VLDB 2026 Research / reviewers in the wild / expert
Martin Macák
dblp:242/2076
· DBLP profile ↗
16ranked-venue papers
11as first author
10since 2021 · last 2026
0000-0001-9655-9228ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Artificial intelligence and machine learning · 6 · 4 first-author · 3 since 2021Security and privacy · 6 · 5 first-author · 4 since 2021Databases, data management, data science and information retrieval · 5 · 3 first-author · 3 since 2021Software engineering, systems software and programming languages · 4 · 2 first-author · 2 since 2021Applied, interdisciplinary, general and emerging computing · 4 · 2 first-author · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Process-driven visual analysis of cybersecurity capture the flag exercisesabstractHands-on training sessions become a standard way to develop and increase knowledge in cybersecurity. As practical cybersecurity exercises are strongly process-oriented with knowledge-intensive processes, process mining techniques and models can help enhance learning analytics tools. The design of our open-source analytical dashboard is backed by guidelines for visualizing multivariate networks complemented with temporal views and clustering. The design aligns with the requirements for post-training analysis of a special subset of cybersecurity exercises — supervised Capture the Flag games. Usability is demonstrated in a case study using trainees’ engagement measurement to reveal potential flaws in training design or organization. Radek Oslejsek, Radoslav Chudovský, Martin Macák |
Inf. Syst. | 3 |
| 2023 | CopAS: A Big Data Forensic Analytics System
Martin Macák, Tomás Rebok, Matus Stovcik, Mouzhi Ge, Bruno Rossi 0001, Barbora Buhnova |
IoTBDS | 1 |
| 2023 | Detecting Masquerading Traitors from Process Visualization of Computer UsageabstractInsider attacks in organizations are currently one of the most crucial cybersecurity challenges. Traitors are one of the most dangerous types of insider attackers. They are difficult to detect because they know the organization, processes, defense mechanisms, and employees. Besides abusing their rights and accesses, they can use their co-workers’ rights and accesses. They can hide their activities to perform attacks inconspicuously. The current masquerader detection techniques usually rely on the fact that the masquerader is an outsider, making them unable to detect attacks from the traitor. To detect these insider attackers, which we call masquerading traitors, we propose the human-as-solution approach and engage the employees in deciding whether the usage of their rights and accesses is suspicious and, therefore, might be performed by a masquerading traitor. Martin Macák, Radek Oslejsek, Barbora Buhnova |
TrustCom | 1 |
| 2023 | Addressing insider attacks via forensic-ready risk managementabstractCyberattacks perpetrated by insiders are difficult to prevent using traditional security approaches. Often, such attackers misuse legitimate access to the system to conduct an attack, or an external attacker manipulates or masquerades as an insider to gain access, bypassing the security controls. A possible solution to this problem are forensic-ready software systems that support the eventual forensic investigation. For example, assuring that appropriate evidence of an attack would be generated and assessable if needed. While not primarily aimed at prevention, the controls of forensic-ready systems can be used to ensure reliable post-incident investigation in the case of an insider attack. Currently, however, there is a gap in adequate methods for identifying requirements and assessment of such systems. Therefore, we propose FR-ISSRM, a risk management approach to derive the forensic readiness requirements addressing insider attacks. The requirements, once implemented, assist in the reliable uncovering culprit, root cause, damage of the attack, and overall improvement of security posture. The approach is then demonstrated in three cases covering typical insider attacks. Lukas Daubner, Martin Macák, Raimundas Matulevicius, Barbora Buhnova, Sofija Maksovic, Tomás Pitner |
J. Inf. Secur. Appl. | 2 |
| 2022 | Scenarios for Process-Aware Insider Attack Detection in ManufacturingabstractManufacturing production heavily depends on the processes that need to be followed during manufacturing. As there might be many reasons behind possible deviations from these processes, the deviations can also cover ongoing insider attacks, e.g., intended to perform sabotage or espionage on these infrastructures. Insider attacks can cause tremendous damage to a manufacturing company because an insider knows how to act inconspicuously, making insider attacks very hard to detect. In this paper, we examine the potential of process-mining methods for insider-attack detection in the context of manufacturing, which is a new and promising application context for process-aware methods. To this end, we present five manufacturing-related scenarios of insider threats identified in cooperation with a manufacturing company, where the process mining could be most helpful in the detection of their respective attack events. We describe these scenarios and demonstrate the utilization of process mining in this context, creating ground for further future research. Martin Macák, Radek Vaclavek, Dasa Kusniráková, Raimundas Matulevicius, Barbora Buhnova |
ARES | 1 |
| 2022 | Evaluating Code Improvements in Software Quality Course ProjectsabstractSoftware quality sits at the core of software engineering as a discipline. Yet, although each university software-engineering and the software-development course covers software quality to some extent, practitioners still lament on graduates’ readiness for practise for this very reason—poor quality of their code. As a result, we have engaged university industrial partners in designing a master-degree Software Quality course that puts the key software quality topics in one place. Stanislav Chren, Martin Macák, Bruno Rossi 0001, Barbora Buhnova |
EASE | 2 |
| 2022 | Process Mining Analysis of Puzzle-Based Cybersecurity TrainingabstractThe hands-on cybersecurity training quality is crucial to mitigate cyber threats and attacks effectively. However, practical cybersecurity training is strongly process-oriented, making the post-training analysis very difficult. This paper presents process-mining methods applied to the learning analytics workflow. We introduce a unified approach to reconstructing behavioral graphs from sparse event logs of cyber ranges. Furthermore, we discuss significant data features that affect their practical usability for educational process mining. Based on that, methods of dealing with the complexity of process graphs are presented, taking advantage of the puzzle-based gamification of in-class training sessions. Martin Macák, Radek Oslejsek, Barbora Buhnova |
ITiCSE (1) | 1 |
| 2021 | Game Achievement Analysis: Process Mining Approach
Martin Macák, Lukas Daubner, Julia Jamnicka, Barbora Buhnova |
ADMA | 1 |
| 2021 | Cybersecurity Analysis via Process Mining: A Systematic Literature Review
Martin Macák, Lukas Daubner, Mohammadreza Fani Sani, Barbora Buhnova |
ADMA | 1 |
| 2021 | Identification of Unintentional Perpetrator Attack Vectors using Simulation Game: A Case StudyabstractIn our digital era, insider attacks are among the serious underresearched areas of the cybersecurity landscape.A significant type of insider attack is facilitated by employees without malicious intent.They are called unintentional perpetrators.We proposed mitigating these threats using a simulationgame platform to detect the potential attack vectors.This paper introduces and implements a scenario that demonstrates the usability of this approach in a case study.This work also helps to understand players' behavior when they are not told upfront that they will be a target of social engineering attacks.Furthermore, we provide relevant acquired observations for future research. Martin Macák, Stefan Bojnak, Barbora Buhnova |
FedCSIS | 1 |
| 2020 | Towards verifiable evidence generation in forensic-ready systemsabstractWith the increasing threat of cybercrime, there is also an increasing need for the forensic investigation of those crimes. However, the topic of systematic preparation on the possible forensic investigation during the software development, called forensic readiness, has only been explored since recently. Thus, there are still many challenges and open issues. One of the obstacles is ensuring the correct implementation. Moreover, the growing volume and variety of digital evidence produced by the systems have to be put into consideration. It is especially important in the critical information infrastructure domain where potential cyberattacks could impact the safety of people. In this paper, we present research towards verification of forensic readiness in software development, with a focus on digital evidence they produce, to assist the advancement of this research domain. Furthermore, we formulate a process that serves a template for designing, developing, and refining a verification method for forensic-ready software systems. Lukas Daubner, Martin Macák, Barbora Buhnova, Tomás Pitner |
IEEE BigData | 2 |
| 2020 | How well a multi-model database performs against its single-model variants: Benchmarking OrientDB with Neo4j and MongoDBabstractDigitalization is currently the key factor for progress, with a rising need for storing, collecting, and processing large amounts of data. In this context, NoSQL databases have become a popular storage solution, each specialized on a specific type of data. Next to that, the multi-model approach is designed to combine benefits from different types of databases, supporting several models for data. Despite its versatility, a multi-model database might not always be the best option, due to the risk of worse performance comparing to the single-model variants. It is hence crucial for software engineers to have access to benchmarks comparing the performance of multi-model and single-model variants. Moreover, in the current Big Data era, it is important to have cluster infrastructure considered within the benchmarks. In this paper, we aim to examine how the multi-model approach performs compared to its single-model variants. To this end, we compare the OrientDB multi-model database with the Neo4j graph database and the MongoDB document store. We do so in the cluster setup, to enhance state of the art in database benchmarks, which is not yet giving much insight into cluster-operating database performance. Martin Macák, Matus Stovcik, Barbora Buhnova, Michal Merjavy |
FedCSIS | 1 |
| 2020 | Big Data Processing Tools Navigation DiagramabstractBig Data processing has become crucial in many domains because the amount of the produced data has enormously increased almost everywhere. The effective selection of the right Big Data processing tool is hard due to the high number and large variety of the available state-of-the-art tools. Many research results agree that there is no one best Big Data solution for all needs and requirements. It is therefore essential to be able to navigate more efficiently in the world of Big Data processing tools. In this paper, we present a map of current Big Data processing tools, recommended according to their capabilities and advantageous properties identified in previously published academic benchmarks. This map—as a navigation diagram—is aimed at helping researchers and practitioners to filter a large amount of available Big Data processing tools according to the requirements and properties of their tasks. Additionally, we provide recommendations for future experiments comparing Big Data processing tools, to improve the navigation diagram. Martin Macák, Hind Bangui, Barbora Buhnova, András J. Molnár, Csaba István Sidló |
IoTBDS | 1 |
| 2020 | The Suitability of Graph Databases for Big Data Analysis: A Benchmark
Martin Macák, Matus Stovcik, Barbora Buhnova |
IoTBDS | 1 |
| 2020 | A Cross-Domain Comparative Study of Big Data ArchitecturesabstractNowadays, a variety of Big Data architectures are emerging to organize the Big Data life cycle. While some of these architectures are proposed for general usage, many of them are proposed in a specific application domain such as smart cities, transportation, healthcare, and agriculture. There is, however, a lack of understanding of how and why Big Data architectures vary in different domains and how the Big Data architecture strategy in one domain may possibly advance other domains. Therefore, this paper surveys and compares the Big Data architectures in different application domains. It also chooses a representative architecture of each researched application domain to indicate which Big Data architecture from a given domain the researchers and practitioners may possibly start from. Next, a pairwise cross-domain comparison among the Big Data architectures is presented to outline the similarities and differences between the domain-specific architectures. Finally, the paper provides a set of practical guidelines for Big Data researchers and practitioners to build and improve Big Data architectures based on the knowledge gathered in this study. Martin Macák, Mouzhi Ge, Barbora Buhnova |
Int. J. Cooperative Inf. Syst. | 1 |
| 2019 | Big Data Platform for Smart Grids Power Consumption Anomaly DetectionabstractBig data processing in the Smart Grid context has many large-scale applications that require real-time data analysis (e.g., intrusion and data injection attacks detection, electric device health monitoring).In this paper, we present a big data platform for anomaly detection of power consumption data.The platform is based on an ingestion layer with data densification options, Apache Flink as part of the speed layer and HDFS/KairosDB as data storage layers.We showcase the application of the platform to a scenario of power consumption anomaly detection, benchmarking different alternative frameworks used at the speed layer level (Flink, Storm, Spark). Jakub Lipcak, Martin Macák, Bruno Rossi 0001 |
FedCSIS | 2 |