EDBT 2026 Demo / reviewers in the wild / expert
Willi Lazarov
dblp:354/0933
· DBLP profile ↗
6ranked-venue papers
5as first author
6since 2021 · last 2026
0000-0001-6820-8391ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 4 · 4 first-author · 4 since 2021Artificial intelligence and machine learning · 2 · 1 first-author · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 1 first-author · 2 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Comparative analysis of OSINT tools, techniques, and legal aspectsabstractOpen Source Intelligence (OSINT) has emerged as a crucial practice in the digital era, driven by the rapid growth of information available on the internet and its expanding applications across multiple sectors. This study examines the role of OSINT as a vital tool in domains such as the indexed internet, social networks, the darknet, archives, and network devices. We present a comparative analysis over 140 tools, services, and databases usable for OSINT. The analysis reveals significant diversity in functionality, licensing, and accessibility, with no single solution capable of meeting all intelligence needs. The findings emphasize the necessity of combining multiple tools with manual methods to acquire accurate and reliable intelligence, while also highlighting persistent challenges, including limited integrations, licensing constraints, and the volatility of online sources. Beyond technical and methodological aspects, OSINT practice is shaped by complex legal and ethical considerations, as the public availability of data does not guarantee lawful use. This study provides a legal analysis of the General Data Protection Regulation (GDPR) and the Budapest Convention in relation to OSINT investigations. As compliance remains context-specific, the study underscores that the future of OSINT depends not only on technological advancement, but also on strong legal and ethical responsibility to mitigate risks of liability and reputational harm. Willi Lazarov, Vojtech Moravec, Pavel Loutocký, Jakub Vostoupal, Zdenek Martinasek |
Comput. Secur. | 1 |
| 2025 | Penterep: Comprehensive penetration testing with adaptable interactive checklistsabstractIn the contemporary landscape of cybersecurity, the importance of effective penetration testing is underscored by NIS2, emphasizing the need to assess and demonstrate cyber resilience. This paper introduces an innovative approach to penetration testing that employs interactive checklists, supporting both manual and automated tests, as demonstrated within the Penterep environment. These checklists, functioning as a quantifiable measure of test completeness, guide pentesters through methodological testing, addressing the inherent challenges of the security testing domain. While some may perceive a limitation in the dependency on predefined checklists, the results from a presented case study underscore the criticality of methodological testing. The study reveals that relying solely on fully automated tools would be inadequate to identify all vulnerabilities and flaws without the inclusion of manual tests. Our innovative approach complements established methodologies, such as PTES, OWASP, and NIST, providing crucial support to penetration testers and ensuring a comprehensive testing process. Implemented within the Penterep environment, our approach is designed with deployment flexibility (both on-premises and cloud-based), setting it apart through an overview comparison with existing tools aligned with state-of-the-art penetration testing approaches. This flexible and scalable approach effectively bridges the gap between manual and automated testing, meeting the increasing demands for effectiveness and adaptability in penetration testing. • An innovative approach to penetration testing using adaptable interactive checklists. • Automation of testing to increase its effectiveness and reduce repetitive tasks. • Penetration testing environment design and implementation using high customizability. • Showcase using the provided case study, concluded with lessons learned. Willi Lazarov, Pavel Seda, Zdenek Martinasek, Roman Kummel |
Comput. Secur. | 1 |
| 2024 | Event-based Data Collection and Analysis in the Cyber Range EnvironmentabstractThe need to educate users on cybersecurity to some extent is critical due to the ever-increasing cyber threats. A number of web presentations, books, and other study materials can be used for this purpose. In contrast to passive learning methods, hands-on training offers a deeper perspective but poses considerable technical challenges to its implementation, which can be resolved using cyber range platforms. However, in order to thoroughly evaluate the training and provide sufficient feedback, data must be collected and analyzed. Our paper addresses this problem by developing an event-based approach for data collection and analysis. The use of events allows us to keep a history of an event and reconstruct it retrospectively, especially for further analysis and evaluation. We validated the implemented approach in a cyber range environment, in which we developed an interactive interface to visualize the analyzed data. Willi Lazarov, Samuel Janek, Zdenek Martinasek, Radek Fujdiak |
ARES | 1 |
| 2024 | Sandbox Environment for Offensive and Defensive Training in Smart Metering
David Kohout, Willi Lazarov, Tomás Lieskovan, Petr Mlynek |
IEA/AIE | 2 |
| 2024 | Training Scenario for Security Testing of the Kerberos Protocol
Willi Lazarov, Antonin Bohacik, David Kohout, Radek Fujdiak |
IEA/AIE | 1 |
| 2023 | Interactive Environment for Effective Cybersecurity Teaching and LearningabstractCybersecurity affects all users to some extent, and it is essential to raise awareness about potential cybersecurity risks and improve practical skills from an early stage of their education. This paper addresses these aspects and discusses the research, design, and implementation of a platform for effective cybersecurity teaching and learning. Our main contribution is the creation of an interactive environment with the easy-to-use execution and management of educational and training scenarios. Our solution is tailored for multi-level education, as well as small to medium-sized institutions, and we have validated its effectiveness through several test sessions conducted with university and high school students. In addition, the paper presents selected preliminary results from the testing performed and an overall evaluation of the environment. Willi Lazarov, Tomas Stodulka, Tiina Schafeitel-Tähtinen, Marko Helenius, Zdenek Martinasek |
ARES | 1 |