EDBT 2026 Demo / reviewers in the wild / expert
Hervé Debar
dblp:86/4961
· DBLP profile ↗
57ranked-venue papers
8as first author
4since 2021 · last 2024
0000-0002-1344-4167ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 48 · 7 first-author · 3 since 2021Computer networks · 4 · 1 first-authorArtificial intelligence and machine learning · 2 · 1 since 2021Software engineering, systems software and programming languages · 2Systems, architecture and hardware · 1Databases, data management, data science and information retrieval · 1Theory of computation · 1Applied, interdisciplinary, general and emerging computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | Mealy Verifier: An Automated, Exhaustive, and Explainable Methodology for Analyzing State Machines in Protocol ImplementationsabstractMany network protocol specifications are long and lack clarity, which paves the way to implementation errors. Such errors have led to vulnerabilities for secure protocols such as SSH and TLS. Active automata learning, a black-box method, is an efficient method to discover discrepancies between a specification and its implementation. It consists in extracting state machines by interacting with a network stack. It can be (and has been) combined with model checking to analyze the obtained state machines. Model checking is designed for exhibiting a single model violation instead of all model violations and thus leads to a limited understanding of implementation errors. As far as we are aware, there is only one specialized exhaustive method available for analyzing the outcomes of active automata learning applied to network protocols,Fiterau-Brostean’s method. We propose an alternative method, to improve the discovery of new bugs and vulnerabilities and enhance the exhaustiveness of model verification processes. In this article, we apply our method to two use cases: SSH, where we focus on the analysis of existing state machines and OPC UA, for which we present a full workflow from state machine inference to state machine analysis. Arthur Tran Van, Olivier Levillain, Hervé Debar |
ARES | 3 |
| 2023 | An Improved Honeypot Model for Attack Detection and AnalysisabstractThis paper presents a new model and design for honeypots, and the results obtained the implementation and exposure on the internet of an high interaction honeypot. We show that our model can allow higher interaction with attackers while preserving integrity and attractiveness. In our work, we use threat analysis based on the MITRE ATT&CK taxonomy to describe the design and supervision constraints of our honeypot with it’s situation in our implemented architecture. We exposed our infrastructure during seventeen days and collected information about several actors and attack methods, from which we extracted previously undocumented Indicators of Compromise. Marwan Abbas-Escribano, Hervé Debar |
ARES | 2 |
| 2022 | Towards a Systematic and Automatic Use of State Machine Inference to Uncover Security Flaws and Fingerprint TLS Stacks
Aina Toky Rasoamanana, Olivier Levillain, Hervé Debar |
ESORICS (3) | 3 |
| 2021 | CVSS-BERT: Explainable Natural Language Processing to Determine the Severity of a Computer Security Vulnerability from its DescriptionabstractWhen a new computer security vulnerability is publicly disclosed, only a textual description of it is available. Cybersecurity experts later provide an analysis of the severity of the vulnerability using the Common Vulnerability Scoring System (CVSS). Specifically, the different characteristics of the vulnerability are summarized into a vector (consisting of a set of metrics), from which a severity score is computed. However, because of the high number of vulnerabilities disclosed everyday this process requires lot of manpower, and several days may pass before a vulnerability is analyzed. We propose to leverage recent advances in the field of Natural Language Processing (NLP) to determine the CVSS vector and the associated severity score of a vulnerability from its textual description in an explainable manner. To this purpose, we trained multiple BERT classifiers, one for each metric composing the CVSS vector. Experimental results show that our trained classifiers are able to determine the value of the metrics of the CVSS vector with high accuracy. The severity score computed from the predicted CVSS vector is also very close to the real severity score attributed by a human expert. For explainability purpose, gradient-based input saliency method was used to determine the most relevant input words for a given prediction made by our classifiers. Often, the top relevant words include terms in agreement with the rationales of a human cybersecurity expert, making the explanation comprehensible for end-users. Mustafizur R. Shahid, Hervé Debar |
ICMLA | 2 |
| 2020 | A Quantitative Study of Vulnerabilities in the Internet of Medical Things
Hervé Debar, Razvan Beuran, Yasuo Tan |
ICISSP | 1 |
| 2020 | Automated Saturation Mitigation Controlled by Deep Reinforcement LearningabstractRecent developments in orchestration and machine learning have made network automation more feasible, allowing the transition from error-prone and time-consuming manual manipulations to fast and refined automated responses in areas such as security and management. This article investigates the capabilities of a deep reinforcement learning agent to learn how to automatically share prefix announcements of an Autonomous System to its neighbors, in order to mitigate undesired network behaviors and therefore increase network resiliency and security. Our work focuses on network saturation, tackling the problem of network responsiveness in today's massive content delivery context. Results not only prove feasibility of such an agent, but also demonstrate its ability to minimize traffic loss as well as the number of actions to be performed by the automation process. Elkin Aguas, Anthony Lambert, Gregory Blanc, Hervé Debar |
ICNP | 4 |
| 2020 | Generative Deep Learning for Internet of Things Network Traffic GenerationabstractThe rapid development of the Internet of Things (IoT) has prompted a recent interest into realistic IoT network traffic generation. Security practitioners need IoT network traffic data to develop and assess network-based intrusion detection systems (NIDS). Emulating realistic network traffic will avoid the costly physical deployment of thousands of smart devices. From an attacker's perspective, generating network traffic that mimics the legitimate behavior of a device can be useful to evade NIDS. As network traffic data consist of sequences of packets, the problem is similar to the generation of sequences of categorical data, like word by word text generation. Many solutions in the field of natural language processing have been proposed to adapt a Generative Adversarial Network (GAN) to generate sequences of categorical data. In this paper, we propose to combine an autoencoder with a GAN to generate sequences of packet sizes that correspond to bidirectional flows. First, the autoencoder is trained to learn a latent representation of the real sequences of packet sizes. A GAN is then trained on the latent space, to learn to generate latent vectors that can be decoded into realistic sequences. For experimental purposes, bidirectional flows produced by a Google Home Mini are used, and the autoencoder is combined with a Wassertein GAN. Comparison of different network characteristics shows that our proposed approach is able to generate sequences of packet sizes that behave closely to real bidirectional flows. We also show that the synthetic bidirectional flows are close enough to the real ones that they can fool anomaly detectors into labeling them as legitimate. Mustafizur R. Shahid, Gregory Blanc, Houda Jmila, Zonghua Zhang, Hervé Debar |
PRDC | 5 |
| 2020 | Solving security constraints for 5G slice embedding: A proof-of-concept
François Boutigny, Stéphane Betgé-Brezetz, Gregory Blanc, Antoine Lavignotte, Hervé Debar, Houda Jmila |
Comput. Secur. | 5 |
| 2019 | Methodology of a Network Simulation in the Context of an Evaluation: Application to an IDSabstractInternational audience Pierre-Marie Bajan, Christophe Kiennert, Hervé Debar |
ICISSP | 3 |
| 2019 | Anomalous Communications Detection in IoT Networks Using Sparse AutoencodersabstractNowadays, IoT devices have been widely deployed for enabling various smart services, such as, smart home or e-healthcare. However, security remains as one of the paramount concern as many IoT devices are vulnerable. Moreover, IoT malware are constantly evolving and getting more sophisticated. IoT devices are intended to perform very specific tasks, so their networking behavior is expected to be reasonably stable and predictable. Any significant behavioral deviation from the normal patterns would indicate anomalous events. In this paper, we present a method to detect anomalous network communications in IoT networks using a set of sparse autoencoders. The proposed approach allows us to differentiate malicious communications from legitimate ones. So that, if a device is compromised only malicious communications can be dropped while the service provided by the device is not totally interrupted. To characterize network behavior, bidirectional TCP flows are extracted and described using statistics on the size of the first N packets sent and received, along with statistics on the corresponding inter-arrival times between packets. A set of sparse autoencoders is then trained to learn the profile of the legitimate communications generated by an experimental smart home network. Depending on the value of N, the developed model achieves attack detection rates ranging from 86.9% to 91.2%, and false positive rates ranging from 0.1% to 0.5%. Mustafizur R. Shahid, Gregory Blanc, Zonghua Zhang, Hervé Debar |
NCA | 4 |
| 2018 | IoT Devices Recognition Through Network Traffic AnalysisabstractThe growing Internet of Things (IoT) market introduces new challenges for network activity monitoring. Legacy network monitoring is not tailored to cope with the huge diversity of smart devices. New network discovery techniques are necessary in order to find out what IoT devices are connected to the network. In this context, data analysis techniques can be leveraged to find out specific patterns that can help to recognize device types. Indeed, contrary to desktop computers, IoT devices perform very specific tasks making their networking behavior very predictable. In this paper, we present a machine learning based approach in order to recognize the type of IoT devices connected to the network by analyzing streams of packets sent and received. We built an experimental smart home network to generate network traffic data. From the generated data, we have designed a model to describe IoT device network behaviors. By leveraging the t-SNE technique to visualize our data, we are able to differentiate the network traffic generated by different IoT devices. The data describing the network behaviors are then used to train six different machine learning classifiers to predict the IoT device that generated the network traffic. The results are promising with an overall accuracy as high as 99.9% on our test set achieved by Random Forest classifier. Mustafizur R. Shahid, Gregory Blanc, Zonghua Zhang, Hervé Debar |
IEEE BigData | 4 |
| 2018 | Dynamic risk management response system to handle cyber threats
Gustavo Gonzalez Granadillo, Samuel Dubus, Alexander Motzek, Joaquín García 0001, Ender Alvarez, Matteo Merialdo, Serge Papillon, Hervé Debar |
Future Gener. Comput. Syst. | 8 |
| 2017 | ArOMA: An SDN based autonomic DDoS mitigation framework
Rishikesh Sahay, Gregory Blanc, Zonghua Zhang, Hervé Debar |
Comput. Secur. | 4 |
| 2017 | Selection of Pareto-efficient response plans based on financial and operational assessmentsabstractFinding adequate responses to ongoing attacks on ICT systems is a pertinacious problem and requires assessments from different perpendicular viewpoints. However, current research focuses on reducing the impact of an attack irregardless of side effects caused by responses. In order to achieve a comprehensive yet accurate response to possible and ongoing attacks on a managed ICT system, we propose an approach that evaluates a response from two perpendicular perspectives: (1) A response financial impact assessment, considering the financial benefits of restoring and protecting potentially threatened operational capabilities while considering implementation and maintenance costs of responses. (2) A response operational impact assessment, which assesses potential impacts that efficient mitigation actions may inadvertently cause on the organization in an operational perspective, e.g., negative side effects of deploying mitigations. It is the key benefit of the presented approach to combine all obtained evaluations with a multi-dimensional optimization procedure such that a response plan is selected which reduces a state of risk below an admissible level while minimizing potential negative side effects of deliberately taken actions. Alexander Motzek, Gustavo Gonzalez Granadillo, Hervé Debar, Joaquín García 0001, Ralf Möller 0001 |
EURASIP J. Inf. Secur. | 3 |
| 2017 | A polytope-based approach to measure the impact of events against critical infrastructures
Gustavo Gonzalez Granadillo, Joaquín García 0001, Hervé Debar |
J. Comput. Syst. Sci. | 3 |
| 2016 | Selection of Mitigation Actions Based on Financial and Operational Impact AssessmentsabstractFinding adequate responses to ongoing attacks on ICT systems is a pertinacious problem and requires assessments from different perpendicular viewpoints. However, current research focuses on reducing the impact of an attack irregardless of side-effects caused by responses. In order to achieve a comprehensive yet accurate response to possible and ongoing attacks on a managed ICT system, we propose an approach that relies on a response system that continuously quantifies risks, and decides how to respond to cyber-threats that target a monitored ICT system. Our Dynamic Risk Management Response (DRMR) model is composed of two main modules: a Response Financial Impact Assessor (RFIA), which provides an assessment concerning the potential financial impact that responses may cause to an organization, and a Response Operational Impact Assessor (ROIA), which assesses potential impacts that efficient mitigation actions may cause on the organization in an operational perspective. As a result, the DRMR model proposes response plans to mitigate identified risks, enable choice of the most suitable response possibilities to reduce identified risks below an admissible level while minimizing potential negative side effects of deliberately taken actions. Gustavo Gonzalez Granadillo, Alexander Motzek, Joaquín García 0001, Hervé Debar |
ARES | 4 |
| 2016 | StemJail: Dynamic Role CompartmentalizationabstractWhile users tend to indiscriminately use the same device to address every need, exfiltration of information becomes the end game of attackers. Average users need realistic and practical solutions to enable them to mitigate the consequences of a security breach in terms of data leakage. We present StemJail, an open-source security solution to isolate groups of processes pertaining to the same activity into an environment exposing only the relevant subset of user data. At the heart of our solution lies dynamic activity discovery, allowing seamless integration of StemJail into the user workflow. Our userland access control framework only relies on the ability of user to organize data in directories. Thus, it is easily configurable and requires very little user interaction once set up. Moreover, StemJail is designed to run without intrusive changes to the system and to be configured and used by any unprivileged user thanks to the Linux user namespaces. Mickaël Salaün, Marion Daubignard, Hervé Debar |
AsiaCCS | 3 |
| 2016 | An n-Sided Polygonal Model to Calculate the Impact of Cyber Security Events
Gustavo Gonzalez Granadillo, Joaquín García 0001, Hervé Debar |
CRiSIS | 3 |
| 2015 | On the Isofunctionality of Network Access Control ListsabstractIn a networking context, Access Control Lists (ACLs) refer to security rules associated to network equipment, such as routers, switches and firewalls. Methods and tools to automate the management of ACLs distributed among several equipment shall verify if the corresponding ACLs are functionally equivalent. In this paper, we address such a verification process. We present a formal method to verify when two ACLs are iso functional and illustrate our proposal over a practical example. Malek Belhaouane, Joaquín García 0001, Hervé Debar |
ARES | 3 |
| 2015 | TLS Record Protocol: Security Analysis and Defense-in-depth Countermeasures for HTTPSabstractTLS and its main application HTTPS are an essential part of internet security. Since 2011, several attacks against the TLS Record protocol have been presented. To remediate these flaws, countermeasures have been proposed. They were usually specific to a particular attack, and were sometimes in contradiction with one another. All the proofs of concept targeted HTTPS and relied on the repetition of some secret element inside the TLS tunnel. In the HTTPS context, such secrets are pervasive, be they authentication cookies or anti-CSRF tokens. We present a comprehensive state of the art of attacks on the Record protocol and the associated proposed countermeasures. In parallel to the efforts of the community to find reliable long term solutions, we propose masking mechanisms to avoid the repetition of sensitive elements, at the transport or application level. We also assess the feasibility and efficiency of such defense-in-depth mechanisms. The recent POODLE vulnerability confirmed our proposals could thwart unknown attacks, since they would have blocked it. Olivier Levillain, Baptiste Gourdin, Hervé Debar |
AsiaCCS | 3 |
| 2015 | Attack Volume Model: Geometrical Approach and Application
Gustavo Gonzalez Granadillo, Grégoire Jacob, Hervé Debar |
CRiSIS | 3 |
| 2015 | Automated Classification of C&C Connections Through Malware URL Clustering
Nizar Kheir, Gregory Blanc, Hervé Debar, Joaquín García 0001, Dingqi Yang |
SEC | 3 |
| 2015 | Evaluating the Comprehensive Complexity of Authorization-based Access Control Policies using Quantitative MetricsabstractInternational audience Malek Belhaouane, Joaquín García 0001, Hervé Debar |
SECRYPT | 3 |
| 2015 | Using a 3D Geometrical Model to Improve Accuracy in the Evaluation and Selection of Countermeasures Against Complex Cyber Attacks
Gustavo Gonzalez Granadillo, Joaquín García 0001, Hervé Debar |
SecureComm | 3 |
| 2014 | Policy Enforcement Point Model
Yosra Ben Mustapha, Hervé Debar, Gregory Blanc |
SecureComm (1) | 2 |
| 2013 | Parsifal: Writing efficient and robust binary parsers, quicklyabstractFor our needs, we wrote several parsers to analyse a lot of SSL/TLS data. As the collected messages were sometimes corrupted or invalid, standard tools did not allow for sound and robust dissection. Parsifal, an OCaml-based parsing engine, allowed us to gain insight into several important protocols. Parsifal also proved to be versatile and might be useful to the security community to write efficient and robust binary dissectors. As security researchers, we need robust tools on which we can depend. The starting point of Parsifal was a study of large amounts of SSL data. The data collected contained legitimate SSL messages, as well as invalid messages and other protocols (HTTP, SSH). To face this challenge and extract relevant information, we wrote several parsers, using different languages, which resulted in Parsifal, an OCaml-based parsing engine. The contribution of Parsifal to security is twofold. First we provide sound tools to analyse complex file formats or network protocols. Secondly we implement robust detection/sanitization systems. The goal of this paper is to present Parsifal and to use it to write a network protocol parser (DNS) and a file format parser (PNG). The PNG parser will then be used to build a PNG sanitizer. Alternatively, an X.509 certificate signing request validator can be implemented. Olivier Levillain, Hervé Debar, Benjamin Morin |
CRiSIS | 2 |
| 2012 | One year of SSL internet measurementabstractOver the years, SSL/TLS has become an essential part of internet security. As such, it should offer robust and state-of-the-art security, in particular for HTTPS, its first application. Theoretically, the protocol allows for a trade-off between secure algorithms and decent performance. Yet in practice, servers do not always support the latest version of the protocol, nor do they all enforce strong cryptographic algorithms. Olivier Levillain, Arnaud Ébalard, Benjamin Morin, Hervé Debar |
ACSAC | 4 |
| 2012 | HADEGA: A novel MPLS-based mitigation solution to handle network attacksabstractWe present HADEGA, a novel adaptive mitigation solution to handle the impact of network attacks. By extracting information from network detection alerts, and build upon the Multiprotocol Label Switching (MPLS) standard, the solution assigns labels and quality of service treatments to suspicious flows. As a result, those labeled flows are controlled and properly handled inside the core network of service providers. We conducted simulations in order to evaluate the efficiency of our approach. Results are presented. Nabil Hachem, Hervé Debar, Joaquín García 0001 |
IPCCC | 2 |
| 2012 | Challenges for Advanced Security Monitoring - The MASSIF Project
Roland Rieke, Elsa Prieto, Hervé Debar, Andrew Hutchison |
TrustBus | 4 |
| 2010 | Formalization of Viruses and Malware Through Process AlgebrasabstractAbstract virology has seen the apparition of successive viral models, all based on Turing-equivalent formalisms. Considering recent malware, these are only partially covered because functional formalisms do not support interactive computations. This article provides a basis for a unified malware model, founded on the Join-Calculus. In terms of expressiveness, the process-based model supports the fundamental notion of self-replication but also interactions, concurrency and non-termination to cover evolved malware. In terms of protection, detection undecidability and prevention by isolation still hold. Additional results are established: calculus fragments where detection is decidable, definition of a non-infection property, potential solutions to restrict propagation. Grégoire Jacob, Eric Filiol, Hervé Debar |
ARES | 3 |
| 2010 | A Service Dependency Model for Cost-Sensitive Intrusion Response
Nizar Kheir, Nora Cuppens, Frédéric Cuppens, Hervé Debar |
ESORICS | 4 |
| 2010 | Ex-SDF: An Extended Service Dependency Framework for Intrusion Impact Assessment
Nizar Kheir, Nora Cuppens, Frédéric Cuppens, Hervé Debar |
SEC | 4 |
| 2009 | A Service Dependency Modeling Framework for Policy-Based Response Enforcement
Nizar Kheir, Hervé Debar, Frédéric Cuppens, Nora Cuppens, Jouni Viinikka |
DIMVA | 2 |
| 2009 | Malware Behavioral Detection by Attribute-Automata Using Abstraction from Platform and Language
Grégoire Jacob, Hervé Debar, Eric Filiol |
RAID | 2 |
| 2009 | An ontology-based approach to react to network attacksabstractIntrusion detection requirements enforced by Intrusions Detection Systems (IDSs) are generally considered independently from the remainder of the security policy. Our approach is to consider that intrusion detection requirements are actually a part of the access control policy. This provides means to formally specify in a reaction policy what should happen in case of intrusion. It is then possible to integrate these requirements into a deploying process in order to automatically configure security components. In this paper, we propose a contextual and ontology-based approach to express and instantiate this reaction policy. We then define a reaction process based on the concepts of dynamic threat organisation and threat contexts and a set of rules used to map alerts onto threat contexts to perform the instantiation of the policy-based reaction in response to the detected intrusion. Nora Cuppens, Frédéric Cuppens, Fabien Autrel, Hervé Debar |
Int. J. Inf. Comput. Secur. | 4 |
| 2008 | An ontology-based approach to react to network attacksabstractTo address the evolution of security incidents in current communication networks it is important to react quickly and efficiently to an attack. The RED (Reaction after Detection) project is defining and designing solutions to enhance the detection/reaction process, improving the overall resilience of IP networks to attacks and help telecommunication and service providers to maintain sufficient quality of service and respect service level agreements. Within this project, a main component is in charge of instantiating new security policies that counteract the network attacks. This paper proposes an ontology-based approach to instantiate these security policies. This technology provides a way to map alerts into attack contexts, which are used to identify the policies to be applied in the network to solve the threat. For this, ontologies to describe alerts and policies are defined, using inference rules to perform such mappings. Nora Cuppens, Frédéric Cuppens, Jorge E. López de Vergara, Enrique Vázquez, Javier Guerra, Hervé Debar |
CRiSIS | 6 |
| 2008 | Negotiation of Prohibition: An Approach Based on Policy Rewriting
Nora Cuppens, Frédéric Cuppens, Diala Abi Haidar, Hervé Debar |
SEC | 4 |
| 2007 | Resource Classification Based Negotiation in Web ServicesabstractTrust establishment is necessary in every negotiation between entities from different security domains. It is seen as a first step before gaining access to protected resources. In this paper, we introduce a new classification methodology for protected resources. We use this classification to define the behavior of entities within a state based negotiation process. This process is enforced by two modules, the negotiation module and the exception treatment module. The first one intercepts all the requests for access. It collects credentials and exchanges policies according to the available negotiation policies. The second one is called by the first one whenever an exception is raised. An exception is a non negotiated denied access or locked negotiation. Diala Abi Haidar, Nora Cuppens, Frédéric Cuppens, Hervé Debar |
IAS | 4 |
| 2006 | Improving Security Management through Passive Network ObservationabstractDetailed and reliable knowledge of the characteristics of an information system is becoming a very important feature for operational security. Unfortunately, vulnerability assessment tools have important side effects on the monitored information systems. In this paper, we propose an approach to gather or deduce information similar to vulnerability assessment reports, based on passive network observation. Information collected goes beyond classic server vulnerability assessment, enabling compliance verification of desktop clients. Yohann Thomas, Hervé Debar, Benjamin Morin |
ARES | 2 |
| 2006 | Time series modeling for IDS alert managementabstractIntrusion detection systems create large amounts of alerts. Significant part of these alerts can be seen as background noise of an operational information system, and its quantity typically overwhelms the user. In this paper we have three points to make. First, we present our findings regarding the causes of this noise. Second, we provide some reasoning why one would like to keep an eye on the noise despite the large number of alerts. Finally, one approach for monitoring the noise with reasonable user load is proposed. The approach is based on modeling regularities in alert flows with classical time series methods. We present experimentations and results obtained using real world data. Jouni Viinikka, Hervé Debar, Ludovic Mé, Renaud Séguier |
AsiaCCS | 2 |
| 2006 | Using Contextual Security Policies for Threat Response
Hervé Debar, Yohann Thomas, Nora Cuppens, Frédéric Cuppens |
DIMVA | 1 |
| 2006 | Security information management as an outsourced serviceabstractPurpose – Security information management (SIM) has emerged recently as a strong need to ensure the ongoing security of information systems. However, deploying a SIM and the associated sensors is a challenge in any organization, as the complexity and cost of such a project are difficult to bear. This paper aims to present an architecture for outsourcing a SIM platform, and discuss the issues associated with the deployment of such an environment. Hervé Debar, Jouni Viinikka |
Inf. Manag. Comput. Secur. | 1 |
| 2004 | A Serial Combination of Anomaly and Misuse IDSes Applied to HTTP TrafficabstractCombining an "anomaly" and a "misuse" IDSes offers the advantage of separating the monitored events between normal, intrusive or unqualified classes (i.e. not known as an attack, but not recognize as safe either). In this article, we provide a framework to systematically reason about the combination of anomaly and misuse components. This framework applied to Web servers lead us to propose a serial architecture, using a drastic anomaly component with a sensitive misuse component. This architecture provides the operator with better qualification of the detection results, raises lower amount of false alarms and unqualified events. Elvis Tombini, Hervé Debar, Ludovic Mé, Mireille Ducassé |
ACSAC | 2 |
| 2004 | Honeypots: Practical Means to Validate Malicious Fault AssumptionsabstractWe report on an experiment run with several honeypots for 4 months. The motivation of this work resides in our wish to use data collected by honeypots to validate fault assumptions required when designing intrusion-tolerant systems. This work in progress establishes the foundations for a feasibility study into that direction. After a review of the state of the art with respect to honeypots, we present our test bed, discuss results obtained and lessons learned. Avenues for future work are also proposed. Marc Dacier, Fabien Pouget, Hervé Debar |
PRDC | 3 |
| 2004 | Monitoring IDS Background Noise Using EWMA Control Charts and Alert Information
Jouni Viinikka, Hervé Debar |
RAID | 2 |
| 2003 | Correlation of Intrusion Symptoms: An Application of Chronicles
Benjamin Morin, Hervé Debar |
RAID | 2 |
| 2002 | Evaluation of the Diagnostic Capabilities of Commercial Intrusion Detection Systems
Hervé Debar, Benjamin Morin |
RAID | 1 |
| 2002 | M2D2: A Formal Data Model for IDS Alert Correlation
Benjamin Morin, Ludovic Mé, Hervé Debar, Mireille Ducassé |
RAID | 3 |
| 2001 | Aggregation and Correlation of Intrusion-Detection Alerts
Hervé Debar, Andreas Wespi |
Recent Advances in Intrusion Detection | 1 |
| 2000 | A Lightweight Tool for Detecting Web Server Attacks
Magnus Almgren, Hervé Debar, Marc Dacier |
NDSS | 2 |
| 2000 | Intrusion Detection Using Variable-Length Audit Trail Patterns
Andreas Wespi, Marc Dacier, Hervé Debar |
Recent Advances in Intrusion Detection | 3 |
| 2000 | Fixed- vs. Variable-Length Patterns for Detecting Suspicious Process BehaviorabstractThis paper addresses the problem of creating patterns that can be used to model the normal behavior of a given process. The models can be used for intrusion-detection purposes. First, we present a novel method to generate input data sets that enable us to observe the normal behavior of a process in a secure environment. Second, we propose various techniques to derive either fixed-length or variable-length patterns from the input data sets. We show the advantages and drawbacks of each technique, based on the results of the experiments we have run on our testbed. Andreas Wespi, Hervé Debar, Marc Dacier, Mehdi Nassehi |
J. Comput. Secur. | 2 |
| 1999 | Building an Intrusion-Detection System to Detect Suspicious Process Behavior
Andreas Wespi, Hervé Debar |
Recent Advances in Intrusion Detection | 2 |
| 1999 | Authenticating public terminals
N. Asokan, Hervé Debar, Michael Steiner 0001, Michael Waidner |
Comput. Networks | 2 |
| 1999 | Towards a taxonomy of intrusion-detection systems
Hervé Debar, Marc Dacier, Andreas Wespi |
Comput. Networks | 1 |
| 1998 | Fixed vs. Variable-Length Patterns for Detecting Suspicious Process Behavior
Hervé Debar, Marc Dacier, Mehdi Nassehi, Andreas Wespi |
ESORICS | 1 |
| 1992 | A neural network component for an intrusion detection systemabstractAn approach toward user behavior modeling that takes advantage of the properties of neural algorithms is described, and results obtained on preliminary testing of the approach are presented. The basis of the approach is the IDES (Intruder Detection Expert System) which has two components, an expert system looking for evidence of attacks on known vulnerabilities of the system and a statistical model of the behavior of a user on the computer system under surveillance. This model learns the habits a user has when he works with the computer, and raises warnings when the current behavior is not consistent with the previously learned patterns. The authors suggest the time series approach to add broader scope to the model. They therefore feel the need for alternative techniques and introduce the use of a neural network component for modeling user's behavior as a component for the intrusion detection system.> Hervé Debar, Monique Becker, Didier Siboni |
S&P | 1 |