VLDB 2026 Research / reviewers in the wild / expert
Gencer Erdogan
dblp:02/7950
· DBLP profile ↗
18ranked-venue papers
10as first author
7since 2021 · last 2025
0000-0001-9407-5748ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 11 · 4 first-author · 5 since 2021Software engineering, systems software and programming languages · 6 · 6 first-author · 2 since 2021Theory of computation · 1Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Systematisation of Security Risk Knowledge Across Different Domains: A Case Study of Security Implications of Medical Devices
Laura Carmichael, Stephen Taylor 0002, Samuel M. Senior, Mike Surridge, Gencer Erdogan, Simeon Tverdal |
ICISSP (1) | 5 |
| 2023 | Cybersecurity Awareness and Capacities of SMEsabstractSmall and Medium Enterprises (SMEs) are increasingly exposed to cyber risks. Some of the main reasons include budget constraints, the employees’ lack of cybersecurity awareness, cross-sectoral cyber risks, lack of security practices at organizational level, and so on. To equip SMEs with appropriate tools and guidelines that help mitigate their exposure to cyber risk, we must better understand the SMEs’ context and their needs. Thus, the contribution of this paper is a survey based on responses collected from 141 SMEs based in the UK, where the objective is to obtain information to better understand their level of cybersecurity awareness and practices they apply to protect against cyber risks. Our results indicate that although SMEs do apply some basic cybersecurity measures to mitigate cyber risks, there is a general lack of cybersecurity awareness and lack of processes and tools to improve cybersecurity practices. Our findings provide to the cybersecurity community a better understanding of the SME context in terms of cybersecurity awareness and cybersecurity practices, and may be used as a foundation to further develop appropriate tools and processes to strengthen the cybersecurity of SMEs. Gencer Erdogan, Ragnhild Halvorsrud, Costas Boletsis, Simeon Tverdal, John Brian Pickering |
ICISSP | 1 |
| 2023 | Privacy-Aware IoT: State-of-the-Art and ChallengesabstractThe consumer IoT is now prevalent and creates an enormous amount of fine-grained, detailed information about consumers’ everyday actions, personalities, and preferences. Such detailed information brings new and unique privacy challenges. The consumers are not aware of devices that surround them. There is a lack of transparency and absence of support for consumers to control the collection and processing of their personal and sensitive data. This paper reports on a review of state-of-the-art on privacy protection in IoT, with respect to privacy enhancing technologies (PETs) and GDPR-specific privacy principles. Drawing on a thorough analysis of 36 full papers, we identify key privacy challenges in IoT that need to be addressed to provide consumers with transparency and control over their personal data. The privacy challenges we have identified are (1) the lack of technical expertise in privacy notice comprehension, (2) the lack of transparency and control of personal data, and (3) the lack of personalized privacy recommendations. Shukun Tokas, Gencer Erdogan, Ketil Stølen |
ICISSP | 2 |
| 2023 | A Systematic Review of Secure IoT Data SharingabstractThe Internet of Things (IoT) is more and more omnipresent. The greater values of the IoT can be realized by enabling data sharing between different stakeholders. However, one of the biggest challenges is ensuring security and enabling trust for IoT data sharing. In this paper, we identify state-of-the-art (SotA) approaches and techniques for secure IoT data sharing. We present high-level results emphasizing the SotA trend and revealing the most addressed domains, as well as more in-depth details such as procedures and methods used to preserve security in the data sharing environment. The blockchain technology, smart contracts, and InterPlanetary File System (IPFS) are among the most widely used approaches. As today’s solutions explore a more decentralized approach to data sharing, there are several aspects to consider. Based on the findings, we have identified potential research directions for future work, including the differences between public and private blockchains, the combinat (More) Phu Nguyen, Gencer Erdogan |
ICISSP | 3 |
| 2022 | Needs and Challenges Concerning Cyber-risk Assessment in the Cyber-physical Smart GridabstractCyber-risk assessment methods are used by energy companies to manage security risks in smart grids. However, current standards, methods and tools do not adequately provide the support needed in practice and the industry is struggling to adopt and carry out cyber-risk assessments. The contribution of this paper is twofold. First, we interview six companies from the energy sector to better understand their needs and challenges. Based on the interviews, we identify seven success criteria cyber-risk assessment methods for the energy sector need to fulfill to provide adequate support. Second, we present the methods CORAS, VAF, TM-STRIDE, and DA-SAN and evaluate the extent to which they fulfill the identified success criteria. Based on the evaluation, we provide lessons learned in terms of gaps that need to be addressed in general to improve cyber-risk assessment in the context of smart grids. Our results indicate the need for the following improvements: 1) ease of use and comprehensible m ethods, 2) support to determine whether a method is a good match for a given context, 3) adequate preparation to conduct cyber-risk assessment, 4) manage complexity, 5) adequate support for risk estimation, 6) support for trustworthiness and uncertainty handling, and 7) support for maintaining risk assessments. Gencer Erdogan, Inger Anne Tøndel, Shukun Tokas, Michele Garau, Martin Gilje Jaatun |
ICSOFT | 1 |
| 2021 | A Systematic Mapping Study on Approaches for Al-Supported Security Risk AssessmentabstractEffective assessment of cyber risks in the increasingly dynamic threat landscape must be supported by artificial intelligence techniques due to their ability to dynamically scale and adapt. This article provides the state of the art of AI-supported security risk assessment approaches in terms of a systematic mapping study. The overall goal is to obtain an overview of security risk assessment approaches that use AI techniques to identify, estimate, and/or evaluate cyber risks. We carried out the systematic mapping study following standard processes and identified in total 33 relevant primary studies that we included in our mapping study. The results of our study show that on average, the number of papers about AI-supported security risk assessment has been increasing since 2010 with the growth rate of 133% between 2010 and 2020. The risk assessment approaches reported have mainly been used to assess cyber risks related to intrusion detection, malware detection, and industrial systems. The approaches focus mostly on identifying and/or estimating security risks, and primarily make use of Bayesian networks and neural networks as supporting AI methods/techniques. Gencer Erdogan, Enrique Garcia-Ceja, Åsmund Hugo, Phu Hong Nguyen, Sagar Sen |
COMPSAC | 1 |
| 2021 | Developing Cyber-risk Centric Courses and Training Material for Cyber Ranges: A Systematic ApproachabstractThe use of cyber ranges to train and develop cybersecurity skills and awareness is attracting more attention, both in public and private organizations. However, cyber ranges typically focus mainly on hands-on exercises and do not consider aspects such as courses, learning goals and learning objectives, specific skills to train and develop, etc. We address this gap by proposing a method for developing courses and training material based on identified roles and skills to be trained in cyber ranges. Our method has been used by people with different background grouped in academia, critical infrastructure, research, and service providers who have developed 22 courses including hands-on exercises. The developed courses have been tried out in pilot studies by SMEs. Our assessment shows that the method is feasible and that it considers learning and educational aspects by facilitating the development of courses and training material for specific cybersecurity roles and skills. Gencer Erdogan, Antonio Álvarez Romero, Niccolò Zazzeri, Anze Zitnik, Mariano Basile, Giorgio Aprile, Mafalda Osório, Claudia Pani, Ioannis Kechaoglou |
ICISSP | 1 |
| 2020 | Tool Support for Risk-driven Planning of Trustworthy Smart IoT Systems within DevOpsabstractThe Internet of Things is rising in popularity across many different domains, such as build automation, healthcare, electrical smart metering and physical security. Many prominent IT experts and companies like Gartner expect there to be a continued rise in the amount of IoT endpoints, with an estimated 5.8 million endpoints in 2020. With the rapid growth of the devices, the physical nature of these devices, and the amount of data collected, there will be a greater need for trustworthiness. These devices often gather personal data and as the devices have relatively less computational power than other devices, security and privacy risks are greater. With the IoT systems often operating in highly dynamic environments, the development of these systems should often be done in an iterative manner. DevOps is an increasingly popular agile practice which combines the development and operations of systems to provide continuous delivery. This is well suited for the development of IoT systems. However, there is currently a lack of support for risk driven planning of trustworthy smart IoT systems within DevOps. This thesis investigates currently available tools and methods for the planning of trustworthy smart IoT systems within DevOps. We also propose a tool-supported method with the purpose of assisting developers in the planning phase of DevOps with identifying security and privacy risks, and executing risk assessment algorithms. Furthermore we facilitate automatic real-time security and privacy risk assessment through our custom made API. Moreover we conduct a case study where we apply both our method and tool in a real-life smart home case. Based on our initial result we argue that our tool-supported method: is easy to use and understandable for developers, supports the planning of trustworthy smart IoT systems in the DevOps practice in terms of security and privacy risk assessment and it is appropriate for use in the DevOps practice in terms of adapting to new plans and flexible in response to changes in the system. Andreas Thompson, Gencer Erdogan |
ICISSP | 2 |
| 2020 | An Approach to Train and Evaluate the Cybersecurity Skills of Participants in Cyber Ranges based on Cyber-Risk Models
Gencer Erdogan, Åsmund Hugo, Antonio Álvarez Romero, Dario Varano, Niccolò Zazzeri, Anze Zitnik |
ICSOFT | 1 |
| 2019 | A Feasibility Study of a Method for Identification and Modelling of Cybersecurity Risks in the Context of Smart Power GridsabstractPower grids are undergoing a digital transformation are therefore becoming increasingly complex. As a result of this they are also becoming vulnerable in new ways. With this development come also numerous risks. Cybersecurity is therefore becoming crucial for ensuring resilience of this infrastructure which is critical to safety of humans and societies. Risk analysis of cybersecurity in the context of smart power grids is, however, particularly demanding due to its interdisciplinary nature, including domains such as digital security, the energy domain, power networks, the numerous control systems involved, and the human in the loop. This poses special requirements to cybersecurity risk identification within smart power grids, which challenge the existing state-of-the-art. This paper proposes a customized four-step approach to identification and modelling of cybersecurity risks in the context of smart power grids. The aim is that the risk model can be presented to decision makers in a suitable interface, thereby serving as a useful support for planning, design and operation of smart power grids. The approach applied in this study is based on parts of the CORAS method for model-based risk analysis. The paper also reports on results and experiences from applying the approach in a realistic industrial case with a distribution system operator (DSO) responsible for hosting a pilot installation of the self-healing functionality within a power distribution grid. The evaluation indicates that the approach can be applied in a realistic setting to identify cybersecurity risks. The experiences from the case study moreover show that the presented approach is, to a large degree, well suited for its intended purpose, but it also points to areas in need for improvement and further evaluation. Aida Omerovic, Hanne Vefsnmo, Gencer Erdogan, Oddbjørn Gjerde, Eivind Gramme, Stig Simonsen |
COMPLEXIS | 3 |
| 2019 | A Systematic Mapping Study of Deployment and Orchestration Approaches for IoTabstractInternational audience Phu Hong Nguyen, Nicolas Ferry 0001, Gencer Erdogan, Stéphane Lavirotte, Jean-Yves Tigli, Arnor Solberg |
IoTBDS | 3 |
| 2018 | An Empirical Study on the Comprehensibility of Graphical Security Risk Models Based on Sequence Diagrams
Vetle Volden-Freberg, Gencer Erdogan |
CRiSIS | 2 |
| 2017 | A Method for Developing Qualitative Security Risk Assessment Algorithms
Gencer Erdogan, Atle Refsdal |
CRiSIS | 1 |
| 2017 | A Method for Developing Algorithms for Assessing Cyber-Risk CostabstractWe present a method for developing executable algorithms for quantitative cyber-risk assessment. Exploiting techniques from security risk modeling and actuarial approaches, the method pragmatically combines use of available empirical data and expert judgments. The input to the algorithms are indicators providing information about the target of analysis, such as suspicious events observed in the network. Automated execution of the algorithms facilitates continuous assessment. Gencer Erdogan, Alejandra Gonzalez, Atle Refsdal, Fredrik Seehusen |
QRS | 1 |
| 2016 | Evaluation of the CORAL Approach for Risk-driven Security Testing based on an Industrial Case Study
Gencer Erdogan, Ketil Stølen, Jan Øyvind Aagedal |
ICISSP | 1 |
| 2014 | Approaches for the combined use of risk analysis and testing: a systematic literature review
Gencer Erdogan, Ragnhild Kobro Runde, Fredrik Seehusen, Ketil Stølen |
Int. J. Softw. Tools Technol. Transf. | 1 |
| 2010 | Security Modeling and Tool Support AdvantagesabstractSecurity modeling is an important part of software security, especially when it comes to making security knowledge more easily accessible. The purpose of this paper is to give an overview of some of the current approaches to graphical security modeling and present an initial study related to benefits of tool support.Our working hypothesis is that specialized security modeling tools will substantially outperform more general, prevailing tools, and we have sought indications of evidence for this claim. The study consisted of the following steps; (1) Investigate state-of-the-art security modeling formalisms and tools, (2) Select a security modeling formalism for further analysis and implement dedicated tool support for it, (3) Perform testing related to usability and performance aspects, comparing the tool to a general purpose drawing/modeling tool, and (4) Compare and analyze the results. The study included ten test subjects with a similar background and education, and we got clear indications that our hypothesis is valid. Egil Trygve Baadshaug, Gencer Erdogan, Per Håkon Meland |
ARES | 2 |
| 2010 | Security Testing in Agile Web Application Development - A Case Study Using the EAST Methodology
Gencer Erdogan, Per Håkon Meland, Derek Mathieson |
XP | 1 |