EDBT 2026 Demo / reviewers in the wild / expert
Daniel Schlette
dblp:267/6739
· DBLP profile ↗
5ranked-venue papers
3as first author
4since 2021 · last 2024
0000-0002-4847-522XORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 4 · 3 first-author · 3 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | Do You Play It by the Books? A Study on Incident Response Playbooks and Influencing FactorsabstractIncident response "playbooks" are structured sets of operational procedures organizations use to instruct humans or machines on performing countermeasures against cybersecurity threats. These playbooks generally combine information about a given threat and organizational aspects relevant within the context of an organization. Both types of information are crucial for using, maintaining, and sharing playbooks across organizations as they ensure effectiveness and confidentiality. While practitioners show great interest in playbooks, their characteristics have not yet been thoroughly investigated from a research perspective. For this reason, we explore the topic by analyzing what is inside a playbook. Our approach consists of a comprehensive empirical assessment of available data (1217 playbooks), an online study with 147 participants, and final in-depth interviews with nine security professionals to consolidate and validate our findings. We notably find intrinsic ambiguities in the way practitioners and organizations define their playbooks. Furthermore, we notice that available playbooks cannot be used outright which might currently impair their wide use across different cybersecurity actors. As a result, we can conclude that organizations do "play it by the books" but individually define what is inside their playbooks and which areas of incident response they might address. Daniel Schlette, Philip Empl, Marco Caselli, Thomas Schreck, Günther Pernul |
SP | 1 |
| 2022 | SOAR4IoT: Securing IoT Assets with Digital TwinsabstractAs more and more security tools provide organizations with cybersecurity capabilities, security analysts are overwhelmed by security events. Resolving these events is challenging due to extensive manual processes, limited financial resources, and human errors. Security Orchestration, Automation, and Response (SOAR) is an established approach to manage security tools and assets. However, SOAR platforms typically integrate traditional IT systems only. Additional considerations are required to deal with the Internet of Things (IoT), its multiple devices and complex networks. Therefore, we adapt SOAR to IoT. We first aggregate existing research and information on SOAR and SOAR platforms. We envision the SOAR4IoT framework, making IoT assets manageable for SOAR via middleware. We implement a prototypical digital twin-based SOAR application integrating IoT assets and security tools to validate our framework. The experimental setup includes two playbooks coping with Mirai and Sybil attacks. Results show feasibility as our SOAR application enables securing IoT assets with digital twins. Philip Empl, Daniel Schlette, Daniel Zupfer, Günther Pernul |
ARES | 2 |
| 2022 | Harnessing Digital Twin Security Simulations for systematic Cyber Threat IntelligenceabstractUnderstanding cybersecurity threats, attacks, and incidents is crucial for organizations to perform preventive or re-active measures. Nevertheless, detailed Cyber Threat Intelligence (CTI) is reluctantly shared. Digital twins, the virtual counterparts of real-world assets, offer security simulation capabilities. The simulation of attack scenarios on industrial control systems (ICS) with digital twins yields valuable threat information. In our work, we outline the systematic steps towards a structured threat report starting with digital twin security simulations: We first present the course of action and define formal requirements for framework deployment. We then conduct an attack simulation with a prototypical digital twin application to evaluate our frame-work. Using the STIX2.1 standard, we assist CTI generation by providing utility tools guiding through the process steps. Our experimental results show that a STIX2.1 CTI report can be systematically constructed with the opportunity to customize according to the use case at hand. Adding digital twin security simulations to the list of CTI sources can provide shareable CTI and help organizations improve their security posture. Marietheres Dietz, Daniel Schlette, Günther Pernul |
COMPSAC | 2 |
| 2021 | CTI-SOC2M2 - The quest for mature, intelligence-driven security operations and incident response capabilities
Daniel Schlette, Manfred Vielberth, Günther Pernul |
Comput. Secur. | 1 |
| 2020 | Security Enumerations for Cyber-Physical Systems
Daniel Schlette, Florian Menges, Thomas Baumer, Günther Pernul |
DBSec | 1 |