Bogdan Ksiezopolski

dblp:95/5933 · DBLP profile ↗
← Back
10ranked-venue papers
2as first author
3since 2021 · last 2026
0000-0003-1904-3222ORCID · reported

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 5 · 2 first-author · 2 since 2021Artificial intelligence and machine learning · 3 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 3Software engineering, systems software and programming languages · 2Databases, data management, data science and information retrieval · 1Theory of computation · 1
YearPublicationVenuePosition
2026 LogSanitizer: Defending LLM-Integrated SOCs against Backdoor Triggers Delivered through Firewall Logs
Leszek Wronski, Bogdan Ksiezopolski
SECRYPT (1)2
2021 Cybersecurity Ontology for Dynamic Analysis of IT Systems
abstract
Today’s IT systems are characterized by a high complexity and the increasing number of sub-systems, as well as the physical equipment needed. That raises the problem of keeping the whole architecture secure, as it has been revealed in recent years by numerous scandals related to data leaks from inadequately secured systems. Several ontology-based approaches tied to the cybersecurity domain have been developed aiming at solving the problem of identifying vulnerabilities in real world systems. Unfortunately, these approaches do not address the essential problem: since real IT system architectures are dynamic and highly variable, it is necessary to enable real-time inventory and observation of all system components, as well as to retrieve up-to-date data about those systems and potential risks. The current paper has a threefold purpose. First, we examine the existing cybersecurity ontologies and identify the deficiencies that prevent us from using them in real, dynamic IT systems. Next, we introduce and propose a framework based on the Dynamic CyberSecurity Ontology, which fills the existing gaps in current solutions. Finally, we outline a monitoring system based on the developed ontology, which implements automatic data mining mechanisms that aggregate results from dynamic knowledge sources, such as Shodan or Censys. As a result, the ontological examination of systems over time becomes possible.
Jakub Pastuszuk, Patryk Burek, Bogdan Ksiezopolski
KES3
2021 A New Method of Testing Machine Learning Models of Detection for Targeted DDoS Attacks
Mateusz Kozlowski, Bogdan Ksiezopolski
SECRYPT2
2019 Cryptographic keys management system based on DNA strands
abstract
Security of cryptographic keys is one of the most important issues in a key management process.The question arises whether modern technology really allows for a high level of physical protection and security of sensitive data and cryptographic keys.The article considers various contemporary types of threats associated with the storage of secret keys.We present an innovative way to store sensitive data, using DNA strands as a medium, which significantly reduces hazard connected with electronic devices based data storage and makes the key management process independent of third parties.
Marek Miskiewicz, Bogdan Ksiezopolski
FedCSIS2
2018 A new WAF-based architecture for protecting web applications against CSRF attacks in malicious environment
abstract
Web application firewall is an application firewall for HTTP applications.Typical WAF uses static analysis of HTTP request, defined as a set of rules, to find potentially dangerous payloads in the requests.Generally, these rules cover common attacks such as cross-site scripting (XSS) and SQL injection which are server-related attacks.Cross-site scripting is clientside attack however the server is attacked and forced to return malicious response.Rule-based approach becomes useless when the attack is client-related, for example employing malware on the banking site.Malware allows to change the transfer data.This scenario is hard to detect because the browser displays valid transfer data and data is changed to the thieves' accounts number at the communication stage.In this paper we introduce a new web-based architecture for protecting web applications against CSRF attacks in malicious environemnt.In our approach we extend a classic, static WAF approach with historical and behavioral analysis, based on actions performed by the user in the past.
Michal Srokosz, Damian Rusinek, Bogdan Ksiezopolski
FedCSIS3
2018 Cybersecurity: trends, issues, and challenges
Krzysztof Cabaj, Zbigniew Kotulski, Bogdan Ksiezopolski, Wojciech Mazurczyk
EURASIP J. Inf. Secur.3
2015 The Robust Measurement Method for Security Metrics Generation
abstract
In the today's world in many organizations, the information security management is one of the most important tasks to be done. Among the tasks which must be considered during security management is that the processes need to be monitored and verified. In the article, we introduce a new security measurement model which extends the approach presented in the ISO/IEC 27004 with measurements validation methods. The presented method generates the security metrics which are robust and reproductable. Our approach systematizes and organizes security metrics development process focusing on the performance and the security of systems, products, processes and services. We also present the Crypto-Metrics Tool (CMTool) which prepares the benchmarking and validates obtained results according to the proposed method. Finally, we present the case study of the proposed method for generating robust benchmarking of the cryptographic modules by means of the CMTool.
Katarzyna Mazur, Bogdan Ksiezopolski, Zbigniew Kotulski
Comput. J.2
2012 QoP-ML: Quality of protection modelling language for cryptographic protocols
Bogdan Ksiezopolski
Comput. Secur.1
2010 CMAC, CCM and GCM/GMAC: Advanced modes of operation of symmetric block ciphers in wireless sensor networks
Pawel Szalachowski, Bogdan Ksiezopolski, Zbigniew Kotulski
Inf. Process. Lett.2
2007 Adaptable security mechanism for dynamic environments
Bogdan Ksiezopolski, Zbigniew Kotulski
Comput. Secur.1