VLDB 2026 Research / reviewers in the wild / expert
Vincent Drury
dblp:248/1699
· DBLP profile ↗
5ranked-venue papers
2as first author
4since 2021 · last 2023
0000-0002-3227-6090ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 3 · 2 first-author · 3 since 2021Human-computer interaction and ubiquitous computing · 2 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2023 | Easier in Reverse: Simplifying URL Reading for Phishing URLs via Reverse Domain Name NotationabstractPhishing attacks are a persistent problem to users and organizations world-wide, resulting in monetary loss and providing a first step in more complex attacks. Vincent Drury, Jakob Drees, Ulrike Meyer |
ARES | 1 |
| 2022 | Dating Phish: An Analysis of the Life Cycles of Phishing Attacks and CampaignsabstractPhishing attacks are still a general and world-wide threat to users of the Internet. In the past, several approaches to detect phishing websites earlier and shorten the time frame between their creation and inclusion in a blocklist have been proposed. Understanding the life cycle of phishing attacks, in particular the time of their creation and the time span from the first to last attack in a campaign, provides additional insights into the potential success of these methods. In this paper, we present an analysis of the life cycles of 133,667 phishing websites based on the publicly available information from certificates, whois, as well as images and resources on the phishing websites themselves. While we confirm the findings from previous work, that many websites have short lifetimes of only several days, we also note that the timing information from phishing websites using public hosting or compromised infrastructure is far less accurate in dating the creation of the websites. We further cluster the phishing websites into campaigns based on patterns in their domain names, and find that the detected campaigns often take place over several weeks, with an average duration of almost 12 days. Our results showcase advantages and limitations for the early detection of phishing websites, in particular regarding the time span between the creation of a website and its inclusion in a blocklist, and how patterns in domain names remain the same over a period of up to several weeks in the phishing campaigns analyzed in this paper. Vincent Drury, Luisa Lux, Ulrike Meyer |
ARES | 1 |
| 2022 | Better the Phish You Know: Evaluating Personalization in Anti-Phishing Learning Games
René Röpke, Vincent Drury, Ulrike Meyer, Ulrik Schroeder |
CSEDU (2) | 2 |
| 2021 | Finding Phish in a Haystack: A Pipeline for Phishing Classification on Certificate Transparency LogsabstractCurrent popular phishing prevention techniques mainly utilize reactive blocklists, which leave a “window of opportunity” for attackers during which victims are unprotected. One possible approach to shorten this window aims to detect phishing attacks earlier, during website preparation, by monitoring Certificate Transparency (CT) logs. Previous attempts to work with CT log data for phishing classification exist, however they lack evaluations on actual CT log data. In this paper, we present a pipeline that facilitates such evaluations by addressing a number of problems when working with CT log data. The pipeline includes dataset creation, training, and past or live classification of CT logs. Its modular structure makes it possible to easily exchange classifiers or verification sources to support ground truth labeling efforts and classifier comparisons. We test the pipeline on a number of new and existing classifiers, and find a general potential to improve classifiers for this scenario in the future. We publish the source code of the pipeline and the used datasets along with this paper [12], thus making future research in this direction more accessible. Arthur Drichel, Vincent Drury, Justus von Brandt, Ulrike Meyer |
ARES | 2 |
| 2020 | Towards Personalized Game-Based Learning in Anti-Phishing EducationabstractAs anti-phishing games emerge as a scalable, motivational and effective approach to anti-phishing education for non-professional end-users, problems arise due to the missing relevance of a games' content and context. If a game presents examples unknown or without relevance to the user, the learning potential is limited as users have no point of reference. To provide more meaningful, relevant game content to users, we propose a personalization pipeline for data collection, content generation and delivery for anti-phishing learning games. René Röpke, Ulrik Schroeder, Vincent Drury, Ulrike Meyer |
ICALT | 3 |