VLDB 2026 Research / reviewers in the wild / expert
Shaymaa Mamdouh Khalil
dblp:324/1310
· DBLP profile ↗
3ranked-venue papers
3as first author
3since 2021 · last 2026
0000-0001-5487-1512ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 3 · 3 first-author · 3 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Bridging industrial control systems design and testing through threat modeling-driven penetration testing - a microgrid case studyabstractWhile threat modeling is widely recommended to support penetration test planning, penetration testing can, in turn, serve to verify and validate design-phase threat modeling outcomes. Yet, this interrelation remains largely overlooked in academic research. To address this gap, this study proposes BRIDGE, a nine-stage threat modeling-driven penetration testing methodology that connects the design and testing phases. Guided by design-phase threat modeling results, the methodology supports structured test selection, enabling a more focused and efficient testing process. The study introduces a mapping of MITRE ATT&CK for ICS techniques to STRIDE threat categories, establishing a key link between high-level threat analysis performed during system design and the intermediate-level attack representation required for penetration test planning. The methodology’s practical applicability is demonstrated through a real-world case study of a recently deployed microgrid system. The study also examines the effectiveness of CVSS v4.0 compared to v3.1 in representing the distinctive risk profile of ICS vulnerabilities, considering both security requirements and potential safety impacts. This research provides practical guidance for ICS cybersecurity practitioners to enhance penetration test planning efficiency, ensure adequate coverage of critical threat testing, and streamline collaboration with third-party testers. Researchers can leverage the proposed methodology and the MITRE ATT&CK to STRIDE mapping to develop detailed ICS testing procedures, thereby contributing to the advancement of structured ICS security testing practices. Shaymaa Mamdouh Khalil, Hayretdin Bahsi, Tarmo Korõtko |
Comput. Secur. | 1 |
| 2024 | Threat modeling of industrial control systems: A systematic literature reviewabstractThreat modeling is the process of identifying and mitigating potential threats to a system. It was originally developed to enhance software security during the design phase but has since been adapted for Industrial Control Systems (ICSs). ICSs are complex and interconnected systems that control critical infrastructure, such as power plants, water treatment facilities, and manufacturing plants. As such, they are major targets for cyberattacks, which may lead to human casualties, severe national security impacts, and financial instability. This systematic literature review explores the existing threat modeling methodologies for ICSs and emphasizes the importance of employing methodical frameworks that cover safety, security, and privacy aspects with clear procedural guidelines. The review reveals that ICSs threat modeling often lacks validation to ensure that the used methodologies are effective in identifying and mitigating threats. This study emphasizes the need to develop and apply better validation metrics in case studies. The main goal of this review is to help cyber security researchers and practitioners in selecting a suitable threat modeling approach that facilitates the creation of ICSs with an acceptable level of security. Shaymaa Mamdouh Khalil, Hayretdin Bahsi, Tarmo Korõtko |
Comput. Secur. | 1 |
| 2023 | Threat Modeling of Cyber-Physical Systems - A Case Study of a Microgrid SystemabstractCyber threat modeling is an analytical process that is used for identifying the potential threats against a system and supporting the selection of security requirements in the early stages of the system development life cycle. Thus, threat modeling is a vital instrument for the realization of the secure-by-design principle. Despite being a well-known practice in software development projects, its adaptation to cyber-physical systems still requires systematic elaboration. The complex interactions between cyber and physical spaces and their reflection on the cyber threat landscape constitute a significant challenge for the system development teams. This study proposes a detailed methodology to apply STRIDE to cyber-physical systems and demonstrates its applicability in a case study of a microgrid system. Our methodology provides a systematic threat elicitation procedure based on an attack taxonomy that was created for this research. This paper also shows how assets could be identified, data flow diagrams formed, trust boundaries determined, and threats prioritized, in the case of a cyber-physical system. Shaymaa Mamdouh Khalil, Hayretdin Bahsi, Henry Ochieng' Dola, Tarmo Korõtko, Kieran McLaughlin, Vahur Kotkas |
Comput. Secur. | 1 |