Eric Totel

dblp:85/5807 · DBLP profile ↗
← Back
28ranked-venue papers
2as first author
6since 2021 · last 2025
0009-0009-2774-007XORCID · reported

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 24 · 2 first-author · 5 since 2021Software engineering, systems software and programming languages · 2 · 1 since 2021Human-computer interaction and ubiquitous computing · 1
YearPublicationVenuePosition
2025 Generating Causal Logs to Explain Attacks
Viet-Huy Ha, Vincent Gauthier, Eric Totel
CRiSIS3
2024 DDoS Mitigation while Preserving QoS: A Deep Reinforcement Learning-Based Approach
abstract
The deployment of 5G networks has significantly improved connectivity, providing remarkable speed and capacity. These networks rely on Software-Defined Networking (SDN) to enhance control and flexibility. However, this advancement poses critical challenges including expanded attack surface due to network virtualization and the risk of unauthorized access to critical infrastructure. Since traditional cybersecurity methods are inadequate in addressing the dynamic nature of modern cyber attacks, employing artificial intelligence (AI), and deep reinforcement learning (DRL) in particular, was investigated to enhance 5G networks security. This interest arises from the ability of these techniques to dynamically respond and adapt their defense strategies according to encountered situations and real-time threats. Our proposed mitigation system uses a DRL framework, enabling an intelligent agent to dynamically adjust its defense strategies against a range of DDoS attacks, exploiting ICMP, TCP SYN, and UDP, within an SDN environment designed to mirror real-life user behaviors. This approach aims to maintain the network’s performance while concurrently mitigating the impact of the real-time attacks, by providing adaptive and automated countermeasures according to the network’s situation.
Shurok Khozam, Gregory Blanc, Sébastien Tixeuil, Eric Totel
NetSoft4
2023 A Privacy-Preserving Infrastructure to Monitor Encrypted DNS Logs
Adam Oumar Abdel-Rahman, Olivier Levillain, Eric Totel
CRiSIS3
2023 Towards Understanding Alerts raised by Unsupervised Network Intrusion Detection Systems
abstract
The use of Machine Learning for anomaly detection in cyber security-critical applications, such as intrusion detection systems, has been hindered by the lack of explainability. Without understanding the reason behind anomaly alerts, it is too expensive or impossible for human analysts to verify and identify cyber-attacks. Our research addresses this challenge and focuses on unsupervised network intrusion detection, where only benign network traffic is available for training the detection model. We propose a novel post-hoc explanation method, called AE-pvalues, which is based on the p-values of the reconstruction errors produced by an Auto-Encoder-based anomaly detection method. Our work identifies the most informative network traffic features associated with an anomaly alert, providing interpretations for the generated alerts. We conduct an empirical study using a large-scale network intrusion dataset, CICIDS2017, to compare the proposed AE-pvalues method with two state-of-the-art baselines applied in the unsupervised anomaly detection task. Our experimental results show that the AE-pvalues method accurately identifies abnormal influential network traffic features. Furthermore, our study demonstrates that the explanation outputs can help identify different types of network attacks in the detected anomalies, enabling human security analysts to understand the root cause of the anomalies and take prompt action to strengthen security measures.
Maxime Lanvin, Pierre-François Gimenez, Yufei Han 0001, Frédéric Majorczyk, Ludovic Mé, Eric Totel
RAID6
2022 Errors in the CICIDS2017 Dataset and the Significant Differences in Detection Performances It Makes
Maxime Lanvin, Pierre-François Gimenez, Yufei Han 0001, Frédéric Majorczyk, Ludovic Mé, Eric Totel
CRiSIS6
2022 DAEMON: Dynamic Auto-encoders for Contextualised Anomaly Detection Applied to Security MONitoring
Alexandre Dey, Eric Totel, Benjamin Costé
SEC2
2020 Heterogeneous Security Events Prioritization Using Auto-encoders
Alexandre Dey, Eric Totel, Sylvain Navers
CRiSIS2
2020 Sec2graph: Network Attack Detection Based on Novelty Detection on Graph Structured Data
Laetitia Leichtnam, Eric Totel, Nicolas Prigent, Ludovic Mé
DIMVA2
2019 Discovering Correlations: A Formal Definition of Causal Dependency Among Heterogeneous Events
abstract
In order to supervise the security of a large infrastructure, the administrator deploys multiple sensors and intrusion detection systems on several critical places in the system. It is easier to explain and detect attacks if more events are logged. Starting from a suspicious event (appearing as a log entry), the administrator can start his investigation by manually building the set of previous events that are linked to this event of interest. Accordingly, the administrator attempts to identify links among the logged events in order to retrieve those that correspond to the traces of the attacker's actions in the supervised system; previous work is aimed at building these connections. In practice, however, this type of link is not trivial to define and discover. Hence, there is a real necessity to describe and define formally the semantics of these links in literature. In this paper, a clear definition of this relationship, called contextual event causal dependency, is introduced and proposed. The work presented in this paper aims at defining a formal model that would ideally unify previous work on causal dependencies among heterogeneous events. We define a relationship among events that enables the discovery of all events, which can be considered as the cause (in the past) or the effect (in the future) of an event of interest(e.g., an indicator of compromise, produced by an attacker action). This model is gradually introduced and defined by merging two previously defined causality models from the distributed system and operating system research areas (i.e., Lamport's and d'Ausbourg's). Our model takes into consideration heterogeneous events that emanate from different abstraction layers (e.g., network, system, and application) with the main objective of formally defining a causal relationship among logged events. Thereafter, we show how existing implementations separately allow the computation of parts of the model. Finally, we describe the implementation and assessment of the model according to real attacks on distributed environments and its accuracy to extract all causally linked events related to a given attack event trace.
Charles Xosanavongsa, Eric Totel, Olivier Bettan
EuroS&P2
2019 An Efficient and Scalable Intrusion Detection System on Logs of Distributed Applications
David Lanoë, Michel Hurfin, Eric Totel, Carlos Maziero
SEC3
2018 A Scalable and Efficient Correlation Engine to Detect Multi-Step Attacks in Distributed Systems
abstract
In distributed systems and in particular in industrial SCADA environments, alert correlation systems are necessary to identify complex multi-step attacks within the huge amount of alerts and events. In this paper we describe an automata-based correlation engine developed in the context of a European project where the main stakeholder was an energy distribution company. The behavior of the engine is extended to fit new requirements. In the proposed solution, a fully automated process generates thousands of correlation rules. Despite this major scalability challenge, the designed correlation engine exhibits good performances. Expected rates of incoming low level alerts approaching several hundreds of elements per second are tolerated. Moreover, the used data structures allow to quickly handle dynamic changes of the set of correlation rules. As some attack steps are not observed, the correlation engine can be tuned to raise an alert when all the attack steps except k of them have been detected. To be able to react to an ongoing attack by taking countermeasures, alerts must also be raised as soon as a significant prefix of an attack scenario is recognized. Fulfilling these additional requirements leads to increase the memory consumption. Therefore purge mechanisms are also proposed and analyzed. An evaluation of the tool is conducted in the context of a SCADA environment.
David Lanoë, Michel Hurfin, Eric Totel
SRDS3
2017 Connectivity extraction in cloud infrastructures
abstract
For management and security purposes, cloud providers should know the connectivity graph between virtual machines. Since traditional methods used in physical networks produce incomplete results and are hardly usable in the Cloud, we propose to use information provided by a Cloud Management Software and an SDN controller, to compute the connectivity graph in those environments. Our approach shows an exact, complete and up-to-date connectivity graphs computation on a representative infrastructure, in reasonable time.
Pernelle Mensah, Samuel Dubus, Wael Kanoun, Christine Morin, Guillaume Piolle, Eric Totel
CNSM6
2017 Connectivity graph reconstruction for networking cloud infrastructures
abstract
Cloud providers have an incomplete view of their hosted virtual infrastructures managed by a Cloud Management System (CMS) and a Software Defined Network (SDN) controller. For various security reasons (e.g. isolation verification, modeling attack paths in the network), it is necessary to know which virtual machines can interact via network protocols. This requires building a connectivity graph between the virtual machines, that we can extract with the knowledge of the overall topology and the deployed network security policy. Existing methodologies for building such models for physical networks produce incomplete results. Moreover, they are not suitable for cloud infrastructures due to either their intrusiveness or lack of connectivity discovery. We propose a method to compute the connectivity graph, relying on information provided by both the CMS and the SDN controller. Connectivity can first be extracted from knowledge databases, then dynamically updated on the occurrence of cloud-related events. This approach shows an exact, complete and up-to-date connectivity graphs computation on a representative infrastructure, in reasonable time.
Pernelle Mensah, Samuel Dubus, Wael Kanoun, Christine Morin, Guillaume Piolle, Eric Totel
NCA6
2017 Hypercollecting semantics and its application to static analysis of information flow
abstract
We show how static analysis for secure information flow can be expressed and proved correct entirely within the framework of abstract interpretation. The key idea is to define a Galois connection that directly approximates the hyperproperty of interest. To enable use of such Galois connections, we introduce a fixpoint characterisation of hypercollecting semantics, i.e. a "set of sets" transformer. This makes it possible to systematically derive static analyses for hyperproperties entirely within the calculational framework of abstract interpretation. We evaluate this technique by deriving example static analyses. For qualitative information flow, we derive a dependence analysis similar to the logic of Amtoft and Banerjee (SAS '04) and the type system of Hunt and Sands (POPL '06). For quantitative information flow, we derive a novel cardinality analysis that bounds the leakage conveyed by a program instead of simply deciding whether it exists. This encompasses problems that are hypersafety but not k-safety. We put the framework to use and introduce variations that achieve precision rivalling the most recent and precise static analyses for information flow.
Mounir Assaf, David A. Naumann, Julien Signoles, Eric Totel, Frédéric Tronel
POPL4
2017 STARLORD: Linked security data exploration in a 3D graph
abstract
In this paper, we present a novel model and visualization approach for heterogeneous sources of data. We represent our data by using a model inspired by STIX. Then, we use clustering algorithms to select interesting information to explore in a visualization panel. The visualization is based on a 3D graph representation that highlights the link between malicious event and allows to focus on relevant security artifacts. We illustrate our approach with two case studies using datasets containing network capture of the wannacry attack.
Laetitia Leichtnam, Eric Totel, Nicolas Prigent, Ludovic Mé
VizSEC2
2014 Automatic generation of correlation rules to detect complex attack scenarios
abstract
In large distributed information systems, alert correlation systems are necessary to handle the huge amount of elementary security alerts and to identify complex multi-step attacks within the flow of low level events and alerts. In this paper, we show that, once a human expert has provided an action tree derived from an attack tree, a fully automated transformation process can generate exhaustive correlation rules that would be tedious and error prone to enumerate by hand. The transformation relies on a detailed description of various aspects of the real execution environment (topology of the system, deployed services, etc.). Consequently, the generated correlation rules are tightly linked to the characteristics of the monitored information system. The proposed transformation process has been implemented in a prototype that generates correlation rules expressed in an attack description language.
Erwan Godefroy, Eric Totel, Michel Hurfin, Frédéric Majorczyk
IAS2
2013 Program Transformation for Non-interference Verification on Programs with Pointers
Mounir Assaf, Julien Signoles, Frédéric Tronel, Eric Totel
SEC4
2012 Detecting attacks against data in web applications
abstract
RRABIDS (Ruby on Rails Anomaly Based Intrusion Detection System) is an application level intrusion detection system for applications implemented with the Ruby on Rails framework. It is aimed at detecting attacks against data in the context of web applications. This anomaly based IDS focuses on the modeling of the application profile in the absence of attacks (called normal profile) using invariants. These invariants are discovered during a learning phase. Then, they are used to instrument the web application at source code level, so that a deviation from the normal profile can be detected at run-time. This paper illustrates on simple examples how the approach detects well known categories of web attacks that involve a state violation of the application, such as SQL injections. Finally, an assessment phase is performed to evaluate the accuracy of the detection provided by the proposed approach.
Romaric Ludinard, Eric Totel, Frédéric Tronel, Vincent Nicomette, Mohamed Kaâniche, Eric Alata, Rim Akrout, Yann Bachy
CRiSIS2
2011 Preventing data leakage in service orchestration
abstract
Web Services are currently the base of a lot a e-commerce applications. Nevertheless, clients often use these services without knowing anything about their internals. Moreover, they have no clue about the use of their personal data inside the global applications. In this paper, we offer the opportunity to the user to specify constraints on the use of its personal data. To ensure the privacy of data at runtime, we define a distributed security policy model. This policy is configured at runtime by the user of the BPEL program. This policy is enforced within a BPEL interpreter, and ensures that no information flow can be produced from the user data to unauthorized services. However, the dynamic aspects of web services lead to situations where the policy prohibits the nominal operation of orchestration (e.g., when using a service that is unknown by the user). To solve this problem, we propose to let user to dynamically permit exceptional unauthorized flows. In order to make decision, the user is provided with all information necessary for decision-making. We also present an implementation inside the Orchestra BPEL interpreter. As far as we know this implementation is the first information flow monitor for web services that is also end-user configurable.
Thomas Demongeot, Eric Totel, Yves Le Traon
IAS2
2011 Detecting Illegal System Calls Using a Data-Oriented Detection Model
Jonathan-Christofer Demay, Frédéric Majorczyk, Eric Totel, Frédéric Tronel
SEC3
2009 SIDAN: A tool dedicated to software instrumentation for detecting attacks on non-control-data
abstract
Anomaly based intrusion detection systems rely on the build of a normal behavior model. When a deviation from this normal behavior is detected, an alert is raised. This anomaly approach, unlike the misuse approach, is able to detect unknown attacks. A basic technique to build such a model for a program is to use the system call sequences of the process. To improve the accuracy and completeness of this detection model, we can add information related to the system call, such as its arguments or its execution context. But even then, attacks that target non-control-data may be missed and attacks on control-data may be adapted to bypass the detection mechanism using evasion techniques. We propose in this article an approach that focuses on the detection of non-control-data attacks. Our approach aims at exploiting the internal state of a program to detect a memory corruption on non-control-data that could lead to an illegal system call. To achieve this, we propose to build a data-oriented detection model by statically analyzing a program source code. This model is used to instrument the program by adding reasonableness checks that verify the consistent state of the data items the system calls depend on. We thus argue that it is possible to detect a program misuse issued by a non-control-data attack inside the program during its execution. While keeping a low overhead, this approach allows to detect non-control-data attacks.
Jonathan-Christofer Demay, Eric Totel, Frédéric Tronel
CRiSIS2
2009 Building an Application Data Behavior Model for Intrusion Detection
Olivier Sarrouy, Eric Totel, Bernard Jouga
DBSec2
2009 Automatic Software Instrumentation for the Detection of Non-control-data Attacks
Jonathan-Christofer Demay, Eric Totel, Frédéric Tronel
RAID2
2009 Application Data Consistency Checking for Anomaly Based Intrusion Detection
Olivier Sarrouy, Eric Totel, Bernard Jouga
SSS2
2008 Anomaly Detection with Diagnosis in Diversified Systems using Information Flow Graphs
Frédéric Majorczyk, Eric Totel, Ludovic Mé, Ayda Saïdane
SEC2
2006 A Dependable Intrusion Detection Architecture Based on Agreement Services
Michel Hurfin, Jean-Pierre Le Narzul, Frédéric Majorczyk, Ludovic Mé, Ayda Saïdane, Eric Totel, Frédéric Tronel
SSS6
2005 COTS Diversity Based Intrusion Detection and Application to Web Servers
Eric Totel, Frédéric Majorczyk, Ludovic Mé
RAID1
2004 A Language Driven IDS for Event and Alert Correlation
Eric Totel, Bernard Vivinis, Ludovic Mé
SEC1