Project Phase 2: 01/2022-08/2024
Presentation
Telecom operators and operators of vital importance need detection systems that can keep pace with large, heterogeneous, and constantly changing infrastructures. Conventional security operations center workflows collect large volumes of NetFlow or IPFIX data, search for suspicious sequences, and then decide whether to trigger a countermeasure. This passive model becomes less suitable as the scale and diversity of IoT and critical-infrastructure networks increase.
DAMIAGE investigates a more active approach to attack detection. It leverages network observations and uses graph-based analysis to identify abnormal changes. The objective is to support detection in real time or close to real time while developing security capabilities for critical infrastructures in France.
Partners
- IMT Atlantique
- SLA Advisor
Results
- A graph-based cyber-threat detection system for large-scale and critical infrastructure networks.
- Community-dynamics metrics applied to unsupervised attack detection.
Publications
- Julien Michel, and Pierre Parrend. 2023. “Metrics for community dynamics applied to unsupervised attacks detection.” Rencontre des Jeunes Chercheurs en Inteligence Artificielle (RJCIA). Paper.
- Julien Michel, and Pierre Parrend. 2025. “Graph-Based Intelligent Cyber Threat Detection System.” In Handbook of AI-Driven Threat Detection and Prevention: A Holistic Approach to Security, edited by Pankaj Bhambri and Jose Anand A. CRC Press. ISBN 9781032859743. Paper.
- Julien Michel, and Pierre Parrend. 2025. “T-robust spaces with dynamic graphs metrics for mitigating concept drift in attack detection.” In International Conference on Knowledge-Based and Intelligent Information and Engineering Systems (KES). Paper.
Project page: DAMIAGE