VLDB 2026 Research / reviewers in the wild / expert
Marco M. Cook
dblp:270/6143
· DBLP profile ↗
7ranked-venue papers
4as first author
7since 2021 · last 2026
0000-0002-5232-2381ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 4 · 3 first-author · 4 since 2021Computer networks · 2 · 1 first-author · 2 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021Theory of computation · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Not all who wander are lost: Industrial Network Topology Inference via Tomography ProbingabstractUnderstanding the topology of, and interconnectivity within a computer network is fundamental to enabling security, optimising performance, and ensuring digital resilience. This is particularly challenging in the context of Industrial Control Systems (ICS) where networks use alternative topological structures and comprise legacy equipment that is often poorly documented. In this paper, we investigate how network tomography techniques can be used to achieve topology inference in ICS environments. Topology inference through network tomography enables the network topology to be identified without direct monitoring of the internal network elements, making it a promising technique for use in ICS networks which can be difficult to monitor due to being highly physically distributed or difficult to access. Through experimental analysis of active measurement techniques, we evaluate Round Trip Time (RTT) probes and the efficacy of different inference algorithms such as Rooted Neighbour Joining and Maximum Likelihood Tree to achieve topology discovery. The results highlight that existing topology inference approaches achieve average accuracies between 59.7% and 88.6%. Furthermore, we identify that topology structure has the greatest impact on inference accuracy, with PLC vendor and traffic volumes providing lower variation in performance. Robert Molloy, Marco M. Cook, Dimitrios P. Pezaros |
ICC | 2 |
| 2026 | With Power comes Responsibility: Attack Synthesis for Industrial Control Systems using Large Language ModelsabstractLarge Language Models (LLM) such as ChatGPT, Meta AI, and Google Gemini have become highly accessible and ubiquitous across a wide range of applications, including speech synthesis, code generation, and media content creation. Recent research indicates that an alternative motivation for such tools is to rapidly develop malware to conduct cyber attacks. In this article, we investigate how generative LLM tools can be used to synthesise cyber-attacks targeting Industrial Control Systems (ICS). We introduce a methodology that uses LLMs to generate attack techniques based on the MITRE attack framework to target a variety of Programmable Logic Controllers (PLC) models from by different industrial vendors. We investigate the capability of five leading off-the-shelf LLMs by providing different levels of attacker context to enhance the generation. Through a comprehensive evaluation of the generated code and the resulting LLM outputs, we demonstrate that current general-purpose LLMs are capable of identifying the necessary steps required to synthesise attacks that can manipulate the operations of real PLCs. We highlight that the success of LLM-generated PLC cyberattacks depends on the level of target context initially provided, emphasising the importance of mitigating early-stage reconnaissance attacks in OT environments. Marco M. Cook, Andrei Stoica, Awais Aziz Shah, Dimitrios P. Pezaros |
ACM Trans. Priv. Secur. | 1 |
| 2025 | Online Model Checking for Anomaly Detection in Industrial Control SystemsabstractCyber attacks on Industrial Control Systems (ICSs) are becoming increasingly sophisticated, undermining the ability of these systems to manage critical processes and compromising the availability of key public infrastructure. Detecting system anomalies is an important element in the identification of cyber attacks, allowing the rapid deployment of crucial incident-response activities. In this paper, we introduce a novel anomaly detection approach that integrates SPIN model checking into ICS environments to detect anomalies in live system data. Our approach uses the application code extracted from Programmable Logic Controllers (PLCs) to generate the dynamic system model, requiring only a small amount of test data to validate their design. We evaluate our approach by generating models using a representative physical hydroelectric dam testbed containing real PLCs. These models are used to analyse synthetic data containing potential irregularities that could occur within the dam as a result of false data injection attacks. Our approach was shown to identify anomalies and verify normal system behaviour. Our evaluation shows that the models achieved high performance while maintaining explainability and delivering metrics of 99.99% precision, 99.05% recall, a 99.52% F1-score, and 99.05% accuracy. Douglas Fraser, Alice Miller 0001, Marco M. Cook, Dimitrios P. Pezaros |
iFM | 3 |
| 2025 | Artefact Provenance Graphs for Anomaly Inference in Industrial Control Systems
Marco M. Cook, Dimitrios P. Pezaros |
SEC (1) | 1 |
| 2024 | Sizzler: Sequential Fuzzing in Ladder Diagrams for Vulnerability Detection and Discovery in Programmable Logic ControllersabstractProgrammable Logic Controllers (PLCs) constitute the basis of Industrial Control Systems (ICSs) underpinning sectors ranging from nuclear, up to energy and manufacturing. Currently, PLC vulnerability assessment practices employed by ICS operators are limited due to their reliance on empirical observations of visible code crashes prompted by PLC compilers. In parallel, the prevalent PLC firmware dependency on proprietary vendor routines restricts the composition of generic vulnerability detection or discovery schemes for zero-day threat vectors. In this work, we propose Sizzler: a novel vendor-independent vulnerability discovery framework specific to PLC applications operating with logic realised through ladder diagrams. Sizzler extends the current state of the art by proposing the optimal synergy of a mutation-based fuzzing strategy using Sequential Generative Adversarial Network (SeqGAN). By virtue of critical vendor restrictions on emulating PLC firmware, we also refine the Quick Emulator (QEMU)’s General Purpose I/O (GPIO) and the Inter-Integrated Circuit (I2C) protocols to evaluate and compare Sizzler across 30 PLC ladder diagram programs compiled from LDmicro and OpenPLC projects over five widely used Micro-Controller Units (MCUs). It is noteworthy that Sizzler has successfully identified vulnerabilities in ladder diagrams within a relatively short time frame based on our proprietary dataset and secured a CVE-ID. Moreover, through a comparison of Sizzler with prevalent fuzzing techniques over the commonly used Magma and LAVA-M datasets we exhibit its wider applicability on embedded systems and identify its limitations. Marco M. Cook, Angelos K. Marnerides |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2023 | PLCPrint: Fingerprinting Memory Attacks in Programmable Logic ControllersabstractProgrammable Logic Controllers (PLCs) constitute the functioning basis of Industrial Control Systems (ICS) and hence are often a focal point for attackers to exploit. Previous attacks have seen PLC memory maliciously altered in order to disrupt the underlying physical process. Different types of memory attack can cause a similar impact on the PLC’s operation and result in indistinguishable physical manifestations. Consequently, delays in triaging attacks through digital forensic practices can induce significant financial loss, physical damage to the infrastructure, and degradation of safety. In this work, we propose PLCPrint, a novel vendor-independent fingerprinting approach that utilises PLC memory artefacts to perform detection and classification of memory attacks. PLCPrint uses PLC memory register mapping, a novel method exploiting the relationship between PLC registers and memory artefacts including the PLC application code. Through this, registers are assigned a Mapping Condition (MC) to indicate how they exist within the PLC memory artefacts. We evaluate the performance of PLCPrint over realistic emulations conducted at a real testbed emulating water filtration and distribution. Through PLCPrint we depict how MC deviations are utilised within supervised learning schemes such as to adequately classify PLC memory attacks with high accuracy performance. In general, we demonstrate that PLCPrint fills the gap in the context of attack technique triaging since this has been a missing element within current ICS forensics schemes. Marco M. Cook, Angelos K. Marnerides, Dimitrios P. Pezaros |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2022 | Anomaly Diagnosis in Cyber-Physical SystemsabstractCyber-Physical Systems (CPS) constitute the operational basis for a number of critical national infrastructure (CNI) sectors including but not limited to manufacturing, smart electrical grids and water utilities, where programmable networked systems enable physical processes. Programmable Logic Controllers (PLCs) play a vital role in this by controlling CPS processes and consequently have become a primary target for cyber attacks that aim to disrupt CPS. By contrast with conventional networked setups, the operational and safety-critical importance of PLCs introduce challenges for CNI operators on empirically determining if an incident is a cyber-attack or a system fault as both occurrences can display similar outputs on the physical process. Moreover, existing anomaly detection techniques explicit to PLCs primarily give indication of an incident rather than attempting to categorise what the incident is. In this paper, we introduce a novel PLC anomaly diagnosis framework defined by a two-stage identification and classification approach based on novelty detection. Through the use of PLC run-time and network communication data generated by physical processes on a representational CPS testbed, we achieve an average of 99.35% on anomaly profiling accuracy and highlight the distinctions between system faults and cyber-attacks. In general, we demonstrate a practical approach that can be adopted by next generation CPS cyber defence tools. Marco M. Cook, Cory Paterson, Angelos K. Marnerides, Dimitrios P. Pezaros |
ICC | 1 |