VLDB 2026 Research / reviewers in the wild / expert
Tyler Moore 0001
dblp:01/5331 · also Tyler W. Moore
· DBLP profile ↗
26ranked-venue papers
6as first author
7since 2021 · last 2026
0000-0002-8771-8191ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 21 · 4 first-author · 6 since 2021Computer networks · 2 · 2 first-authorDatabases, data management, data science and information retrieval · 2 · 1 since 2021Artificial intelligence and machine learning · 1Theory of computation · 1Applied, interdisciplinary, general and emerging computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | How security-related stress and self-efficacy influence actual behavior: An empirical study
Seth Hastings, Tyler Moore 0001, Bradley Brummel, Salvatore Aurigemma |
Comput. Secur. | 2 |
| 2025 | How informative are cybersecurity risk disclosures? Empirical analysis of firms targeted by ransomware
Matthew Adams, Tyler Moore 0001 |
Comput. Secur. | 2 |
| 2024 | A Cost-Sensitive Approach for Managing Intrusion Alerts in OT Environments
Alex Howe, Andrew Morin, Mauricio Papa, Tyler Moore 0001 |
CRITIS | 4 |
| 2023 | Empirically evaluating the effect of security precautions on cyber incidents
Neil Gandal, Tyler Moore 0001, Michael Riordan, Noa Barnir |
Comput. Secur. | 2 |
| 2022 | Longitudinal Study of Internet-Facing OpenSSH Update Patterns
Jonathan West, Tyler Moore 0001 |
PAM | 2 |
| 2021 | SoK: A Framework for Asset Discovery: Systematizing Advances in Network Measurements for Protecting OrganizationsabstractAsset discovery is fundamental to any organization's cybersecurity efforts. Indeed, one must accurately know which assets belong to an IT infrastructure before the infrastructure can be secured. While practitioners typically rely on a relatively small set of well-known techniques, the academic literature on the subject is voluminous. In particular, the Internet measurement research community has devised a number of asset discovery techniques to support many measurement studies over the past five years. In this paper, we systematize asset discovery techniques by constructing a framework that comprehensively captures how network identifiers and services are found. We extract asset discovery techniques from recent academic literature in security and networking and place them into the systematized framework. We then demonstrate how to apply the framework to several case studies of asset discovery workflows, which could aid research reproducibility. These case studies further suggest opportunities for researchers and practitioners to uncover and identify more assets than might be possible with traditional techniques. Mathew Vermeer, Jonathan West, Alejandro Cuevas Villalba, Shuonan Niu, Nicolas Christin, Michel van Eeten, Tobias Fiebig, Carlos Gañán, Tyler Moore 0001 |
EuroS&P | 9 |
| 2021 | An examination of the cryptocurrency pump-and-dump ecosystem
J. T. Hamrick, Farhang Rouhi, Arghya Mukherjee, Amir Feder, Neil Gandal, Tyler Moore 0001, Marie Vasek |
Inf. Process. Manag. | 6 |
| 2018 | Revisiting the Risks of Bitcoin Currency Exchange ClosureabstractBitcoin has enjoyed wider adoption than any previous cryptocurrency; yet its success has also attracted the attention of fraudsters who have taken advantage of operational insecurity and transaction irreversibility. We study the risk that investors face from the closure of Bitcoin exchanges, which convert between Bitcoins and hard currency. We examine the track record of 80 Bitcoin exchanges established between 2010 and 2015. We find that nearly half (38) have since closed, with customer account balances sometimes wiped out. Fraudsters are sometimes to blame, but not always. Twenty-five exchanges suffered security breaches, 15 of which subsequently closed. We present logistic regressions using longitudinal data on Bitcoin exchanges aggregated quarterly. We find that experiencing a breach is correlated with a 13 times greater odds that an exchange will close in that same quarter. We find that higher-volume exchanges are less likely to close (each doubling in trade volume corresponds to a 12% decrease in the odds of closure). We also find that exchanges that derive most of their business from trading less popular (fiat) currencies, which are offered by at most one competitor, are less likely to close. Tyler Moore 0001, Nicolas Christin, Janos Szurdi |
ACM Trans. Internet Techn. | 1 |
| 2017 | Herding Vulnerable Cats: A Statistical Approach to Disentangle Joint Responsibility for Web Security in Shared HostingabstractHosting providers play a key role in fighting web compromise, but their ability to prevent abuse is constrained by the security practices of their own customers. Shared hosting, offers a unique perspective since customers operate under restricted privileges and providers retain more control over configurations. We present the first empirical analysis of the distribution of web security features and software patching practices in shared hosting providers, the influence of providers on these security practices, and their impact on web compromise rates. We construct provider-level features on the global market for shared hosting -- containing 1,259 providers -- by gathering indicators from 442,684 domains. Exploratory factor analysis of 15 indicators identifies four main latent factors that capture security efforts: content security, webmaster security, web infrastructure security and web application security. We confirm, via a fixed-effect regression model, that providers exert significant influence over the latter two factors, which are both related to the software stack in their hosting environment. Finally, by means of GLM regression analysis of these factors on phishing and malware abuse, we show that the four security and software patching factors explain between 10% and 19% of the variance in abuse at providers, after controlling for size. For web-application security for instance, we found that when a provider moves from the bottom 10% to the best-performing 10%, it would experience 4 times fewer phishing incidents. We show that providers have influence over patch levels--even higher in the stack, where CMSes can run as client-side software--and that this influence is tied to a substantial reduction in abuse levels. Samaneh Tajalizadehkhoob, Tom van Goethem, Maciej Korczynski, Arman Noroozian, Rainer Böhme, Tyler Moore 0001, Wouter Joosen, Michel van Eeten |
CCS | 6 |
| 2017 | Practicing a Science of Security: A Philosophy of Science PerspectiveabstractOur goal is to refocus the question about cybersecurity research from 'is this process scientific' to 'why is this scientific process producing unsatisfactory results'. We focus on five common complaints that claim cybersecurity is not or cannot be scientific. Many of these complaints presume views associated with the philosophical school known as Logical Empiricism that more recent scholarship has largely modified or rejected. Modern philosophy of science, supported by mathematical modeling methods, provides constructive resources to mitigate all purported challenges to a science of security. Therefore, we argue the community currently practices a science of cybersecurity. A philosophy of science perspective suggests the following form of practice: structured observation to seek intelligible explanations of phenomena, evaluating explanations in many ways, with specialized fields (including engineering and forensics) constraining explanations within their own expertise, inter-translating where necessary. A natural question to pursue in future work is how collecting, evaluating, and analyzing evidence for such explanations is different in security than other sciences. Jonathan M. Spring, Tyler Moore 0001, David J. Pym |
NSPW | 2 |
| 2017 | Polymorphic malware detection using sequence classification methods and ensemblesabstractIdentifying malicious software executables is made difficult by the constant adaptations introduced by miscreants in order to evade detection by antivirus software. Such changes are akin to mutations in biological sequences. Recently, high-throughput methods for gene sequence classification have been developed by the bioinformatics and computational biology communities. In this paper, we apply methods designed for gene sequencing to detect malware in a manner robust to attacker adaptations. Whereas most gene classification tools are optimized for and restricted to an alphabet of four letters (nucleic acids), we have selected the Strand gene sequence classifier for malware classification. Strand’s design can easily accommodate unstructured data with any alphabet, including source code or compiled machine code. To demonstrate that gene sequence classification tools are suitable for classifying malware, we apply Strand to approximately 500 GB of malware data provided by the Kaggle Microsoft Malware Classification Challenge (BIG 2015) used for predicting nine classes of polymorphic malware. Experiments show that, with minimal adaptation, the method achieves accuracy levels well above 95% requiring only a fraction of the training times used by the winning team’s method. Jake Drew, Michael Hahsler, Tyler Moore 0001 |
EURASIP J. Inf. Secur. | 3 |
| 2016 | Measuring the Influence of Perceived Cybercrime Risk on Online Service AvoidanceabstractCybercrime is a pervasive threat for today's Internet-dependent society. While the real extent and economic impact is hard to quantify, scientists and officials agree that cybercrime is a huge and still growing problem. A substantial fraction of cybercrime's overall costs to society can be traced to indirect opportunity costs, resulting from unused online services. This paper presents a parsimonious model that builds on technology acceptance research and insights from criminology to identify factors that reduce Internet users' intention to use online services. We hypothesize that avoidance of online banking, online shopping and online social networking is increased by cybercrime victimization and media reports. The effects are mediated by the perceived risk of cybercrime and moderated by the user's confidence online. We test our hypotheses using a structural equation modeling analysis of a representative pan-European sample. Our empirical results confirm the negative impact of perceived risk of cybercrime on the use of all three online service categories and support the role of cybercrime experience as an antecedent of perceived risk of cybercrime. We further show that more confident Internet users perceive less cybercriminal risk and are more likely to use online banking and online shopping, which highlights the importance of consumer education. Markus Riek, Rainer Böhme, Tyler Moore 0001 |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2016 | Hacking Is Not Random: A Case-Control Study of Webserver-Compromise RiskabstractWe describe a case-control study to identify risk factors that are associated with higher rates of webserver compromise. We inspect a random sample of around 200,000 webservers and automatically identify attributes hypothesized to affect the susceptibility to compromise, notably content management system (CMS) and webserver type. We then cross-list this information with data on webservers hacked to serve phishing pages or redirect to unlicensed online pharmacies. We find that webservers running WordPress and Joomla are more likely to be hacked than those not running any CMS, and that servers running Apache and Nginx are more likely to be hacked than those running Microsoft IIS. We also identify several WordPress plugins and Joomla extensions that associated with compromise. Furthermore, using a series of logistic regressions, we find that a CMS's market share is positively correlated with website compromise. Surprisingly, we find that webservers running outdated software are less likely to be compromised than those running up-to date software. We present evidence that this is true for core WordPress software (the most popular CMS platform) and many associated plugins. Finally, we examine what happens to webservers following compromise. We find that under 5 percent of hacked WordPress websites are subsequently updated, but those that do are recompromised about half as often as those that do not update. Marie Vasek, John Wadleigh, Tyler Moore 0001 |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2015 | The E-Commerce Market for "Lemons": Identification and Analysis of Websites Selling Counterfeit GoodsabstractWe investigate the practice of websites selling counterfeit goods. We inspect web search results for 225 queries across 25 brands. We devise a binary classifier that predicts whether a given website is selling counterfeits by examining automatically extracted features such as WHOIS information, pricing and website content. We then apply the classifier to results collected between January and August 2014. We find that, overall, 32% of search results point to websites selling fakes. For 'complicit' search terms, such as "replica rolex", 39% of the search results point to fakes, compared to 20% for 'innocent' terms, such as "hermes buy online". Using a linear regression, we find that brands with a higher street price for fakes have higher incidence of counterfeits in search results, but that brands who take active countermeasures such as filing DMCA requests experience lower incidence of counterfeits in search results. Finally, we study how the incidence of counterfeits evolves over time, finding that the fraction of search results pointing to fakes remains remarkably stable. John Wadleigh, Jake Drew, Tyler Moore 0001 |
WWW | 3 |
| 2014 | A Nearly Four-Year Longitudinal Study of Search-Engine PoisoningabstractWe investigate the evolution of search-engine poisoning using data on over 5 million search results collected over nearly 4 years. We build on prior work investigating search-redirection attacks, where criminals compromise high-ranking websites and direct search traffic to the websites of paying customers, such as unlicensed pharmacies who lack access to traditional search-based advertisements. We overcome several obstacles to longitudinal studies by amalgamating different resources and adapting our measurement infrastructure to changes brought by adaptations by both legitimate operators and attackers. Our goal is to empirically characterize how strategies for carrying out and combating search poisoning have evolved over a relatively long time period. We investigate how the composition of search results themselves has changed. For instance, we find that search-redirection attacks have steadily grown to take over a larger share of results (rising from around 30% in late 2010 to a peak of nearly 60% in late 2012), despite efforts by search engines and browsers to combat their effectiveness. We also study the efforts of hosts to remedy search-redirection attacks. We find that the median time to clean up source infections has fallen from around 30 days in 2010 to around 15 days by late 2013, yet the number of distinct infections has increased considerably over the same period. Finally, we show that the concentration of traffic to the most successful brokers has persisted over time. Further, these brokers have been mostly hosted on a few autonomous systems, which indicates a possible intervention strategy. Nektarios Leontiadis, Tyler Moore 0001, Nicolas Christin |
CCS | 2 |
| 2014 | Optimized combined-clustering methods for finding replicated criminal websitesabstractTo be successful, cybercriminals must figure out how to scale their scams. They duplicate content on new websites, often staying one step ahead of defenders that shut down past schemes. For some scams, such as phishing and counterfeit goods shops, the duplicated content remains nearly identical. In others, such as advanced-fee fraud and online Ponzi schemes, the criminal must alter content so that it appears different in order to evade detection by victims and law enforcement. Nevertheless, similarities often remain, in terms of the website structure or content, since making truly unique copies does not scale well. In this paper, we present a novel optimized combined clustering method that links together replicated scam websites, even when the criminal has taken steps to hide connections. We present automated methods to extract key website features, including rendered text, HTML structure, file structure, and screenshots. We describe a process to automatically identify the best combination of such attributes to most accurately cluster similar websites together. To demonstrate the method’s applicability to cybercrime, we evaluate its performance against two collected datasets of scam websites: fake escrow services and high-yield investment programs (HYIPs). We show that our method more accurately groups similar websites together than those existing general-purpose consensus clustering methods. Jake Drew, Tyler Moore 0001 |
EURASIP J. Inf. Secur. | 2 |
| 2013 | Pick your poison: pricing and inventories at unlicensed online pharmaciesabstractElectronic commerce has transformed how goods are supplied to consumers, but has also exposed weaknesses in supply regulations of certain goods, such as alcohol, weapons or prescription drugs. While licensed pharmacies have tread carefully with online sales, many enterprising operators have been selling pharmaceuticals without a license for years. Despite facing considerable adversity, unlicensed online pharmacies have managed not only to survive, but even to generate considerable revenue. In this paper, we attempt 1) to understand the economic reasons for their success, while facing stiff competition from both legal and illegal alternatives, and 2) to identify characteristics of their supply chains that could be used to disrupt illicit sales. We collected six months' worth of inventory and pricing data from 265 online pharmacies that advertise through search- engine poisoning. We compare this to data from Silk Road, an anonymous online marketplace, and from familymeds.com, a licensed online pharmacy. We discover that instead of directly competing with licensed pharmacies, unlicensed pharmacies often sell drugs that licensed pharmacies do not or cannot sell. Furthermore, unlicensed pharmacies are not only cheaper overall, but they also offer volume discounts. Clustering analysis of inventories reveals that only a few suppliers appear to cater for most unlicensed pharmacies, which suggests that cutting them off could disrupt unlicensed sales. Cross-validating our data with inventories from a random sample of 265 different pharmacies deemed ``not recommended'' by the National Association of Boards of Pharmacy shows that our results are consistent across different types of questionable vendors. Nektarios Leontiadis, Tyler Moore 0001, Nicolas Christin |
EC | 2 |
| 2012 | Beyond the blacklist: modeling malware spread and the effect of interventionsabstractMalware spread among websites and between websites and clients is an increasing problem. Search engines play an important role in directing users to websites and are a natural control point for intervening using mechanisms such as blacklisting. The paper presents a simple Markov model of malware spread through large populations of websites and studies the effect of two interventions that might be deployed by a search provider: blacklisting infected web pages by removing them from search results entirely and a generalization of blacklisting, called depreferencing, in which a website's ranking is decreased by a fixed percentage each time period the site remains infected. We analyze and study the trade-offs between infection exposure and traffic loss due to false positives (the cost to a website that is incorrectly blacklisted) for different interventions. As expected, we find that interventions are most effective when websites are slow to remove infections. Surprisingly, we also find that low infection or recovery rates can increase traffic loss due to false positives. Our analysis also shows that heavy-tailed distributions of website popularity, as documented in many studies, leads to high sample variance of all measured outcomes. This result implies that it will be difficult to determine empirically whether certain website interventions are effective, and it suggests that theoretical models such as the one described in this paper have an important role to play in improving web security. Benjamin Edwards, Tyler Moore 0001, George Stelle, Steven Hofmeyr, Stephanie Forrest |
NSPW | 2 |
| 2011 | Fashion crimes: trending-term exploitation on the webabstractOnline service providers are engaged in constant conflict with miscreants who try to siphon a portion of legitimate traffic to make illicit profits. We study the abuse of "trending" search terms, in which miscreants place links to malware-distributing or ad-filled web sites in web search and Twitter results, by collecting and analyzing measurements over nine months from multiple sources. We devise heuristics to identify ad-filled sites, report on the prevalence of malware and ad-filled sites in trending-term search results, and measure the success in blocking such content. We uncover collusion across offending domains using network analysis, and use regression analysis to conclude that both malware and ad-filled sites thrive on less popular, and less profitable trending terms. We build an economic model informed by our measurements and conclude that ad-filled sites and malware distribution may be economic substitutes. Finally, because our measurement interval spans February 2011, when Google announced changes to its ranking algorithm to root out low-quality sites, we can assess the impact of search-engine intervention on the profits miscreants can achieve. Tyler Moore 0001, Nektarios Leontiadis, Nicolas Christin |
CCS | 1 |
| 2011 | Measuring and Analyzing Search-Redirection Attacks in the Illicit Online Prescription Drug Trade
Nektarios Leontiadis, Tyler Moore 0001, Nicolas Christin |
USENIX Security Symposium | 2 |
| 2010 | Would a 'cyber warrior' protect us: exploring trade-offs between attack and defense of information systemsabstractAs information security shifts from the realm of computer science to national security, the priority for safe and secure systems will be balanced against the appeal of using information insecurity as a strategic asset. In war, those tasked with defending friendly computer networks are also expected to exploit enemy networks. This paper presents two game-theoretic models of vulnerability discovery and exploitation, where nations must choose between protecting themselves by sharing vulnerability information with vendors or pursuing an offensive advantage while remaining at risk. One game describes a cold war of stockpiling, the other allows for actual attack. In both models, we predict that at least one state will have an incentive to pursue an aggressive cyber war posture, rather than secure its own systems. This finding -- that a mutually defensive approach to security is not a stable equilibrium -- holds up under a range of assumptions about social risk of cybercrime, technical sophistication, military aggressiveness and the likelihood of vulnerability rediscovery. We conclude with a discussion of the security policy implications of a militarized cyberspace Tyler Moore 0001, Allan Friedman, Ariel D. Procaccia |
NSPW | 1 |
| 2008 | Fast Exclusion of Errant Devices from Vehicular NetworksabstractVehicular networks, in which cars communicate wirelessly to exchange information on traffic conditions, offer a promising way to improve road safety. Yet ensuring the correct functioning of such a system is essential: malicious or faulty devices transmitting inaccurate messages could trigger accidents. Therefore, any errant device, along with the messages it generates, must be identified and ignored as quickly as possible. This task is especially challenging because traditional approaches to revoking credentials use a central authority, causing long delays during which the network is vulnerable. To eliminate this window of vulnerability, we propose that vehicles locally decide whether to exclude errant devices. We describe two ways of doing so: first, LEAVE, an existing protocol which allows devices to vote by exchanging signed claims of impropriety, and second, Stinger, a new protocol where a device unilaterally removes a misbehaving neighbor by agreeing to limit its own participation. We provide detailed simulations that offer insight into the protocols' operations in the context of vehicular networks and enable a powerful comparison between the strategies. We compare the security and performance properties of LEAVE and Stinger while varying attacker capabilities, traffic conditions, and the accuracy of the misbehavior detection mechanisms. We identify several interesting trade-offs: Stinger is significantly faster than LEAVE at removing errant devices, but LEAVE excludes fewer good devices when the attacker has compromised several devices simultaneously; LEAVE is better at handling false positives, but Stinger scales better when the traffic density increases. As a result, we conclude by outlining a combined protocol that balances the security and performance characteristics of both strategies. Tyler Moore 0001, Maxim Raya, Jolyon Clulow, Panagiotis Papadimitratos, Ross J. Anderson, Jean-Pierre Hubaux |
SECON | 1 |
| 2007 | Information Security Economics - and Beyond
Ross J. Anderson, Tyler Moore 0001 |
CRYPTO | 2 |
| 2007 | Secure Path-Key Revocation for Symmetric Key Pre-distribution Schemes in Sensor Networks
Tyler Moore 0001, Jolyon Clulow |
SEC | 1 |
| 2006 | GSM Cell Site Forensics
Christopher Swenson, Tyler Moore 0001, Sujeet Shenoi |
IFIP Int. Conf. Digital Forensics | 2 |
| 2005 | Using Signaling Information in Telecom Network Forensics
Tyler Moore 0001, Anthony Meehan 0002, Gavin Wylie Manes, Sujeet Shenoi |
IFIP Int. Conf. Digital Forensics | 1 |