EDBT 2026 Demo / reviewers in the wild / expert
Vincent Toubiana
dblp:94/1586
· DBLP profile ↗
10ranked-venue papers
9as first author
2since 2021 · last 2024
0009-0004-9968-1447ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 4 · 3 first-author · 2 since 2021Computer networks · 2 · 2 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | The Effect of Design Patterns on (Present and Future) Cookie Consent Decisions
Nataliia Bielova, Laura Litvine, Anysia Nguyen, Mariam Chammat, Vincent Toubiana, Estelle Hary |
USENIX Security Symposium | 5 |
| 2021 | No need to ask the Android: bluetooth-low-energy scanning without the location permissionabstractBluetooth-Low-Energy (BLE) scanning can be misused by applications to determine a device location. In order to prevent unconsented location tracking by applications, Android conditions the use of some BLE functions to the prior obtention of the location permission and the activation of the location setting. In this paper, we detail a vulnerability that allows applications to perform BLE scans without the location permission. We present another flaw allowing to bypass the active location requirement. Together those flaws allow an application to fully circumvent the location restrictions applying to BLE scanning. The presented vulnerability affects devices running Android 6 up to 11 and could be misused by application developers to track the location of users. This vulnerability has been disclosed to Google and assigned the CVE-2021-0328. Vincent Toubiana, Mathieu Cunche |
WISEC | 1 |
| 2012 | Cookie-based privacy issues on google servicesabstractWith the success of Web applications, most of our data is now stored on various third-party servers where they are processed to deliver personalized services. Naturally, we must be authenticated to access this personal information, but the use of personalized services only restricted by identification could indirectly and silently leak sensitive data. We analyzed Google Web Search access mechanisms and found that the current policy applied to session cookies could be used to retrieve users' personal data. We describe two attack schemes based on the Google's "SID cookie". First, we show that it permits a session fixation attack in which the victim's searches are recorded in the attacker's Google Web Search History. The second attack leverages the search personalization (based on the same SID cookie) to retrieve a part of the victim's click history and even some of her contacts. We implemented a proof of concept of the latter attack on the Firefox Web browser and conducted an experiment with ten volunteers. Thanks to this prototype we were able to recover up to 80% of the user's search click history. Vincent Toubiana, Vincent Verdot, Benoit Christophe |
CODASPY | 1 |
| 2010 | R2M: A Reputation Model for MashupsabstractThe Web 2.0 has changed the Internet landscape, users are no longer only consumers but now also producers of content. The increasing number of personal data published on Web Service Providers fathered a new kind of applications: the mashups. These third-party applications access users' information through service providers' APIs via secure authorization protocols such as OAuth. But these protocols rely on the users who must blindly grant access to each mashup, with no idea beforehand about its trustworthiness. We propose a Reputation Model for Mashups to address this issue. The R2M solution monitors mashups' calls on the Web Service Providers' APIs, detects suspicious activities, and finally reports to the user to collect his feedback in order to collaboratively build the mashup's reputation. We describe an implementation of R2M on the Bell Labs' service Dundal.com to prove its feasibility in a real use case. From this experimentation, we plan to collect user experience to improve the R2M key mechanisms and refine the reputation computation. Vincent Toubiana, Vincent Verdot, Gérard Burnside, Eric Joubert |
CCNC | 1 |
| 2010 | Adnostic: Privacy Preserving Targeted Advertising
Vincent Toubiana, Arvind Narayanan, Dan Boneh, Helen Nissenbaum, Solon Barocas |
NDSS | 1 |
| 2010 | A global security architecture for operated hybrid WLAN mesh networks
Vincent Toubiana, Houda Labiod, Laurent Reynaud, Yvon Gourhant |
Comput. Networks | 1 |
| 2008 | An analysis of ASMA performances against packet dropping attacks in dense networksabstractIn mobile ad hoc networks (MANETs), multihop transmissions rely on nodes collaboration to correctly route and forward packets to their final destination. However, collaboration of intermediate nodes is not guaranteed and non-collaborative nodes may drop packets they are asked to forward. Such behaviour, known as packet dropping, results of nodespsila selfishness or maliciousness and has dramatic effects on networks performances. Most of proposed solutions to counter packet dropping are either based on trust management or multipath routing, but no solution combines both trust management and multipath routing. Adaptive Secured Multipath for Ad hoc networks (ASMA) is a security framework which adapts security to the application requirements; evaluates trustworthy relationship based on localized trust model and efficiently combines multipath routing into trust management. In this paper we study ASMA performance against the most classical and simple packet dropping attack: Black Hole attack. Aiming to evaluate ASMA in dense networks, we use a realistic scenario representing a subway environment which brings interesting features and may be a prolific context for MANET application development. Through simulations we compare the performances of DSR and ASMA associated to DSR in attacked pure MANETs. Simulation results illustrate that ASMA-DSR outperforms DSR under different attack configurations and is totally adapted for dense and large networks. Vincent Toubiana, Houda Labiod, Laurent Reynaud, Yvon Gourhant |
ISCC | 1 |
| 2008 | Towards a flexible security management solution for dynamic MANETsabstractSince MANETs are mainly composed of lightweight devices with limited capabilities, efficiently manage security is crucial to reduce the performance degradation and resources consumption. Actually, managing MANETspsila security is a hard challenge due to the inherent complexity and the tremendous number of parameters which should be considered. To provide efficient security management, we focus on three main parameters: the secured device capabilities, the associated network security and the secured applications. The solution we propose, named Adaptive Secured Multipath for Ad hoc networks (ASMA) is a scalable, flexible and application-oriented framework able to manage security depending on the application requirements and the network security conditions. ASMA is based on a structure called macrograph combining both dynamic trust management and multipath routing. The macrograph structure is capable to estimate transmission security in order to assure that communications are established only when they match applications security requirements. ASMA flexibility offers compliance with most on-demand routing protocols and security tools. In this paper we present simulation results for ASMA associated with AOMDV (a multipath declination of AODV) routing protocol and compare results with AOMDV. We show that ASMA-AOMDV outperforms AOMDV, dividing by three the packet loss rate in networks including 20% of malicious nodes, while causing only 3% of additional loss in safe networks. Vincent Toubiana, Houda Labiod |
NOMS | 1 |
| 2008 | Performance comparison of multipath reactive Ad hoc routing protocolsabstractThe recent proliferation of wireless devices extends the scope of mobile ad hoc networks (MANETs) applications beyond the military domain to include civil and commercial application scenarios. Since MANETs are composed of mobile terminals with limited resources, guaranteeing their security remains an unsolved and motivating challenge. Due to advantageous features like infrastructureless and spontaneous deployment, MANETs offer an opportunity to set up temporary, dynamic and local networks for low cost. However, some of their characteristics like unreliability of wireless links, dynamic topology, and absence of underlying infrastructure raise serious problems which become critical when security is also considered. Multipath routing scheme enhances the robustness of routing protocols and offers a mean to mitigate networks mobility impact and node misbehaviors. In this paper we compare the performances of five multipath routing protocols: three node-disjoint multipath routing protocols and two routing protocols based on a Untrusted Node Disjoint (UND) path scheme. Comparisons between these protocols highlight the improvements raised by the UND scheme under different attack configurations. Vincent Toubiana, Houda Labiod, Laurent Reynaud, Yvon Gourhant |
PIMRC | 1 |
| 2007 | Event Based Mobility Model for Subway Scenarios
Vincent Toubiana, Houda Labiod, Bennet Fischer |
WiMob | 1 |