EDBT 2026 Demo / reviewers in the wild / expert
Oleg Brodt
dblp:302/4502
· DBLP profile ↗
9ranked-venue papers
0as first author
9since 2021 · last 2026
0000-0002-2909-8676ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 6 · 6 since 2021Systems, architecture and hardware · 2 · 2 since 2021Computer networks · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | UEFI Memory Forensics: A Framework for UEFI Threat AnalysisabstractModern computing systems rely on the Unified Extensible Firmware Interface (UEFI), which has replaced the legacy Basic Input/Output System (BIOS) as the firmware standard for the modern boot process. Although the UEFI represents a significant advancement in system firmware, it is increasingly targeted by threat actors seeking to exploit its execution environment and take advantage of its persistence mechanisms. While some security-related analysis of UEFI components has been performed--primarily via debugging and runtime behavior testing--to the best of our knowledge, no prior study has specifically addressed the capturing and analysis of volatile UEFI runtime memory to detect malicious exploitation during the pre-OS phase. This gap in UEFI forensic tools limits the ability to conduct in-depth security analysis in pre-OS environments. Such a gap is particularly surprising, given that memory forensics is widely regarded as foundational to modern incident response, as reflected by the popularity of above-OS memory analysis frameworks, such as Rekall, Volatility, and MemProcFS. To address the lack of below-OS memory forensics, we introduce a framework for UEFI memory forensics. The proposed framework consists of two components: UEFIMemDump, a memory acquisition tool, and UEFIDumpAnalysis, an extendable collection of analysis modules capable of detecting malicious activities such as function pointer hooking, inline hooking, malicious image loading, and gadget-based control-flow manipulation. Our proof-of-concept implementation demonstrates the framework's ability to detect modern UEFI threats, such as Thunderstrike, CosmicStrand, and Glupteba bootkits. By providing an open-source solution, our work enables researchers and practitioners to investigate firmware-level threats, develop additional analysis modules, and advance overall below-OS security through UEFI memory analysis. Kalanit Suzan Segal, Hadar Cochavi Gorelik, Oleg Brodt, Yuval Elbahar, Yuval Elovici, Asaf Shabtai |
EuroS&P | 3 |
| 2025 | Detection of compromised functions in a serverless cloud environment
Lavi Ben-Shimol, Danielle Lavi, Eitan Klevansky, Oleg Brodt, Dudu Mimran, Yuval Elovici, Asaf Shabtai |
Comput. Secur. | 4 |
| 2025 | Adversarial machine learning threat analysis and remediation in Open Radio Access Network (O-RAN)
Edan Habler, Ron Biton, Dan Avraham, Eitan Klevansky, Dudu Mimran, Oleg Brodt, Heiko Lehmann, Yuval Elovici, Asaf Shabtai |
J. Netw. Comput. Appl. | 6 |
| 2025 | Observability and Incident Response in Managed Serverless Environments Using Ontology-Based Log MonitoringabstractIn fully managed serverless environments, cloud service providers handle the underlying infrastructure, reducing application developers’ operational and maintenance efforts. However, these environments limit the use of traditional cybersecurity frameworks and tools, compromising observability and situational awareness capabilities for security tasks (e.g., risk assessment, incident response). Additionally, existing security frameworks for serverless applications often lack generalizability across architectures and require specialized expertise. In this paper, we propose a three-layer security stack for fully managed serverless applications. The first layer establishes a foundational generic ontology that models serverless application resources and their interactions using API logs. In the second layer, the ontology is leveraged via perimeterless pipeline, to map the logs into a unified application activity KG, and in the third layer, two situational awareness tools that utilize the graph-based representation are implemented: (1) an incident response dashboard that leverages the ontology to visualize and examine application activity logs in the context of cybersecurity alerts; our user study showed that this dashboard enabled participants to respond 10% more accurately and almost twice as fast than the examined baseline tool, and (2) a criticality of asset (CoA) risk assessment framework that enables efficient expert-based prioritization in cybersecurity contexts; our expert-based questionnaire demonstrated strong agreement, achieving a Kendall-W score of 0.7179. Lavi Ben-Shimol, Edita Grolman, Aviad Elyashar, Inbar Maimon, Dudu Mimran, Oleg Brodt, Martin Strassmann, Heiko Lehmann, Yuval Elovici, Asaf Shabtai |
IEEE Trans. Cloud Comput. | 6 |
| 2024 | SMART: Serverless Module Analysis and Recognition Technique for Managed ApplicationsabstractServerless Function-as-a-Service (FaaS) environments enable developers to build and run cloud applications without the need to manage the underlying servers and computing infrastructure, allowing them to focus on implementing the application logic. Such environments contain numerous functions and dynamic resources, e.g., APIs and databases, making it challenging to gain insight and context of internal events i.e., recognize modules. Module in a serverless application is a set of functions and resources, that represents a functional unit that shares logical context. This paper presents SMART, a method for automatic analysis and recognition of modules for managed serverless applications. The proposed method creates an event-based graph by analyzing the standard serverless logs that document events involving the application’s functions and resources and utilizes well-known community detection algorithms (such as Louvain), with graph centrality metrics (such as degree centrality) to recognize the modules. SMART enables high-level visibility of the application’s structure and logical context which can facilitate security analysis and contribute to improved decision-making of incident response handlers, who typically do not have direct access to the application’s design and code, which can lead to challenges in fully understanding the system’s intricacies. We focused on the popular Amazon Web Services (AWS) Lambda serverless computing platform and evaluated the proposed method on three different demo applications (Airline Booking, VOD, and E-commerce). We compared SMART’s performance to four overlapping community detection algorithms and showed that it outperformed them in the task of module recognition, with a maximum improvement of 61% on the omega index metric compared to the Speaker-Listener Label Propagation algorithm. In addition, we demonstrate that the use of large language models (LLMs) with the knowledge gained by SMART can enrich security analysis insights. Adi Ashkenazi, Edita Grolman, Aviad Elyashar, Dudu Mimran, Oleg Brodt, Yuval Elovici, Asaf Shabtai |
CCGrid | 5 |
| 2024 | Green Security: A Framework for Measurement and Optimization of Energy Consumption of Cybersecurity SolutionsabstractInformation and communication technology (ICT) is playing an expanding and critical role in our modern lives. Due to its proliferation, ICT has a significant impact on global energy consumption, which in turn contributes to air pollution, climate change, water pollution, etc. The proliferation of ICT has been accompanied by the emergence of cybersecurity technologies and solutions, which play an integral role in society's digitalization. Wherever there is ICT, there is a need to secure it, resulting in an increase in global cybersecurity energy consumption as well. This paper discusses the energy-related aspects of cybersecurity solutions and defines a “Green Security” taxonomy. We highlight the inefficiencies stemming from various cybersecu-rity practices, such as processing the same data repeatedly. Within this context, we analyze cybersecurity solutions in common use cases, demonstrating the inherent energy consumption inefficiencies. In addition, we propose a method of measuring the energy consumed by cybersecurity solutions and present several optimization strategies that reduce their energy consumption. We evaluate our proposed optimization strategies and demonstrate their ability to reduce energy consumption while considering the organizational risk profile and maintaining the required security level. Sagi Brudni, Sapir Anidgar, Oleg Brodt, Dudu Mimran, Asaf Shabtai, Yuval Elovici |
EuroS&P | 3 |
| 2024 | OSSIntegrity: Collaborative open-source code integrity verification
Mor Nahum, Edita Grolman, Inbar Maimon, Dudu Mimran, Oleg Brodt, Aviad Elyashar, Yuval Elovici, Asaf Shabtai |
Comput. Secur. | 5 |
| 2022 | Security of Open Radio Access Networks
Dudu Mimran, Ron Biton, Yehonatan Kfir, Eitan Klevansky, Oleg Brodt, Heiko Lehmann, Yuval Elovici, Asaf Shabtai |
Comput. Secur. | 5 |
| 2022 | On the vulnerability of anti-malware solutions to DNS attacks
Asaf Nadler, Ron Biton, Oleg Brodt, Asaf Shabtai |
Comput. Secur. | 3 |