Network


Latest external collaboration on country level. Dive into details by clicking on the dots.

Hotspot


Dive into the research topics where Stéphane Mocanu is active.

Publication


Featured researches published by Stéphane Mocanu.


nordic conference on secure it systems | 2016

Detecting Process-Aware Attacks in Sequential Control Systems

Oualid Koucham; Stéphane Mocanu; Guillaume Hiet; Jean-Marc Thiriet; Frédéric Majorczyk

Industrial control systems (ICS) can be subject to highly sophisticated attacks which may lead the process towards critical states. Due to the particular context of ICS, protection mechanisms are not always practical, nor sufficient. On the other hand, developing a process-aware intrusion detection solution with satisfactory alert characterization remains an open problem. This paper focuses on process-aware attacks detection in sequential control systems. We build on results from runtime verification and specification mining to automatically infer and monitor process specifications. Such specifications are represented by sets of temporal safety properties over states and events corresponding to sensors and actuators. The properties are then synthesized as monitors which report violations on execution traces. We develop an efficient specification mining algorithm and use filtering rules to handle the large number of mined properties. Furthermore, we introduce the notion of activity and discuss its relevance to both specification mining and attack detection in the context of sequential control systems. The proposed approach is evaluated in a hardware-in-the-loop setting subject to targeted process-aware attacks. Overall, due to the explicit handling of process variables, the solution provides a better characterization of the alerts and a more meaningful understanding of false positives.


emerging technologies and factory automation | 2016

A Test bed dedicated to the Study of Vulnerabilities in IEC 61850 Power Utility Automation Networks

Maëlle Kabir-Querrec; Stéphane Mocanu; Jean-Marc Thiriet; Eric Savary

Industrial control systems rely more and more on digital technologies. Although the cyber risk such technologies induce is widely judged as serious, especially for critical infrastructures, these systems have generally not been designed to serve cybersecurity purposes. Instead they were thought first for serving operational efficiency. It thus becomes critical to study cyber threats in industrial environments and experimental test beds are needed to evaluate risks, physical consequences of cyber incidents, and performance of countermeasures. The test bed we present here focuses on studying cyber risks and their mitigation in IEC 61850 power utility automation systems. The operational part is composed of engineering computers, supervision software, off-the-shelf intelligent relays (Intelligent Electronic Device - IED), a hardware-in-the-loop process simulation, and the cybersecurity tools include an attack generation station and a network analyzer. In this paper, we present the operational part, giving details on the power grid hardware-in-the-loop simulation and its importance in the understanding of cyber consequences on the global system. The article concludes giving preliminary experimental results showing consequences of a false data injection attack on a simple electrical architecture.


Journées C&ESAR 2015. Intelligence Artificielle et Cybersécurité | 2015

Architecture des systèmes d'automatisation des postes résiliente aux attaques des trames GOOSE

Maëlle Kabir-Querrec; Stéphane Mocanu; Pascal Bellemain; Jean-Marc Thiriet; Eric Savary


GreHack 2015 | 2015

Corrupted GOOSE Detectors: Anomaly Detection in Power Utility Real-Time Ethernet Communications

Maëlle Kabir-Querrec; Stéphane Mocanu; Pascal Bellemain; Jean-Marc Thiriet; Eric Savary


IFAC-PapersOnLine | 2018

Efficient Mining of Temporal Safety Properties for Intrusion Detection in Industrial Control Systems

Oualid Koucham; Stéphane Mocanu; Guillaume Hiet; Jean-Marc Thiriet; Frédéric Majorczyk


Rendez-Vous de la Recherche et de l'Enseignement de la Sécurité des Systèmes d'Information (RESSI 2016) | 2016

Cybersecurity of smart-grid control systems: Intrusion detection in IEC 61850 automation systems

Maëlle Kabir-Querrec; Stéphane Mocanu; Jean-Marc Thiriet; Eric Savary


Rendez-Vous de la Recherche et de l'Enseignement de la Sécurité des Systèmes d'Information (RESSI 2016) | 2016

Classification des approches de détection d'intrusions dans les systèmes de contrôle industriels et axes d'amélioration

Oualid Koucham; Stéphane Mocanu; Guillaume Hiet; Jean-Marc Thiriet; Frédéric Majorczyk


26th European Safety and Reliability Conference (ESREL 2016) | 2016

Dependability Optimization of Process-level Protection in an IEC-61850-Based Substation

Ahmed Altaher; Stéphane Mocanu; Jean-Marc Thiriet


arXiv: Networking and Internet Architecture | 2015

Evaluation of Time-Critical Communications for IEC 61850-Substation Network Architecture

Ahmed Altaher; Stéphane Mocanu; Jean-Marc Thiriet


Rendez-Vous de la Recherche et de l'Enseignement de la Sécurité des Systèmes d'Information (RESSI 2015) | 2015

Cybersécurité des sous-stations électriques IEC 61850

Stéphane Mocanu; Maëlle Kabir-Querrec; Jean-Marc Thiriet; Eric Savary

Collaboration


Dive into the Stéphane Mocanu's collaboration.

Top Co-Authors

Avatar
Top Co-Authors

Avatar

Oualid Koucham

Centre national de la recherche scientifique

View shared research outputs
Top Co-Authors

Avatar
Researchain Logo
Decentralizing Knowledge