EDBT 2026 Demo / reviewers in the wild / expert
Stéphane Mocanu
dblp:89/1174
· DBLP profile ↗
14ranked-venue papers
0as first author
13since 2021 · last 2025
0000-0002-3074-2430ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 6 · 6 since 2021Systems, architecture and hardware · 4 · 3 since 2021Software engineering, systems software and programming languages · 3 · 3 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Host-Based Intrusion Detection for Industrial Control SystemsabstractIndustrial Control Systems (ICS) are increasingly vulnerable to cyberattacks, particularly those that circumvent standard Network-Based Intrusion Detection Systems (NIDS) and manipulate control logic. The present investigation looks at a unique technique for improving ICS security: effectively incorporating lightweight Host-Based Intrusion Detection Systems (HIDS) into Programmable Logic Controllers (PLCs). This technique provides a more comprehensive and rapid degree of security through monitoring device activity in real time. The methodology uses formal specification methods to generate attributes from industrial control logic and regulations that can be verified at runtime. A simplified runtime monitor is built into the PLC's scanning cycle to ensure it meets real-time operating requirements. The approach is tested on the G-ICS testbed, establishing groundwork for hybrid detection methods that integrate host and network-level alerts for enhanced anomaly detection and system resilience. Omayma Alla, Stéphane Mocanu |
NetSoft | 2 |
| 2025 | Safety-security convergence: Automation of IEC 62443-3-2abstractIndustrial Control Systems (ICS) are designed to provide a service, such as power generation or water treatment, while protecting people, assets, and the environment against hazard. However, ICS now integrate Information Technology (IT) and are interconnected with the outside world such as the Internet, thereby exposing their infrastructures to cyberattacks. Cyberattacks have thus become new threats for industrial system operations and, more specifically, for their safety. To address the issue, this paper presents a comprehensive cybersecurity risk assessment for the safety of ICS. We apply our method to automate industrial cybersecurity risk assessment as specified in the recent (2020) IEC 62443-3-2 standard, which is widely used in the industrial cybersecurity domain. By automating parts of these risk assessment processes, we can reduce the error-prone manual efforts and increase the consistency of risk assessment. More specifically, the proposed risk assessment comprises three parts which, respectively: (1) identify the specific vulnerabilities of industrial control systems, (2) determine the attack scenarios that compromise the safety of the system and (3) assess whether the attack scenarios are tolerable by the organization’s policy. In the first part, we automated the entire threat modeling process of Microsoft Threat Modeling Tool by developing an automatable method for building the system model, in the form of a data flow diagram, from a standard XML file called PLCOpen. This automation of the Microsoft Threat Modeling Tool process enables us to automate vulnerability identification for industrial control systems. In the second part, we enhance a previous work that generates theoretical safety-compromising attack scenarios by building a complete attack scenario from system vulnerabilities to safety compromise. Finally, in the third part, we rank the attack scenarios using a specific risk matrix in order to determine which scenarios exceed the risk tolerable by the organization and therefore require additional controls. Mike Da Silva, Stéphane Mocanu, Maxime Puys, Pierre-Henri Thevenon |
Comput. Secur. | 2 |
| 2024 | An IEC 62443-security oriented domain specific modelling languageabstractAs the historically isolated industrial control systems become increasingly connected, the threat posed by cyberattacks soars. To remedy this issue, industrial standards dedicated to the cybersecurity of ICS have been developed in the last twenty years, namely the IEC 62443 series. These standards provide guidelines to the creation and maintenance of a secure ICS, from the concept phase to its eventual disposal. This standard notably assume a specific Zone/Conduit model for systems, as a basis for building the security program. This model currently lacks computer-aided design tools, which are essential to the adoption of a standard. In this paper, we will present a domain specific modeling language, able to describe IEC 62443 compliant systems. Our main contributions are the DSL’s syntax, which tries to formalize the informal model found in the standard, and the validation rules applied to it that ensure the described installations are secure by design, according to a set of hypotheses. Jolahn Vaudey, Stéphane Mocanu, Gwenaël Delaval, Éric Rutten |
ARES | 2 |
| 2024 | Behavior-Based Intrusion Detection Approach Deployed on a Naval TestbedabstractThis paper presents an application of an intrusion detection approach onto a naval physical testbed. The deployed approach is tailored for complex Industrial Control Systems (ICSs). Such systems play a critical role in managing complex industrial processes and ensuring their security against cyber threats is a major concern. Our work concerns Process-Aware Attacks (PAAs) which are sophisticated attacks aiming at disrupting ICS physical processes. The methodology instantiates a specification-based and process-aware Network Intrusion Detection System (NIDS). The specifications are systematically extracted from international and industry standards. In order to be monitored, such specifications are translated into security requirements which are verified during the execution of the system. Our IDS relies on network traffic capture on fieldbuses as well as Ethernet networks. In addition to our previous work, deploying our approach on a realistic naval testbed allows us to demonstrate its extensibility to different environments. Furthermore, the evaluation of our approach shows both its good detection capabilities and scalability. Estelle Hotellier, Nahi Boukhobza, Franck Sicard, Julien Francq, Stéphane Mocanu |
ETFA | 5 |
| 2024 | Explainable AI for Process-Aware Attack Detection in Industrial Control SystemsabstractIndustrial Control System cybersecurity has become an important study area after the occurrence of several mediatic events in the 2010’s (Stuxnet, BlackEnergy, Industroyer). Two common characteristics of these attacks are the fact that they were not violating the communication protocols being "stealth" for classical pattern-based detection methods and that they explicitly target the physical process. In this paper we study the performance and explainability of an artificial intelligence based detection system for the detection of such sophisticated attacks. Léa Astrid Kenmogne, Stéphane Mocanu |
NetSoft | 2 |
| 2024 | Self-reconfiguration of industrial control systems as a response to cyberattacksabstractAs industrial control systems become increasingly connected, the threat of cyberattacks grows in turn. Classical IT reactions that prioritize confidentiality, like network isolation, cannot be applied as they lead to a loss of availability, hence an issue of safety criticality. This work proposes a reconfiguration-based reaction to attacks, migrating control programs away from compromised components. This reconfiguration is carried out by a controller which solves a constraint programming (CP) problem whenever a compromised device is detected. This controller is automatically generated based on a model of IEC 62443 compliant systems. This approach is tested both on generated models of arbitrary size and to control a set of real Programmable Logic Controller (PLC) overseeing a small-scale training factory. Jolahn Vaudey, Stéphane Mocanu, Gwenaël Delaval, Éric Rutten |
NetSoft | 2 |
| 2024 | Standard specification-based intrusion detection for hierarchical industrial control systems
Estelle Hotellier, Franck Sicard, Julien Francq, Stéphane Mocanu |
Inf. Sci. | 4 |
| 2024 | A model-based approach for self-adaptive security in CPS: Application to smart grids
Salim Chehida, Éric Rutten, Guillaume Giraud, Stéphane Mocanu |
J. Syst. Archit. | 4 |
| 2023 | PLC Logic-Based Cybersecurity Risks Identification for ICSabstractIn recent years, Informational Technologies (IT) was massively deployed into Industrial Control Systems (ICS) mainly for its economic benefits. However, this new paradigm, converging IT and Operational Technologies (OT), brings new challenges that companies need to face. Historically, ICS had to cope with safety requirements which ensure the protection of people, environment, and assets. Now, ICS must deal with additional threats, coming from cyberattacks, in order to maintain safety. For that purpose, it becomes essential to develop new cybersecurity technologies and methodologies that allow to assess the safety of ICS against cyberattacks. Mike Da Silva, Maxime Puys, Pierre-Henri Thevenon, Stéphane Mocanu |
ARES | 4 |
| 2023 | Automated ICS template for STRIDE Microsoft Threat Modeling ToolabstractIndustrial Control Systems (ICS) are specific systems that combine information technology (IT) and operational technology (OT). Due to their interconnection and remote accessibility, they become a target for cyberattacks. As a result of their complexity and heterogeneity in terms of devices and communication protocols, specific security controls and risk analysis methods need to be developed. In particular, in order to reduce the effort of deployment of risk analysis on such complex systems, automated methods need to be provided. This paper deals with automation of the risk identification process for ICS using the STRIDE threat modeling framework. We extend the well-known STRIDE modeling tool, namely Microsoft Threat Modeling Tool (MTMT), with an incremental template dedicated to ICS and provide additional tools to automate the analysis using specific vulnerability extraction from Internet CVE databases. Mike Da Silva, Maxime Puys, Pierre-Henri Thevenon, Stéphane Mocanu, Nelson Nkawa |
ARES | 4 |
| 2023 | Model-based Self-adaptive Management in a Smart Grid SubstationabstractThe design of Cyber Physical Systems (CPS) is becoming increasingly complex due to the dynamic changes in their environments and infrastructures, requiring them to be self-adaptive. An important class of CPS is Industrial Control Systems (ICS), where a major trend is to upgrade from historically specific hardware and technologies towards more software-defined, virtual approaches involving the Could-Fog-Edge continuum. In this work, we propose a model-based approach for the design of the self-adaptation in ICS, inspired by, and applied to an industrial case study in Smart Grids, more particularly an electrical substation from RTE (the French Energy Transmission company). The problem is to allocate and reallocate dynamically a set of control functions upon a distributed computing infrastructure, with self-adaptation to variations and perturbations. We define and implement the model-based autonomic management feedback loop using constraint programming, to describe the space of possible configurations, as well as the constraints and objectives formalizing the operators strategies. This model is used in simulation, calling the constraints solver at each cycle of the loop. Salim Chehida, Karim Fellah, Éric Rutten, Guillaume Giraud, Stéphane Mocanu |
ETFA | 5 |
| 2022 | Cross-domain alert correlation methodology for industrial control systems
Oualid Koucham, Stéphane Mocanu, Guillaume Hiet, Jean-Marc Thiriet, Frédéric Majorczyk |
Comput. Secur. | 2 |
| 2021 | Hardware-In-The-Loop Labs for SCADA Cybersecurity Awareness and TrainingabstractIn this paper, we present a SCADA cybersecurity awareness and training program based on a Hands-On training using two twin cyber-ranges named WonderICS and G-ICS. These labs are built using a Hardware-In-the-Loop simulation system of the physical process developed by the two partners. The cyber-ranges allow replication of realistic Advanced Persistent Threat (APT) attacks and demonstration of known vulnerabilities, as they rely on real industrial control devices and softwares. In this work, we present both the demonstration scenarios used for awareness on WonderICS and the training programs developed for graduate students on G-ICS. Maxime Puys, Pierre-Henri Thevenon, Stéphane Mocanu |
ARES | 3 |
| 2016 | A Test bed dedicated to the Study of Vulnerabilities in IEC 61850 Power Utility Automation NetworksabstractIndustrial control systems rely more and more on digital technologies. Although the cyber risk such technologies induce is widely judged as serious, especially for critical infrastructures, these systems have generally not been designed to serve cybersecurity purposes. Instead they were thought first for serving operational efficiency. It thus becomes critical to study cyber threats in industrial environments and experimental test beds are needed to evaluate risks, physical consequences of cyber incidents, and performance of countermeasures. The test bed we present here focuses on studying cyber risks and their mitigation in IEC 61850 power utility automation systems. The operational part is composed of engineering computers, supervision software, off-the-shelf intelligent relays (Intelligent Electronic Device - IED), a hardware-in-the-loop process simulation, and the cybersecurity tools include an attack generation station and a network analyzer. In this paper, we present the operational part, giving details on the power grid hardware-in-the-loop simulation and its importance in the understanding of cyber consequences on the global system. The article concludes giving preliminary experimental results showing consequences of a false data injection attack on a simple electrical architecture. Maelle Kabir-Querrec, Stéphane Mocanu, Jean-Marc Thiriet, Eric Savary |
ETFA | 2 |