Fatiha Zaïdi

dblp:91/3486 · DBLP profile ↗
← Back
24ranked-venue papers
1as first author
3since 2021 · last 2024
0000-0003-3414-8815ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 15 · 1 since 2021Computer networks · 4Theory of computation · 3Artificial intelligence and machine learning · 2Security and privacy · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Theoretical computer science
2 papers
Automated reasoning and model checking · 100%
Computer architecture, parallel and distributed computing, and storage systems
1 paper
Parallel and multicore computing · 100%

Topics — the 5 heaviest of 5, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Automated reasoning and model checking › certification
certificates
0.212015
Certificates for Parameterized Model Checking · FM 2015
Automated reasoning and model checking › model checking › infinite-state model checking
parameterized model checking
0.212015
Certificates for Parameterized Model Checking · FM 2015
Parallel and multicore computing › parallel algorithms
parallel model checking
0.112012
Cubicle: A Parallel SMT-Based Model Checker for Parameterized Systems - Tool Paper · CAV 2012
Automated reasoning and model checking
parameterized verification
0.112012
Cubicle: A Parallel SMT-Based Model Checker for Parameterized Systems - Tool Paper · CAV 2012
Automated reasoning and model checking › model checking › symbolic model checking
SMT-based model checking
0.112012
Cubicle: A Parallel SMT-Based Model Checker for Parameterized Systems - Tool Paper · CAV 2012

Methods — techniques the papers use, named apart from their topics

parallel model checking · 0.3SMT · 0.3
YearPublicationVenuePosition
2024 Towards the adoption of automated cyber threat intelligence information sharing with integrated risk assessment
abstract
In the domain of cybersecurity, effective threat intelligence and information sharing are critical operations for ensuring appropriate and timely response against threats, but limited in automation, standardization, and ease of use in current platforms. This paper introduces a Cyber Threat Intelligence (CTI) Information Sharing platform, designed for critical infrastructures and cyber-physical systems. Our platform integrates existing cybersecurity tools and leverages digital twin technology, enhancing threat analysis and mitigation capabilities. It features an automated process for disseminating standardized and structured intelligence, utilizing the Malware Information Sharing Platform (MISP) for effective dissemination. A significant enhancement is the integration of risk assessment tools, which enriches the shared intelligence with detailed risk information, supporting an informed decision-making. The platform encompasses a user-friendly dashboard and a robust backend, streamlining the threat intelligence cycle and transforming raw data coming from diverse sources into actionable insights. Overall the CTI4BC platform presents a solution to overcome challenges in the CTI sharing, contributing to a more resilient cybersecurity domain.
Valeria Valdés Ríos, Fatiha Zaïdi, Ana R. Cavalli, Angel Rego
ARES2
2023 Testing techniques to assess impact and cascading effects
abstract
The rapid evolution of digital environments and their integration into critical operations of our society have led to substantial challenges in advancing cybersecurity to ensure the proper functioning of these systems . In the face of over-evolving cyber threats and attacks, systems must be equipped with robust mechanisms for protection. In this context, resilience techniques aim to mitigate such treats. However, the evaluation of these techniques is a crucial process, enabling informed decision-making and proactive threat mitigation. This article introduces a methodology based on regression testing for evaluating the impact and cascading effects of resilience strategies. It delves into the methodology’s adaptability across different scenarios and provides insights about the evaluation process.
Valeria Valdés Ríos, Ana R. Cavalli, Fatiha Zaïdi, Wissam Mallouli
CloudCom3
2022 A Formal Approach for Complex Attacks Generation based on Mutation of 5G Network Traffic
abstract
International audience
Zujany Salazar, Fatiha Zaïdi, Wissam Mallouli, Ana R. Cavalli, Huu Nghia Nguyen, Edgardo Montes de Oca
ICSOFT2
2020 A Coloured Petri Nets Based Attack Tolerance Framework
abstract
Web services provide a general basis of convenient access and operation for cloud applications. However, such services become very vulnerable when being attacked, especially in the situation where service continuity is one of the most important requirements. This issue highlights the necessity to apply reliable and formal methods to attack tolerance in Web services. In this paper, we propose a Coloured Petri Nets based method for attack tolerance by modelling and analysing basic behaviours of attack-network interaction, attack detectors and their tolerance solutions. Furthermore, complex attacks can be analysed and tolerance solutions deployed by identifying these basic attack-network interactions and composing their solutions. The validity of our method is demonstrated through a case study on attack tolerance in cloud-based medical information storage.
Wenbo Zhou 0003, Philippe Dague, Lei Liu 0040, Lina Ye, Fatiha Zaïdi
APSEC5
2020 Parameterized Model Checking on the TSO Weak Memory Model
Sylvain Conchon, David Declerck, Fatiha Zaïdi
J. Autom. Reason.3
2019 Attack Tolerance for Services-Based Applications in the Cloud
Georges Ouffoue, Fatiha Zaïdi, Ana R. Cavalli
ICTSS2
2017 Monitoring Dynamic Mobile Ad-Hoc Networks: A Fully Distributed Hybrid Architecture
abstract
The mobile ad-hoc networks (MANETs) represent a broad area of study and market interest. They provide a wide set of applications in multiple domains. In that context, the functional and non-functional monitoring of these networks is crucial. For that purpose, monitoring techniques have been deeply studied in wired networks using gossip-based or hierarchical-based approaches. However, when applied to a MANET, several problematics arise mainly due to the absence of a centralized administration, the inherent MANETs constraints and the nodes mobility. In this paper, we present a hybrid distributed monitoring architecture for mobile adhoc networks in context of mobility pattern. We get inspired of gossip-based and hierarchical-based algorithms for query dissemination and data aggregation. We define gossip-based mechanisms that help our virtual hierarchical topology to complete the data aggregation, and then ensure the stability and robustness of our approach in dynamic environments. Further, we propose a fully distributed monitoring protocol that ease the nodes communications. We evaluate our approach through a simulated testbed by using NS3 and Docker, and illustrate the efficiency of our mechanisms.
Stéphane Maag, Fatiha Zaïdi
AINA3
2017 Compiling Parameterized X86-TSO Concurrent Programs to Cubicle- W
Sylvain Conchon, David Declerck, Fatiha Zaïdi
ICFEM3
2017 How Web Services Can Be Tolerant to Intruders through Diversification
abstract
The efforts and findings of the last decades of research on the formalization and the verification of Web services have given a certain level of assurance on Web services. However new challenges such as high availability and security issues are not fully addressed. In fact, Web services are exposed to attacks that appear continuously. These issues have naturally paved the way to a new research topic that aims at providing new techniques for making Web services attack tolerant. In this paper, we present a state of the art of attack tolerance, especially for Web services. We also present our approach to address such issues through a combination of techniques leveraging in particular diversification. The paper ends with our promising results and a discussion to highlight the perspectives and research direction.
Georges Ouffoue, Fatiha Zaïdi, Ana R. Cavalli, Mounir Lallali
ICWS2
2016 MANETs monitoring with a distributed hybrid architecture
abstract
Monitoring techniques have been deeply studied in wired networks using gossip and hierarchical approaches. However, when applied to a MANET, several problematics arise. We present a hybrid distributed monitoring architecture for MANETs. We get inspired of gossip-based and hierarchical-based algorithms for query dissemination and data aggregation. We define gossip-based mechanisms that help our virtual hierarchical topology to complete the data aggregation, and then ensure the stability and robustness of our approach in dynamic environments. We propose a fully distributed monitoring protocol that ease the nodes communications. We evaluate our approach by using NS3 and Docker.
Stéphane Maag, Fatiha Zaïdi
NCA3
2016 Effectively Testing of Timed Composite Systems using Test Case Prioritization
abstract
A composite system consists of several components which can be developed separately and deployed in distributed environments.Executing test cases on such kind of systems requires more effort due to their size and their distributed environments.A critical issue is to prioritize efficient test cases to be firstly executed.We present in this paper a framework to generate test cases and to select the efficient ones to test the composite systems with taking into account time properties.Particularly, the framework generates a set of test cases based on a model of the system, which cover a given test objective.The test cases are then prioritized in an execution order to detect quickly faults, thus reducing the efforts of test execution and increasing the effectiveness of the testing process.The framework is complemented with an open-source toolchain for automating test case generation.It has been experimentally evaluated on the European Train Control System case study.The initial results show that the approach can save 40% of test execution effort.
Huu Nghia Nguyen, Fatiha Zaïdi, Ana R. Cavalli
SEKE2
2015 Certificates for Parameterized Model Checking
Sylvain Conchon, Alain Mebsout, Fatiha Zaïdi
FM3
2015 Guiding Testers' Hands in Monitoring Tools: Application of Testing Approaches on SIP
Xiaoping Che, Stéphane Maag, Huu Nghia Nguyen, Fatiha Zaïdi
ICTSS4
2014 A Framework for Distributed Testing of Timed Composite Systems
abstract
Software systems are more and more complex. They are usually constructed by combining several components which can be implemented separately and deployed in distributed environments. This paper presents a framework for testing these kind of systems. Particularly, each component of a system is tested by a tester and there is no communication between testers. The tester is guided by local test cases that are generated from the composition of models of components where the communication among components may be synchronous or asynchronous. The framework is complemented with a tool chain for automating test generation. The paper presents also a case study on the European Train Control System.
Huu Nghia Nguyen, Fatiha Zaïdi, Ana R. Cavalli
APSEC (1)2
2013 Invariants for finite instances and beyond
Sylvain Conchon, Amit Goel, Sava Krstic, Alain Mebsout, Fatiha Zaïdi
FMCAD5
2013 Automatic skeleton generation for data-aware service choreographies
abstract
Service-oriented engineering is an emerging software development paradigm for distributed collaborative applications. Services are developed independently and are composed to achieve common requirements. Service choreographies define such requirements from a global perspective, based on interactions among a set of participants that are implemented as services. In this paper, we support a reliable data-aware service choreography development process through a dedicated projection. It extracts, from a choreography, a behavioral skeleton for each of its participants. The projection is valuable in a top-down approach, where developers have only to complete the skeletons with some business code in order to get a distributed application that matches the choreography requirements. The projection is also valuable in a bottom-up approach, where the skeletons can act as controllers between reused services in order to enforce the respect of the choreography. Our approach is supported with a tool that can be downloaded or used online.
Huu Nghia Nguyen, Pascal Poizat, Fatiha Zaïdi
ISSRE3
2012 Cubicle: A Parallel SMT-Based Model Checker for Parameterized Systems - Tool Paper
Sylvain Conchon, Amit Goel, Sava Krstic, Alain Mebsout, Fatiha Zaïdi
CAV5
2012 A Symbolic Framework for the Conformance Checking of Value-Passing Choreographies
Huu Nghia Nguyen, Pascal Poizat, Fatiha Zaïdi
ICSOC3
2010 A component based testing technique for a MANET routing protocol
abstract
This paper deals with the crucial challenging issue of testing the conformance of the MANET routing protocols. Indeed, because of the inherent constraints of such networks such as a dynamic topology, to formally test these protocols becomes a tough problem. Most of the studies taking into account a formal model of the protocol is faced to the combinatorial state space explosion issue when deploying and analyzing that model. In our work we present how to cope with that problem by drawing inspiration of the model-checker research domain and an integration of a component-based testing algorithm dedicated to the automatic generation of OLSR test sequences from a formal model written in Promela.
Fatiha Zaïdi, Mounir Lallali, Stéphane Maag
AICCSA1
2010 WebMov: A Dedicated Framework for the Modelling and Testing of Web Services Composition
abstract
This paper presents a methodology and a set of tools for the modelling, validation and testing of Web service composition, conceived and developed within the French national project WebMov. This methodology includes several modelling techniques, based mainly on some variations of Timed Extended Finite State Machines (TEFSM) formalism, which provide a formal model of the BPEL description of Web services composition. These models are used as a reference for the application of different test generation and passive testing techniques for conformance and robustness checking. The whole WebMov methodology is integrated within a dedicated framework, composed by a set of tools that implement the model representation, the test generation and passive testing algorithms. This framework also permits the interaction of these tools to achieve specific modelling and testing activities in a complementary way. A case study based on a real service, a Travel Reservation Web Service, is presented as well as the results of the application of the proposed WebMov methodology and tools.
Ana R. Cavalli, Tien-Dung Cao, Wissam Mallouli, Eliane Martins, Andrey Sadovykh, Sébastien Salva, Fatiha Zaïdi
ICWS7
2010 Supple: a flexible probabilistic data dissemination protocol for wireless sensor networks
abstract
We propose a flexible proactive data dissemination approach for data gathering in self-organized Wireless Sensor Networks (WSN). Our protocol Supple, effectively distributes and stores monitored data in WSNs such that it can be later sent to or retrieved by a sink. Supple empowers sensors with the ability to make on the fly forwarding and data storing decisions and relies on flexible and self-organizing selection criteria, which can follow any predefined distribution law. Using formal analysis and simulation, we show that Supple is effective in selecting storing nodes that respect the predefined distribution criterion with low overhead and limited network knowledge.
Aline Carneiro Viana, Thomas Hérault, Thomas Largillier, Sylvain Peyronnet, Fatiha Zaïdi
MSWiM5
2005 A passive testing approach based on invariants: application to the WAP
Emmanuel Bayse, Ana R. Cavalli, Manuel Núñez 0001, Fatiha Zaïdi
Comput. Networks4
2001 A Service-Component Testing Method and a Suitable CORBA Architecture
abstract
This paper presents a method for service-component testing and a suitable CORBA test architecture. This test environment allows the service validation from its components and is a close step towards the execution of the obtained tests on a CORBA environment. Two aspects are relevant: the test of components and the test architecture. The testing method for components is new: it is based on the generation of partial graphs and avoids the combinatorial explosion of number of states of the global system. The test architecture on a CORBA platform is also new, since there are few works on testing based on these environments. As an application we present a case study on a real conference call service.
Ana R. Cavalli, Bruno Defude, Christian Rinderknecht, Fatiha Zaïdi
ISCC4
1999 Hit-or-Jump: An algorithm for embedded testing with applications to IN services
Ana R. Cavalli, David Lee 0001, Christian Rinderknecht, Fatiha Zaïdi
FORTE4