EDBT 2026 Demo / reviewers in the wild / expert
Ayda Saïdane
dblp:91/6694
· DBLP profile ↗
8ranked-venue papers
2as first author
0since 2021 · last 2011
—ORCID · none
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 5 · 2 first-authorArtificial intelligence and machine learning · 1Systems, architecture and hardware · 1Computer networks · 1Software engineering, systems software and programming languages · 1Applied, interdisciplinary, general and emerging computing · 1
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Network and information security
1 paper |
Systems and software security · 100% | |
| Computer networks
1 paper |
Internet architecture and protocols · 100% | |
| Computer architecture, parallel and distributed computing, and storage systems
1 paper |
Distributed systems · 100% |
Topics — the 2 heaviest of 3, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Systems and software security
intrusion tolerance |
0.1 | 1 | 2009 | The Design of a Generic Intrusion-Tolerant Architecture for Web Servers · IEEE Trans. Dependable Secur. Comput. 2009 |
Distributed systems
fault tolerance |
0.0 | 1 | 2009 | The Design of a Generic Intrusion-Tolerant Architecture for Web Servers · IEEE Trans. Dependable Secur. Comput. 2009 |
Methods — techniques the papers use, named apart from their topics
proxy mediation · 0.3diversity · 0.3
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2011 | Towards improving security testability of AADL architecture modelsabstractToday computer systems are becoming very complex and often depending on some off-the-shelf components or external service providers. Validating the security aspects of these systems is a highly challenging goal, especially when we target security critical systems where guarantees must be provided on the robustness of the produced systems. Model Driven Engineering (MDE) is becoming popular and well accepted in both academia and critical systems industry. In our work, we aim to propose a novel MDE compliant security validation methodology based on architecture model based testing. In this paper, we focus on security modeling for improving the testability of the architecture models and facilitating the evaluation of the proposed test generation and selection methods. More specifically, we are interested in extending the SAE standard AADL [1] to improve the quality of the security test cases generated from AADL models. Ayda Saïdane, Nicolas Guelfi |
NSS | 1 |
| 2009 | A Pattern-Based General Security Framework: An eBusiness Case StudyabstractSecurity and domain specific regulations are critical for any organization. Unfortunately, achieving these prerequisites in a socio-technical environment is a difficult task. For example, let us consider the aspect of computer security: neither software developers nor regulatory authorities are security experts. Therefore, it is important that security experts' knowledge is captured and made available to software developers. Security patterns are a suitable prescription to capture experts' solutions to commonly recurring security problems. In this paper, we present the application of a general framework, based on security patterns, used to develop secure applications. It covers the entire process of solution development: defining organizational security requirements using SECURE TROPOS, formalizing the pattern using SI*, implementing the pattern, integrating it into the final application, and monitoring the runtime. All these phases are discussed and illustrated with an eBusiness case study: the loan origination process. Azzedine Benameur, Serge Fenet, Ayda Saïdane, Smriti Kumar Sinha |
HPCC | 3 |
| 2009 | How to capture and use legal patterns in ITabstractIn our own previous work [1], we looked at the problem of designing IT solutions ( Security Patterns) accounting for legal and organizational issues. The proposed pattern de- sign and validation process require legal experts to describe patterns in natural language. Such a description is parsed by a natural language processor on the basis of a semantic template [2]. The annotated description is then used to automatically generate graphical models of SI* patterns, which are revised by security engineers using a CASE Tool 1. The intriguing question that we address in this paper is the opposite of the mainstream one: Challenge 1. You have a technical solution (e.g. a se- curity and dependability pattern). Can some of your system requirements be implemented by legal means? This challenge might seem at odd with intuition but only because we don't bring the usage of patterns to their logi- cal end: if an answer to a legal, organizational or technical security requirement can be an organizati... Alzbeta Krausová, Fabio Massacci, Ayda Saïdane |
ICAIL | 3 |
| 2009 | A self-protecting and self-healing framework for negotiating services and trust in autonomic communication systems
Nicola Dragoni, Fabio Massacci, Ayda Saïdane |
Comput. Networks | 3 |
| 2009 | The Design of a Generic Intrusion-Tolerant Architecture for Web ServersabstractNowadays, more and more information systems are connected to the Internet and offer Web interfaces to the general public or to a restricted set of users. Such openness makes them likely targets for intruders, and conventional protection techniques have been shown insufficient to prevent all intrusions in such open systems. This paper proposes a generic architecture to implement intrusion-tolerant Web servers. This architecture is based on redundancy and diversification principles in order to increase the system resilience to attacks: usually, an attack targets a particular software, running on a particular platform, and fails on others. The architecture is composed of redundant proxies that mediate client requests to a redundant bank of diversified application servers. The redundancy is deployed here to increase system availability and integrity. To improve performance, adaptive redundancy is applied: the redundancy level is selected according to the current alert level. The architecture can be used for static servers, that is, for Web distribution of stable information (updated offline) and for fully dynamic systems where information updates are executed immediately on an online database. The feasibility of this architecture has been demonstrated by implementing an example of a travel agency Web server, and the first performance tests are satisfactory, both for request execution times and recovery after incidents. Ayda Saïdane, Vincent Nicomette, Yves Deswarte |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2008 | Anomaly Detection with Diagnosis in Diversified Systems using Information Flow Graphs
Frédéric Majorczyk, Eric Totel, Ludovic Mé, Ayda Saïdane |
SEC | 4 |
| 2006 | A Dependable Intrusion Detection Architecture Based on Agreement Services
Michel Hurfin, Jean-Pierre Le Narzul, Frédéric Majorczyk, Ludovic Mé, Ayda Saïdane, Eric Totel, Frédéric Tronel |
SSS | 5 |
| 2002 | Event Log based Dependability Analysis of Windows NT and 2K SystemsabstractThis paper presents a measurement-based dependability study using event logs collected during about 3 years from 133 Windows NT and 2K workstations and servers interconnected through a LAN. We focus on the identification of machine reboots, the classification of of their causes, and the evaluation of statistics characterizing the uptimes, downtimes, and the availability of the Windows NT and 2K machines. Cristina Simache, Mohamed Kaâniche, Ayda Saïdane |
PRDC | 3 |