VLDB 2026 Research / reviewers in the wild / expert
Christopher Bellman
dblp:181/3038
· DBLP profile ↗
7ranked-venue papers
4as first author
2since 2021 · last 2023
0000-0003-1996-7943ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 5 · 2 first-author · 2 since 2021Artificial intelligence and machine learning · 1 · 1 first-authorSoftware engineering, systems software and programming languages · 1 · 1 first-authorDatabases, data management, data science and information retrieval · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2023 | Systematic analysis and comparison of security advice as datasets
Christopher Bellman, Paul C. van Oorschot |
Comput. Secur. | 1 |
| 2023 | Security Best Practices: A Critical Analysis Using IoT as a Case StudyabstractAcademic research has highlighted the failure of many Internet of Things (IoT) product manufacturers to follow accepted practices, while IoT security best practices have recently attracted considerable attention worldwide from industry and governments. Given current examples of security advice, confusion is evident from guidelines that conflate desired outcomes with security practices to achieve those outcomes. We explore a surprising lack of clarity, and void in the literature, on what (generically) best practice means, independent of identifying specific individual practices or highlighting failure to follow best practices. We consider categories of security advice, and analyze how they apply over the lifecycle of IoT devices. For concreteness in discussion, we use iterative inductive coding to code and systematically analyze a set of 1,013 IoT security best practices, recommendations, and guidelines collated from industrial, government, and academic sources. Among our findings, of all analyzed items, 68% fail to meet our definition of an (actionable) practice, and 73% of all actionable advice relates to the software development lifecycle phase, highlighting the critical position of manufacturers and developers. We hope that our work provides a basis for the community to better understand best practices, identify and reach consensus on specific practices, and find ways to motivate relevant stakeholders to follow them. David Barrera 0003, Christopher Bellman, Paul C. van Oorschot |
ACM Trans. Priv. Secur. | 2 |
| 2019 | Analysis, Implications, and Challenges of an Evolving Consumer IoT Security LandscapeabstractThe Internet of Things (IoT) is a rapidly growing subset of our modern computing architecture, and as such, provides significant new attack surface. The history of IoT has provided a substantial body of topics to look back on: IoT's evolution, products, and major security incidents including the largest botnet ever witnessed. Unique to IoT, its architecture, interaction design, and scale make its many issues distinct from those in the Internet of Computers (IoC). Its perceptions, understandings, and definitions have evolved over time, thus requiring an updated focus from the perspective of security and cyberphysical safety. We take a fresh look at challenges and opportunities in IoT security, the characteristics that uniquely distinguish it from the IoC, and identify security-related questions that they raise. Our aim is to provide an up-to-date view of the IoT security landscape and technical security issues to help guide both existing and especially new researchers looking for challenging open problems that remain largely unaddressed. Christopher Bellman, Paul C. van Oorschot |
PST | 1 |
| 2019 | Inside out - A study of users' perceptions of password memorability and recall
Ruba AlOmari, Miguel Vargas Martin, Shane MacDonald, Amit Maraj, Ramiro Liscano, Christopher Bellman |
J. Inf. Secur. Appl. | 6 |
| 2018 | Studying developer build issues and debugger usage via timeline analysis in visual studio IDEabstractEvery day, most software developers use development tools to write, build, and maintain their code. The most crucial of such tools is the integrated development environment (IDE), in which developers create and build code. Therefore, it is important to understand how developers perform their work and what impact each action has on their workflow to further enhance their productivity. In this work, we study the KaVE dataset of developer interactions within the Microsoft Visual Studio IDE and analyze a number of topics extracted from the data. First, we propose a method for developing what we call "timelines" that chronologically map an individual development session, and from this, we study build failures, code debugger usage, and we propose a metric for measuring developer throughput. We find that the timeline analysis may prove to be an invaluable tool for developer self-assessment and key to uncovering problem areas regarding build failures. Moreover, we find that developers spend a significant amount of time debugging their code, utilizing features such as breakpoints to resolve issues. Finally, we see that the developer metric can be used for self assessment, giving value to the amount of effort, put forth by a developer, in a given session. Christopher Bellman, Ahmad Seet, Olga Baysal |
MSR | 1 |
| 2017 | Use of Machine Learning for Detection of Unaware Facial Recognition Without Individual TrainingabstractEfforts in detecting unaware facial recognitions using consumer-grade brain-computer interfaces have been able to classify these recognitions with high accuracies using intra-participant datasets. Seeking a more generalized approach to classifying facial recognition, we propose an interparticipant dataset comprised of pre-recorded data where new data can be immediately tested. An experiment was conducted where participants viewed images of faces in a two-day experiment. Participants learned a number of faces for unaware recognition during the following day’s session. Three recognition classes were recorded: no recognition, unaware recognition, and aware recognition. Using data features containing the highest levels of variance, we find that an interparticipant dataset can be used to train a classifier and achieve classification F-scores of 0.71. This suggests that detecting recognition can be achieved through pre-constructed datasets and used more readily in practical applications. Christopher Bellman, Miguel Vargas Martin |
ICMLA | 1 |
| 2017 | What Your Brain Says About Your Password: Using Brain-Computer Interfaces to Predict Password MemorabilityabstractRecent advances in brain-computer interfaces (BCI) have enabled them as affordable consumer-grade devices for nonmedical purposes such as academic research, marketing, and entertainment. We report on the possibility of using BCIs to classify passwords into two classes—one class may be deemed as memorable and the other one as non-memorable—based on electroencephalogram (EEG) potentials collected by the BCI upon presenting the passwords to human participants. The memorable set consists of the most commonly used passwords, also known as "worst passwords lists", while the non-memorable set consists of randomly generated strings of characters, symbols, and numbers. When classifying passwords as memorable vs. nonmemorable, a classification accuracy of 76.5% was achieved. We found a positive correlation between password EEG features and password recall. We also report on users' choice of passwords, where 74% of participants were found to inadvertently choose the password with higher elicited voltage, when presented with two passwords to choose from. Ruba AlOmari, Miguel Vargas Martin, Shane MacDonald, Christopher Bellman, Ramiro Liscano, Amit Maraj |
PST | 4 |