EDBT 2026 Demo / reviewers in the wild / expert
Marina Krotofil
dblp:136/2619 · also Maryna Krotofil
· DBLP profile ↗
6ranked-venue papers
4as first author
2since 2021 · last 2024
—ORCID · none
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 4 · 2 first-author · 2 since 2021Systems, architecture and hardware · 2 · 2 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | A Tale of Two Industroyers: It was the Season of DarknessabstractIn this paper, we study two pieces of malware that attempted to create blackouts in Ukraine. In particular, we design and develop a new sandbox that emulates different networks, devices, and other characteristics so that we can execute malware targeting substation equipment and understand in detail the specific sequence of actions the attackers could perform on substation equipment. We also study the effects that future similar malware can have. Our findings include new malware behavior not previously documented (such as the detailed algorithm for the MMS protocol payload) and an illustration of how attacking different targets will produce different effects. Luis E. Salazar, Sebastián R. Castro, Juan Lozano, Keerthi Koneru, Emmanuele Zambon, Ross Baldick, Marina Krotofil, Alonso Rojas, Alvaro A. Cárdenas |
SP | 8 |
| 2021 | PCaaD: Towards automated determination and exploitation of industrial systemsabstractOver the last decade, Programmable Logic Controllers (PLCs) have been increasingly targeted by attackers to obtain control over industrial processes that support critical services.Such targeted attacks typically require detailed knowledge of system-specific attributes, including hardware configurations, adopted protocols, and PLC control-logic, i.e., process comprehension.The consensus from both academics and practitioners suggests stealthy process comprehension obtained from a PLC alone, to execute targeted attacks, is impractical.In contrast, we assert that current PLC programming practices open the door to a new vulnerability class, affording attackers an increased level of process comprehension.To support this, we propose the concept of Process Comprehension at a Distance (PCaaD), as a novel methodological and automatable approach towards the system-agnostic identification of PLC library functions.This leads to the targeted exfiltration of operational data, manipulation of control-logic behavior, and establishment of covert command and control channels through unused memory.We validate PCaaD on widely used PLCs through its practical application. Benjamin Green 0001, Richard Derbyshire, Marina Krotofil, William Knowles, Daniel Prince, Neeraj Suri |
Comput. Secur. | 3 |
| 2015 | The Process Matters: Ensuring Data Veracity in Cyber-Physical SystemsabstractCyber-physical systems are characterized by an IT infrastructure controlling effects in the physical world. Attacks are intentional actions trying to cause undesired physical effects. When process data originating in the physical world is manipulated before being handed to the IT infrastructure, the data security property called "veracity" or trustworthiness will be violated. There is no canonical IT security solution guaranteeing that the inputs from a sensor faithfully represent reality. However, the laws of physics may help the defender to detect impossible or implausible sensor readings. Marina Krotofil, Jason Larsen, Dieter Gollmann |
AsiaCCS | 1 |
| 2014 | CPS: driving cyber-physical systems to unsafe operating conditions by timing DoS attacks on sensor signalsabstractDoS attacks on sensor measurements used for industrial control can cause the controller of the process to use stale data. If the DoS attack is not timed properly, the use of stale data by the controller will have limited impact on the process; however, if the attacker is able to launch the DoS attack at the correct time, the use of stale data can cause the controller to drive the system to an unsafe state. Marina Krotofil, Alvaro A. Cárdenas, Bradley Manning, Jason Larsen |
ACSAC | 1 |
| 2013 | Industrial control systems security: What is happening?abstractIncreasing awareness of ICS security issues has brought about a growing body of work in this area, including pioneering contributions based on realistic control system logs and network traces. This paper surveys the state of the art in ICS security research, including efforts of industrial researchers, highlighting the most interesting works. Research efforts are grouped into divergent areas, where we add “secure control” as a new category to capture security goals specific to control systems that differ from security goals in traditional IT systems. Marina Krotofil, Dieter Gollmann |
INDIN | 1 |
| 2013 | Industrial control systems security: What is happening?abstractIncreasing awareness of ICS security issues has brought about a growing body of work in this area, including pioneering contributions based on realistic control system logs and network traces. This paper surveys the state of the art in ICS security research, including efforts of industrial researchers, highlighting the most interesting works. Research efforts are grouped into divergent areas, where we add “secure control” as a new category to capture security goals specific to control systems that differ from security goals in traditional IT systems. Marina Krotofil, Dieter Gollmann |
INDIN | 1 |