EDBT 2026 Demo / reviewers in the wild / expert
Elena Fedorchenko
dblp:04/9378 · also Elena Doynikova
· DBLP profile ↗
17ranked-venue papers
7as first author
3since 2021 · last 2025
0000-0001-6707-9153ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 9 · 5 first-author · 2 since 2021Artificial intelligence and machine learning · 2 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | What are your privacy risks? Privacy risk assessment based on privacy policies analysis
Evgenia Novikova, Elena Fedorchenko, Igor V. Kotenko |
Expert Syst. Appl. | 2 |
| 2024 | Automated Assessment of the Exploits Using Deep Learning Methods
Elena Fedorchenko, Nikita Busko, Evgenia Novikova |
CRiSIS | 1 |
| 2021 | Towards Security Decision Support for large-scale Heterogeneous Distributed Information SystemsabstractThe paper considers the challenge of security decision support for automated intrusion prevention within large-scale heterogeneous distributed information systems. The authors outline the main types of modern information systems, their features, and interconnections. They analyse existing research and solutions in the area of security decision support for the different types of large-scale heterogeneous distributed information systems, their functionality, used models, methods and metrics, advantages and disadvantages, and compare them. Finally, the authors outline the main challenges and tasks in the area and propose a common approach for security decision support. In the future work the authors plan to detail and implement the proposed approach. Ivan Murenin, Elena Fedorchenko, Igor V. Kotenko |
SIN | 2 |
| 2020 | Towards Attacker Attribution for Risk Analysis
Elena Fedorchenko, Evgenia Novikova, Diana Levshun, Igor V. Kotenko |
CRiSIS | 1 |
| 2020 | Selection of Countermeasures against Harmful Information based on the Assessment of Semantic Content of Information Objects in the Conditions of UncertaintyabstractThe paper suggests models, an algorithm and a common technique for selection of countermeasures against harmful information based on the assessment of semantic content of information objects in the conditions of uncertainty. The methods of processing of incomplete, conflicting and fuzzy knowledge are used. A version of the common algorithm for eliminating the uncertainties of assessment and categorization of information objects' semantic content while detecting harmful information is analysed. The results of operation of the technique to determine the list of available countermeasures considering the responsibility areas are discussed. Igor B. Parashchuk, Elena Fedorchenko, Igor Saenko 0001, Igor V. Kotenko |
INISTA | 2 |
| 2020 | Stateful RORI-based countermeasure selection using hypergraphs
Gustavo Gonzalez Granadillo, Elena Fedorchenko, Joaquín García 0001, Igor V. Kotenko, Andrey Fedorchenko |
J. Inf. Secur. Appl. | 2 |
| 2020 | Stateful RORI-based countermeasure selection using hypergraphs
Gustavo Gonzalez Granadillo, Elena Fedorchenko, Joaquín García 0001, Igor V. Kotenko, Andrey Fedorchenko |
J. Inf. Secur. Appl. | 2 |
| 2019 | Ontology of Metrics for Cyber Security AssessmentabstractDevelopment of metrics that are valuable for assessing security and decision making is an important element of efficient counteraction to cyber threats. The paper proposes an ontology of metrics for cyber security assessment. The developed ontology is based on determining the concepts and relations between primary features of initial security data and forming a set of hierarchically interconnected security metrics. The paper describes the main classes of the proposed ontology, the revealed relations, the involved security metrics, and the used data sources. The publicly available sources of security data are analyzed to get primary security metrics. Application of the approach is shown on a case study. The main feature of the proposed ontology is representation of security metrics as separate instances of ontology. It allows using the relations between the concepts of ontology for calculating integral metrics reflecting the security state. Elena Fedorchenko, Andrey Fedorchenko, Igor V. Kotenko |
ARES | 1 |
| 2018 | Determination of Security Threat Classes on the basis of Vulnerability Analysis for Automated Countermeasure SelectionabstractCurrently the task of automated security monitoring and responding to security incidents is highly relevant. The authors propose an approach to determine weaknesses of the analyzed system on the basis of its known vulnerabilities for further specification of security threats. It is relevant for the stage of determining the necessary and sufficient set of security countermeasures for specific information systems. The required set of security response tools and means depends on the determined threats. The possibility of practical implementation of the approach follows from the connectivity between open databases of vulnerabilities, weaknesses, and attacks. The authors applied various classification methods for vulnerabilities considering values of their properties. The paper describes source data used for classification, their preprocessing stage, and the classification results. The obtained results and the methods for their enhancement are discussed. Elena Fedorchenko, Andrey Fedorchenko, Igor V. Kotenko |
ARES | 1 |
| 2018 | The Multi-Layer Graph Based Technique for Proactive Automatic Response Against Cyber AttacksabstractThe paper evolves an approach for proactive automatic cyber security incident response. The approach is based on usage of data from open sources, analytical modeling and a hierarchical integrated set of heterogeneous security metrics. The paper outlines the features of the analytical models that are crucial for countermeasure selection. It determines a set of security metrics for countermeasure selection. The algorithms that implement the suggested multi-layer countermeasure selection technique are specified. Introduction of the layers allows getting the result at any time with the maximum accuracy depending on the available data. The experiments that demonstrate the efficiency of the suggested technique are outlined. Elena Fedorchenko, Igor V. Kotenko |
PDP | 1 |
| 2017 | CVSS-based Probabilistic Risk Assessment for Cyber Situational Awareness and Countermeasure SelectionabstractThe paper suggests several techniques for computer network risk assessment based on Common Vulnerability Scoring System (CVSS) and attack modeling. Techniques use a set of integrated security metrics and consider input data from security information and event management (SIEM) systems. Risk assessment techniques differ according to the used input data. They allow to get risk assessment considering requirements to the accuracy and efficiency. Input data includes network characteristics, attacks, attacker characteristics, security events and countermeasures. The tool that implements these techniques is presented. Experiments demonstrate operation of the techniques for different security situations. Elena Fedorchenko, Igor V. Kotenko |
PDP | 1 |
| 2016 | Dynamical Calculation of Security Metrics for Countermeasure Selection in Computer NetworksabstractThe paper considers the issue of countermeasures selection for ongoing computer network attacks. The suggested technique is based on the countermeasure model that was defined on the base of the open standards, the family of interrelated security metrics and the security analysis technique based on attack graphs and service dependencies. The technique was implemented in a security assessment and countermeasure selection system. This technique was validated on case studies. It is applicable for security information and event management systems. Igor V. Kotenko, Elena Fedorchenko |
PDP | 2 |
| 2015 | Countermeasure Selection Based on the Attack and Service Dependency Graphs for Security Incident Management
Elena Fedorchenko, Igor V. Kotenko |
CRiSIS | 1 |
| 2015 | Countermeasure Selection in SIEM Systems Based on the Integrated Complex of Security MetricsabstractThe paper considers a technique for countermeasure selection in security information and event management (SIEM) systems. The developed technique is based on the suggested complex of security metrics. For the countermeasure selection the set of security metrics is extended with an additional level needed for security decision support. This level is based on the countermeasure effectiveness metrics. Key features of the suggested technique are application of the attack and service dependencies graphs, the introduced model of the countermeasure and the suggested metrics of the countermeasure effectiveness, cost and collateral damage. Other important feature of the technique is providing the solution on the countermeasure implementation in any time on the base of the current security state and security events. Igor V. Kotenko, Elena Fedorchenko |
PDP | 2 |
| 2014 | Security Metrics Based on Attack Graphs for the Olympic Games ScenarioabstractAnalysis of security risks and calculation of security metrics is an important task for Security Information and Events Management (SIEM) systems. It allows recognizing the current security situation and necessary countermeasures. The paper considers technique for calculation of security metrics on the base of attack graphs and service dependencies. The technique uses several assessment aspects or levels (topological, attack graph level, attacker level, events level and system level) and allows customization according to different parameters of SIEM system operation. We discuss also the application of this technique for the "Olympic Games" case study. Igor V. Kotenko, Elena Fedorchenko, Andrey Chechulin |
PDP | 2 |
| 2013 | The Ontology of Metrics for Security Evaluation and Decision Support in SIEM SystemsabstractAnalysis of computer network security is a serious challenge. Many security metrics has been proposed for this purpose, but their effective use for rapid and reliable security evaluation and generation of countermeasures in SIEM systems remains an important problem. The use of ontologies for security information representation in SIEM systems contributes largely to the success of this task. However, most of works on ontological security data representation does not take into account the ontologies of security metrics. This paper proposes a new approach on using security metrics which is based on their ontological representation and serves for comprehensive security evaluation and subsequent countermeasure generation. The novelty of the proposed approach is that ontology of security metrics is viewed as a core component of a countermeasure decision support system. The proposed solutions are tested on a specific example. Igor V. Kotenko, Olga Polubelova, Igor Saenko 0001, Elena Fedorchenko |
ARES | 4 |
| 2011 | Security Analysis of Information Systems Taking into Account Social Engineering AttacksabstractThe paper suggests an attack trees based approach to security analysis of information systems. The approach considers both software-technical and social engineering attacks. It extends the approach to network security analysis based on software-technical attacks which was suggested earlier by the authors of this paper. The main difference is in generalizing the suggested approach for information systems and in use of different conceptions, models and frameworks related to social-engineering attacks. In particular, we define conceptions of legitimate users and control areas. Besides, social-engineering attacks and attacks that require physical access to control areas are included to the attack trees used for security analysis. The paper also describes a security analysis toolkit based on the approach suggested and experiments with it to define the security level of information system. Igor V. Kotenko, Mikhail Stepashkin, Elena Fedorchenko |
PDP | 3 |