EDBT 2026 Demo / reviewers in the wild / expert
Marco Caselli
dblp:125/3305
· DBLP profile ↗
13ranked-venue papers
3as first author
7since 2021 · last 2025
0000-0003-4883-797XORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 12 · 3 first-author · 6 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | SoK: Automated TTP Extraction from CTI Reports - Are We There Yet?
Marvin Büchel, Tommaso Paladini, Stefano Longari, Michele Carminati, Stefano Zanero, Hodaya Binyamini, Gal Engelberg, Daniel Klein 0003, Giancarlo Guizzardi, Marco Caselli, Andrea Continella, Maarten van Steen, Andreas Peter 0001, Thijs van Ede |
USENIX Security Symposium | 10 |
| 2024 | A Security Alert Investigation Tool Supporting Tier 1 Analysts in Contextualizing and Understanding Network Security EventsabstractThe investigations run by tier 1 (T1) analysts in a Security Operation Center are critical to the SOC operations as they represent the first gateway to alert escalation and incident response. Critically, they demand an accurate and as-complete-as-possible understanding of the events surrounding the investigated alert. This is a complex task inexperienced T1 analysts can easily lose track of. In this work, we collaborate with a commercial SOC to develop an alert investigation support tool to help inexperienced analysts identify and collect all the information relevant to the investigation of an alert. We evaluate the prototype tool with two qualitative studies. The first study employs T1 analysts from the SOC to evaluate the conformity of the tool to the underpinning analysis process. The second study employs 57 students, recruited from the same pool where the SOC acquires its junior analysts from, to evaluate whether it helps inexperienced analysts develop a complete understanding of events surrounding security alert data. Our findings suggest that employing the tool helps inexperienced analysts form a more accurate understanding of attacks, at no time cost. We discuss the wider implications for research and practice. Leon Kersten, Santiago Darré, Tom Mulders, Emmanuele Zambon, Marco Caselli, Chris Snijders 0001, Luca Allodi |
ACSAC | 5 |
| 2024 | Inferring Recovery Steps from Cyber Threat Intelligence Reports
Zsolt Levente Kucsván, Marco Caselli, Andreas Peter 0001, Andrea Continella |
DIMVA | 2 |
| 2024 | REPLICAWATCHER: Training-less Anomaly Detection in Containerized Microservices
Asbat El Khairi, Marco Caselli, Andreas Peter 0001, Andrea Continella |
NDSS | 2 |
| 2024 | Do You Play It by the Books? A Study on Incident Response Playbooks and Influencing FactorsabstractIncident response "playbooks" are structured sets of operational procedures organizations use to instruct humans or machines on performing countermeasures against cybersecurity threats. These playbooks generally combine information about a given threat and organizational aspects relevant within the context of an organization. Both types of information are crucial for using, maintaining, and sharing playbooks across organizations as they ensure effectiveness and confidentiality. While practitioners show great interest in playbooks, their characteristics have not yet been thoroughly investigated from a research perspective. For this reason, we explore the topic by analyzing what is inside a playbook. Our approach consists of a comprehensive empirical assessment of available data (1217 playbooks), an online study with 147 participants, and final in-depth interviews with nine security professionals to consolidate and validate our findings. We notably find intrinsic ambiguities in the way practitioners and organizations define their playbooks. Furthermore, we notice that available playbooks cannot be used outright which might currently impair their wide use across different cybersecurity actors. As a result, we can conclude that organizations do "play it by the books" but individually define what is inside their playbooks and which areas of incident response they might address. Daniel Schlette, Philip Empl, Marco Caselli, Thomas Schreck, Günther Pernul |
SP | 3 |
| 2022 | Identifying Near-Optimal Single-Shot Attacks on ICSs with Limited Process Knowledge
Herson Esquivel-Vargas, John H. Castellanos, Marco Caselli, Nils Ole Tippenhauer, Andreas Peter 0001 |
ACNS | 3 |
| 2021 | On the Integration of Course of Action Playbooks into Shareable Cyber Threat IntelligenceabstractMotivated by the introduction of CACAO, the first open standard that harmonizes the way we document courses of action in a machine-readable format for interoperability, and the benefits for cybersecurity operations derived from utilizing, and coupling and sharing course of action playbooks with cyber threat intelligence, we introduce a uniform metadata template that supports managing and integrating course of action playbooks into knowledge representation and knowledge management systems. We demonstrate the applicability of our approach through two use-case implementations. We utilize the playbook metadata template to introduce functionality and integrate course of action playbooks, such as CACAO, into the MISP threat intelligence platform and the OASIS Threat Actor Context ontology. Vasileios Mavroeidis, Pavel Eis, Martin Zádník, Marco Caselli, Bret Jordan |
IEEE BigData | 4 |
| 2020 | Putting Attacks in Context: A Building Automation Testbed for Impact Assessment from the Victim's Perspective
Herson Esquivel-Vargas, Marco Caselli, Geert Jan Laanstra, Andreas Peter 0001 |
DIMVA | 2 |
| 2019 | BACRank: Ranking Building Automation and Control System Components by Business Continuity Impact
Herson Esquivel-Vargas, Marco Caselli, Erik Tews, Doina Bucur, Andreas Peter 0001 |
SAFECOMP | 2 |
| 2017 | DECANTeR: DEteCtion of Anomalous outbouNd HTTP TRaffic by Passive Application FingerprintingabstractWe present DECANTeR, a system to detect anomalous outbound HTTP communication, which passively extracts fingerprints for each application running on a monitored host. The goal of our system is to detect unknown malware and backdoor communication indicated by unknown fingerprints extracted from a host's network traffic. We evaluate a prototype with realistic data from an international organization and datasets composed of malicious traffic. We show that our system achieves a false positive rate of 0.9% for 441 monitored host machines, an average detection rate of 97.7%, and that it cannot be evaded by malware using simple evasion techniques such as using known browser user agent values. We compare our solution with DUMONT [24], the current state-of-the-art IDS which detects HTTP covert communication channels by focusing on benign HTTP traffic. The results show that DECANTeR outperforms DUMONT in terms of detection rate, false positive rate, and even evasion-resistance. Finally, DECANTeR detects 96.8% of information stealers in our dataset, which shows its potential to detect data exfiltration. Riccardo Bortolameotti, Thijs van Ede, Marco Caselli, Maarten H. Everts, Pieter H. Hartel, Rick Hofstede, Willem Jonker, Andreas Peter 0001 |
ACSAC | 3 |
| 2016 | Specification Mining for Intrusion Detection in Networked Control Systems
Marco Caselli, Emmanuele Zambon, Johanna Amann, Robin Sommer, Frank Kargl |
USENIX Security Symposium | 1 |
| 2014 | A Security Assessment Methodology for Critical Infrastructures
Marco Caselli, Frank Kargl |
CRITIS | 1 |
| 2013 | On the Feasibility of Device Fingerprinting in Industrial Control Systems
Marco Caselli, Dina Hadziosmanovic, Emmanuele Zambon, Frank Kargl |
CRITIS | 1 |