EDBT 2026 Demo / reviewers in the wild / expert
Philipp Reinecke
dblp:42/5902
· DBLP profile ↗
11ranked-venue papers
3as first author
3since 2021 · last 2023
0000-0002-2411-0891ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 4 · 3 first-authorSecurity and privacy · 3 · 2 since 2021Software engineering, systems software and programming languages · 3 · 1 first-authorComputer networks · 1Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2023 | A systematic method for measuring the performance of a cyber security operations centre analystabstractAnalysts who work in a Security Operations Centre (SOC) play an essential role in supporting businesses to protect their computer networks against cyber attacks. To manage analysts efficiently and effectively, SOC managers and stakeholders use Key Performance Indicators (KPIs) to evaluate their performance. However, existing literature suggests a lack of a systematic approach for assessing analysts’ performance. Even though cyber security researchers advocate for research into this area, little effort has been made by researchers to address this gap. Drawing on the results of a Delphi panel with industry experts and the principles of the Analytic Hierarchy Process (AHP), this paper interrogates the problem and proposes a systematic weighted approach for measuring the performance of an analyst in a SOC. The proposed method, referred to as a SOC Analyst Assessment Method (SOC-AAM), was evaluated in two SOCs as a part of an experimental case study. The results of the empirical evaluation show that the SOC-AAM enables SOC managers and stakeholders to quantify and assess analysts’ performance in a systematic manner. The SOC-AAM also provides a novel guideline for assessing the quality of incident analysis and the quality of incident reports. This study will be of interest to practitioners and cyber security researchers seeking to understand the operations of a SOC analyst. Enoch Agyepong, Yulia Cherdantseva, Philipp Reinecke, Pete Burnap |
Comput. Secur. | 3 |
| 2022 | Bane or Boon: Measuring the effect of evasive malware on system call classifiersabstractMalware refers to software that is designed to achieve a malicious purpose usually to benefit its creator. To accomplish this, malware hides its true purpose from its target and malware analysts until it has established a foothold on the victim’s machine. Malware analysts, therefore, have to find increasingly sophisticated methods to detect malware prompting malware authors to increase the number of evasive techniques employed by their malware. Dynamic malware analysis has been framed as a potential solution as it runs malware in its preferred environment to ensure that it observes its true behaviour. However, it is usually a restricted form of the preferred environment and malware may only be run for two minutes or less. This means that if malware does not demonstrate its malicious intent within that time frame and environment, the behaviour observed and subsequently learned may not be the behaviour that needs to be prevented. There is a risk that classifiers trained using the standard dynamic malware analysis process will only recognise malware by its evasive behaviour rather than a mix of behaviours. In this paper, we study the extent to which classifiers are dependent on evasive behaviour when identifying malware. We achieve this by training them on real ransomware and benignware and then testing their ability to detect carefully crafted simulated ransomware. The simulated ransomware gives us the freedom to create samples with different levels of evasive and malicious behaviour. The simulated samples, like the real samples, are run in a sandboxed environment where data is collected at a user- and Kernel-level. The results of our experiments indicated that, in general, the classifiers were more likely to label the simulated samples as malicious once the amount of evasive behaviour present in a sample went beyond a threshold. Generally, this threshold was crossed when the simulated ransomware waited 2 s or more between each file it encrypted. Additionally, the classifiers trained on the user-level data were not as robust against small changes in system calls made. Whereas, when trained on system calls gathered at a Kernel, system-wide level, the classifiers’ results were less variable. Finally, in attempting to simulate malware for our experiments, we discovered that the field of malware simulation is relatively unstudied despite its potential and therefore provide recommendations for simulating malware for system-call analysis. Matthew Nunes, Pete Burnap, Philipp Reinecke, Kaelon Lloyd |
J. Inf. Secur. Appl. | 3 |
| 2022 | Cybersecurity Challenges in the Offshore Oil and Gas Industry: An Industrial Cyber-Physical Systems (ICPS) PerspectiveabstractThere has been significant interest within the offshore oil and gas industry to utilise Industrial Internet of Things (IIoT) and Industrial Cyber-Physical Systems (ICPS) . There has also been a corresponding increase in cyberattacks targeted at oil and gas companies. Offshore oil production requires remote access to and control of large and complex hardware resources. This is achieved by integrating ICPS, Supervisory, Control and Data Acquisition (SCADA) systems, and IIoT technologies. A successful cyberattack against an oil and gas (O&G) offshore asset could have a major impact on the environment, marine ecosystem and safety of personnel. Any disruption to the world’s supply of O&G can also have an effect on oil prices and the global economy. We describe the cyberattack surface within the oil and gas industry, discussing emerging trends in the offshore sub-sector and provide a historical perspective of known cyberattacks. We also present a case study of a subsea control system architecture typically used in offshore O&G operations and highlight potential vulnerabilities affecting the components of the system. This study is the first to provide a detailed analysis of attack vectors in a subsea control system. The analysis provided can be used to understand key vulnerabilities in such systems and may be used to implement efficient mitigation methods. Abubakar Sadiq Mohammed, Philipp Reinecke, Pete Burnap, Omer F. Rana, Eirini Anthi |
ACM Trans. Cyber Phys. Syst. | 2 |
| 2019 | Getting to the root of the problem: A detailed comparison of kernel and user level data for dynamic malware analysisabstractDynamic malware analysis is fast gaining popularity over static analysis since it is not easily defeated by evasion tactics such as obfuscation and polymorphism. During dynamic analysis it is common practice to capture the system calls that are made to better understand the behaviour of malware. There are several techniques to capture system calls, the most popular of which is a user-level hook. To study the effects of collecting system calls at different privilege levels and viewpoints, we collected data at a process-specific user-level using a virtualised sandbox environment and a system-wide kernel-level using a custom-built kernel driver. We then tested the performance of several state-of-the-art machine learning classifiers on the data. Random Forest was the best performing classifier with an accuracy of 95.2% for the kernel driver and 94.0% at a user-level. The combination of user and kernel level data gave the best classification results with an accuracy of 96.0% for Random Forest. This may seem intuitive but was hitherto not empirically demonstrated. Additionally, we observed that machine learning algorithms trained on data from the user-level tended to use the anti-debug/anti-vm features in malware to distinguish it from benignware. Whereas, when trained on data from our kernel driver, machine learning algorithms seemed to use the differences in the general behaviour of the system to make their prediction, which explains why they complement each other so well. Our results show that capturing data at different privilege levels will affect the classifier’s ability to detect malware, with kernel-level providing more utility than user-level for malware classification. Despite this, there exist more established user-level tools than kernel-level tools, suggesting more research effort should be directed at kernel-level. In short, this paper provides the first objective, evidence-based comparison of user and kernel level data for the purposes of malware classification. Matthew Nunes, Pete Burnap, Omer F. Rana, Philipp Reinecke, Kaelon Lloyd |
J. Inf. Secur. Appl. | 4 |
| 2015 | GRnet: A Tool for Gnetworks with RestartabstractGnetworks extend standard queueing networks as to include different types of customers or jobs. In addition to ordinary jobs also signals, or negative jobs can arrive to a queue. A signal removes a job from the queue instead of adding one. The interpretation of a signal as retry is very natural and induces semantics to the arrival of a signal. The job that is hit by the signal first leaves the queue but then immediately returns as a new job. The mathematical specification of Gnetworks with retry has become a cumbersome task. Therefore we present in this tool-demo paper a new tool that will support the specification and analysis of Gnetwork models with retries. Katinka Wolter, Philipp Reinecke, Matthias Dräger |
ICPE | 2 |
| 2014 | Does a given vector-matrix pair correspond to a PH distribution?
Philipp Reinecke, Miklós Telek |
Perform. Evaluation | 1 |
| 2013 | Multiple class G-networks with restartabstractRestart is a common technique for improving response-times in complex systems where the causes of delays can either not be discerned, or not be addressed by the user. With restart, the user aborts a running job that exceeds a deadline, and resubmits it to the system immediately. In many common scenarios, this approach can reduce the response-times that the user experiences. Restart has been well-studied for scenarios where only one user applies restart, and typically in cases where queueing effects can be neglected. In this paper we approach the question of restart in a scenario where restart is applied by many users in a system that can be modelled as an open queueing network. We apply the G-Networks formalism to this problem. We use negative customers to model the abortion and retry of a request. The open G-network uses multiple classes with phase-type distributed service times. This allows the approximation of a preemptive repeat different behaviour as it is natural for multiple restarts of a request. We compute the response time of a request and show that an optimal restart interval can be found. The results are compared with simulation. Jean-Michel Fourneau, Katinka Wolter, Philipp Reinecke, Tilman Krauss, Alexandra Danilkina |
ICPE | 3 |
| 2012 | Micro and macro views of discrete-state markov models and their application to efficient simulation with phase-type distributionsabstractNo abstract available. Philipp Reinecke, Miklós Telek, Katinka Wolter |
SIGMETRICS | 1 |
| 2012 | Gossip routing, percolation, and restart in wireless multi-hop networksabstractRoute and service discovery in wireless multi-hop networks applies flooding or gossip routing to disseminate and gather information. Since packets may get lost, retransmissions of lost packets are required. In many protocols the retransmission timeout is fixed in the protocol specification. In this paper we demonstrate that optimization of the timeout is required in order to ensure proper functioning of flooding schemes. Based on an experimental study, we apply percolation theory and derive analytical models for computing the optimal restart timeout. To the best of our knowledge, this is the first comprehensive study of gossip routing, percolation, and restart in this context. Bastian Blywis, Philipp Reinecke, Mesut Günes, Katinka Wolter |
WCNC | 2 |
| 2010 | Evaluating the adaptivity of computing systems
Philipp Reinecke, Katinka Wolter, Aad P. A. van Moorsel |
Perform. Evaluation | 1 |
| 2009 | On-line monitoring for model-based QoS management in IEEE 802.11 wireless networksabstractEnsuring Quality of Service (QoS) in wireless networks poses an open problem in many application domains. We propose an automatic on-line QoS monitoring and management infrastructure that can be incorporated into existing network setups. Based on model-based assessment of current and future QoS conditions, our solution will control traffic in the network through a combination of admission control, enforced handover, traffic shaping and transmission parameter adjustments. Correctness of the model is evaluated through experimental evaluation and simulations. We implement a prototype of the proposed system using open-source components. Johannes Semmler, Katinka Wolter, Philipp Reinecke |
MASCOTS | 3 |