VLDB 2026 Research / reviewers in the wild / expert
Robin Berthier
dblp:58/4729
· DBLP profile ↗
12ranked-venue papers
2as first author
1since 2021 · last 2025
0009-0001-3669-7378ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 9 · 2 first-author · 1 since 2021Systems, architecture and hardware · 6 · 1 first-authorSoftware engineering, systems software and programming languages · 2 · 1 first-authorComputer networks · 1
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Network and information security
3 papers |
Cyber-physical and IoT security · 68% Network security · 32% | |
| Computer networks
1 paper |
Internet of things and sensor networks · 100% |
Topics — the 6 heaviest of 8, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Cyber-physical and IoT security
critical infrastructure protection |
0.9 | 2 | 2025 | The Challenges and Opportunities with Cybersecurity Regulations: A Case Study of the US Electric Power Sector · CCS 2025 Seclius: An Information Flow-Based, Consequence-Centric Security Metric · IEEE Trans. Parallel Distributed Syst. 2015 |
Network security › intrusion detection and prevention › intrusion detection › alert processing
alert prioritization |
0.2 | 1 | 2015 | Seclius: An Information Flow-Based, Consequence-Centric Security Metric · IEEE Trans. Parallel Distributed Syst. 2015 |
Network security › intrusion detection and prevention
intrusion detection |
0.2 | 1 | 2015 | Seclius: An Information Flow-Based, Consequence-Centric Security Metric · IEEE Trans. Parallel Distributed Syst. 2015 |
Network security
security metrics |
0.2 | 1 | 2015 | Seclius: An Information Flow-Based, Consequence-Centric Security Metric · IEEE Trans. Parallel Distributed Syst. 2015 |
Cyber-physical and IoT security
smart grid security |
0.2 | 1 | 2013 | A Multi-Sensor Energy Theft Detection Framework for Advanced Metering Infrastructures · IEEE J. Sel. Areas Commun. 2013 |
Internet of things and sensor networks › cyber-physical systems › smart grid
advanced metering infrastructure |
0.0 | 1 | 2013 | A Multi-Sensor Energy Theft Detection Framework for Advanced Metering Infrastructures · IEEE J. Sel. Areas Commun. 2013 |
Methods — techniques the papers use, named apart from their topics
information fusion · 0.3anomaly detection · 0.3machine learning for security requirement learning · 0.2information flow analysis · 0.2
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | The Challenges and Opportunities with Cybersecurity Regulations: A Case Study of the US Electric Power SectorabstractIn various industries, cybersecurity regulations have been enacted in an effort to drive improvements to organizational security postures. Despite the prominent influence of these regulations, there has been limited prior investigation of how organizations engage with these regulations and the challenges that they face. Assessing these factors is vital for understanding the impact of cybersecurity regulations in practice and how to enhance them moving forward. Sena Sahin, Burak Sahin, Robin Berthier, Katherine R. Davis 0001, Saman A. Zonouz, Frank Li 0001 |
CCS | 3 |
| 2016 | An Internet-wide view of ICS devicesabstractIndustrial control systems have become ubiquitous, enabling the remote, electronic control of physical equipment and sensors. Originally designed to operate on closed networks, the protocols used by these devices have no built-in security. However, despite this, an alarming number of systems are connected to the public Internet and an attacker who finds a device often can cause catastrophic damage to physical infrastructure. We consider two aspects of ICS security in this work: (1) what devices have been inadvertently exposed on the public Internet, and (2) who is searching for vulnerable systems. First, we implement five common SCADA protocols in ZMap and conduct a survey of the public IPv4 address space finding more than 60K publicly accessible systems. Second, we use a large network telescope and high-interaction honeypots to find and profile actors searching for devices. We hope that our findings can both motivate and inform future work on securing industrial control systems. Ariana Mirian, Zane Ma, David Adrian, Matthew Tischer, Thasphon Chuenchujit, Timothy M. Yardley, Robin Berthier, Joshua Mason, Zakir Durumeric, J. Alex Halderman, Michael D. Bailey |
PST | 7 |
| 2015 | Seclius: An Information Flow-Based, Consequence-Centric Security MetricabstractIt is critical to monitor IT systems that are part of energy delivery system infrastructure. The problem with intrusion detection systems (IDSes) is that they often produce thousands of alerts daily that must be dealt with by administrators manually. To provide situational awareness, detection systems usually employ (alert, priority) mappings that are either built in the IDS without consideration of the high-level mission objectives of the infrastructure, or manually defined by administrators through a time-consuming task that requires deep system-level expertise. In this paper, we present Seclius, an online security evaluation framework that translates low-level IDS alerts into a high-level system security measure and provides a ranking of past malicious events and affected system assets based on how crucial they are for the organization. Seclius significantly reduces human involvement by automatically learning system characteristics, providing a simple formalism that administrators can use to define security requirements. Experiments on a process control network with real vulnerabilities and a multistep attack show that Seclius can accurately report system security with low performance overhead and support the time-constrained security decision-making process that is necessary for critical infrastructure. Saman A. Zonouz, Robin Berthier, Himanshu Khurana, William H. Sanders, Timothy M. Yardley |
IEEE Trans. Parallel Distributed Syst. | 2 |
| 2013 | Secloud: A cloud-based comprehensive and lightweight security solution for smartphones
Saman A. Zonouz, Amir Houmansadr, Robin Berthier, Nikita Borisov, William H. Sanders |
Comput. Secur. | 3 |
| 2013 | A Multi-Sensor Energy Theft Detection Framework for Advanced Metering InfrastructuresabstractThe advanced metering infrastructure (AMI) is a crucial component of the smart grid, replacing traditional analog devices with computerized smart meters. Smart meters have not only allowed for efficient management of many end-users, but also have made AMI an attractive target for remote exploits and local physical tampering with the end goal of stealing energy. While smart meters posses multiple sensors and data sources that can indicate energy theft, in practice, the individual methods exhibit many false positives. In this paper, we present AMIDS, an AMI intrusion detection system that uses information fusion to combine the sensors and consumption data from a smart meter to more accurately detect energy theft. AMIDS combines meter audit logs of physical and cyber events with consumption data to more accurately model and detect theft-related behavior. Our experimental results on normal and anomalous load profiles show that AMIDS can identify energy theft efforts with high accuracy. Furthermore, AMIDS correctly identified legitimate load profile changes that more elementary analyses classified as malicious. Stephen E. McLaughlin, Brett Holbert, Ahmed M. Fawaz, Robin Berthier, Saman A. Zonouz |
IEEE J. Sel. Areas Commun. | 4 |
| 2012 | Safeguarding academic accounts and resources with the University Credential Abuse Auditing SystemabstractWhether it happens through malware or through phishing, loss of one's online identity is a real and present danger. While many attackers seek credentials to realize financial gain, an analysis of the compromised accounts at our own institutions reveals that perpetrators often steal university credentials to gain free and unfettered access to information. This nontraditional motivation for credential theft puts a special burden on the academic institutions that provide these accounts. In this paper, we describe the design, implementation, and evaluation of a system for safeguarding academic accounts and resources called the University Credential Abuse Auditing System (UCAAS). We evaluate UCAAS at two major research universities with tens of thousands of user accounts and millions of login events during a two-week period. We show the UCAAS to be useful in reducing this burden, having helped the university security teams identify a total of 125 compromised accounts with zero false positives during the trail. Jing Zhang 0027, Robin Berthier, Will Rhee, Michael D. Bailey, Partha P. Pal, Farnam Jahanian, William H. Sanders |
DSN | 2 |
| 2011 | DarkNOC: Dashboard for Honeypot Management
Bertrand Sobesto, Michel Cukier, Matti A. Hiltunen, Dave Kormann, Gregg Vesonder, Robin Berthier |
LISA | 6 |
| 2011 | Specification-Based Intrusion Detection for Advanced Metering InfrastructuresabstractIt is critical to develop an effective way to monitor advanced metering infrastructures (AMI). To ensure the security and reliability of a modernized power grid, the current deployment of millions of smart meters requires the development of innovative situational awareness solutions to prevent compromised devices from impacting the stability of the grid and the reliability of the energy distribution infrastructure. To address this issue, we introduce a specification-based intrusion detection sensor that can be deployed in the field to identify security threats in real time. This sensor monitors the traffic among meters and access points at the network, transport, and application layers to ensure that devices are running in a secure state and their operations respect a specified security policy. It does this by implementing a set of constraints on transmissions made using the C12.22 standard protocol that ensure that all violations of the specified security policy will be detected. The soundness of these constraints was verified using a formal framework, and a prototype implementation of the sensor was evaluated with realistic AMI network traffic. Robin Berthier, William H. Sanders |
PRDC | 1 |
| 2011 | Characterizing Attackers and Attacks: An Empirical StudyabstractThis paper describes an empirical research study to characterize attackers and attacks against targets of opportunity. A honey net infrastructure was built and deployed over 167 days that leveraged three different honey pot configurations and a SSH-based authentication proxy to attract and follow attackers over several weeks. A total of 211 attack sessions were recorded and evidence was collected at each stage of the attack sequence: from discovery to intrusion and exploitation of rogue software. This study makes two important contributions: 1) we introduce a new approach to measure attacker skills, and 2) we leverage keystroke profile analysis to differentiate attackers beyond their IP address of origin. Gabriel Salles-Loustau, Robin Berthier, Etienne Collange, Bertrand Sobesto, Michel Cukier |
PRDC | 2 |
| 2009 | Analyzing the process of installing rogue softwareabstractThis practical experience report presents the results of an experiment aimed at understanding the sequence of malicious actions following a remote compromise. The type of rogue software installed during attacks was used to classify and understand sequences of malicious actions. For this experiment, we used four Linux target computers running SSH with simple passwords. During the eight-month data collection period, we recorded a total of 1,171 attack sessions. In these sessions, attackers typed a total of 20,335 commands that we categorized into 24 specific actions. These actions were analyzed based on the type of rogue software installed by attackers. Robin Berthier, Jorge Arjona, Michel Cukier |
DSN | 1 |
| 2007 | Profiling Attacker Behavior Following SSH CompromisesabstractThis practical experience report presents the results of an experiment aimed at building a profile of attacker behavior following a remote compromise. For this experiment, we utilized four Linux honeypot computers running SSH with easily guessable passwords. During the course of our research, we also determined the most commonly attempted usernames and passwords, the average number of attempted logins per day, and the ratio of failed to successful attempts. To build a profile of attacker behavior, we looked for specific actions taken by the attacker and the order in which they occurred. These actions were: checking the configuration, changing the password, downloading a file, installing/running rogue code, and changing the system configuration. Daniel Ramsbrock, Robin Berthier, Michel Cukier |
DSN | 2 |
| 2006 | A Statistical Analysis of Attack Data to Separate AttacksabstractThis paper analyzes malicious activity collected from a test-bed, consisting of two target computers dedicated solely to the purpose of being attacked, over a 109 day time period. We separated port scans, ICMP scans, and vulnerability scans from the malicious activity. In the remaining attack data, over 78% (i.e., 3,677 attacks) targeted port 445, which was then statistically analyzed. The goal was to find the characteristics that most efficiently separate the attacks. First, we separated the attacks by analyzing their messages. Then we separated the attacks by clustering characteristics using the K-Means algorithm. The comparison between the analysis of the messages and the outcome of the K-Means algorithm showed that 1) the mean of the distributions of packets, bytes and message lengths over time are poor characteristics to separate attacks and 2) the number of bytes, the mean of the distribution of bytes and message lengths as a function of the number packets are the best characteristics for separating attacks Michel Cukier, Robin Berthier, Susmit Panjwani, Stephanie Tan |
DSN | 2 |