EDBT 2026 Demo / reviewers in the wild / expert
Frédéric Tronel
dblp:t/FredericTronel · also Frederic Tronel
· DBLP profile ↗
28ranked-venue papers
0as first author
2since 2021 · last 2025
0000-0002-2420-6105ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 13 · 1 since 2021Systems, architecture and hardware · 5Software engineering, systems software and programming languages · 4Computer networks · 2Databases, data management, data science and information retrieval · 2Theory of computation · 2Human-computer interaction and ubiquitous computing · 1
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Software engineering, system software, and programming languages
1 paper |
Program analysis · 100% | |
| Network and information security
1 paper |
Systems and software security · 100% | |
| Computer architecture, parallel and distributed computing, and storage systems
1 paper |
Distributed systems · 100% |
Topics — the 7 heaviest of 8, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Program analysis › static analysis
abstract interpretation |
0.3 | 1 | 2017 | Hypercollecting semantics and its application to static analysis of information flow · POPL 2017 |
Program analysis › static analysis
information flow analysis |
0.3 | 1 | 2017 | Hypercollecting semantics and its application to static analysis of information flow · POPL 2017 |
Program analysis
static analysis |
0.3 | 1 | 2017 | Hypercollecting semantics and its application to static analysis of information flow · POPL 2017 |
Systems and software security › information flow control
quantitative information flow |
0.1 | 1 | 2017 | Hypercollecting semantics and its application to static analysis of information flow · POPL 2017 |
Distributed systems
fault tolerance |
0.0 | 1 | 2000 | Computing Global Functions in Asynchronous Distributed Systems with Perfect Failure Detectors · IEEE Trans. Parallel Distributed Syst. 2000 |
Distributed systems › fault tolerance
failure detection |
0.0 | 1 | 2000 | Computing Global Functions in Asynchronous Distributed Systems with Perfect Failure Detectors · IEEE Trans. Parallel Distributed Syst. 2000 |
Distributed systems › fault tolerance › failure detection
perfect failure detector |
0.0 | 1 | 2000 | Computing Global Functions in Asynchronous Distributed Systems with Perfect Failure Detectors · IEEE Trans. Parallel Distributed Syst. 2000 |
Methods — techniques the papers use, named apart from their topics
abstract interpretation · 0.6galois connections · 0.3galois connection · 0.3early decision protocol · 0.1asynchronous rounds · 0.1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | HYPERSEC: An Extensible Hypervisor-Assisted Framework for Kernel Rootkit Detection
Lionel Hemmerlé, Guillaume Hiet, Frédéric Tronel, Pierre Wilke, Jean-Christophe Prévotet |
ISC | 3 |
| 2022 | RT-DFI: Optimizing Data-Flow Integrity for Real-Time SystemsabstractInternational audience Nicolas Bellec 0001, Guillaume Hiet, Simon Rokicki, Frédéric Tronel, Isabelle Puaut |
ECRTS | 4 |
| 2017 | Hypercollecting semantics and its application to static analysis of information flowabstractWe show how static analysis for secure information flow can be expressed and proved correct entirely within the framework of abstract interpretation. The key idea is to define a Galois connection that directly approximates the hyperproperty of interest. To enable use of such Galois connections, we introduce a fixpoint characterisation of hypercollecting semantics, i.e. a "set of sets" transformer. This makes it possible to systematically derive static analyses for hyperproperties entirely within the calculational framework of abstract interpretation. We evaluate this technique by deriving example static analyses. For qualitative information flow, we derive a dependence analysis similar to the logic of Amtoft and Banerjee (SAS '04) and the type system of Hunt and Sands (POPL '06). For quantitative information flow, we derive a novel cardinality analysis that bounds the leakage conveyed by a program instead of simply deciding whether it exists. This encompasses problems that are hypersafety but not k-safety. We put the framework to use and introduce variations that achieve precision rivalling the most recent and precise static analyses for information flow. Mounir Assaf, David A. Naumann, Julien Signoles, Eric Totel, Frédéric Tronel |
POPL | 5 |
| 2017 | Information Flow Tracking for Linux Handling Concurrent System Calls and Shared Memory
Laurent Georget, Mathieu Jaume, Guillaume Piolle, Frédéric Tronel, Valérie Viet Triem Tong |
SEFM | 4 |
| 2017 | Bitcoin a Distributed Shared Register
Emmanuelle Anceaume, Romaric Ludinard, Maria Potop-Butucaru, Frédéric Tronel |
SSS | 4 |
| 2015 | Kayrebt: An activity diagram extraction and visualization toolset designed for the Linux codebaseabstractWe present Extractor and Viewer, two tools from the Kayrebt toolset. The former is a plugin for the Gnu Compiler Collection (GCC) which builds pseudo-UML2 activity diagrams from C source code. It is specifically designed to handle the Linux kernel, a large and complex codebase. Use cases for this tool are numerous. The diagrams extracted from the C source code can be used to get a better insight of the control or data flow inside a program, or to evaluate the complexity of a function at a glance. Kayrebt::Viewer is a GUI designed for visualizing and navigating between the diagrams to explore source code. Laurent Georget, Frédéric Tronel, Valérie Viet Triem Tong |
VISSOFT | 2 |
| 2013 | Intrusion detection in distributed systems, an approach based on taint markingabstractThis paper presents a new framework for distributed intrusion detection based on taint marking. Our system tracks information flows between applications of multiple hosts gathered in groups (i.e. sets of hosts sharing the same distributed information flow policy) by attaching taint labels to system objects such as files, sockets, Inter Process Communication (IPC) abstractions, and memory mappings. Labels are carried over the network by tainting network packets. A distributed information flow policy is defined for each group at the host level by labeling information and defining how users and applications can legally access, alter or transfer information towards other trusted or untrusted hosts. As opposed to existing approaches, where information is most often represented by two security levels (low/high, public/private etc.), our model identifies each piece of information within a distributed system, and defines their legal interaction in a fine-grained manner. Hosts store and exchange security labels in a peer to peer fashion, and there is no central monitor. Our IDS is implemented in the Linux kernel as a Linux Security Module (LSM) and runs standard software on commodity hardware with no required modification. The only trusted code is our modified operating system kernel. We finally present a scenario of intrusion in a web service running on multiple hosts, and show how our distributed IDS is able to report security violations at each host level. Christophe Hauser, Frédéric Tronel, Colin J. Fidge, Ludovic Mé |
ICC | 2 |
| 2013 | Program Transformation for Non-interference Verification on Programs with Pointers
Mounir Assaf, Julien Signoles, Frédéric Tronel, Eric Totel |
SEC | 3 |
| 2012 | Detecting attacks against data in web applicationsabstractRRABIDS (Ruby on Rails Anomaly Based Intrusion Detection System) is an application level intrusion detection system for applications implemented with the Ruby on Rails framework. It is aimed at detecting attacks against data in the context of web applications. This anomaly based IDS focuses on the modeling of the application profile in the absence of attacks (called normal profile) using invariants. These invariants are discovered during a learning phase. Then, they are used to instrument the web application at source code level, so that a deviation from the normal profile can be detected at run-time. This paper illustrates on simple examples how the approach detects well known categories of web attacks that involve a state violation of the application, such as SQL injections. Finally, an assessment phase is performed to evaluate the accuracy of the detection provided by the proposed approach. Romaric Ludinard, Eric Totel, Frédéric Tronel, Vincent Nicomette, Mohamed Kaâniche, Eric Alata, Rim Akrout, Yann Bachy |
CRiSIS | 3 |
| 2011 | Modeling and evaluating targeted attacks in large scale dynamic systemsabstractIn this paper we consider the problem of targeted attacks in large scale peer-to-peer overlays. These attacks aimed at exhausting key resources of targeted hosts to diminish their capacity to provide or receive services. To defend the system against such attacks, we rely on clustering and implement induced churn to preserve randomness of nodes identifiers so that adversarial predictions are impossible. We propose robust join, leave, merge and split operations to discourage brute force denial of services and pollution attacks. We show that combining a small amount of randomization in the operations, and adequately tuning the sojourn time of peers in the same region of the overlay allows first to decrease the effect of targeted attacks at cluster level, and second to prevent pollution propagation in the whole overlay. Emmanuelle Anceaume, Bruno Sericola, Romaric Ludinard, Frédéric Tronel |
DSN | 4 |
| 2011 | Information Flow Control for Intrusion Detection Derived from MAC PolicyabstractMost of today's MAC implementations can be turned into permissive mode, where no enforcement is performed but alerts are raised instead. This behavior is very close to an anomaly IDS except that the system is configured through a MAC policy. MAC implementations such as SELinux and AppArmor come with a default policy including real life and practical rules ready to be used as is or as a basis for a custom policy. In this paper, we first propose an extension of an IDS based on information flow control. We address issues concerning programs execution and improve its expressiveness in terms of security policy. This extended model can be configured to reach a wide variety of different security goals. Particularly, it allows for information flow checking based on users and/or programs dependent policy rules. Furthermore, suspicious modification of binary programs can be detected to avoid malware execution. We also propose an algorithm for deriving an AppArmor MAC policy into an information flow policy, and thus get the advantage of having a ready to use policy offering good security. We finally show a practical example of deriving such a policy in order to configure our IDS. Stephane Geller, Christophe Hauser, Frédéric Tronel, Valérie Viet Triem Tong |
ICC | 3 |
| 2011 | Detecting Illegal System Calls Using a Data-Oriented Detection Model
Jonathan-Christofer Demay, Frédéric Majorczyk, Eric Totel, Frédéric Tronel |
SEC | 4 |
| 2009 | SIDAN: A tool dedicated to software instrumentation for detecting attacks on non-control-dataabstractAnomaly based intrusion detection systems rely on the build of a normal behavior model. When a deviation from this normal behavior is detected, an alert is raised. This anomaly approach, unlike the misuse approach, is able to detect unknown attacks. A basic technique to build such a model for a program is to use the system call sequences of the process. To improve the accuracy and completeness of this detection model, we can add information related to the system call, such as its arguments or its execution context. But even then, attacks that target non-control-data may be missed and attacks on control-data may be adapted to bypass the detection mechanism using evasion techniques. We propose in this article an approach that focuses on the detection of non-control-data attacks. Our approach aims at exploiting the internal state of a program to detect a memory corruption on non-control-data that could lead to an illegal system call. To achieve this, we propose to build a data-oriented detection model by statically analyzing a program source code. This model is used to instrument the program by adding reasonableness checks that verify the consistent state of the data items the system calls depend on. We thus argue that it is possible to detect a program misuse issued by a non-control-data attack inside the program during its execution. While keeping a low overhead, this approach allows to detect non-control-data attacks. Jonathan-Christofer Demay, Eric Totel, Frédéric Tronel |
CRiSIS | 3 |
| 2009 | Analytical Study of Adversarial Strategies in Cluster-based OverlaysabstractAwerbuch and Scheideler have shown that peer-to-peer overlays networks can survive Byzantine attacks only if malicious nodes are not able to predict what will be the topology of the network for a given sequence of join and leave operations. In this paper we investigate adversarial strategies by following specific protocols. Our analysis demonstrates first that an adversary can very quickly subvert DHT-based overlays by simply never triggering leave operations. We then show that when all nodes (honest and malicious ones) are imposed on a limited lifetime, the system eventually reaches a stationary regime where the ratio of polluted clusters is bounded, independently from the initial amount of corruption in the system. Emmanuelle Anceaume, Francisco Vilar Brasileiro, Romaric Ludinard, Bruno Sericola, Frédéric Tronel |
PDCAT | 5 |
| 2009 | Automatic Software Instrumentation for the Detection of Non-control-data Attacks
Jonathan-Christofer Demay, Eric Totel, Frédéric Tronel |
RAID | 3 |
| 2009 | Brief Announcement: Induced Churn to Face Adversarial Behavior in Peer-to-Peer Systems
Emmanuelle Anceaume, Francisco Vilar Brasileiro, Romaric Ludinard, Bruno Sericola, Frédéric Tronel |
SSS | 5 |
| 2006 | A Dependable Intrusion Detection Architecture Based on Agreement Services
Michel Hurfin, Jean-Pierre Le Narzul, Frédéric Majorczyk, Ludovic Mé, Ayda Saïdane, Eric Totel, Frédéric Tronel |
SSS | 7 |
| 2006 | Brief Announcement: Performance Analysis of Cyclon, an Inexpensive Membership Management for Unstructured P2P Overlays
François Bonnet 0001, Frédéric Tronel, Spyros Voulgaris |
DISC | 2 |
| 2001 | Primary Component Asynchronous Group Membership as an Instance of a Generic Agreement FrameworkabstractGroup-based computing is becoming more and more popular when one has to design middleware able to support reliable distributed applications. This paradigm is made of two basic services, namely, a group membership service and a group communication service. More generally, a group is a set of processes cooperating to carry out a common task (e.g., copies of a replicated server, participants in a transaction or users in a CSCW-based application). Due to the desire of new processes to join the group, to the desire of a group member to leave it, or to process crashes, the composition of a group can evolve dynamically. The set of processes that currently implements the group is called the current view of the group. This paper addresses the specification and the implementation of a primary component group membership service. Primary component means that the specification imposes to have a single view at any time. The paper first proposes a specification for the problem. Then it presents a protocol that implements that specification in asynchronous distributed systems equipped with failure detectors. This primary component group membership protocol is obtained as an appropriate instantiation of a general agreement framework. Fabíola Greve, Michel Hurfin, Michel Raynal, Frédéric Tronel |
ISADS | 4 |
| 2001 | Eva: An Event-Based Framework for Developing Specialized Communication ProtocolsabstractPresents a framework for the development of higher level communication protocols that provides extra functionalities not supplied by standard off-the-shelf lower level communication protocols. The framework is based on the event channel abstraction which allows circumventing the main drawbacks of the layered-based approach traditionally used to develop such protocols, whilst at the same time providing a flexible, simple and well structured way to implement them. The event channel service provided by EVA establishes how entities that share the same address space interact. Then, the application designer has the opportunity to define the most appropriate lower level communication protocols that control the way entities that execute within different processes will interact. The framework specifies a way to accommodate these protocols and provides several standard protocol implementations. Further a development methodology is described for constructing applications on top of the framework. In designing the framework, we have followed the approach of using, whenever possible, well established concepts, thus the paper also discusses the utilisation of such concepts in improving both the efficiency and the structuring of the framework and of the applications to be built on top of it. Francisco Vilar Brasileiro, Fabíola Greve, Frédéric Tronel, Michel Hurfin, Jean-Pierre Le Narzul |
NCA | 3 |
| 2001 | An Adaptive Failure Detection ProtocolabstractThe detection of process failures is a crucial problem system designers have to cope with in order to build fault-tolerant distributed platforms. Unfortunately, it is impossible to distinguish with certainty a crashed process from a very slow process in a purely asynchronous distributed system. This prevents some problems from being solved in such systems. That is why failure detector oracles have been introduced to circumvent these impossibility results. The paper presents a relatively simple protocol that allows a process to "monitor" another process, and consequently to detect its crash. This protocol relies as much as possible on application messages to do this monitoring. Different from previous process crash detection protocols, it uses control messages only when no application message is sent by the monitoring process to the observed process. When the underlying system satisfies the partial synchrony assumption, it actually implements an eventually perfect failure detector (i.e., a failure detector of the class usually denoted OP). Moreover if the average observed transmission delay is finite and the upper layer application terminates within a bounded number of steps for any failure detector in OP after the failure detector becomes "perfect", then, when run with the proposed protocol, it also terminates correctly. These properties make the protocol inexpensive, implementable, and powerful. The paper also describes performance measurements of an implementation of the protocol. Christof Fetzer, Michel Raynal, Frédéric Tronel |
PRDC | 3 |
| 2000 | The Best of Both Worlds: A Hybrid Approach to Solve ConsensusabstractIt is now well recognized that the consensus problem is a fundamental problem when one has to implement fault-tolerant distributed services in asynchronous distributed systems prone to process crash failures. This paper considers the binary consensus problem in such a system. Following an approach investigated by Aguilera and Toueg, it proposes a simple binary consensus protocol that combines failure detection and randomization. This protocol terminates deterministically when the failure detection mechanism works correctly; it terminates with probability 1, otherwise. A performance evaluation of the protocol is also provided. Last but not least, it is important to note that the proposed protocol is both efficient and simple. Additionally it can be simplified to give rise either to a deterministic failure detector-based consensus protocol or to a randomized consensus protocol. Achour Mostéfaoui, Michel Raynal, Frédéric Tronel |
DSN | 3 |
| 2000 | Computing Global Functions in Asynchronous Distributed Systems Prone to Process CrashesabstractGlobal data is a vector with one entry per process. Each entry must be filled with an appropriate value provided by the corresponding process. Several distributed computing problems amount to compute a function on global data. This paper proposes a protocol to solve such problems in the context of asynchronous distributed systems where processes may fail by crashing. The main problem that has to be solved lies in computing the global data and in providing each non-crashed process with a copy of it, despite the possible crash of some processes. To be consistent, the global data must contain (at least) all the values provided by the processes that do not crash. This defines the global data computation (GDC) problem. To solve this problem, processes execute a sequence of asynchronous rounds during which they construct (in a decentralized way) the value of the global data, and eventually each process gets a copy of it. To cope with process crashes, the protocol uses a perfect failure detector. The proposed protocol has been designed to be time-efficient. It allows early decisions. Let t be the maximum number of processes that may crash (t Jean-Michel Hélary, Michel Hurfin, Achour Mostéfaoui, Michel Raynal, Frédéric Tronel |
ICDCS | 5 |
| 2000 | From Binary Consensus to Multivalued Consensus in asynchronous message-passing systems
Achour Mostéfaoui, Michel Raynal, Frédéric Tronel |
Inf. Process. Lett. | 3 |
| 2000 | Computing Global Functions in Asynchronous Distributed Systems with Perfect Failure DetectorsabstractA Global Data is a vector with one entry per process. Each entry must be filled with an appropriate value provided by the corresponding process. Several distributed computing problems amount to compute a function on a global data. This paper proposes a protocol to solve such problems in the context of asynchronous distributed systems where processes may fail by crashing. The main problem that has to be solved lies in computing the global data and in providing each noncrashed process with a copy of it, despite the possible crash of some processes. To be consistent, the global data must contain, at least, all the values provided by the processes that do not crash. This defines the Global Data Computation (GDC) problem. To solve this problem, processes execute a sequence of asynchronous rounds during which they construct, in a decentralized way, the value of the global data and eventually each process gets a copy of it. To cope with process crashes, the protocol uses a perfect failure detector. The proposed protocol has been designed to be time efficient: it allows early decision. Let t be the maximum number of processes that may crash, t Jean-Michel Hélary, Michel Hurfin, Achour Mostéfaoui, Michel Raynal, Frédéric Tronel |
IEEE Trans. Parallel Distributed Syst. | 5 |
| 1999 | On Classes of Problems in Asynchronous Distributed Systems with Process CrashesabstractThis paper is on classes of problems encountered in asynchronous distributed systems in which processes can crash but links are reliable. The hardness of a problem is defined with respect to the difficulty to solve it despite failures: a problem is easy if it can be solved in presence of failures, otherwise it is hard. Three classes of problems are defined: F, NF and NFC. F is the class of easy problems, namely, those that can be solved in presence of failures (e.g., reliable broadcast). The class NF includes harder problems, namely, the ones that can be solved in a non-faulty system (e.g., consensus). The class NFC (NF-complete) is a subset of NF that includes the problems that are the most difficult to solve in presence of failures. It is shown that the terminating reliable broadcast problem, the non-blocking atomic commitment problem and the construction of a perfect failure detector (problem P) are equivalent problems and belong to NFC. Moreover the consensus problem is not in NFC. The paper presents a general reduction protocol that reduces any problem of NF to P. This shows that P is a problem that lies at the core of distributed fault-tolerance. Eddy Fromentin, Michel Raynal, Frédéric Tronel |
ICDCS | 3 |
| 1999 | A General Framework to Solve Agreement ProblemsabstractAgreement problems are among the most important problems designers of distributed systems have to cope with. A way to solve them is to first provide a solution to the Consensus problem and then to reduce each agreement problem to Consensus. This "run-time customizing" approach is particularly relevant when upper layer applications have to solve several distinct agreement problems. We investigate a "compile-time customizing" approach to automatically generate ad hoc agreement protocols. A general agreement framework, characterized by six "versatility" parameters, is defined. Appropriate instantiations of these parameters provide particular agreement protocols. This approach is particularly suited to generate efficient agreement protocols. Michel Hurfin, Raimundo José de Araújo Macêdo, Michel Raynal, Frédéric Tronel |
SRDS | 4 |
| 1999 | Restricted failure detectors: Definition and reduction protocols
Michel Raynal, Frédéric Tronel |
Inf. Process. Lett. | 2 |