VLDB 2026 Research / reviewers in the wild / expert
Yulia Cherdantseva
dblp:118/7522
· DBLP profile ↗
8ranked-venue papers
3as first author
4since 2021 · last 2026
0000-0002-3527-1121ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 8 · 3 first-author · 4 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Beyond the automation gap: A survey of continuous audit for IoT securityabstractDespite decades of research into automated compliance, real-world adoption remains surprisingly low. This implementation gap is particularly significant for auditing Internet of Things (IoT) environments, where the sheer volume of connected devices makes manual security auditing challenging. This adoption gap could cause severe business and governance risks, such as operational disruptions and massive regulatory penalties. By following PRISMA methodology, our review investigates why computer-assisted auditing technologies fail to gain traction in practice. We trace the evolution of compliance automation and reveal a fundamental disconnect: the adoption gap emerges not from technological inadequacy but from interconnected research tensions that neglected the traceability and auditability of the audit itself. Our analysis suggests that closing the adoption gap requires research realignment in a human-centered auditing framework that could be supported by technologies and identifies where each could augment human auditors. Rather than pursuing ever-more sophisticated automation, we argue that effective auditing tools must augment human expertise through responsible human–computer interaction. The review synthesizes diverse approaches across process mining, rule-based matching, machine learning, and language models, consistently finding that technical excellence alone cannot bridge the implementation gap. We conclude by presenting a research roadmap that guides security researchers toward building practically viable solutions that leverage strong technological foundations while addressing the urgent, real-world needs of auditors. Obrina Candra Briliyant, Amir Javed, Yulia Cherdantseva |
Comput. Secur. | 3 |
| 2023 | A systematic method for measuring the performance of a cyber security operations centre analystabstractAnalysts who work in a Security Operations Centre (SOC) play an essential role in supporting businesses to protect their computer networks against cyber attacks. To manage analysts efficiently and effectively, SOC managers and stakeholders use Key Performance Indicators (KPIs) to evaluate their performance. However, existing literature suggests a lack of a systematic approach for assessing analysts’ performance. Even though cyber security researchers advocate for research into this area, little effort has been made by researchers to address this gap. Drawing on the results of a Delphi panel with industry experts and the principles of the Analytic Hierarchy Process (AHP), this paper interrogates the problem and proposes a systematic weighted approach for measuring the performance of an analyst in a SOC. The proposed method, referred to as a SOC Analyst Assessment Method (SOC-AAM), was evaluated in two SOCs as a part of an experimental case study. The results of the empirical evaluation show that the SOC-AAM enables SOC managers and stakeholders to quantify and assess analysts’ performance in a systematic manner. The SOC-AAM also provides a novel guideline for assessing the quality of incident analysis and the quality of incident reports. This study will be of interest to practitioners and cyber security researchers seeking to understand the operations of a SOC analyst. Enoch Agyepong, Yulia Cherdantseva, Philipp Reinecke, Pete Burnap |
Comput. Secur. | 2 |
| 2023 | Operations-informed incident response playbooksabstractCyber security incident response playbooks are critical for establishing an effective incident response capability within organizations. We identify a significant conceptual gap in the current research and practice of cyber security playbook design: the lack of ability to communicate the operational impact of an incident and of incident response on an organization. In this paper, we present a mechanism to address the gap by introducing the operational context into an incident response playbook. This conceptual contribution calls for a shift from playbooks that consist only of process models to playbooks that consist of process models closely linked with a model of operations. We describe a novel approach to embed a model of operations into the incident response playbook and link it with the playbook's incident response activities. This allows to reflect, in an accurate and systematic way, the interdependencies and mutual influences of incident response activities on operations and vice versa. The approach includes the use of a new metric for evaluating the change in operations in coordination with critical thresholds, supporting decision-making during cyber security incident response. We demonstrate the application of the proposed approach to playbook design in the context of a ransomware attack incident response, using a newly developed open-source tool. Avi Shaked, Yulia Cherdantseva, Pete Burnap, Peter Maynard 0001 |
Comput. Secur. | 2 |
| 2022 | Model-Based Incident Response PlaybooksabstractInevitably, all systems are vulnerable, and none are impervious to attack. Incident response is an important element in maintaining the cyber security posture of organizations. Incident response practitioners often rely on process descriptions in the form of playbooks as recipes for handling incidents as they occur. However, current practices and mechanisms do not offer a disciplined approach to designing and representing playbooks, risking the effectiveness of the playbooks in directing and coordinating incident response. In this paper, we propose a formal, model-based design approach to designing cyber security incident response playbooks. We provide a tool prototype for the approach, developed using the Eclipse framework, and demonstrate how it can accommodate playbooks. Finally, we discuss how the approach can improve aspects of incident response throughout its lifecycle, by correctly prescribing and coordinating response actions as well as supporting organizational learning. Avi Shaked, Yulia Cherdantseva, Pete Burnap |
ARES | 2 |
| 2016 | A review of cyber security risk assessment methods for SCADA systemsabstractThis paper reviews the state of the art in cyber security risk assessment of Supervisory Control and Data Acquisition (SCADA) systems. We select and in-detail examine twenty-four risk assessment methods developed for or applied in the context of a SCADA system. We describe the essence of the methods and then analyse them in terms of aim; application domain; the stages of risk management addressed; key risk management concepts covered; impact measurement; sources of probabilistic data; evaluation and tool support. Based on the analysis, we suggest an intuitive scheme for the categorisation of cyber security risk assessment methods for SCADA systems. We also outline five research challenges facing the domain and point out the approaches that might be taken. Yulia Cherdantseva, Pete Burnap, Andrew Blyth, Peter Eden, Hugh Soulsby, Kristan Stoddart |
Comput. Secur. | 1 |
| 2016 | A multifaceted evaluation of the reference model of information assurance & security
Yulia Cherdantseva, Jeremy Hilton, Omer F. Rana, Wendy Ivins |
Comput. Secur. | 1 |
| 2015 | A Cyber Forensic Taxonomy for SCADA Systems in Critical Infrastructure
Peter Eden, Andrew Blyth, Pete Burnap, Yulia Cherdantseva, Hugh Soulsby, Kristan Stoddart |
CRITIS | 4 |
| 2013 | A Reference Model of Information Assurance & SecurityabstractInformation Assurance & Security (IAS) is a dynamic domain which changes continuously in response to the evolution of society, business needs and technology. This paper proposes a Reference Model of Information Assurance & Security (RMIAS), which endeavours to address the recent trends in the IAS evolution, namely diversification and deperimetrisation. The model incorporates four dimensions: Information System Security Life Cycle, Information Taxonomy, Security Goals and Security Countermeasures. In addition to the descriptive knowledge, the RMIAS embeds the methodological knowledge. A case study demonstrate show the RMIAS assists with the development and revision of an Information Security Policy Document. Yulia Cherdantseva, Jeremy Hilton |
ARES | 1 |