siong Lim, Qiang Ni, Antonios Gouglidis, Wissam Mallouli |
ARES | 7 |
| 2022 | A Formal Approach for Complex Attacks Generation based on Mutation of 5G Network TrafficabstractInternational audience Zujany Salazar, Fatiha Zaïdi, Wissam Mallouli, Ana R. Cavalli, Huu Nghia Nguyen, Edgardo Montes de Oca |
ICSOFT | 3 |
| 2021 | A Threat-Based Cybersecurity Risk Assessment Approach Addressing SME NeedsabstractCybersecurity incidents are commonplace nowadays, and Small- and Medium-Sized Enterprises (SMEs) are exceptionally vulnerable targets. The lack of cybersecurity resources available to SMEs implies that they are less capable of dealing with cyber-attacks. Motivation to improve cybersecurity is often low, as the prerequisite knowledge and awareness to drive motivation is generally absent at SMEs. A solution that aims to help SMEs manage their cybersecurity risks should therefore not only offer a correct assessment but should also motivate SME users. From Self-Determination Theory (SDT), we know that by promoting perceived autonomy, competence, and relatedness, people can be motivated to take action. In this paper, we explain how a threat-based cybersecurity risk assessment approach can help to address the needs outlined in SDT. We propose such an approach for SMEs and outline the data requirements that facilitate automation. We present a practical application covering various user interfaces, showing how our threat-based cybersecurity risk assessment approach turns SME data into prioritised, actionable recommendations. Max van Haastrecht, Injy Sarhan, Alireza Shojaifar, Louis Baumgartner, Wissam Mallouli, Marco Spruit |
ARES | 5 |
| 2021 | GEIGER: Solution for small businesses to protect themselves against cyber-threatsabstractIn a world where cybersecurity has an increasing importance, any company, regardless of what sector, size or activity is related to, should rely on tools and solutions that can help it to be secure in the best possible way. The GEIGER platform described in this paper acts as a perfect fit for micro and small enterprises (MSEs). These companies need to be protected against threats but sometimes do not have the resources (money, personnel, time…) to deal with them. Often, private cybersecurity solutions are either expensive or hard to implement for micro and small companies. However, GEIGER is designed to bring cybersecurity principles, security countermeasures and awareness in a smooth and friendly way, with special focus on the MSEs. Its ability to adapt to new challenges comes in handy when dealing with sophisticated threats and the functionalities provided to help MSEs adopting a more prominent security posture. Having the support of an innovative solution can help MSEs to achieve a more effective approach regarding cybersecurity, which leads to a better overall business management and operation. José Javier de Vicente Mohino, Wissam Mallouli, José Francisco Ruiz, Max van Haastrecht |
ARES | 2 |
| 2021 | 5Greplay: a 5G Network Traffic Fuzzer - Application to Attack InjectionabstractThe fifth generation of mobile broadband is more than just an evolution to provide more mobile bandwidth, massive machine-type communications, and ultra-reliable and low-latency communications. It relies on a complex, dynamic and heterogeneous environment that implies addressing numerous testing and security challenges. In this paper we present 5Greplay, an open-source 5G network traffic fuzzer that enables the evaluation of 5G components by replaying and modifying 5G network traffic by creating and injecting network scenarios into a target that can be a 5G core service (e.g., AMF, SMF) or a RAN network (e.g., gNodeB). The tool provides the ability to alter network packets online or offline in both control and data planes in a very flexible manner. The experimental evaluation conducted against open-source based 5G platforms, showed that the target services accept traffic being altered by the tool, and that it can reach up to 9.56 Gbps using only 1 processor core to replay 5G traffic. Zujany Salazar, Huu Nghia Nguyen, Wissam Mallouli, Ana R. Cavalli, Edgardo Montes de Oca |
ARES | 3 |
| 2021 | SANCUS: Multi-layers Vulnerability Management Framework for Cloud-native 5G networksabstractAbstract: Security, Trust and Reliability are crucial issues in mobile 5G networks from both hardware and software perspectives. These issues are of significant importance when considering implementations over distributed environments, i.e., corporate Cloud environment over massively virtualized infrastructures as envisioned in the 5G service provision paradigm. The SANCUS1 solution intends providing a modular framework integrating different engines in order to enable next‐generation 5G system networks to perform automated and intelligent analysis of their firmware images at massive scale, as well as the validation of applications and services. SANCUS also proposes a proactive risk assessment of network applications and services by means of maximising the overall system resilience in terms of security, privacy and reliability. This paper presents an overview of the SANCUS architecture in its current release as well as the pilots use cases that will be demonstrated at the end of the project and used for validating the concepts. Charilaos C. Zarakovitis, Dimitrios Klonidis, Zujany Salazar, Anna Prudnikova, Arash Bozorgchenani, Qiang Ni, Charalambos Klitis, George Guirgis, Ana R. Cavalli, Nicholas Sgouros, Eftychia Makri, Antonios Lalas, Konstantinos Votis, George Amponis, Wissam Mallouli |
ARES | 15 |
| 2021 | VeriDevOps: Automated Protection and Prevention to Meet Security Requirements in DevOpsabstractCurrent software development practices are increasingly based on using both COTS and legacy components which make such systems prone to security vulnerabilities. The modern practice addressing ever changing conditions, DevOps, promotes frequent software deliveries, however, verification methods artifacts should be updated in a timely fashion to cope with the pace of the process. VeriDevOps, Horizon 2020 project, aims at providing a faster feedback loop for verifying the security requirements and other quality attributes of large scale cyber-physical systems. VeriDevOps focuses on optimizing the security verification activities, by automatically creating verifiable models directly from security requirements formulated in natural language, using these models to check security properties on design models and then generating artefacts such as, tests or monitors that can be used later in the DevOps process. The main drivers for these advances are: Natural Language Processing, a combined formal verification and model-based testing approach, and machine-learning-based security monitors. VeriDevOps is in its initial stage - the project started on 1.10.2020 and it will run for three years. In this paper we will present the major conceptual ideas behind the project approach as well as the organizational settings. Andrey Sadovykh, Gunnar Widforss, Dragos Truscan, Eduard Paul Enoiu, Wissam Mallouli, Rosa Iglesias, Alessandra Bagnato, Olga Hendel |
DATE | 5 |
| 2021 | A Framework for Security Monitoring of Real IoT TestbedsabstractInternational audience Vinh Hoa La, Edgardo Montes de Oca, Wissam Mallouli, Ana R. Cavalli |
ICSOFT | 3 |
| 2020 | Metrics-driven DevSecOps
Wissam Mallouli, Ana R. Cavalli, Alessandra Bagnato, Edgardo Montes de Oca |
ICSOFT | 1 |
| 2019 | Towards Content-Centric Control Plane Supporting Efficient Anomaly Detection FunctionsabstractAnomaly detection remains a challenging task due to both the ever more complex functions that need to be executed and the evolution of current networking devices which induces limitation of computational resources such as the Internet of Things (IoT). Furthermore, results of anomaly function computations can be repeated gradually over time or executed in neighboring nodes, thus leading to a waste of such limited computing resources in constrained nodes. To tackle these issues, the content-centric paradigm enhanced with computing features offers a promising solution to reduce the computation resources and finally improve the scalability of anomaly detection functions. In this paper, we propose a first step toward a content-oriented control plane which enables the distribution of the processing and the sharing of results of anomaly detection functions in the network. We present the way we leverage NFN to support Bayesian Network inference to detect anomalies in network traffic. The relevance and performance of our proposed approach are demonstrated by considering the Content Poisoning Attack (CPA) through numerous experiment data. Hoang Long Mai, Guillaume Doyen, Wissam Mallouli, Edgardo Montes de Oca, Olivier Festor |
CNSM | 3 |
| 2019 | Toward Content-Oriented Orchestration: SDN and NFV as Enabling Technologies for NDN
Hoang Long Mai, Messaoud Aouadj, Guillaume Doyen, Wissam Mallouli, Edgardo Montes de Oca, Olivier Festor |
IM | 4 |
| 2019 | Industrial IoT Security Monitoring and Test on Fed4Fire+ Platforms
Edgardo Montes de Oca, Wissam Mallouli, Ana R. Cavalli, Brecht Vermeulen, Matevz Vucnik |
ICTSS | 3 |
| 2019 | Service level agreement-based GDPR compliance and security assurance in (multi)Cloud-based systemsabstractCompliance with the new European General Data Protection Regulation (Regulation (EU) 2016/679, GDPR) and security assurance are currently two major challenges of Cloud‐based systems. GDPR compliance implies both privacy and security mechanisms definition, enforcement and control, including evidence collection. This study presents a novel DevOps framework aimed at supporting Cloud consumers in designing, deploying and operating (multi)Cloud systems that include the necessary privacy and security controls for ensuring transparency to end‐users, third parties in service provision (if any) and law enforcement authorities. The framework relies on the risk‐driven specification at design time of privacy and security level objectives in the system service level agreement and in their continuous monitoring and enforcement at runtime. Erkuden Rios, Eider Iturbe, Xabier Larrucea, Massimiliano Rak, Wissam Mallouli, Jacek Dominiak, Victor Muntés-Mulero, Peter Matthews, Luis Gonzalez |
IET Softw. | 5 |
| 2019 | Reliable Detection of Interest Flooding Attack in Real Deployment of Named Data NetworkingabstractNamed data networking (NDN) is a disruptive yet promising architecture for the future Internet, in which the content diffusion mechanisms are shifted from the conventional host-centric to content-centric ones so that the data delivery can be significantly improved. After a decade of research and development, NDN and the related NDN forwarding daemon implementations are now mature enough to enable stakeholders, such as telcos, to consider them for a real deployment. Consequently, NDN and IP will likely cohabit, and the future Internet may be formed of isolated administrative domains, each deploying one of these two network paradigms. The security question of the resulting architecture naturally arises. In this paper, we consider the case of denial of service. Even though the interest flooding attack (IFA) has been largely studied and mitigated through NACK packets in pure NDN networks, we demonstrate in this paper through experimental assessments that there are still some ways to mount such an attack, and especially in the context of coupling NDN with IP, which can hardly be addressed by current solutions. Subsequently, we leverage the hypothesis testing theory to develop a generalized likelihood ratio test adapted to evolve IFA attacks. Simulations show the relevance of the proposed model for guaranteeing the prescribed probability of false alarm and highlight the trade-off between detection power and delay. Finally, we consider a real deployment scenario where NDN is coupled with IP to carry HTTP traffic. We show that the model of IFA attacks is not very accurate in practice and further develops a sequential detector to keep a high detection accuracy. By considering data from the testbed, we show the efficiency of the overall detection method. Tan N. Nguyen, Hoang Long Mai, Rémi Cogranne, Guillaume Doyen, Wissam Mallouli, Luong Nguyen, Moustapha El Aoun, Edgardo Montes de Oca, Olivier Festor |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2018 | Enhancing Software Development Process Quality based on Metrics Correlation and SuggestionabstractInternational audience Sarah A. Dahab, Erika Silva, Stéphane Maag, Ana R. Cavalli, Wissam Mallouli |
ICSOFT | 5 |
| 2018 | Towards a security monitoring plane for named data networking and its application against content poisoning attackabstractNamed Data Networking (NDN) is the most mature proposal of the Information Centric Networking paradigm, a clean-slate approach for the Future Internet. Although NDN was designed to tackle security issues inherent to IP networks natively, newly introduced security attacks in its transitional phase threaten NDN's practical deployment. Therefore, a security monitoring plane for NDN is indispensable before any potential deployment of this novel architecture in an operating context by any provider. We propose an approach for the monitoring and anomaly detection in NDN nodes leveraging Bayesian Network techniques. A list of monitored metrics is introduced as a quantitative measure to feature the behavior of an NDN node. By leveraging the hypothesis testing theory, a micro detector is developed to detect whenever the metric significantly changes from its normal behavior. A Bayesian network structure that correlates alarms from micro detectors is designed based on the expert knowledge of the NDN specification and the NFD implementation. The relevance and performance of our security monitoring approach are demonstrated by considering the Content Poisoning Attack (CPA), one of the most critical attacks in NDN, through numerous experiment data collected from a real NDN deployment. Hoang Long Mai, Tan N. Nguyen, Guillaume Doyen, Rémi Cogranne, Wissam Mallouli, Edgardo Montes de Oca, Olivier Festor |
NOMS | 5 |
| 2018 | Leveraging NFV for the deployment of NDN: Application to HTTP traffic transportabstractFor a few years, Network-Function Virtualization (NFV) acts as the most promising solution for the flexible implementation and management of future network services. If most of current efforts in this area focus on IP-based Virtual Network Functions (VNF), the case of Information-Centric Networking (ICN) is interesting since it can demonstrate that NFV is a promising technology for ISP to deploy such new innovative network stacks. In this context, we propose to design and implement a NFV compliant architecture to easily deploy ICN islands. Especially, at the core of this architecture, we present an HTTP/NDN gateway, which enables our network to carry real HTTP traffic. Finally, we show early functional experimental results of an initial testbed deployment exhibiting the capability of our global infrastructure to retrieve the top- 1000 of the most popular web sites. Xavier Marchal, Moustapha El Aoun, Bertrand Mathieu, Thibault Cholez, Guillaume Doyen, Wissam Mallouli, Olivier Festor |
NOMS | 6 |
| 2018 | A Framework for Testing and Monitoring Security Policies: Application to an Electronic Voting SystemabstractTesting and monitoring the effectiveness of security policies under pervasive system architectures is still a major challenging problem for the research community as well as industrials. The inherent characteristics of these systems such as the heterogeneous communicating devices and the multiple used technologies make the burden more overwhelming when dealing with security measures and policies. This paper aims to bridge this gap through the introduction of a formal design of security policies to make security monitoring operation more efficient. Hence, a formal framework is proposed to actively test web-based systems, as an example of these pervasive architectures. The goal of our technique is to check the compliance of the targeted web application to a set of generic security requirements such as confidentiality, integrity and availability as well as to a set of user-related security constraints. Our approach has been applied to a real industrial electronic voting application provided by the Scytl company. Several experiments show the merit of our technique in verifying the correctness of security measures of the targeted application. This framework is part of the INTER-TRUST solution intended to ensure secure inter-operation between communicating systems and provide solutions to test and monitor them. Khalifa Toumi, Mohamed H. E. Aouadi, Ana R. Cavalli, Wissam Mallouli, Jordi Puiggali, Pol Valletb Montfort |
Comput. J. | 4 |
| 2017 | Multi-cloud Applications Security Monitoring
Pamela Carvallo, Ana R. Cavalli, Wissam Mallouli, Erkuden Rios |
GPC | 3 |
| 2016 | An approach for deploying and monitoring dynamic security policies
José Miguel Horcas, Monica Pinto 0001, Lidia Fuentes, Wissam Mallouli, Edgardo Montes de Oca |
Comput. Secur. | 4 |
| 2015 | Monitoring and Securing New Functions Deployed in a Virtualized Networking EnvironmentabstractNetwork operators are currently very cautious before deploying a new network equipment. This is done only if the new networking solution is fully monitored, secured and can provide rapid revenues (short Return of Investment). For example, the NDN (Named Data Networking) solution is admitted as promising but still uncertain, thus making network operators reluctant to deploy it. Having a flexible environment would allow network operators to initiate the deployment of new network solutions at low cost and low risk. The virtualization techniques, appeared a few years ago, can help to provide such a flexible networking architecture. However, with it, emerge monitoring and security issues which should be solved. In this paper, we present our secure virtualized networking environment to deploy new functions and protocol stacks in the network, with a specific focus on the NDN use-case as one of the potential Future Internet technology. As strong requirements for a network operator, we then focus on monitoring and security components, highlighting where and how they can be deployed and used. Finally, we introduce our preliminary evaluation, with a focus on security, before presenting the test bed, involving end-users consuming real contents, that we will set up for the assessment of our approach. Bertrand Mathieu, Guillaume Doyen, Wissam Mallouli, Thomas Silverston, Olivier Bettan, François-Xavier Aguessy, Thibault Cholez, Abdelkader Lahmadi, Patrick Truong, Edgardo Montes de Oca |
ARES | 3 |
| 2015 | Dynamic Deployment and Monitoring of Security Policies
José Miguel Horcas, Monica Pinto 0001, Lidia Fuentes, Wissam Mallouli, Edgardo Montes de Oca |
TrustBus | 4 |
| 2014 | QoE Estimation for Web Service Selection Using a Fuzzy-Rough Hybrid Expert SystemabstractWith the proliferation of web services on the Inter-net, it has become important for service providers to select the best services for their clients in accordance to their functional and non-functional requirements. Generally, QoS parameters are used to select the most performing web services, however, these parameters do not necessarily reflect the user's satisfaction. Therefore, it is necessary to estimate the quality of web services on the basis of user satisfaction, i.e., Quality of Experience(QoE). In this paper, we propose a novel method based on a fuzzy-rough hybrid expert system for estimating QoE of web services for web service selection. It also presents how different QoS parameters impact the QoE of web services. For this, we conducted subjective tests in controlled environment with real users to correlate QoS parameters to subjective QoE. Based on this subjective test, we derive membership functions and inference rules for the fuzzy system. Membership functions are derived using a probabilistic approach and inference rules are generated using Rough Set Theory (RST). We evaluated our system in a simulated environment in MATLAB. The simulation results show that the estimated web quality from our system has a high correlation with the subjective QoE obtained from the participants in controlled tests. Jeevan Pokhrel, Felipe Lalanne, Ana R. Cavalli, Wissam Mallouli |
AINA | 4 |
| 2014 | How to Evaluate Trust Using MMT
Khalifa Toumi, Wissam Mallouli, Edgardo Montes de Oca, César Andrés, Ana R. Cavalli |
NSS | 2 |
| 2014 | Evaluating Web Service QoE by Learning Logic NetworksabstractInternational audience Natalia Kushik, Nina Yevtushenko 0001, Ana R. Cavalli, Wissam Mallouli, Jeevan Pokhrel |
WEBIST (1) | 4 |
| 2012 | A systematic approach to integrate common timed security rules within a TEFSM-based system specification
Amel Mammar, Wissam Mallouli, Ana R. Cavalli |
Inf. Softw. Technol. | 2 |
| 2011 | Using Testing Techniques for Vulnerability Detection in C Programs
Amel Mammar, Ana R. Cavalli, Willy Jimenez, Wissam Mallouli, Edgardo Montes de Oca |
ICTSS | 4 |
| 2010 | WebMov: A Dedicated Framework for the Modelling and Testing of Web Services CompositionabstractThis paper presents a methodology and a set of tools for the modelling, validation and testing of Web service composition, conceived and developed within the French national project WebMov. This methodology includes several modelling techniques, based mainly on some variations of Timed Extended Finite State Machines (TEFSM) formalism, which provide a formal model of the BPEL description of Web services composition. These models are used as a reference for the application of different test generation and passive testing techniques for conformance and robustness checking. The whole WebMov methodology is integrated within a dedicated framework, composed by a set of tools that implement the model representation, the test generation and passive testing algorithms. This framework also permits the interaction of these tools to achieve specific modelling and testing activities in a complementary way. A case study based on a real service, a Travel Reservation Web Service, is presented as well as the results of the application of the proposed WebMov methodology and tools. Ana R. Cavalli, Tien-Dung Cao, Wissam Mallouli, Eliane Martins, Andrey Sadovykh, Sébastien Salva, Fatiha Zaïdi |
ICWS | 3 |
| 2010 | Timed Extended Invariants for the Passive Testing of Web ServicesabstractThe service-oriented approach is becoming more and more popular to integrate highly heterogeneous systems. Web services are the natural evolution of conventional middleware technologies to support Web-based and enterprise level integration. Formal testing of such Web-based technology is a key point to guarantee its reliability. In this paper, we choose a non-intrusive approach based on monitoring to propose a conformance passive testing methodology to check that a composed Web service respects its functional requirements. This methodology is based on a set of formal invariants representing properties to be tested including data and time constraints. Passive testing of an industrial system (that uses a composition of Web services) is briefly presented to demonstrate the effectiveness of the proposed approach. Gerardo Morales, Stéphane Maag, Ana R. Cavalli, Wissam Mallouli, Edgardo Montes de Oca, Bachar Wehbi |
ICWS | 4 |
| 2009 | A Formal Framework to Integrate Timed Security Rules within a TEFSM-Based System SpecificationabstractFormal methods are very useful in software industry and are becoming of paramount importance in practical engineering techniques. They involve the design and the modeling of various system aspects expressed usually through different paradigms. In this paper, we propose to combine two modeling formalisms in order to express both functional and security timed requirements of a system. First, the system behavior is specified based on its functional requirements using TEFSM (timed extended finite state machine) formalism. Second, this model is augmented by applying a set of dedicated algorithms to integrate timed security requirements specified in Nomad language. This language is well adapted to express security properties such as permissions, prohibitions and obligations with time considerations. The resulting secure model can be used for several purposes such as code generation, specification correctness proof, model checking or automatic test generation. In this paper, we applied our approach to a France Telecom(France Telecom is the main telecommunication company in France) Travel service in order to demonstrate its feasibility. Wissam Mallouli, Amel Mammar, Ana R. Cavalli |
APSEC | 1 |
| 2009 | An Automated Passive Testing Approach for the IMS PoC ServiceabstractAlthough the adoption of the IP Multimedia Subsystem (IMS) keeps growing, IMS applications are often integrated to the system without being formally tested. In this work, we are interested in the IMS Push over Cellular (PoC) service, an OMA standard. We propose a conformance passive testing approach to check that its implementation respects the main standard requirements. This approach is based on a set of formal invariants representing the most relevant expected properties to be tested. Two testing phases are applied: the verification of the invariants against the service specification and their testing on the PoC collected execution traces. Felipe Lalanne, Stéphane Maag, Edgardo Montes de Oca, Ana R. Cavalli, Wissam Mallouli, Arnaud Gonguet |
ASE | 5 |
| 2008 | Two Complementary Tools for the Formal Testing of Distributed Systems with Time ConstraintsabstractThe complexity and the variety of the deployed time dependent systems, as well as the high degree of reliability required for their global functioning, justify the care provided to the design of the best possible tests. Moreover,it is significant to automate these steps with an aim of reducing the time and the development cost and especially of increasing the reliability of the offered products. In this paper, we present two different tools to test systems with time constraints. The first one allows to automatically generate test cases based on model-based active testing techniques. Whereas the second tool is based on passive testing approach to check that the collected system traces respect a set of formal properties called Invariants. Ana R. Cavalli, Edgardo Montes de Oca, Wissam Mallouli, Mounir Lallali |
DS-RT | 3 |
| 2008 | Modeling System Security Rules with Time Constraints Using Timed Extended Finite State MachinesabstractSecurity and reliability are of paramount importance in designing and building real-time systems because any security failure can put the public and the environment at risk. In this paper, we propose a framework to take timed security requirements into account from the design stage of the system building. Our approach consists of two main steps. First, the system behavior is specified based on its functional requirements using TEFSM (Timed Extended Finite State Machine) formalism. Second, this model is augmented by applying a set of dedicated algorithms to integrate timed security properties specified in Nomad language. Nomad is a formal language well adapted to express timed security properties with timed constraints. We also briefly present a France Telecom Travel system as a case study to demonstrate the reliability of our framework. Wissam Mallouli, Amel Mammar, Ana R. Cavalli |
DS-RT | 1 |
| 2008 | Security Rules Specification and Analysis Based on Passive TestingabstractSecurity is a critical issue in dynamic and open distributed environments such as network-based services or wireless networks. To ensure that a certain level of security is maintained in such environments, the system behavior has to be restrained by a security policy in order to regulate the nature and the context of actions that can be performed within the system, according to specific roles. In this paper, we propose a passive testing approach that permits to check whether a system respects its security policy. To reach this goal, we specify this policy using 'Nomad' formal language which is based on deontic and temporal logics. This language is well adapted to passive testing methods that aim to analyze collected system execution traces in order to give a verdict about their conformity with to the system security requirements. Finally, we apply our methodology to an industrial case study provided by SAP group to demonstrate its reliability. Wissam Mallouli, Fayçal Bessayah, Ana R. Cavalli, Azzedine Benameur |
GLOBECOM | 1 |
| 2007 | A formal approach for testing security rulesabstractNowadays, security policies are the key point of every modern infrastructure. The specification and the testing of such policies are the fundamental steps in the development of a secure system since any error in a set of rules is likely to harm the global security. To address both challenges, we propose a framework to specify security policies and test their implementation on a system. Our framework makes it possible to generate in an automatic manner, test sequences, in order to validate the conformance of a security policy. system behavior is specified using a formal description technique based on extended finite state machine (EFSM) [12]. The integration of security rules within the system specification is performed by specific algorithms. Then, the automatic tests generation is performed using a dedicated tool, called SIRIUS, developed in our laboratory. Finally, we briefly present a weblog system as a case study to demonstrate the reliability of our framework. Wissam Mallouli, Jean-Marie Orset, Ana R. Cavalli, Nora Cuppens, Frédéric Cuppens |
SACMAT | 1 |
| 2006 | Light Client Management Protocol for Wireless Mesh NetworksabstractThe future of wireless networks evolves toward more simple ways for users to get connected while on the move. In this perspective, Wireless Mesh Networks constitutes one of the key technologies for next generation wireless networks. In this paper we present LCMP, a new protocol for client management in wireless mesh networks. LCMP performs on-demand path setup for clients and supports clients mobility by introducing new light mechanisms that take full advantage of the mesh architecture. The work on LCMP and mesh routing is still in progress at LOMNT laboratory. In this papel; we highlight some ongoing work. Bachar Wehbi, Wissam Mallouli, Ana R. Cavalli |
MDM | 2 |