VLDB 2026 Research / reviewers in the wild / expert
Paul Smith 0001
dblp:86/5797-1
· DBLP profile ↗
30ranked-venue papers
3as first author
3since 2021 · last 2025
0000-0002-8990-6751ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 10 · 1 first-authorSecurity and privacy · 9 · 2 since 2021Systems, architecture and hardware · 2 · 1 first-author · 1 since 2021Human-computer interaction and ubiquitous computing · 2Applied, interdisciplinary, general and emerging computing · 2Artificial intelligence and machine learning · 1Software engineering, systems software and programming languages · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | AI-Augmented Scenario Design: Experiences from a National Cybersecurity Exercise
Lenhard Reuter, Paul Smith 0001, Florian Skopik |
CRITIS | 2 |
| 2023 | Digital Twin-Enhanced Incident Response for Cyber-Physical SystemsabstractCyber-physical systems underpin many of our society’s critical infrastructures. Ensuring their cyber security is important and complex. A major activity in this regard is cyber security incident response, whose primary goal is to detect and mitigate cyber-attacks in order to ensure the continuity and resilience of services. For cyber-physical systems this is particularly challenging because it requires insights both from the cyber and physical (process) domains and the engagement of stakeholders that are not strictly concerned with cyber security. A technology that is receiving a lot of attention are digital twins – virtual representations of real-world (cyber-physical) systems. They can be used to support tasks such as estimating the state of a system and exploring the consequences of interventional activities (e.g., upgrades). David Allison, Paul Smith 0001, Kieran McLaughlin |
ARES | 2 |
| 2022 | Digital Twin-Enhanced Methodology for Training Edge-Based Models for Cyber Security ApplicationsabstractDigital twins can address the problem of data scarcity during the training machine learning models, as they can be used to simulate and explore a range of process conditions and system states that are too difficult or dangerous to explore in real-world Cyber-Physical Systems (CPSs). Meanwhile, advances in industrial control systems technology have enabled increasingly complex functionality to be deployed on or near so-called edge devices, such as Programmable Logic Controllers (PLCs).In this paper, we propose a methodology for training a machine learning model offline using data extracted from a digital twin, before converting the model for deployment on an edge device to perform anomaly detection. To examine the model’s suitability for anomaly detection, we execute several simulations of fault conditions. Results show that the model can successfully predict normal operations as well as identify faults and cyber-attacks. There is a negligible drop in performance on the edge device, when compared to executing the model on a personal computer, but it remains suitable for the application. David Allison, Paul Smith 0001, Kieran McLaughlin |
INDIN | 2 |
| 2020 | Subverting Network Intrusion Detection: Crafting Adversarial Examples Accounting for Domain-Specific Constraints
Martin Teuffenbach, Ewa Piatkowska, Paul Smith 0001 |
CD-MAKE | 3 |
| 2020 | Towards a Systematic Approach for Smart Grid Hazard Analysis and Experiment SpecificationabstractThe transition to the smart grid introduces complexity to the design and operation of electric power systems. This complexity has the potential to result in safety-related losses that are caused, for example, by unforeseen interactions between systems and cyber-attacks. Consequently, it is important to identify potential losses and their root causes, ideally during system design. This is non-trivial and requires a systematic approach. Furthermore, due to complexity, it may not possible to reason about the circumstances that could lead to a loss; in this case, experiments are required. In this work, we present how two complementary deductive approaches can be usefully integrated to address these concerns: Systems Theoretic Process Analysis (STPA) is a systems approach to identifying safety-related hazard scenarios; and the ERIGrid Holistic Test Description (HTD) provides a structured approach to refine and document experiments. The intention of combining these approaches is to enable a systematic approach to hazard analysis whose findings can be experimentally tested. We demonstrate the use of this approach with a reactive power voltage control case study for a low voltage distribution network. Paul Smith 0001, Ewa Piatkowska, Edmund Widl, Filip Andren, Thomas I. Strasser |
INDIN | 1 |
| 2019 | Self-Organization and Resilience for Networked Systems: Design Principles and Open Research IssuesabstractNetworked systems form the backbone of modern society, underpinning critical infrastructures such as electricity, water, transport and commerce, and other essential services (e.g., information, entertainment, and social networks). It is almost inconceivable to contemplate a future without even more dependence on them. Indeed, any unavailability of such critical systems is - even for short periods - a rather bleak prospect. However, due to their increasing size and complexity, they also require some means of autonomic formation and self-organization. This paper identifies the design principles and open research issues in the twin fields of self-organization and resilience for networked systems. In combination, they offer the prospect of combating threats and allowing essential services that run on networked systems to continue operating satisfactorily. This will be achieved, on the one hand, through the (self-)adaptation of networked systems and, on the other hand, through structural and operational resilience techniques to ensure that they can detect, defend against, and ultimately withstand challenges. Simon A. Dobson, David Hutchison 0001, Andreas Mauthe, Alberto E. Schaeffer Filho, Paul Smith 0001, James P. G. Sterbenz |
Proc. IEEE | 5 |
| 2018 | Stealthy Attacks on Smart Grid PMU State EstimationabstractSmart grids require communication networks for supervision functions and control operations. With this they become attractive targets for attackers. In newer power grids, State Estimation (SE) is often performed based on Kalman Filters (KFs) to deal with noisy measurement data and detect Bad Data (BD) due to failures in the measurement system. Nevertheless, in a setting where attackers can gain access to modify sensor data, they can exploit the fact that SE is used to process the data. In this paper, we show how an attacker can modify Phasor Measurement Unit (PMU) sensor data in a way that it remains undetected in the state estimation process. We show how anomaly detection methods based on innovation gain fail if an attacker is aware of the state estimation and uses the right strategy to circumvent detection. Sarita Paudel, Paul Smith 0001, Tanja Zseby |
ARES | 2 |
| 2017 | Security assurance assessment methodology for hybrid clouds
Aleksandar Hudic, Paul Smith 0001, Edgar R. Weippl |
Comput. Secur. | 2 |
| 2017 | STPA-SafeSec: Safety and security analysis for cyber-physical systemsabstractCyber-physical systems tightly integrate physical processes and information and communication technologies. As today's critical infrastructures, e.g., the power grid or water distribution networks, are complex cyber-physical systems, ensuring their safety and security becomes of paramount importance. Traditional safety analysis methods, such as HAZOP, are ill-suited to assess these systems. Furthermore, cybersecurity vulnerabilities are often not considered critical, because their effects on the physical processes are not fully understood. In this work, we present STPA-SafeSec, a novel analysis methodology for both safety and security. Its results show the dependencies between cybersecurity vulnerabilities and system safety. Using this information, the most effective mitigation strategies to ensure safety and security of the system can be readily identified. We apply STPA-SafeSec to a use case in the power grid domain, and highlight its benefits. Ivo Friedberg, Kieran McLaughlin, Paul Smith 0001, David M. Laverty, Sakir Sezer |
J. Inf. Secur. Appl. | 3 |
| 2016 | A One-Class NIDS for SDN-Based SCADA SystemsabstractPower systems are undergoing an intense process of modernization, and becoming highly dependent on networked systems used to monitor and manage system components. These so-called Smart Grids comprise energy generation, transmission, and distribution subsystems, which are monitored and managed by Supervisory Control and Data Acquisition (SCADA) systems. In this paper, we discuss the benefits of using Software-Defined Networking (SDN) to assist in the deployment of next generation SCADA systems. We also present a specific Network-Based Intrusion Detection System (NIDS) for SDN-based SCADA systems, which uses SDN to capture network information and is responsible for monitoring the communication between power grid components. Our approach relies on SDN to periodically gather statistics from network devices, which are then processed by One-Class Classification (OCC) algorithms. Given that attack traces in SCADA networks are scarce and not publicly disclosed by utility companies, the main advantage of using OCC algorithms is that they do not depend on known attack signatures to detect possible malicious traffic. Our results indicate that OCC algorithms achieve an approximate accuracy of 98% and can be effectively used to detect cyber-attacks targeted against SCADA systems. Eduardo Germano da Silva, Anderson Santos da Silva, Juliano Araújo Wickboldt, Paul Smith 0001, Lisandro Z. Granville, Alberto E. Schaeffer Filho |
COMPSAC | 4 |
| 2016 | From old to new: Assessing cybersecurity risks for an evolving smart grid
Lucie Langer, Florian Skopik, Paul Smith 0001, Markus Kammerstetter |
Comput. Secur. | 3 |
| 2015 | Resilience support in software-defined networking: A survey
Anderson Santos da Silva, Paul Smith 0001, Andreas Mauthe, Alberto E. Schaeffer Filho |
Comput. Networks | 2 |
| 2014 | Network anomaly detection in the cloud: The challenges of virtual service migrationabstractThe use of virtualisation technology in the cloud enables services to migrate within and across geographically diverse data centres, e.g., to enable load balancing and fault tolerance. An important part of securing cloud services is being able to detect anomalous behaviour, caused by attacks, that is evident in network traffic. However, it is not clear whether virtual service migration adversely affects the performance of contemporary network-based anomaly detection approaches. In this paper, we explore this issue, and show that wide-area virtual service migration can adversely affect state of the art approaches to network flow-based anomaly detection techniques, potentially rendering them unusable. Kirila Adamova, Dominik Schatzmann, Bernhard Plattner, Paul Smith 0001 |
ICC | 4 |
| 2014 | Management patterns: SDN-enabled network resilience managementabstractSoftware-defined networking provides abstractions and a flexible architecture for the easy configuration of network devices, based on the decoupling of the data and control planes. This separation has the potential to considerably simplify the implementation of resilience functionality (e.g., traffic classification, anomaly detection, traffic shaping) in future networks. Although software-defined networking in general, and OpenFlow as its primary realisation, provide such abstractions, support is still needed for orchestrating a collection of OpenFlow-enabled services that must cooperate to implement network-wide resilience. In this paper, we describe a resilience management framework that can be readily applied to this problem. An important part of the framework are policy-controlled management patterns that describe how to orchestrate individual resilience services, implemented as OpenFlow applications. Paul Smith 0001, Alberto E. Schaeffer Filho, David Hutchison 0001, Andreas Mauthe |
NOMS | 1 |
| 2014 | Resilience and opportunistic forwarding: Beyond average value analysis
Fredrik Bjurefors, Merkourios Karaliopoulos, Christian Rohner, Paul Smith 0001, George Theodoropoulos, Per Gunningberg |
Comput. Commun. | 4 |
| 2013 | An Architectural Model for Deploying Critical Infrastructure Services in the CloudabstractThe Cloud Computing operational model is a major recent trend in the IT industry, which has gained tremendous momentum. This trend will likely also reach the IT services that support Critical Infrastructures (CI), because of the potential cost savings and benefits of increased resilience due to elastic cloud behaviour. However, realizing CI services in the cloud introduces security and resilience requirements that existing offerings do not address well. For example, due to the opacity of cloud environments, the risks of deploying cloud-based CI services are difficult to assess, especially at the technical level, but also from legal or business perspectives. This paper discusses challenges and objectives related to bringing CI services into cloud environments, and presents an architectural model as a basis for the development of technical solutions with respect to those challenges. Marcus Schöller, Roland Bless, Frank Pallas, Jens Horneber, Paul Smith 0001 |
CloudCom (1) | 5 |
| 2013 | Determining Risks from Advanced Multi-step Attacks to Critical Information Infrastructures
Zhendong Ma, Paul Smith 0001 |
CRITIS | 2 |
| 2013 | PReSET: A toolset for the evaluation of network resilience strategies
Alberto E. Schaeffer Filho, Andreas Mauthe, David Hutchison 0001, Paul Smith 0001, Michael Fry 0001 |
IM | 4 |
| 2013 | Simulation and evaluation of network resilience with PReSET
Alberto E. Schaeffer Filho, Andreas Mauthe, David Hutchison 0001, Paul Smith 0001, Michael Fry 0001 |
IM | 4 |
| 2013 | Situational Awareness for Improving Network Resilience Management
Mixia Liu, Paul Smith 0001, David Hutchison 0001 |
ISPEC | 3 |
| 2012 | A framework for the design and evaluation of network resilience managementabstractNetwork resilience strategies aim to maintain acceptable levels of network operation in the face of challenges, such as malicious attacks, operational overload or equipment failures. Often the nature of these challenges requires resilience strategies comprising mechanisms across multiple protocol layers and in disparate locations of the network. In this paper, we address the problem of resilience management and advocate that a new approach is needed for the design and evaluation of resilience strategies. To support the realisation of this approach we propose a framework that enables (1) the offline evaluation of resilience strategies to combat several types of challenges, (2) the generalisation of successful solutions into reusable patterns of mechanisms, and (3) the rapid deployment of appropriate patterns when challenges are observed at run-time. The evaluation platform permits the simulation of a range of challenge scenarios and the resilience strategies used to combat these challenges. Strategies that can successfully address a particular type of challenge can be promoted to become resilience patterns. Patterns can thus be used to rapidly deploy resilience configurations of mechanisms when similar challenges are detected in the live network. Alberto E. Schaeffer Filho, Paul Smith 0001, Andreas Mauthe, David Hutchison 0001, Michael Fry 0001 |
NOMS | 2 |
| 2012 | Resilience Strategies for Networked Malware Detection and Remediation
Michael Fry 0001, Bernhard Plattner, Paul Smith 0001, Alberto E. Schaeffer Filho |
NSS | 4 |
| 2010 | Resilience and survivability in communication networks: Strategies, principles, and survey of disciplines
James P. G. Sterbenz, David Hutchison 0001, Egemen K. Çetinkaya, Justin P. Rohrer, Marcus Schöller, Paul Smith 0001 |
Comput. Networks | 7 |
| 2010 | Designing for social interaction with mundane technologies: issues of security and trust
Sara Bury, Johnathan Ishmael, Nicholas J. P. Race, Paul Smith 0001 |
Pers. Ubiquitous Comput. | 4 |
| 2009 | OpenLIDS: a lightweight intrusion detection system for wireless mesh networksabstractWireless mesh networks are being used to provide Internet access in a cost efficient manner. Typically, consumer-level wireless access points with modified software are used to route traffic to potentially multiple back-haul points. Malware infected computers generate malicious traffic, which uses valuable network resources and puts other systems at risk. Intrusion detection systems can be used to detect such activity. Cost constraints and the decentralised nature of WMNs make performing intrusion detection on mesh devices desirable. However, these devices are typically resource constrained. This paper describes the results of examining their ability to perform intrusion detection. Our experimental study shows that commonly-used deep packet inspection approaches are unreliable on such hardware. We implement a set of lightweight anomaly detection mechanisms as part of an intrusion detection system, called OpenLIDS. We show that even with the limited hardware resources of a mesh device, it can detect current malware behaviour in an efficient way. Fabian Hugelshofer, Paul Smith 0001, David Hutchison 0001, Nicholas J. P. Race |
MobiCom | 2 |
| 2008 | From Detection to Remediation: A Self-Organized System for Addressing Flash Crowd ProblemsabstractA flash crowd event can be characterised by a dramatic increase in requests for a service over a relatively short period of time. Often, these events lead to a loss of service because of the saturation of the target server and associated network resources. This paper presents a set of mechanisms that can be used to make Web servers and associated resources more resilient to flash crowd events. Specifically, we present a novel admission control mechanism that uses a detection mechanism we developed in earlier work to adjust the admission rate of HTTP requests to a Web server. We demonstrate, via simulations, that the admission control mechanism can be used to protect a Web server from the effects of a flash crowd event, protect the traffic of other services that are hosted on the same network as a targeted Web server, and in combination with a push-back mechanism reduce the effect of flash crowd traffic on an ISP's network that is serving the Web server. The mechanisms presented here are exemplars that fit within a resilience strategy we are developing - D2R2+DR - which is summarised here. Linlin Xie, Paul Smith 0001, David Hutchison 0001, Mark Banfield, Helmut Leopold, James P. G. Sterbenz |
ICC | 2 |
| 2008 | Intrusion detection systems for community wireless mesh networksabstractWireless mesh networks are being increasingly used to provide affordable network connectivity to communities where wired deployment strategies are either not possible or are prohibitively expensive. Unfortunately, computer networks (including mesh networks) are frequently being exploited by increasingly profit-driven and insidious attackers, which can affect their utility for legitimate use. In response to this, a number of countermeasures have been developed, including intrusion detection systems that aim to detect anomalous behaviour caused by attacks. We present a set of socio-technical challenges associated with developing an intrusion detection system for a community wireless mesh network. The attack space on a mesh network is particularly large; we motivate the need for and describe the challenges of adopting an asset-driven approach to managing this space. Finally, we present an initial design of a modular architecture for intrusion detection, highlighting how it addresses the identified challenges. Dwight J. Makaroff, Paul Smith 0001, Nicholas J. P. Race, David Hutchison 0001 |
MASS | 2 |
| 2008 | Towards an Understanding of Security Concerns within CommunitiesabstractThis paper documents some of the socio-technical issues involved in developing security measures for a community environment, looking at the users of a wireless mesh network deployed within a rural village in north west England. We adopt an interdisciplinary methodological approach in eliciting requirements, to analyse the success of treating a community as an 'organisation' and implementing an approach, an OCTAVE method; in its original form designed to uncover security elements for businesses. Using a focus group technique we chart some of the assets and security concerns of the community members, leading to a greater understanding of people's perceptions of security, both personally and within the community, and the role of security in their regular computer usage. Sara Bury, Johnathan Ishmael, Nicholas J. P. Race, Paul Smith 0001, Mark Rouncefield |
WiMob | 4 |
| 2006 | Locating resources in a programmable networking environment
Paul Smith 0001, Steven Simpson, David Hutchison 0001 |
Comput. Networks | 1 |
| 2005 | Performance enhancement via two-layer support for peer-to-peer systems using active networkingabstractThe stratification of Internet protocols segregates network functionality into two broad layers: the overlay layer (application level) and the underlay layer (network level). Overlay networks are typically not aware of the operation of underlay networks, and conversely underlay networks are blind of the services executing at the overlay layer. Even though there is a prolific deployment of overlay networking based services, this architectural design is proving to have a number of deficiencies. Typically, such services make poor use of underlying networking resources, leading to degraded user-perceived quality of service. We propose a two-layer coordination and control framework aimed at optimizing network performance and enhancing user-perceived service. The framework and corresponding middleware structure make use of active networking technology. We choose peer-to-peer systems as our overlay study case, and discuss the problems associated with providing two-layer optimization and application support for such systems. Finally, we draw conclusions about the potential benefits of this approach and point towards possible directions of future work. Linlin Xie, David Hutchison 0001, Paul Smith 0001 |
ISADS | 3 |