VLDB 2026 Research / reviewers in the wild / expert
Efrén López-Morales
dblp:277/7996
· DBLP profile ↗
6ranked-venue papers
4as first author
5since 2021 · last 2026
0009-0001-4014-4776ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 6 · 4 first-author · 5 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Discovering Blind-Trust Vulnerabilities in PLC Binaries via State Machine Recovery
Fangzhou Dong, Arvind S. Raj, Efrén López-Morales, Yan Shoshitaishvili, Tiffany Bao, Adam Doupé, Muslum Ozgur Ozmen, Ruoyu Wang 0001 |
NDSS | 3 |
| 2026 | HoneySat: A Network-based Satellite Honeypot Framework
Efrén López-Morales, Ulysse Planta, Gabriele Marra, Carlos Gonzalez-Cortes, Jacob Hopkins, Majid Garoosi, Elías Obreque, Carlos E. Rubio-Medrano, Ali Abbasi 0002 |
NDSS | 1 |
| 2024 | Securing Cyber-Physical Systems via Advanced Cyber Threat Intelligence MethodsabstractMany services that make our modern society work, such as communications and transportation, are only possible thanks to Cyber-Physical Systems (CPS).This makes CPS the target of cyberattacks that aim to disrupt our society.One tool that we can leverage to protect CPS is Cyber Threat Intelligence (CTI).CTI is threat information that helps us understand a threat actor's techniques.However, current CTI on CPS is limited as current methods cannot collect and analyze data on the latest cyberattacks against CPS.In this dissertation research description, we address this problem by developing three new methods that advance the state-of-the-art CTI of three different CPS: Industrial Control Systems (ICS), Satellites, and Connected Autonomous Vehicles (CAV).The first research project involves the development of a novel threat taxonomy for programmable logic controllers (PLCs), which are a key part of ICS.The second project is the development of a satellite honeypot to collect data on adversaries' techniques.The third and final project involves the development of a CAV sandbox that allows us to test cyberattacks on CAVs to collect raw threat intelligence.Our preliminary results include a novel ICS threat matrix and a high-interaction satellite honeypot in the literature, which pushes the state of the art of CTI for CPS forward. Efrén López-Morales |
CCS | 1 |
| 2024 | The Imitation Game: Exploring Brand Impersonation Attacks on Social Media Platforms
Bhupendra Acharya, Dario Lazzaro, Efrén López-Morales, Adam Oest, Muhammad Saad 0001, Antonio Emanuele Cinà, Lea Schönherr, Thorsten Holz |
USENIX Security Symposium | 3 |
| 2024 | SoK: Security of Programmable Logic Controllers
Efrén López-Morales, Ulysse Planta, Carlos E. Rubio-Medrano, Ali Abbasi 0002, Alvaro A. Cárdenas |
USENIX Security Symposium | 1 |
| 2020 | HoneyPLC: A Next-Generation Honeypot for Industrial Control SystemsabstractIndustrial Control Systems (ICS) provide management and control capabilities for mission-critical utilities such as the nuclear, power, water, and transportation grids. Within ICS, Programmable Logic Controllers (PLCs) play a key role as they serve as a convenient bridge between the cyber and the physical worlds, e.g., controlling centrifuge machines in nuclear power plants. The critical roles that ICS and PLCs play have made them the target of sophisticated cyberattacks that are designed to disrupt their operation, which creates both social unrest and financial losses. In this context, honeypots have been shown to be highly valuable tools for collecting real data, e.g., malware payload, to better understand the many different methods and strategies that attackers use. However, existing state-of-the-art honeypots for PLCs lack sophisticated service simulations that are required to obtain valuable data. Worse, they cannot adapt while ICS malware keeps evolving, and attack patterns become more sophisticated. To overcome these shortcomings, we present HoneyPLC, a high-interaction, extensible, and malware collecting honeypot supporting a broad spectrum of PLCs models and vendors. Results from our experiments show that HoneyPLC exhibits a high level of camouflaging: it is identified as real devices by multiple widely used reconnaissance tools, including Nmap, Shodan's Honeyscore, the Siemens Step7 Manager, PLCinject, and PLCScan, with a high level of confidence. We deployed HoneyPLC on Amazon AWS and recorded a large amount of interesting interactions over the Internet, showing not only that attackers are in fact targeting ICS systems, but also that HoneyPLC can effectively engage and deceive them while collecting data samples for future analysis. Efrén López-Morales, Carlos E. Rubio-Medrano, Adam Doupé, Yan Shoshitaishvili, Ruoyu Wang 0001, Tiffany Bao, Gail-Joon Ahn |
CCS | 1 |