VLDB 2026 Research / reviewers in the wild / expert
Zdenek Martinasek
dblp:136/6617
· DBLP profile ↗
11ranked-venue papers
2as first author
5since 2021 · last 2026
0000-0002-6504-5619ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 11 · 2 first-author · 5 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Comparative analysis of OSINT tools, techniques, and legal aspectsabstractOpen Source Intelligence (OSINT) has emerged as a crucial practice in the digital era, driven by the rapid growth of information available on the internet and its expanding applications across multiple sectors. This study examines the role of OSINT as a vital tool in domains such as the indexed internet, social networks, the darknet, archives, and network devices. We present a comparative analysis over 140 tools, services, and databases usable for OSINT. The analysis reveals significant diversity in functionality, licensing, and accessibility, with no single solution capable of meeting all intelligence needs. The findings emphasize the necessity of combining multiple tools with manual methods to acquire accurate and reliable intelligence, while also highlighting persistent challenges, including limited integrations, licensing constraints, and the volatility of online sources. Beyond technical and methodological aspects, OSINT practice is shaped by complex legal and ethical considerations, as the public availability of data does not guarantee lawful use. This study provides a legal analysis of the General Data Protection Regulation (GDPR) and the Budapest Convention in relation to OSINT investigations. As compliance remains context-specific, the study underscores that the future of OSINT depends not only on technological advancement, but also on strong legal and ethical responsibility to mitigate risks of liability and reputational harm. Willi Lazarov, Vojtech Moravec, Pavel Loutocký, Jakub Vostoupal, Zdenek Martinasek |
Comput. Secur. | 5 |
| 2025 | Penterep: Comprehensive penetration testing with adaptable interactive checklistsabstractIn the contemporary landscape of cybersecurity, the importance of effective penetration testing is underscored by NIS2, emphasizing the need to assess and demonstrate cyber resilience. This paper introduces an innovative approach to penetration testing that employs interactive checklists, supporting both manual and automated tests, as demonstrated within the Penterep environment. These checklists, functioning as a quantifiable measure of test completeness, guide pentesters through methodological testing, addressing the inherent challenges of the security testing domain. While some may perceive a limitation in the dependency on predefined checklists, the results from a presented case study underscore the criticality of methodological testing. The study reveals that relying solely on fully automated tools would be inadequate to identify all vulnerabilities and flaws without the inclusion of manual tests. Our innovative approach complements established methodologies, such as PTES, OWASP, and NIST, providing crucial support to penetration testers and ensuring a comprehensive testing process. Implemented within the Penterep environment, our approach is designed with deployment flexibility (both on-premises and cloud-based), setting it apart through an overview comparison with existing tools aligned with state-of-the-art penetration testing approaches. This flexible and scalable approach effectively bridges the gap between manual and automated testing, meeting the increasing demands for effectiveness and adaptability in penetration testing. • An innovative approach to penetration testing using adaptable interactive checklists. • Automation of testing to increase its effectiveness and reduce repetitive tasks. • Penetration testing environment design and implementation using high customizability. • Showcase using the provided case study, concluded with lessons learned. Willi Lazarov, Pavel Seda, Zdenek Martinasek, Roman Kummel |
Comput. Secur. | 3 |
| 2024 | Event-based Data Collection and Analysis in the Cyber Range EnvironmentabstractThe need to educate users on cybersecurity to some extent is critical due to the ever-increasing cyber threats. A number of web presentations, books, and other study materials can be used for this purpose. In contrast to passive learning methods, hands-on training offers a deeper perspective but poses considerable technical challenges to its implementation, which can be resolved using cyber range platforms. However, in order to thoroughly evaluate the training and provide sufficient feedback, data must be collected and analyzed. Our paper addresses this problem by developing an event-based approach for data collection and analysis. The use of events allows us to keep a history of an event and reconstruct it retrospectively, especially for further analysis and evaluation. We validated the implemented approach in a cyber range environment, in which we developed an interactive interface to visualize the analyzed data. Willi Lazarov, Samuel Janek, Zdenek Martinasek, Radek Fujdiak |
ARES | 3 |
| 2023 | Interactive Environment for Effective Cybersecurity Teaching and LearningabstractCybersecurity affects all users to some extent, and it is essential to raise awareness about potential cybersecurity risks and improve practical skills from an early stage of their education. This paper addresses these aspects and discusses the research, design, and implementation of a platform for effective cybersecurity teaching and learning. Our main contribution is the creation of an interactive environment with the easy-to-use execution and management of educational and training scenarios. Our solution is tailored for multi-level education, as well as small to medium-sized institutions, and we have validated its effectiveness through several test sessions conducted with university and high school students. In addition, the paper presents selected preliminary results from the testing performed and an overall evaluation of the environment. Willi Lazarov, Tomas Stodulka, Tiina Schafeitel-Tähtinen, Marko Helenius, Zdenek Martinasek |
ARES | 5 |
| 2022 | On Secure and Side-Channel Resistant Hardware Implementations of Post-Quantum CryptographyabstractCurrently, many post-quantum cryptography schemes have been implemented on various hardware platforms in order to provide efficient solutions in cybersecurity services. As researchers and hardware developers focus primarily on designs providing small latency and requiring fewer hardware resources, their implementations could seldom omit protection techniques against various physical attacks. This paper studies potential attacks on the cryptography implementations that run on Field-Programmable Gate Array (FPGA) platforms. We mainly analyze how Post-Quantum Cryptography (PQC) implementations could be vulnerable on various platforms. Further, we aim at the FPGA-based implementations of National Institute of Standards and Technology (NIST)’s PQC competition finalists. Our study should present to developers the current overview of attacks and countermeasures that can be implemented on specific PQC schemes on FPGA platforms. Moreover, we present novel implementation of one universal countermeasure component and reveal additional resources that are needed. Petr Jedlicka, Lukas Malina, Tomas Gerlich, Zdenek Martinasek, Jan Hajny, Petr Socha |
ARES | 4 |
| 2018 | Secure and efficient two-factor zero-knowledge authentication solution for access control systems
Lukas Malina, Petr Dzurenda, Jan Hajny, Zdenek Martinasek |
Comput. Secur. | 4 |
| 2017 | Robust profiled attacks: should the adversary trust the dataset?abstractSide‐channel attacks provide tools to analyse the degree of resilience of a cryptographic device against adversaries measuring leakages (e.g. power traces) on the target device executing cryptographic algorithms. In 2002, Chari et al . introduced template attacks (TA) as the strongest parametric profiled attacks in an information theoretic sense. Few years later, Schindler et al . proposed stochastic attacks (representing other parametric profiled attacks) as improved attacks (with respect to TA) when the adversary has information on the data‐dependent part of the leakage. Less than ten years later, the machine learning field provided non‐parametric profiled attacks especially useful in high dimensionality contexts. In this study, the authors provide new contexts in which profiled attacks based on machine learning outperform conventional parametric profiled attacks: when the set of leakages contains errors or distortions. More precisely, the authors found that (i) profiled attacks based on machine learning remain effective in a wide range of scenarios, and (ii) TA are more sensitive to distortions and errors in the profiling and attacking sets. Liran Lerman, Zdenek Martinasek, Olivier Markowitch |
IET Inf. Secur. | 2 |
| 2016 | Crucial pitfall of DPA Contest V4.2 implementationabstractAbstract Differential power analysis (DPA) is a powerful side‐channel key recovery attack that efficiently breaks cryptographic algorithm implementations. In order to prevent these types of attacks, hardware designers and software programmers make use of masking and hiding techniques. DPA contest is an international framework that allows researchers to compare their power analysis attacks under the same conditions. The latest version of DPA contest, denoted as V4.2, provides an improved implementation of the rotating S‐box masking scheme where low‐entropy boolean masking is combined with the shuffling technique to protect Advanced Encryption Standard implementation on a smart card. The improvements were designed based on the awareness of implementation lacks analyzed from attacks carried out during the previous DPA contest V4. Therefore, this new approach is devised to resist most of the proposed attacks to the original rotating S‐box masking implementation. In this paper, we investigate the security of this new implementation in practice. Our analysis, focused on exploiting the first‐order leakage, discovered important lacks. The main vulnerability observed is that an adversary can mount a standard DPA attack aimed at the S‐box output in order to recover the whole secret key even when a shuffling technique is used. We tested this observation on a public dataset and implemented a successful attack that revealed the secret key using only 35 power traces. Copyright © 2017 John Wiley & Sons, Ltd. Zdenek Martinasek, Félix Iglesias, Lukas Malina, Josef Martinasek |
Secur. Commun. Networks | 1 |
| 2013 | Optimization of Power Analysis Using Neural Network
Zdenek Martinasek, Jan Hajny, Lukas Malina |
CARDIS | 1 |
| 2013 | Privacy-preserving SVANETs - Privacy-preserving Simple Vehicular Ad-hoc Networks
Jan Hajny, Lukas Malina, Zdenek Martinasek, Vaclav Zeman |
SECRYPT | 3 |
| 2013 | Efficient Group Signatures with Verifier-local Revocation Employing a Natural Expiration
Lukas Malina, Jan Hajny, Zdenek Martinasek |
SECRYPT | 3 |