VLDB 2026 Research / reviewers in the wild / expert
Stephen D. Wolthusen
dblp:w/StephenDWolthusen
· DBLP profile ↗
56ranked-venue papers
10as first author
5since 2021 · last 2025
0009-0000-6565-6797ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 46 · 10 first-author · 5 since 2021Computer networks · 4Graphics, computer vision, multimedia, augmented reality and games · 2Applied, interdisciplinary, general and emerging computing · 2Human-computer interaction and ubiquitous computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Optimal Pathways in Hierarchical Smart Distribution Grid Models with Large Scale Adversarial Attacks and Dynamic Adversaries
Natasa Gajic, Stephen D. Wolthusen |
CRITIS | 2 |
| 2024 | Locally Optimal Information Pathways in the Presence of Static Adversaries for a Hierarchical Smart Distribution Grid Model
Natasa Gajic, Stephen D. Wolthusen |
CRITIS | 2 |
| 2024 | "Paying the Rent" A Formal Methods Riposte to "Living Off the Land" Attacks
Richard McEvoy, Stephen D. Wolthusen |
CRITIS | 2 |
| 2024 | A Re-transmission Algorithm for Phasor Data Concentrators for Resilience Enhancement of State Estimation
James G. Wright, Stephen D. Wolthusen |
CRITIS | 2 |
| 2023 | Adaptable Smart Distribution Grid Topology Generation for Enhanced Resilience
Natasa Gajic, Stephen D. Wolthusen |
critis | 2 |
| 2018 | In-Cycle Sequential Topology Faults and Attacks: Effects on State Estimation
Ammara Gul, Stephen D. Wolthusen |
CRITIS | 2 |
| 2018 | Efficient Analysis to Protect Control into Critical Infrastructures
Stephen D. Wolthusen |
CRITIS | 2 |
| 2018 | A Dynamic Distributed Architecture for Preserving Privacy of Medical IoT Monitoring Measurements
Salaheddin Darwish, Ilia Nouretdinov, Stephen D. Wolthusen |
ICOST | 3 |
| 2018 | Detection of Untrustworthy IoT Measurements Using Expert Knowledge of Their Joint Distribution
Ilia Nouretdinov, Salaheddin Darwish, Stephen D. Wolthusen |
ICOST | 3 |
| 2017 | A Smart Micro-Grid Architecture for Resource Constrained EnvironmentsabstractMicro-grids offer a cost-effective approach to providing reliable power supply in isolated and disadvantaged communities. These communities present a special case where access to national power networks is either non-existent or intermittent due to load-shedding to provision urban areas and/or due to high interconnection costs. By necessity, such micro-grids rely on renewable energy sources that are variable and so only partly predictable. Ensuring reliable power provisioning and billing must therefore be supported by demand management and fair-billing policies. Furthermore, since trusted centralized grid management is not always possible, using a distributed model offers a viable solution approach. However, such a distributed system may be subject to subversion attacks aimed at power theft. In this paper, we present a novel and innovative distributed architecture for power distribution and billing on micro-grids. The architecture is designed to operate efficiently over a lossy communication network, which is an advantage for disadvantaged communities. Since lossy networks are undependable, differentiating system failures from adversarial manipulations is important because grid stability is to a large extent dependent on user participation. To this end, we provide a characterization of potential adversarial models to underline how these can be differentiated from failures. Anne V. D. M. Kayem, Christoph Meinel, Stephen D. Wolthusen |
AINA | 3 |
| 2017 | Security Infrastructure for Service Oriented Architectures at the Tactical Edge
Vasileios Gkioulos, Stephen D. Wolthusen |
CISIS | 2 |
| 2017 | De-Synchronisation Attack Modelling in Real-Time Protocols Using Queue Networks: Attacking the ISO/IEC 61850 Substation Automation Protocol
James G. Wright, Stephen D. Wolthusen |
CRITIS | 2 |
| 2017 | TACTICS: Validation of the security framework developed for tactical SOA
Vasileios Gkioulos, Erko Risthein, Stephen D. Wolthusen |
J. Inf. Secur. Appl. | 3 |
| 2016 | Power Auctioning in Resource Constrained Micro-grids: Cases of Cheating
Anesu M. C. Marufu, Anne V. D. M. Kayem, Stephen D. Wolthusen |
CRITIS | 3 |
| 2016 | Reliable Key Distribution in Smart Micro-Grids
Heinrich Strauss, Anne V. D. M. Kayem, Stephen D. Wolthusen |
CRITIS | 3 |
| 2016 | Access Control and Availability Vulnerabilities in the ISO/IEC 61850 Substation Automation Protocol
James G. Wright, Stephen D. Wolthusen |
CRITIS | 2 |
| 2016 | Fault-tolerant Distributed Continuous Double Auctioning on Computationally Constrained Microgrids
Anesu M. C. Marufu, Anne V. D. M. Kayem, Stephen D. Wolthusen |
ICISSP | 3 |
| 2016 | Limitations of IEC62351-3's public key managementabstractThe ISO/IEC 62351 standard provides a set of security controls and protocols for communications in smart grids based on the ISO/IEC 60870, 61850, and DNP3 standards. It offers the protection goals of confidentiality, integrity, and authentication. In this paper we perform a systematic study of the ISO/IEC 62351-3 standard regarding the use of public key infrastructure in smart grid communication. We show that the standard at present does not align with the quality of service requirements for performance and interoperability in the ISO/IEC 61850 standard and thereby may jeopardise effective operations. We demonstrate that it is possible to claim conformance with the ISO/IEC 62351-3 standard but be vulnerable to denial of service attacks arising from insufficiently specified behaviour for public key certificate validation and revocation. Further issues can give rise to downgrade attacks against cipher suites and protocols used, allowing a man-in-the-middle attacks contrary to the standard's claims. James G. Wright, Stephen D. Wolthusen |
ICNP | 2 |
| 2016 | Policy enforcement system for secure interoperable control in distributed Smart Grid systems
Cristina Alcaraz, Javier López 0001, Stephen D. Wolthusen |
J. Netw. Comput. Appl. | 3 |
| 2015 | MPLS Policy Target Recognition Network
Abdulrahman Al-Mutairi, Stephen D. Wolthusen |
CRiSIS | 2 |
| 2015 | Recovering Structural Controllability on Erdős-Rényi Graphs in the Presence of Compromised Nodes
Bader Alwasel, Stephen D. Wolthusen |
CRITIS | 2 |
| 2015 | A Distributed Continuous Double Auction Framework for Resource Constrained Microgrids
Anesu M. C. Marufu, Anne V. D. M. Kayem, Stephen D. Wolthusen |
CRITIS | 3 |
| 2015 | Inferring relevance and presence of evidence in service-oriented and SaaS architecturesabstractGathering forensic evidence in distributed or cloud environments poses a number of legal, administrative, and technical challenges even at relatively coarse levels of granularity. For Software-as-a-Service (SaaS) and related Service-Oriented Architectures (SOA), however, the addition of loose binding lending such architectures their important flexibility and adaptability renders even identifying possible loci of evidence problematic. Moreover, even where the existence of evidence is known, its relevance for a given hypothesis may vary. We describe an approach to identify the existence of potential evidence based on a causality model of control flow, and seek to prioritise relevance based on a probabilistic graph model. This allows not only the explicit formulation of hypotheses and derivation of criteria for locating and retrieving evidence to be evaluated by Bayesian belief networks (BBN), but to minimise the otherwise highly problematic complexity of maximum a posteriori (MAP) hypotheses based on service orchestration and choreography semantics. Sameera Al-Mulla, Youssef Iraqi, Stephen D. Wolthusen |
ISCC | 3 |
| 2014 | Recovering Structural Controllability on Erdős-Rényi Graphs via Partial Control Structure Re-Use
Bader Alwasel, Stephen D. Wolthusen |
CRITIS | 2 |
| 2014 | An Attack Analysis of Managed Pressure Drilling Systems on Oil Drilling Platforms
Richard McEvoy, Stephen D. Wolthusen |
CRITIS | 2 |
| 2013 | Structural Controllability of Networks for Non-interactive Adversarial Vertex Removal
Cristina Alcaraz, Estefanía Etchevés Miciolino, Stephen D. Wolthusen |
CRITIS | 3 |
| 2013 | Multi-round Attacks on Structural Controllability Properties for Non-complete Random Graphs
Cristina Alcaraz, Estefanía Etchevés Miciolino, Stephen D. Wolthusen |
ISC | 3 |
| 2013 | Anomaly Detection for Ephemeral Cloud IaaS Virtual Machines
Suaad S. Alarifi, Stephen D. Wolthusen |
NSS | 2 |
| 2012 | Towards Concurrent Data Sampling Using GPU CoprocessingabstractHost intrusion detection systems operating on the host under observation itself are limited by an adversary's ability to subvert all data collection and the detection and mitigation mechanisms themselves. Although coprocessor architectures have been proposed to avoid this security mechanism integrity problem, they either involve the application of non-standard hardware or rely on host-bound application programming interfaces (API). This is why, so far, they are only used in the field of network intrusion detection. In this paper, we present our results concerning a concurrent host memory sampling mechanism based on direct memory access (DMA) and demonstrate that it is possible to de-couple GPU kernel execution, thereby providing temporary isolation from the host and allowing data sampling actions to be taken without interruption. We present a security analysis of our approach and detail a proof-of-concept implementation of the autonomous concurrent monitoring and sampling system, thus, validating that self-sufficient data sampling using a commodity coprocessor (i.e. a GPU) is indeed possible. Mark M. Seeger, Stephen D. Wolthusen |
ARES | 2 |
| 2012 | Algebraic Analysis of Attack Impacts and Countermeasures in Critical Infrastructures
Richard McEvoy, Stephen D. Wolthusen |
CRITIS | 2 |
| 2012 | Forensic Tracking and Mobility Prediction in Vehicular Networks
Saif M. Al-Kuwari, Stephen D. Wolthusen |
IFIP Int. Conf. Digital Forensics | 2 |
| 2011 | Defeating Node Based Attacks on SCADA Systems Using Probabilistic Packet Observation
Richard McEvoy, Stephen D. Wolthusen |
CRITIS | 2 |
| 2011 | A propagation model of a vulnerability mitigation computer worm - seawaveabstractIn this paper, we propose and analyze an analytical propagation model of a vulnerability mitigation worm (Seawave). The model takes into consideration the topology structure of enterprise networks such as switches, LANs, and backbone, proposing the first computer worm that use layer two of the OSI model as its main propagation medium. The model also addresses the worm's communication delays due to CAM table reading (α), neighbor switch communication (β), and backbone mapping (ε). We also propose a bandwidth model to measure the traffic generated within different stages of worm propagation. Different simulations of different hierarchical topologies of enterprise networks have been driven to further evaluate and observe the defensive worm's performance in large scale networks. Ziyad S. Al-Salloum, Stephen D. Wolthusen |
NSS | 2 |
| 2011 | Next generation networks
Stephen D. Wolthusen |
Inf. Secur. Tech. Rep. | 1 |
| 2010 | Security and Performance Aspects of an Agent-Based Link-Layer Vulnerability Discovery MechanismabstractThe identification of vulnerable hosts and subsequent deployment of mitigation mechanisms such as service disabling or installation of patches is both time-critical and error-prone. This is in part owing to the fact that malicious worms can rapidly scan networks for vulnerable hosts, but is further exacerbated by the fact that network topologies are becoming more fluid and vulnerable hosts may only be visible intermittently for environments such as virtual machines or wireless edge networks. In this paper we therefore describe and evaluate an agent-based mechanism which uses the spanning tree protocol (STP) to gain knowledge of the underlying network topology to allow both rapid and resource-efficient traversal of the network by agents as well as residual scanning and mitigation techniques on edge nodes. We report performance results, comparing the mechanism against a random scanning worm and demonstrating that network immunity can be largely achieved despite a very limited warning interval. We also discuss mechanisms to protect the agent mechanism against subversion, noting that similar approaches are also increasingly deployed in case of malicious code. Ziyad S. Al-Salloum, Stephen D. Wolthusen |
ARES | 2 |
| 2010 | A Formal Adversary Capability Model for SCADA Environments
Richard McEvoy, Stephen D. Wolthusen |
CRITIS | 2 |
| 2010 | Forensic Tracking and Mobility Prediction in Vehicular Networks
Saif M. Al-Kuwari, Stephen D. Wolthusen |
IFIP Int. Conf. Digital Forensics | 2 |
| 2010 | A link-layer-based self-replicating vulnerability discovery agentabstractWith malicious attacks increasing in speed and propagation intelligence, especially under steadily shrinking time-windows between the announcement of a vulnerability and its exploitation, the need of innovative vulnerability detection techniques increase. Complex and large scale networks, that encounter frequent network devices association and disassociation, make asset management a difficult task. In this paper we propose an effective method to probe for vulnerabilities within an enterprise network, by plotting agents during its gradual propagation. The method utilizes Layer two topology information collected from network switches to achieve minimum bandwidth usage and maximize network coverage. Ziyad S. Al-Salloum, Stephen D. Wolthusen |
ISCC | 2 |
| 2010 | Host-Based Security Sensor Integrity in Multiprocessing Environments
Richard McEvoy, Stephen D. Wolthusen |
ISPEC | 2 |
| 2009 | Trouble Brewing: Using Observations of Invariant Behavior to Detect Malicious Agency in Distributed Control Systems
Richard McEvoy, Stephen D. Wolthusen |
CRITIS | 2 |
| 2009 | A Survey of Forensic Localization and Tracking Mechanisms in Short-Range and Cellular Networks
Saif M. Al-Kuwari, Stephen D. Wolthusen |
ICDF2C | 2 |
| 2009 | Editorial
Stephen D. Wolthusen |
Comput. Secur. | 1 |
| 2008 | Strongly-Resilient and Non-interactive Hierarchical Key-Agreement in MANETs
Rosario Gennaro, Shai Halevi, Hugo Krawczyk, Tal Rabin, Steffen Reidt, Stephen D. Wolthusen |
ESORICS | 6 |
| 2008 | Editorial
Stephen D. Wolthusen |
Comput. Secur. | 1 |
| 2008 | Editorial
Stephen D. Wolthusen |
Comput. Secur. | 1 |
| 2008 | From the Editor-in-Chief
Stephen D. Wolthusen |
Comput. Secur. | 1 |
| 2008 | Editorial
Stephen D. Wolthusen |
Comput. Secur. | 1 |
| 2007 | An Analysis of Cyclical Interdependencies in Critical Infrastructures
Nils Kalstad Svendsen, Stephen D. Wolthusen |
CRITIS | 2 |
| 2007 | A Framework for 3D Geospatial Buffering of Events of Interest in Critical Infrastructures
Nils Kalstad Svendsen, Stephen D. Wolthusen |
CRITIS | 2 |
| 2007 | Connectivity models of interdependency in mixed-type critical infrastructure networks
Nils Kalstad Svendsen, Stephen D. Wolthusen |
Inf. Secur. Tech. Rep. | 2 |
| 2007 | ISTR special issue on critical infrastructure protection
Stephen D. Wolthusen |
Inf. Secur. Tech. Rep. | 1 |
| 2006 | Windows device interface security
Stephen D. Wolthusen |
Inf. Secur. Tech. Rep. | 1 |
| 2005 | A Capability-Based Transparent Cryptographic File SystemabstractData on the file system in mobile internetworked working environments are exposed data to a number of threats ranging from physical theft of storage devices to industrial espionage and intelligence activities. This paper describes a fully transparent, capability-based file system security mechanism for use in heterogeneous computing environments with emphasis on the implementation on the Microsoft Windows NT/XP family of operating systems. This mechanism can provide confidentiality and integrity protection for on- and off-line use through modular cryptographic means and is interoperable between several operating system platforms. Frank Graf, Stephen D. Wolthusen |
CW | 2 |
| 2003 | Goalkeeper: Close-In Interface ProtectionabstractThis paper discusses a potential security issue in common operating system and application environments regarding dynamically attached devices and device interfaces. A set of countermeasures for the identified threats is described along with the integration of countermeasures into a policy-based security infrastructure; finally, an implementation of the countermeasure in the form of a policy enforcement module integrated into the kernel of the Microsoft Windows 2000/XP family of operating systems is described. Stephen D. Wolthusen |
ACSAC | 1 |
| 2001 | Security Policy Enforcement at the File System Level in the Windows NT Operating System FamilyabstractThis paper describes the implementation of an enforcement module for file system security implemented as part of a security architecture for distributed systems which enforces a centrally administered security policy under the Windows NT operating system platform. The mechanism provides mandatory access control, encryption, and auditing on an individual file basis across distributed systems while being fully transparent to both users and application programs and functioning regardless of the type of file system or its attachment mechanism. Stephen D. Wolthusen |
ACSAC | 1 |
| 2001 | Tracing data diffusion in industrial research with robust watermarkingabstractThis paper presents a security system for enforcing security policies throughout distributed environments. The aspects of the system dealing with the protection of digital data using object labeling and mandatory encryption at the OS level are covered briefly; the main focus is on protection provided in the analog domain. This is accomplished by embedding multiple watermarks identifying the copyright owner, the identity of the object, and of users accessing the object into any markable object accessed by users. Christoph Busch 0001, Stephen D. Wolthusen |
MMSP | 2 |