Research Engineer: Cyber Security Events Format for Security Monitoring and Automation

Publié le ven 27/11/2020 - 14:36
Type de contrat
Corps / Catégorie
CentraleSupélec/Inria CIDRE research team
Equipe de recherche
About the research centre
The position will be based in the Rennes Campus of CentraleSupélec, within the CIDRE research team.
CIDRE is a joined research group between CentraleSupélec and Inria, focusing on the security of
information systems.
Inria is the French national research institute dedicated to digital science and technology. Inria employs
2,600 people. Its 200 research project teams, generally run jointly with academic partners, include more
than 3,500 scientists and engineers working to meet the challenges of digital technology, often at the
interface with other disciplines.
Security monitoring is one of the main research axes of the CIDRE team. In this context, the team is
involved in different research projects in collaboration with industrial, governmental and academic
partners. The proposed work will be part of the FUI project entitled SECEF (Security Exchange Format): The goal of this project is to promote format standardization in cybersecurity. More
precisely, we want to address the limitation of the IDMEF1 format and to propose a new RFC for a standard
security event exchange format.
In a traditional security monitoring architecture, such events can be raised by security probes (e.g.
antivirus, IDS, firewall, etc.) and sent to managers (SIEM) that can correlate them and present enriched
information to security operators. If such events correspond to some actual security incident, security
operators have to launch appropriate countermeasures to stop the attack and restore the infected systems
into a clean state. One of the main challenges and current trend in security monitoring consists in
automating the reaction process. To that end, probes have to report useful information to the security
automation process, in a structured and standardized format. Moreover, companies and institutions are
more and more inclined to exchange information regarding threats, to enhance their detection and
reaction capabilities. The security event format developed in the SECEF project should integrate with
existing Cyber Threat Intelligence standardization effort, such as STIX2 or IODEF3.
In this project, the CIDRE team is involved in:
- studying the state of the art in security event formats;
- specifying a new security event format;
- specifying a transport protocol for this security event format;
- participating in standardisation effort.
On an academic research perspective, we would like to explore how the intrusion detection and reaction
approaches we develop in the team could benefit from such a standard security event format. Thus, the
recruited research engineer will also be involved in the development of our research prototypes in
intrusion detection and reaction systems.

The recruited person will be in charge of following the SECEF project for CentraleSupélec. She will
collaborate with the industrial and academic partners of the project.
The recruited person will participate to the study of the state of the art. This includes identifying the needs of recent and future security monitoring and automation tools.
She will directly contribute to the specification of the new security event format and to the specification of the corresponding transport protocol. She will be involved in the standardisation effort of the project,
including attending IETF meetings.
She will demonstrate the benefits of this format through the study and development of realistic uses cases.
To that end, she will contribute to the development of existing and future intrusion detection and response prototypes of the teams, in close collaboration with PhD and permanent researchers of the team. More generally, she will be involved in the research activity of the team.
She will contribute to the dissemination of the results of the project by presenting the results in scientific and technical conferences, writing articles and developing training materials.

Profil / Compétences
Candidates will hold a master’s degree or a PhD degree in Computer Science or related fields.
• Significative experience in computer security.
• Experience in intrusion detection, security monitoring, incident response or Cyber Threat
• Experience in standardisation process and RFC specification is a plus.
• Ability to read and interpret technical journal and reports.
• Very good skills in English communication and writing.
• Ability to write, understand and debug clean, maintainable software code.
• Skilled in Python, C/C++, JSON, HTTP(S).
Diplôme requis
Lieu de travail
centraleSupelec /INRIA Rennes
Date prévisionnelle d'embauche
Date limite de candidature
Durée du contrat (en mois)
Salaire brut mensuel
3000-4200€ brut / mois, selon l’expérience
Application documents:
• Resume and cover letter
• Recommendation letters
• Copy of the last diploma certificate or equivalent document
The applications should be sent to Guillaume Hiet :