VLDB 2026 Research / reviewers in the wild / expert
Stefan Axelsson
dblp:86/2618
· DBLP profile ↗
21ranked-venue papers
9as first author
4since 2021 · last 2024
0000-0002-9085-4469ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 17 · 8 first-author · 4 since 2021Artificial intelligence and machine learning · 2 · 1 first-authorDatabases, data management, data science and information retrieval · 2Computer networks · 1Software engineering, systems software and programming languages · 1 · 1 first-authorHuman-computer interaction and ubiquitous computing · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | Digital Forensic Acquisition Using Private Internet of Things Cloud Application Programming Interfaces
Johannes Olegård, Stefan Axelsson |
IFIP Int. Conf. Digital Forensics | 2 |
| 2022 | Legal and technical questions of file system reverse engineeringabstractReverse engineering of file systems is indispensable for tool testing, accurate evidence acquisition, and correct interpretation of data structures by law enforcement in criminal investigations. This position paper examines emerging techno-legal challenges from the practice of reverse engineering for law enforcement purposes. We demonstrate that this new context creates uncertainties about the legality of tools and methods used for evidence acquisition and the compliance of law enforcement with obligations to protect intellectual property and confidential information. Further identified are gaps between legal provisions and practice related to disclosure and peer-review of sensitive digital forensic methodology, trade secrets in investigations, and governmental vulnerability disclosure. It is demonstrated that reverse engineering of file systems is insufficiently addressed by legislators, which results in a lack of file system interpretation and validation information for law enforcement and their dependence on tools. Outlined are recommendations for further developments of digital forensic regulation. Radina Stoykova, Rune Nordvik, Munnazzar Ahmed, Katrin Franke, Stefan Axelsson, Fergus Toolan |
Comput. Law Secur. Rev. | 5 |
| 2021 | Leveraging USB Power Delivery Implementations for Digital Forensic Acquisition
Gunnar Alendal, Stefan Axelsson, Geir Olav Dyrkolbotn |
IFIP Int. Conf. Digital Forensics | 2 |
| 2021 | Digital Forensic Acquisition Kill Chain - Analysis and Demonstration
Gunnar Alendal, Geir Olav Dyrkolbotn, Stefan Axelsson |
IFIP Int. Conf. Digital Forensics | 3 |
| 2020 | Disk Cluster Allocation Behavior in Windows and NTFSabstractAbstract The allocation algorithm of a file system has a huge impact on almost all aspects of digital forensics, because it determines where data is placed on storage media. Yet there is only basic information available on the allocation algorithm of the currently most widely spread file system; NTFS. We have therefore studied the NTFS allocation algorithm and its behavior empirically. To do that we used two virtual machines running Windows 7 and 10 on NTFS formatted fixed size virtual hard disks, the first being 64 GiB and the latter 1 TiB in size. Files of different sizes were written to disk using two writing strategies and the $Bitmap files were manipulated to emulate file system fragmentation. Our results show that files written as one large block are allocated areas of decreasing size when the files are fragmented. The decrease in size is seen not only within files, but also between them. Hence a file having smaller fragments than another file is written after the file having larger fragments. We also found that a file written as a stream gets the opposite allocation behavior, i. e. its fragments are increasing in size as the file is written. The first allocated unit of a stream written file is always very small and hence easy to identify. The results of the experiment are of importance to the digital forensics field and will help improve the efficiency of for example file carving and timestamp verification. Martin Karresand, Stefan Axelsson, Geir Olav Dyrkolbotn |
Mob. Networks Appl. | 2 |
| 2019 | Exploiting Vendor-Defined Messages in the USB Power Delivery Protocol
Gunnar Alendal, Stefan Axelsson, Geir Olav Dyrkolbotn |
IFIP Int. Conf. Digital Forensics | 2 |
| 2019 | Digital Forensic Atomic Force Microscopy of Semiconductor Memory Arrays
Struan Gray, Stefan Axelsson |
IFIP Int. Conf. Digital Forensics | 2 |
| 2019 | Creating a Map of User Data in NTFS to Improve File Carving
Martin Karresand, Asalena Warnqvist, David Lindahl, Stefan Axelsson, Geir Olav Dyrkolbotn |
IFIP Int. Conf. Digital Forensics | 4 |
| 2017 | Digital Forensic Implications of Collusion Attacks on the Lightning Network
Dmytro Piatkivskyi, Stefan Axelsson, Mariusz Nowostawski |
IFIP Int. Conf. Digital Forensics | 2 |
| 2015 | Do Data Loss Prevention Systems Really Work?
Sara Ghorbanian, Glenn Fryklund, Stefan Axelsson |
IFIP Int. Conf. Digital Forensics | 3 |
| 2013 | File Fragment Analysis Using Normalized Compression Distance
Stefan Axelsson, Kamran Ali Bajwa, Mandhapati Venkata Srikanth |
IFIP Int. Conf. Digital Forensics | 1 |
| 2012 | Using Data Mining for Static Code Analysis of C
Hannes Tribus, Irene Morrigl, Stefan Axelsson |
ADMA | 3 |
| 2012 | Similarity assessment for removal of noisy end user license agreements
Niklas Lavesson, Stefan Axelsson |
Knowl. Inf. Syst. | 2 |
| 2010 | Using Normalized Compression Distance for Classifying File FragmentsabstractWe have applied the generalized and universal distance measure NCD-Normalized Compression Distance-to the problem of determining the types of file fragments via example. A corpus of files that can be redistributed to other researchers in the field was developed and the NCD algorithm using k-nearest-neighbor as a classification algorithm was applied to a random selection of file fragments. The experiment covered circa 2000 fragments from 17 different file types. While the overall accuracy of the n-valued classification only improved the prior probability of the class from approximately 6% to circa 50% overall, the classifier reached accuracies of 85%-100% for the most successful file types. Stefan Axelsson |
ARES | 1 |
| 2009 | Detecting Defects with an Interactive Code Review Tool Based on Visualisation and Machine Learning
Stefan Axelsson, Dejan Baca, Robert Feldt, Darius Sidlauskas, Denis Kacan |
SEKE | 1 |
| 2004 | Visualising Intrusions: Watching the WebserverabstractDespite several years of intensive study, intrusion detection systems still suffer from a key deficiency: A high rate of false alarms. To counteract this, this paper proposes to visualise the state of the computer system such that the operator can determine whether a violation has taken place. To this end a very simple anomaly detection inspired log reduction scheme is combined with graph visualisation, and applied to the log of a webserver with the intent of detecting patterns of benign and malicious (or suspicious) accesses. The combination proved to be effective. The visualisation of the output of the anomaly detection system counteracted its high rate of false alarms, while the anomaly based log reduction helped reduce the log data to manageable proportions. The visualisation was more successful in helping identifying benign accesses than malicious accesses. All the types of malicious accesses present in the log data were found. These keywords were added by machine and not by the authors. This process is experimental and the keywords may be updated as the learning algorithm improves. Stefan Axelsson |
SEC | 1 |
| 2004 | Combining a bayesian classifier with visualisation: understanding the IDSabstractDespite several years of intensive study, intrusion detection systems still suffer from two key deficiencies: Low detection rates and a high rate of false alarms. Stefan Axelsson |
VizSEC | 1 |
| 2003 | Visualisation for Intrusion Detection
Stefan Axelsson |
ESORICS | 1 |
| 2000 | The base-rate fallacy and the difficulty of intrusion detectionabstractMany different demands can be made of intrusion detection systems. An important requirement is that an intrusion detection system be effective ; that is, it should detect a substantial percentage of intrusions into the supervised system, while still keeping the false alarm rate at an acceptable level. This article demonstrates that, for a reasonable set of assumptions, the false alarm rate is the limiting factor for the performance of an intrusion detection system. This is due to the base-rate fallacy phenomenon, that in order to achieve substantial values of the Bayesian detection rate P(Intrusion***Alarm) , we have to achieve a (perhaps in some cases unattainably) low false alarm rate. A selection of reports of intrusion detection performance are reviewed, and the conclusion is reached that there are indications that at least some types of intrusion detection have far to go before they can attain such low false alarm rates. Stefan Axelsson |
ACM Trans. Inf. Syst. Secur. | 1 |
| 1999 | The Base-Rate Fallacy and Its Implications for the Difficulty of Intrusion DetectionabstractMany different demands can be made of intrusion detection systems. An important requirement is that it be effective i.e. that it should detect a substantial percentage of intrusions into the supervised system, while still keeping the false alarm rate at an acceptable level. This paper aims to demonstrate that, for a reasonable set of assumptions, the false alarm rate is the limiting factor for the performance of an intrusion detection system. This is due to the base-rate fallacy phenomenon, that in order to achieve substantial values of the Bayesian detection rate, P(Intrusion|Alarm), we have to achieve a perhaps unattainably low false alarm rate. A selection of reports of intrusion detection performance are reviewed, and the conclusion is reached that there are indications that at least some types of intrusion detection have far to go before they can attain such low false alarm rates. Stefan Axelsson |
CCS | 1 |
| 1999 | On a Difficulty of Intrusion Detection
Stefan Axelsson |
Recent Advances in Intrusion Detection | 1 |