EDBT 2026 Demo / reviewers in the wild / expert
Jean-Louis Lanet
dblp:l/JeanLouisLanet
· DBLP profile ↗
46ranked-venue papers
4as first author
2since 2021 · last 2021
0000-0002-4751-3941ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 39 · 4 first-author · 2 since 2021Software engineering, systems software and programming languages · 4Artificial intelligence and machine learning · 2Theory of computation · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2021 | Under the Dome: Preventing Hardware Timing Information Leakage
Mathieu Escouteloup, Ronan Lashermes, Jacques J. A. Fournier, Jean-Louis Lanet |
CARDIS | 4 |
| 2021 | A behavioural in-depth analysis of ransomware infectionabstractAbstract Ransomware is a type of malware that has spread rapidly over the last 4 years, causing significant damage, especially in Windows environments. It is designed to encrypt or block victim's data, including documents, backups, and databases, unless a ransom is paid. In this study, the authors present the results of their research on Windows crypto‐ransomware during the last 3 years by exploring and discussing the relevant ransomware behaviours. The results of this study can be used to identify or to detect the ransomware. Indeed, these behaviours were extracted from in‐depth manual analysis of more than 20 ransomware families, including the known and the recent families. In addition, some extracted behaviours were automatically searched for more than 200 different ransomware collected during 2019. Yassine Lemmou, Jean-Louis Lanet, El Mamoun Souidi |
IET Inf. Secur. | 2 |
| 2020 | Confiance: detecting vulnerabilities in Java Card appletsabstractThis study focuses on automatically detecting wrong implementations of specifications in Java Card programs, without any knowledge on the source code or the specification itself. To achieve this, an approach based on Natural Language Processing and machine-learning is proposed. First, an oracle gathering methods with similar semantics in groups, is created. This focuses on evaluating our approach performances during the neighborhood discovery. Based on the groups of similar methods automatically retrieved, the anomaly detection relies on the Control Flow Graph of programs of these groups. In order to benchmark our approach's ability to detect vulnerabilities, an oracle of anomaly is created. This oracle knows every anomaly the approach should automatically retrieve. Both the neighborhood discovery and the anomaly detection steps are benchmarked. This approach is implemented in a tool: Confiance, and it is compared to another machine-learning tool for automatic vulnerability detection. The results expose the better performances of Confiance to detect vulnerabilities in open-source programs available online. Léopold Ouairy, Hélène Le Bouder, Jean-Louis Lanet |
ARES | 3 |
| 2020 | A systematic approach toward security in Fog computing: Assets, vulnerabilities, possible countermeasuresabstractSummary Fog computing is an emerging paradigm in the Internet of Things (IoT) space, consisting of a middle computation layer, sitting between IoT devices and Cloud servers. Fog computing provides additional computing, storage, and networking resources in close proximity to where data is being generated and/or consumed. As the Fog layer has direct access to data streams generated by IoT devices and responses/commands sent from the Cloud, it is in a critical position in terms of security of the entire IoT system. Currently, there is no specific tool or methodology for analysing the security of Fog computing systems in a comprehensive way. Generic security evaluation procedures applicable to most information technology products are time consuming, costly, and badly suited to the Fog context. In this article, we introduce a methodology for evaluating the security of Fog computing systems in a systematic way. We also apply our methodology to a generic Fog computing system, showcasing how it can be purposefully used by security analysts and system designers. Mozhdeh Farhadi, Jean-Louis Lanet, Guillaume Pierre, Daniele Miorandi |
Softw. Pract. Exp. | 2 |
| 2019 | Watch Out! Doxware on the Way
Routa Moussaileb, Charles Berti, Guillaume Deboisdeffre, Nora Cuppens, Jean-Louis Lanet |
CRiSIS | 5 |
| 2019 | SEER4US, Secured Energy Efficient Routing for UAV SwarmsabstractThis article introduces SEER4US a secured routing protocol designed for UAV swarm networks. SEER4US is the first protocol providing integrity of routing messages and authentication of their sender with low energy consumption for battery preservation. SEER4US prevents the UAV swarms from usual routing attacks enabled when routing messages are modified or replayed by nodes external to the swarm. SEER4US is an extension of the pro-active routing protocol OLSR designed for mobile ad-hoc networks. SEER4US is also inspired from TESLA, a protocol designed for stream signature allowing authentication of stream messages sender. After specifying SEER4US, we evaluate here the energy requirements of this protocol and we show that the use of lightweight cryptography allows a significant energy saving compared to traditional cryptographic schemes. Benoît Fournier, Gilles Guette, Valérie Viet Triem Tong, Jean-Louis Lanet |
WiMob | 4 |
| 2018 | Let's shock our IoT's heart: ARMv7-M under (fault) attacksabstractA fault attack is a well-known technique where the behaviour of a chip is voluntarily disturbed by hardware means in order to undermine the security of the information handled by the target. In this paper, we explore how Electromagnetic fault injection (EMFI) can be used to create vulnerabilities in sound software, targeting a Cortex-M3 microcontroller. Several use-cases are shown experimentally: control flow hijacking, buffer overflow (even with the presence of a canary), covert backdoor insertion and Return Oriented Programming can be achieved even if programs are not vulnerable in a software point of view. These results suggest that the protection of any software against vulnerabilities must take hardware into account as well. Sébanjila Kevin Bukasa, Ronan Lashermes, Jean-Louis Lanet, Axel Legay |
ARES | 3 |
| 2018 | Ransomware's Early Mitigation MechanismsabstractRansomware remains a modern trend. Attackers are still using cryptovirology forcing victims to pay. Notable attacks have been spreading since 2012, starting with Reveton's ransomware attack to the more recent 2017 WannaCry, Petya and Bad Rabbit cyberattacks. This Ransomware as a Service (RaaS) can lure criminals into developing tools to perform an attack without previous knowledge of the cryptosystem itself. We present in this paper a graph-based ransomware countermeasure to detect malicious threads. It is a new mechanism that doesn't rely on previously used metrics in the literature to detect ransomware such as Shannon's entropy or system calls. An accurate detection is achieved by our solution. The per-thread file system traversal is sufficient to highlight the malicious behaviors. To the best of our knowledge, no previous study has been conducted in this area. The ransomware collection used in our experiments contains more than 700 active examples of ransomware, that were analyzed in our bar metal sandbox environment. Routa Moussaileb, Benjamin Bouget, Aurélien Palisse, Hélène Le Bouder, Nora Cuppens, Jean-Louis Lanet |
ARES | 6 |
| 2018 | Machine learning techniques to predict sensitive patterns to fault attack in the Java Card applicationabstractFault attack represents one of the serious threats against Java Card security. It consists of physical perturbation of chip components to introduce faults in the code execution. A fault may be induced using a laser beam to impact opcodes and operands of instructions. This could lead to a mutation of the application code in such a way that it becomes hostile. Any successful attack may reveal a secret information stored in the card or grant an undesired authorisation. We propose a methodology to recognise, during the development step, the sensitive patterns to the fault attack in the Java Card applications. It is based on the concepts from text categorisation and machine learning. In fact, in this method, we represented the patterns using opcodes n-grams as features, and we evaluated different machine learning classifiers. The results show that the classifiers performed poorly when classifying dangerous sensitive patterns, due to the imbalance of our data-set. The number of dangerous sensitive patterns is much lower than the number of not dangerous patterns. We used resampling techniques to balance the class distribution in our data-set. The experimental results indicated that the resampling techniques improved the accuracy of the classifiers. In addition, our proposed method reduces the execution time of sensitive patterns classification in comparison to the SmartCM tool. This tool is used in our study to evaluate the effect of faults on Java Card applications. Yahiaoui Chahrazed, Jean-Louis Lanet, Mohamed Mezghiche, Karim Tamine |
J. Exp. Theor. Artif. Intell. | 2 |
| 2017 | Real-Time Detection and Reaction to Activity Hijacking Attacks in Android Smartphones (Short Paper)abstractMost Android users are required to communicate sensitive data (passwords, usernames, security codes, and credit card numbers) with applications. Hacker can launch phishing attacks to compromise user data confidentiality. He/She stealthily injects into the foreground a hijacking Activity at the right timing to acquire private information. In this paper, we propose an effective approach that uses the similarity between launched Activities in order to detect and reacts to hijacking attacks during runtime time. We demonstrate the effectiveness of our solution by quantifying the number of false positives that can be generated by our system. We observe that, in the worst case, our solution generates 4.2% of false positives and incurs only 0.39% performance overhead on a CPU-bound micro-benchmark. Anis Bkakria, Mariem Graa, Nora Cuppens, Frédéric Cuppens, Jean-Louis Lanet |
PST | 5 |
| 2017 | Detection of Side Channel Attacks Based on Data Tainting in Android Systems
Mariem Graa, Nora Cuppens, Frédéric Cuppens, Jean-Louis Lanet, Routa Moussaileb |
SEC | 4 |
| 2017 | How TrustZone Could Be Bypassed: Side-Channel Attacks on a Modern System-on-Chip
Sébanjila Kevin Bukasa, Ronan Lashermes, Hélène Le Bouder, Jean-Louis Lanet, Axel Legay |
WISTP | 4 |
| 2017 | Reverse engineering a Java Card memory management algorithm
Abdelhak Mesbah, Jean-Louis Lanet, Mohamed Mezghiche |
Comput. Secur. | 2 |
| 2016 | The Hell Forgery - Self Modifying Codes Shoot Again
Abdelhak Mesbah, Leo Regnaud, Jean-Louis Lanet, Mohamed Mezghiche |
CARDIS | 3 |
| 2016 | A Formal Verification of Safe Update Point Detection in Dynamic Software Updating
Razika Lounas, Nisrine Jafri, Axel Legay, Mohamed Mezghiche, Jean-Louis Lanet |
CRiSIS | 5 |
| 2016 | Ransomware and the Legacy Crypto API
Aurélien Palisse, Hélène Le Bouder, Jean-Louis Lanet, Colas Le Guernic, Axel Legay |
CRiSIS | 3 |
| 2016 | Tracking Explicit and Control Flows in Java and Native Android Apps CodeabstractInternational audience Mariem Graa, Nora Cuppens, Frédéric Cuppens, Jean-Louis Lanet |
ICISSP | 4 |
| 2016 | A Template Attack Against VERIFY PIN AlgorithmsabstractInternational audience Hélène Le Bouder, Thierno Barry 0002, Damien Couroussé, Jean-Louis Lanet, Ronan Lashermes |
SECRYPT | 4 |
| 2016 | Runtime Code Polymorphism as a Protection Against Side Channel Attacks
Damien Couroussé, Thierno Barry 0002, Bruno Robisson, Philippe Jaillon, Olivier Potin, Jean-Louis Lanet |
WISTP | 6 |
| 2015 | Side channel analysis techniques towards a methodology for reverse engineering of Java Card byte-codeabstractSide channel Analysis (SCA) has become a reliable method for cryptanalysts to break cryptographic algorithms. Recently, these methods are used in the aim of reverse engineering program code on Java Card. In addition of Power Analysis (PA), other techniques of side channel analysis exist, such as ElectroMagnetic Analysis (EMA). In this paper, we discuss techniques to apply reverse engineering attack on a Java Card application being executed over a Java Card Virtual Machine (JCVM) by using SCA attacks. Those attacks on smart cards can only be based on a black box approach where the code of applications and operating system are not accessible. To perform reverse engineering, a white box approach providing access to the Java Card is needed. In this paper, we present techniques towards a methodology to discover the code whose access is protected by the virtual machine. Mohammed Amine Kasmi, Mostafa Azizi, Jean-Louis Lanet |
IAS | 3 |
| 2015 | Model-Based Robustness Testing in Event-B Using Mutation
Aymerick Savary, Marc Frappier, Michael Leuschel, Jean-Louis Lanet |
SEFM | 4 |
| 2015 | The ultimate control flow transfer in a Java based smart card
Guillaume Bouffard, Jean-Louis Lanet |
Comput. Secur. | 2 |
| 2014 | Heap ... Hop! Heap Is Also Vulnerable
Guillaume Bouffard, Michael Lackner, Jean-Louis Lanet, Johannes Loinig |
CARDIS | 3 |
| 2014 | Memory Forensics of a Java Card Dump
Jean-Louis Lanet, Guillaume Bouffard, Rokia Lamrani Alaoui, Ranim Chakra, Afef Mestiri, Mohammed Monsif, Abdellatif Fandi |
CARDIS | 1 |
| 2014 | COGITO: Code Polymorphism to Secure DevicesabstractInternational audience Damien Couroussé, Bruno Robisson, Jean-Louis Lanet, Thierno Barry 0002, Hassan N. Noura, Philippe Jaillon, Philippe Lalevée |
SECRYPT | 3 |
| 2013 | Accessing secure information using export file fraudulenceabstractJava Card specification allows to load applications after the post-issuance. Each application to be installed into the card is verified by a Byte Code Verifier which ensures that the application is in compliance with the Java security rules. Guillaume Bouffard, Tom Khefif, Jean-Louis Lanet, Ismael Kane, Sergio Casanova Salvia |
CRiSIS | 3 |
| 2013 | ForewordabstractThis is the proceedings of the Eight International Conference on Risks and Security of Internet and Systems (CRiSIS 2013). The purpose of the conference is to bring together researchers to explore risks and security issues in Internet applications, networks and systems. Each year papers are presented covering topics including trust, security risks and threats, intrusion detection and prevention, access control and security modeling. Jean-Louis Lanet |
CRiSIS | 1 |
| 2013 | Detecting Vulnerabilities in Java-Card Bytecode Verifiers Using Model-Based Testing
Aymerick Savary, Marc Frappier, Jean-Louis Lanet |
IFM | 3 |
| 2013 | Vulnerability Analysis on Smart Cards Using Fault Tree
Guillaume Bouffard, Bhagyalekshmy N. Thampi, Jean-Louis Lanet |
SAFECOMP | 3 |
| 2013 | Virus in a smart card: Myth or reality?
Samiya Hamadouche, Jean-Louis Lanet |
J. Inf. Secur. Appl. | 2 |
| 2013 | Risks induced by Web applications on smart cards
Nassima Kamel, Jean-Louis Lanet |
J. Inf. Secur. Appl. | 2 |
| 2012 | Type Classification against Fault Enabled Mutant in Java Based Smart CardabstractSmart card are often the target of software or hardware attacks. For instance the most recent attacks are based on fault injection which can modify the behavior of applications loaded in the card, changing them as mutant application. In this paper, we propose a new protection mechanism which makes application to be less prone to mutant generation. This countermeasure requires a transformation of the original program byte codes which remains semantically equivalent. It requires a modification of the Java Virtual Machine which remains backward compatible and a dedicated framework to deploy the applications. Hence, our proposition improves the ability of the platform to resist to Fault Enabled Mutant. Jean Dubreuil, Guillaume Bouffard, Jean-Louis Lanet, Julien Iguchi-Cartigny |
ARES | 3 |
| 2012 | Attacks against smart cards: Hands on sessionabstractSmart card are often the target of software or hardware attacks. Recently several logical attacks have been developed that allows to dump the EEPROM memory. This kind of attack are particularly affordable for students who can learn reverse engineering techniques on devices known to be tamper resistant. This tutorial will demonstrate how with a few material a graduate student within a couple of hours is able to reverse an application. Jean-Louis Lanet |
CRiSIS | 1 |
| 2012 | A Friendly Framework for Hidding fault enabled virus for Java Based Smartcard
Tiana Razafindralambo, Guillaume Bouffard, Jean-Louis Lanet |
DBSec | 3 |
| 2011 | Enhancing Fuzzing Technique for OKL4 Syscalls TestingabstractVirtual machine monitor is a hot topic in the embedded community. Apart from high end system, current processors for embedded systems do not have any instructions helping to virtualize an operating system. Based on this fact, most of the current hypervisors for embedded devices use the Para virtualization technique. This is the case of the OKL4 kernel which is based on the L4 micro-kernel and implements among other the Linux kernel as guest OS. We introduce our ongoing work for testing the security of OKL4. We have chosen to focus on the most low level OKL4 interface usable from an external actor: the system call API. Because all operating system components use directly or indirectly these system calls, a minor flaw at this level can impact in chain the entire system including a virtualized kernel. We have developed a model describing the OKL4 system calls. This model also contains all constraints applicable to a system call. Based on these models, we are working on a tool using the constraints to compute a reduced set of system call input values which are highly likely to generate flaws in OKL4 if they are not fully checked by the hypervisor. Amaury Gauthier, Clement Mazin, Julien Iguchi-Cartigny, Jean-Louis Lanet |
ARES | 4 |
| 2011 | Combined Software and Hardware Attacks on the Java Card Control Flow
Guillaume Bouffard, Julien Iguchi-Cartigny, Jean-Louis Lanet |
CARDIS | 3 |
| 2011 | Evaluation of the Ability to Transform SIM Applications into Hostile Applications
Guillaume Bouffard, Jean-Louis Lanet, Jean-Baptiste Machemie, Jean-Yves Poichotte, Jean-Philippe Wary |
CARDIS | 2 |
| 2011 | A Security Mechanism to Increase Confidence in M-TransactionsabstractCurrently, NFC phones are coming in the handheld market, providing facilities to perform m-transactions. Obviously, this type of operation requires special security precautions. Indeed, a malicious code could intercept and hijack the system, even if there is a smart card. For example, the amount of the payment displayed in the terminal can be hijacked by an attacker to fool the user, or user's credential can be stolen thanks to a keylogger (and thus malicious codes can perform unwanted m-transactions automatically). This paper describes a security mechanism based on a graphical Turing test to prevent m-transactions submission by malwares. Firstly it introduces current m-transactions solutions. Then it explains the security mechanism that we propose to tackle the problem of untrusted handheld devices. It also underlines a proof of concept we implemented, to test its feasibility on a SIM card. Finally, it gives information on performances corresponding to the implementation that we made. David Pequegnot, Laurent Cart-Lamy, Aurélien Thomas, Thibault Tigeon, Julien Iguchi-Cartigny, Jean-Louis Lanet |
CRiSIS | 6 |
| 2010 | A new payment protocol over the InternetabstractWe propose in this paper to reuse the existing payment infrastructure to introduce a proof of transaction genuineness computed by a smart card chip. The idea is to divide the amount of the transaction into several sub-amounts, which added together give the total amount. The sub-amounts are function of a secret shared with the bank, which can verify that the split is correct, thus proving that the transaction is authentic. We provide here a description of the algorithm and its implementation in a .NET card. Pierre Girard, Karine Villegas, Jean-Louis Lanet, Aude Plateaux |
CRiSIS | 3 |
| 2010 | Reusing a JML Specification Dedicated to Verification for Testing, and Vice-Versa: Case Studies
Lydie du Bousquet, Yves Ledru, Olivier Maury, Catherine Oriat, Jean-Louis Lanet |
J. Autom. Reason. | 5 |
| 2004 | Enforcing High-Level Security Properties for Applets
Mariela Pavlova, Gilles Barthe, Lilian Burdy, Marieke Huisman, Jean-Louis Lanet |
CARDIS | 5 |
| 2004 | Case Study in JML-Based Software Validation
Lydie du Bousquet, Yves Ledru, Olivier Maury, Catherine Oriat, Jean-Louis Lanet |
ASE | 5 |
| 2002 | Checking Secure Interactions of Smart Card Applets: Extended VersionabstractThis paper presents an approach enabling a smart card issuer to verify that a new applet securely interacts with already downloaded applets. A security policy has been defined that associates levels to applet attributes and methods and defines author Pierre Bieber, Jacques Cazin, Pierre Girard, Jean-Louis Lanet, Virginie Wiels, Guy Zanon |
J. Comput. Secur. | 4 |
| 2000 | Checking Secure Interactions of Smart Card Applets
Pierre Bieber, Jacques Cazin, Pierre Girard, Jean-Louis Lanet, Virginie Wiels, Guy Zanon |
ESORICS | 4 |
| 1999 | New security issues raised by open cards
Pierre Girard, Jean-Louis Lanet |
Inf. Secur. Tech. Rep. | 2 |
| 1998 | Formal Proof of Smart Card Applets Correctness
Jean-Louis Lanet, Antoine Requet |
CARDIS | 1 |