EDBT 2026 Demo / reviewers in the wild / expert
Hugo L. J. Bijmans
dblp:248/1645
· DBLP profile ↗
5ranked-venue papers
5as first author
3since 2021 · last 2026
—ORCID · none
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 4 · 4 first-author · 2 since 2021Artificial intelligence and machine learning · 1 · 1 first-author · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Tickets to Hide: An Inside Look into the Anti-Abuse Ecosystem through Internal Abuse Data
Hugo L. J. Bijmans, Michel van Eeten, Rolf van Wegberg |
NDSS | 1 |
| 2024 | No Time to Choose: Leveraging Internet Scans to Determine IoC LifetimesabstractSharing Indicators of Compromise (IoCs) containing IP addresses used by attackers for command-and-control (C2) through threat intelligence feeds is an everyday practice within the cyber security industry. Once a new IP address is added to a feed, the question arises of when exactly this IP address was under the attacker’s control. Has the attacker been utilizing it for a matter of hours, or has this usage persisted for days? And how long will the attacker maintain control over this IP after being blocklisted? In this work, we delve into the issue of IoC lifetime estimation. We demonstrate and quantify the problems that arise from static retention times, which prompted the introduction of a novel, data-driven technique for C2 IP address lifetime estimation to optimize their retention times, thereby improving the use of threat intelligence in security operations. A combination of datasets conferred historic IP profiles for 1,968 infections associated with four types of malware. Validation through ground truth data labeling revealed a 14 times improvement in false discovery rates compared to a static retention time of 40 days at the expense of a 2.5 times higher false negative rate. We publish our technique and encourage the (scientific) security community to build upon our work to make it more accurate and applicable for real-world use. Hugo L. J. Bijmans, M. S. C. van Leuken |
IEEE Big Data | 1 |
| 2021 | Catching Phishers By Their Bait: Investigating the Dutch Phishing Landscape through Phishing Kit Detection
Hugo L. J. Bijmans, Tim M. Booij, Anneke Schwedersky, Aria Nedgabat, Rolf van Wegberg |
USENIX Security Symposium | 1 |
| 2019 | Just the Tip of the Iceberg: Internet-Scale Exploitation of Routers for CryptojackingabstractThe release of an efficient browser-based cryptominer, as introduced by Coinhive in 2017, has quickly spread throughout the web either as a new source of revenue for websites or exploited within the context of hacks and malicious advertisements. Several studies have analyzed the Alexa Top 1M and found 380 - 3,200 (0.038% - 0.32%) to be actively mining, with an estimated $41,000 per month revenue for the top 10 perpetrators. While placing a cryptominer on a popular website supplies considerable returns from its visitors' web browsers, it only generates revenue while a client is visiting the page. Even though large popular websites attract millions of visitors, the relatively low number of exploiting websites limits the total revenue that can be made. In this paper, we report on a new attack vector that drastically overshadows all existing cryptojacking activity discovered to date. Through a firmware vulnerability in MikroTik routers, cyber criminals are able to rewrite outgoing user traffic and embed cryptomining code in every outgoing web connection. Thus, every web page visited by any user behind an infected router would mine to profit the criminals. Based on NetFlows recorded in a Tier 1 network, semiweekly crawls and telescope traffic, we followed their activities over a period of 10 months, and report on the modus operandi and coordinating infrastructure of the perpetrators, which were during this period in control of up to 1.4M routers, approximately 70% of all MikroTik devices deployed worldwide. We observed different levels of sophistication among adversaries, ranging from individual installations to campaigns involving large numbers of routers. Our results show that cryptojacking through MITM attacks is highly lucrative, a factor of 30 more than previous attack vectors. Hugo L. J. Bijmans, Tim M. Booij, Christian Doerr |
CCS | 1 |
| 2019 | Inadvertently Making Cyber Criminals Rich: A Comprehensive Study of Cryptojacking Campaigns at Internet Scale
Hugo L. J. Bijmans, Tim M. Booij, Christian Doerr |
USENIX Security Symposium | 1 |