EDBT 2026 Demo / reviewers in the wild / expert
Thijs van Ede
dblp:210/4047
· DBLP profile ↗
10ranked-venue papers
2as first author
7since 2021 · last 2026
0000-0003-3865-6390ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 10 · 2 first-author · 7 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Knowing your weaknesses is your greatest strength: Mapping CVE to CWE by leveraging CWE Hierarchy and fine-tuned LLMsabstractEffective defense against threat actors requires that security professionals accurately identify the underlying weaknesses associated with common vulnerabilities and exposures (CVEs). This under standing is crucial for deploying appropriate defensive mechanisms and prioritizing remediation efforts. However, manually mapping CVEs to common weakness enumerations (CWEs) has become increasingly impractical due to the rapid increase of new CVEs and the extensive, complex CWE taxonomy. In 2025, the number of CVEs awaiting analysis exceeded 25,000. To automate the mapping between CVEs and CWEs, we propose to leverage two insights. To harness the power of large language models, we first fine-tune different language models to perform this mapping based on the vulnerability-to-weakness relation. Second, we propose a supervised framework leveraging the hierarchical structure of CWEs, where we first categorize vulnerabilities into broad CWE classes (e.g., Injection, Buffer Overflow), which helps capture high-level patterns, and then utilizes specialized subnet works to distinguish fine-grained differences within each class. Evaluated on a benchmarkthat covers 95% of all CVEs associated with a CWE, our approach improves F1-score by 5% over the best prior supervised method, demonstrating the value of combining model fine-tuning with hierarchy-aware classification. Stefano Simonetto, Ronan Oostveen, Thijs van Ede, Peter Bosch, Willem Jonker |
AsiaCCS | 3 |
| 2025 | Stop Watching Me! Moving from Data Protection to Privacy Preservation in Crowd Monitoring
Fatemeh Marzani, Thijs van Ede, Geert Heijenk, Maarten van Steen |
ARES (1) | 2 |
| 2025 | What Matters Most in Vulnerabilities? Key Term Extraction for CVE-to-CWE Mapping with LLMs
Stefano Simonetto, Ronan Oosteven, Thijs van Ede, Peter Bosch, Willem Jonker |
CANS | 3 |
| 2025 | Beyond CWEs: Mapping Weaknesses in Unstructured Threat Intelligence Text
Stefano Simonetto, Ronan Oosteven, Thijs van Ede, Peter Bosch, Willem Jonker |
CANS | 3 |
| 2025 | SoK: Automated TTP Extraction from CTI Reports - Are We There Yet?
Marvin Büchel, Tommaso Paladini, Stefano Longari, Michele Carminati, Stefano Zanero, Hodaya Binyamini, Gal Engelberg, Daniel Klein 0003, Giancarlo Guizzardi, Marco Caselli, Andrea Continella, Maarten van Steen, Andreas Peter 0001, Thijs van Ede |
USENIX Security Symposium | 14 |
| 2022 | Stepping out of the MUD: Contextual threat information for IoT devices with manufacturer-provided behavior profilesabstractBesides coming with unprecedented benefits, the Internet of Things (IoT) suffers deficits in security measures, leading to attacks increasing every year. In particular, network environments such as smart homes lack managed security capabilities to detect IoT-related attacks; IoT devices hosted therein are thus more easily targeted by threats. As such, context awareness of IoT infections is hard to achieve, preventing prompt response. In this work, we propose MUDscope, an approach to monitor malicious network activities affecting IoT systems in real-world consumer environments. We leverage the recent Manufacturer Usage Description (MUD) specification, which defines networking allow-lists for IoT devices in MUD profiles, to reflect consistent and necessarily-anomalous activities from smart things. Our approach characterizes this traffic and extracts signatures for given attacks. By analyzing attack signatures for multiple devices, we gather insights into emerging attack patterns. We evaluate our approach on both an existing dataset and a new, openly available dataset created for this research. We show that MUDscope detects several attacks targeting IoT devices with an F1-score of 95.77% and correctly identifies signatures for specific attacks with an F1-score of 87.72%. Luca Morgese Zangrandi, Thijs van Ede, Tim M. Booij, Savio Sciancalepore, Luca Allodi, Andrea Continella |
ACSAC | 2 |
| 2022 | DEEPCASE: Semi-Supervised Contextual Analysis of Security EventsabstractSecurity monitoring systems detect potentially malicious activities in IT infrastructures, by either looking for known signatures or for anomalous behaviors. Security operators investigate these events to determine whether they pose a threat to their organization. In many cases, a single event may be insufficient to determine whether certain activity is indeed malicious. Therefore, a security operator frequently needs to correlate multiple events to identify if they pose a real threat. Unfortunately, the vast number of events that need to be correlated often overload security operators, forcing them to ignore some events and, thereby, potentially miss attacks. This work studies how to automatically correlate security events and, thus, automate parts of the security operator workload. We design and evaluate DEEPCASE, a system that leverages the context around events to determine which events require further inspection. This approach reduces the number of events that need to be inspected. In addition, the context provides valuable insights into why certain events are classified as malicious. We show that our approach automatically filters 86.72% of the events and reduces the manual workload of security operators by 90.53%, while underestimating the risk of potential threats in less than 0.001% of cases. Thijs van Ede, Hojjat Aghakhani, Noah Spahn, Riccardo Bortolameotti, Marco Cova, Andrea Continella, Maarten van Steen, Andreas Peter 0001, Christopher Krügel, Giovanni Vigna |
SP | 1 |
| 2020 | FlowPrint: Semi-Supervised Mobile-App Fingerprinting on Encrypted Network Traffic
Thijs van Ede, Riccardo Bortolameotti, Andrea Continella, Daniel J. Dubois, Martina Lindorfer, David R. Choffnes, Maarten van Steen, Andreas Peter 0001 |
NDSS | 1 |
| 2019 | Victim-Aware Adaptive Covert Channels
Riccardo Bortolameotti, Thijs van Ede, Andrea Continella, Maarten H. Everts, Willem Jonker, Pieter H. Hartel, Andreas Peter 0001 |
SecureComm (1) | 2 |
| 2017 | DECANTeR: DEteCtion of Anomalous outbouNd HTTP TRaffic by Passive Application FingerprintingabstractWe present DECANTeR, a system to detect anomalous outbound HTTP communication, which passively extracts fingerprints for each application running on a monitored host. The goal of our system is to detect unknown malware and backdoor communication indicated by unknown fingerprints extracted from a host's network traffic. We evaluate a prototype with realistic data from an international organization and datasets composed of malicious traffic. We show that our system achieves a false positive rate of 0.9% for 441 monitored host machines, an average detection rate of 97.7%, and that it cannot be evaded by malware using simple evasion techniques such as using known browser user agent values. We compare our solution with DUMONT [24], the current state-of-the-art IDS which detects HTTP covert communication channels by focusing on benign HTTP traffic. The results show that DECANTeR outperforms DUMONT in terms of detection rate, false positive rate, and even evasion-resistance. Finally, DECANTeR detects 96.8% of information stealers in our dataset, which shows its potential to detect data exfiltration. Riccardo Bortolameotti, Thijs van Ede, Marco Caselli, Maarten H. Everts, Pieter H. Hartel, Rick Hofstede, Willem Jonker, Andreas Peter 0001 |
ACSAC | 2 |