EDBT 2026 Demo / reviewers in the wild / expert
Raphael Yahalom
dblp:71/2062
· DBLP profile ↗
6ranked-venue papers
4as first author
1since 2021 · last 2025
0000-0001-6616-8293ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 5 · 3 first-author · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 first-author
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Network and information security
4 papers |
Network security · 93% Authentication and access control · 4% Cryptographic protocols and secure computation · 3% | |
| Computer networks
1 paper |
Network measurement and analytics · 100% | |
| Interdisciplinary, comprehensive, and emerging computing
1 paper |
Computational social science and digital humanities · 100% |
Topics — the 12 heaviest of 14, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Computational social science and digital humanities
network science |
0.3 | 1 | 2025 | Supply Chain Characteristics as Predictors of Cyber Risk: A Machine-Learning Assessment · IEEE Trans. Dependable Secur. Comput. 2025 |
Authentication and access control › authentication
authentication protocols |
0.0 | 2 | 1993 | Trust relationships in secure systems-a distributed authentication perspective · S&P 1993 Reasoning about Belief in Cryptographic Protocols · S&P 1990 |
Authentication and access control › user authentication
cross-domain authentication |
0.0 | 1 | 1993 | Trust relationships in secure systems-a distributed authentication perspective · S&P 1993 |
Cryptographic protocols and secure computation
key exchange |
0.0 | 1 | 1993 | Optimality of Multi-Domain Protocols · CCS 1993 |
Authentication and access control › trust management
trust establishment |
0.0 | 1 | 1993 | Trust relationships in secure systems-a distributed authentication perspective · S&P 1993 |
Distributed systems › distributed algorithms
distributed protocols |
0.0 | 1 | 1993 | Optimality of Multi-Domain Protocols · CCS 1993 |
Distributed systems › distributed algorithms
message-optimal protocols |
0.0 | 1 | 1993 | Optimality of Multi-Domain Protocols · CCS 1993 |
Cryptographic protocols and secure computation › security protocol analysis
belief logic |
0.0 | 1 | 1990 | Reasoning about Belief in Cryptographic Protocols · S&P 1990 |
Cryptographic protocols and secure computation
security protocol analysis |
0.0 | 1 | 1990 | Reasoning about Belief in Cryptographic Protocols · S&P 1990 |
Distributed systems › distributed system security
distributed authentication |
0.0 | 1 | 1993 | Trust relationships in secure systems-a distributed authentication perspective · S&P 1993 |
Distributed computing theory
asynchronous systems |
0.0 | 1 | 1993 | Optimality of Multi-Domain Protocols · CCS 1993 |
Authentication and access control
user authentication |
0.0 | 1 | 1990 | Reasoning about Belief in Cryptographic Protocols · S&P 1990 |
Methods — techniques the papers use, named apart from their topics
network science features · 2.6machine learning · 2.6message complexity analysis · 0.0recommendation-based trust derivation · 0.0formal trust modeling · 0.0belief logic · 0.0
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Supply Chain Characteristics as Predictors of Cyber Risk: A Machine-Learning AssessmentabstractThis paper provides the first large-scale data-driven analysis to evaluate the predictive power of digital supply chain attributes for assessing risk of cyberattack data breaches. Motivated by rapid increase in the complexity of digital supply chains and related third-party enabled cyberattacks, the paper provides the first quantitative empirical evidence that digital supply-chain attributes are significant predictors of enterprise cyber risk. The analysis leverages externally observable cybersecurity ratings that aim to capture the quality of the enterprise internal cybersecurity management, but augments these with original supply chain features that are inspired by observed third-party cyberattack scenarios, as well as concepts from network science research. The main quantitative result of the paper is to show that these supply chain network features add significant detection power to predicting enterprise cyber risk, relative to merely using enterprise-only attributes. In particular, compared to a base model that relies only on internal enterprise features, the supply chain network features improve the out-of-sample AUC by 2.3%. Given that a cyber data breach on a specific enterprise is a low probability high impact risk event, these improvements in the prediction power have significant value. Additionally, the model highlights several cybersecurity risk drivers related to third-party cyberattack and breach mechanisms and provides important insights as to what key metrics should be monitored and what interventions might be effective to mitigate these risks. Kevin Hu, Retsef Levi, Raphael Yahalom, El Ghali Zerhouni |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 1999 | e-Commerce Bargain-Hunting with an UnBun ModelabstractFirst-generation comparison-shopping software tools in general have limitations in dealing with bundled products. A new generic model for e-commerce comparison-shopping, based on a logical unBundling of sellers' offerings, is presented. The model captures dominance relationship between offerings and consumer requirements and may serve as a foundation for a variety of shopping decision support software tools. The model provides a basis for defining notions of bargains and designing algorithms for searching for them. Various implications and remaining challenges are outlined. Raphael Yahalom, Stuart E. Madnick |
CoopIS | 1 |
| 1993 | Optimality of Multi-Domain ProtocolsabstractProtocols which include key-distribution and data exchange phases in an asynchronous, shared key, multidomain environment are examined. A model of a distributed system is presented and the goals of the multidomain protocols are formulated. The minimal number of messages for two variants of such protocols is proved. Two multi-domain protocols which contain the minimal number of messages are presented. The results are compared with previously published work. Raphael Yahalom |
CCS | 1 |
| 1993 | Trust relationships in secure systems-a distributed authentication perspectiveabstractThe notion of trust is fundamental in inter-domain authentication protocols. The goal is to develop an effective formalism for explicit expressions of trust relations between entities involved in authentication protocols. Different relevant types of trust are identified and classified. A formalism for expressing trust relations is presented along with an algorithm for deriving trust relations from recommendations. The advantages of the approach are demonstrated by analyzing and comparing the trust relation requirements of a few known authentication protocols.> Raphael Yahalom, Birgit Klein, Thomas Beth |
S&P | 1 |
| 1993 | Optimality of Asynchronous Two-Party Secure Data-Exchange ProtocolsabstractThe problem of setting up two principals in a distributed asynchronous environment for a secure data-exchange session is examined. A model is presented and a theorem regarding necessary and sufficient conditions for establishing an upper bound on the duration between events is proved. The goals of secure data exchange protocols are motivated and precisely stated. A minimality result – establishing the minimal number of messages that are required to achieve these goals, is derived. Finally, a secure data exchange protocol which contains the minimal number of messages is presented, analyzed, and compared with previously published protocols. Raphael Yahalom |
J. Comput. Secur. | 1 |
| 1990 | Reasoning about Belief in Cryptographic ProtocolsabstractA mechanism is presented for reasoning about belief as a systematic way to understand the working of cryptographic protocols. The mechanism captures more features of such protocols than that given by M. Burrows et al. (1989) to which the proposals are a substantial extension. The notion of possession incorporated in the approach assumes that principles can include in messages data they do not believe in, but merely possess. This also enables conclusions such as 'Q possesses the shared key', as in an example to be derived. The approach places a strong emphasis on the separation between the content and the meaning of messages. This can increase consistency in the analysis and, more importantly, introduce the ability to reason at more than one level. The final position in a given run will depend on the level of mutual trust of the specified principles participating in that run.> Roger M. Needham, Raphael Yahalom |
S&P | 3 |