EDBT 2026 Demo / reviewers in the wild / expert
Krzysztof Cabaj
dblp:77/3368
· DBLP profile ↗
23ranked-venue papers
9as first author
9since 2021 · last 2024
0000-0002-5955-5890ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 15 · 7 first-author · 5 since 2021Artificial intelligence and machine learning · 4 · 2 first-author · 2 since 2021Applied, interdisciplinary, general and emerging computing · 4 · 2 first-author · 2 since 2021Software engineering, systems software and programming languages · 3 · 2 first-author · 1 since 2021Systems, architecture and hardware · 1Computer networks · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1Theory of computation · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | Identity and Access Management Architecture in the SILVANUS ProjectabstractSILVANUS is a scientific collaboration EU-funded project with the goal to mitigate the growing impact of wildfires caused by global climate change by implementing a comprehensive global fire prevention strategy. Due to the significant complexity and collaborative nature of the project which involves more than 50 parties, it is a challenge to ensure unified and governed security especially that the platform is based on heterogeneous and multi-component architecture. To ensure the security requirements are delivered, different security architecture perspectives need to be considered and one of these is identity and access management. Pawel Rajba, Natan Orzechowski, Karol Rzepka, Przemyslaw Szary, Dawid Nastaj, Krzysztof Cabaj |
ARES | 6 |
| 2024 | Performance evaluation of Raspberry Pi 4 and STM32 Nucleo boards for security-related operations in IoT environmentsabstractAt present, Internet of Things devices are revolutionizing and impacting increasingly more areas of our daily lives. However, there remain doubts related to the lack of sufficient security in the IoT ecosystem. As such devices have limitations in terms of resources such as computational power and batteries, adding security mechanisms is often perceived as an unnecessary burden, slowing the further expansion of IoT-based solutions and applications. In this study, an investigation is conducted to verify the possibility of applying security measures such as strong encryption without hindering the performance of IoT devices. This factor is especially important from the perspective of the European project SILVANUS, in which various IoT application scenarios are envisioned. Taking into account the above, in this work, an extensive experimental performance evaluation campaign is performed using the DTLS-based encryption of network traffic for two popular boards: Raspberry Pi 4 and STM32 Nucleo. The obtained results demonstrate that the utilization of strong encryption is feasible (with some limitations) on IoT devices, but the resulting performance or battery life is not a reasonable argument anymore to leave IoT ecosystems completely insecure. Karol Rzepka, Przemyslaw Szary, Krzysztof Cabaj, Wojciech Mazurczyk |
Comput. Networks | 3 |
| 2024 | A Meta-Analysis of State-of-the-Art Automated Fake News Detection MethodsabstractRecently, various artificial intelligence (AI)-based methods have been proposed to support humans in detecting disinformation and fake news. The goal of this article is to provide a meta-analysis, and formally evaluate, compare, and benchmark various classes of fake news detection approaches. To this end, the following paper performs a comprehensive analysis of the performance-related results of different models using a range of benchmark datasets. The performed and disclosed meta-analysis compares the statistical significance of differences in a range of performance metrics, including precision,$F1$-score, recall, and balanced accuracy (BACC). The utilized approach features the$5$$\times$$2$cross-validation methodology. The models undergoing the formal evaluation constitute state-of-the-art (SOTA) solutions meeting acceptance criteria. The evaluated approaches draw from the most recent advancements in natural language processing (NLP). The outcome of this work is the formal benchmarking and meta-analysis of fake news detection methods that can be further utilized by the research community, but more importantly by the practitioners and decision-makers that counter fake news on a daily basis, e.g., in press agencies, homeland security agencies, fact-checkers, and so on. This work is the natural extension of the authors’ previous systematic analysis of fake news detection methods and authors’ own fake news detection methods based on machine learning (ML)/artificial intelligence (AI) techniques. Rafal Kozik, Aleksandra Pawlicka, Marek Pawlicki, Michal Choras, Wojciech Mazurczyk, Krzysztof Cabaj |
IEEE Trans. Comput. Soc. Syst. | 6 |
| 2023 | Security Architecture in the SILVANUS projectabstractSILVANUS is a new EU-funded project whose main objectives are to address the causes of wildfires in Europe. To achieve this aim, a dedicated platform for environmentally sustainable and climate-resilient forest management has been developed with the help of many state-of-the-art, modern technologies. One of the major challenges to solve when building such a heterogeneous, multi-component, multipurpose platform is to provide the necessary security architecture. It should ensure that only trusted users and devices (e.g., sensors, drones, UGVs, etc.) would be allowed to use it, and attackers or other third parties would not jeopardize its communication and assets. In this paper, we outline the main design principles, solutions, and mechanisms we have considered when building the security architecture for the SILVANUS platform. Moreover, we present the current state of development of this platform and the main challenges we have been facing. Natan Orzechowski, Karol Rzepka, Przemyslaw Szary, Krzysztof Cabaj, Wojciech Mazurczyk, Helen-Catherine Leligou, Marcin Przybyszewski, Rafal Kozik, Michal Choras |
ARES | 4 |
| 2023 | Combating Disinformation with Holistic Architecture, Neuro-symbolic AI and NLU ModelsabstractIt is important to realize that false news is more than just a deception. Sadly, it is impossible to confirm every bit of information we come across. A normal human impulse is to accept any information that looks sufficiently convincing, relevant, or exciting. In doing so, we often do not realize that we have just contributed to the misinformation of the community to which we belong. As a result, fake news happens to be our collective error. In this paper, we propose an architecture for combating the disinformation problem using a hybrid-based approach. We demonstrate our preliminary results on the health-related fake news dataset. Rafal Kozik, Wojciech Mazurczyk, Krzysztof Cabaj, Aleksandra Pawlicka, Marek Pawlicki, Michal Choras |
DSAA | 3 |
| 2022 | Web Page Harvesting for Automatized Large-scale Digital Images Anomaly DetectionabstractCurrently, digital media content is increasingly being used by cybercriminals for nefarious purposes. Such objects can be used, e.g., to covertly transfer malicious code to the infected host or to exfiltrate sensitive information from the secured perimeter to the attacker’s server. In this paper, we present the design and deployment of a web page harvesting platform that allows performing various types of large-scale analyses, including metadata inspection, detection of hidden data, or evaluation of compliance with the graphical standard. The platform architecture has a distributed, flexible, and modular form, making it easily extendable and efficient. In this article, we also include initial experimental results of the analyzes carried out on the content of 1,000 of the most popular websites. Marcin Kowalczyk, Agnieszka Malanowska, Wojciech Mazurczyk, Krzysztof Cabaj |
ARES | 4 |
| 2022 | Performance Evaluation of DTLS Implementations on RIOT OS for Internet of Things ApplicationsabstractThe popularity, variety, and number of Internet of Things (IoT) devices and solutions have been increasing significantly with each passing year. This diversity of devices, and limited computational, memory, and battery resources make it difficult to apply effective security solutions. That is why dedicated mechanisms for the protection of IoT-based transmissions are developed. One of the most popular solutions is Datagram Transport Layer Security (DTLS), which allows securing datagram-based applications. In this paper, we investigate how efficient the three currently available DTLS implementations provided by the RIOT Operating System are. Based on the results obtained, interested parties can choose the DTLS module that has the best performance for the chosen IoT application. Karol Rzepka, Przemyslaw Szary, Krzysztof Cabaj, Wojciech Mazurczyk |
ARES | 3 |
| 2022 | Resource Partitioning in Phoenix-RTOS for Critical and Noncritical Software for UAV systemsabstractModern embedded systems' increasing complexity and varied safety levels make it hard to coordinate all functionalities within a single run-time environment.Access to more advanced and capacious hardware changes the trend from utilising many separated platforms into one managing the whole compounded airborne system.Providing an appropriate isolation and synchronisation level is achievable only by adapting an operating system with separation mechanisms into UAV systems.This paper introduces Phoenix-RTOS, the microkernel structured real-time operating system designed to be consistent with aerospace standards DO-178C and ARINC 653.The current market offers many counterparts like VxWorks, Integrity 178, PikeOS and many others.These products are well known and used in leading-edge avionics and space projects.However, it is not possible to use them in many low-budget projects due to the high price.The Phoenix-RTOS differs from others and is an open-source project becoming a standard solution for energy, gas meters and UAV systems.In this paper, we focus on the currently designed mechanisms of microkernel architecture for providing a mixed-criticality system, particularly for compliance with ARINC 653.Engineers have been identifying time and space partitioning issues to cope with tight worst-case execution bounds of critical tasks. Hubert Buczynski, Pawel Pisarczyk, Krzysztof Cabaj |
FedCSIS | 3 |
| 2021 | Study of the Error Detection and Correction Scheme for Distributed Network Covert ChannelsabstractInformation hiding in communication networks is gaining recently increased attention from the security community. This is because such techniques are a double-edged sword that, on the one hand, can be used, e.g., to enhance the privacy of Internet users while on the other can be utilized by malware developers to enable a covert communication feature in malicious software. This means that to understand the risks that data hiding poses, it is of utmost importance to study the inner workings of potential information hiding methods and accompanying mechanisms (e.g., those that provide reliability of such communications) as well as to develop effective and efficient countermeasures. That is why, in this paper we perform a systematic experimental evaluation of the error detection and correcting scheme, which is suitable for complex network data hiding approaches, i.e., distributed network covert channels (DNCCs). The obtained results prove that the proposed solution guarantees secret communication reliability even when faced with severe networking conditions up to 20% of data corruption while maintaining a stable covert data rate. Piotr Nowakowski, Piotr Zórawski, Krzysztof Cabaj, Wojciech Mazurczyk |
ARES | 3 |
| 2020 | Distributed packet inspection for network security purposes in software-defined networking environmentsabstract5G networks are foreseen to offer rich ubiquitous communication infrastructure with wide range of high-quality services. However, as they are formed using a mix of modern network technologies ensuring their security is crucial. Currently, Software Defined Networking is envisioned as a key technology to provide security in 5G. However, due to its centralized nature SDN-based systems may suffer from performance issues and are difficult to scale. That is why in this paper, we propose a novel distributed packet inspection method which is easy to scale, migrate and is able to utilize any existing SDN controller software. Instead of running a single instance of SDN controller process we propose to utilize multiple processes and to distribute the traffic in a fair manner across running instances. In result, such a load-balancing solution is able to run independently on multiple machines allowing for highly scalable solution. Performed experimental evaluation proves that such solution is efficient and effective. Piotr Nowakowski, Piotr Zórawski, Krzysztof Cabaj, Marcin Gregorczyk, Maciej Purski, Wojciech Mazurczyk |
ARES | 3 |
| 2020 | Network covert channels detection using data mining and hierarchical organisation of frequent sets: an initial studyabstractCurrently, malware developers are increasingly turning their attention towards various types of information hiding techniques to conceal their malicious actions on the compromised machine or the network. One group of such mechanisms are network covert channels (CCs) which utilize subtle modifications to the legitimate network traffic to carry secret data. Unfortunately, nowadays no general detection approach exists that is able to fight covert communication in an efficient and scalable manner. On the contrary, typically for a given information hiding technique a dedicated detection solution is devised. That is why, in this paper we investigate possibility to utilize data mining approach to detect network covert channels: both distributed and undistributed. Specifically, we propose to rely on the hierarchical organisation of frequent sets discovered by the data mining algorithm and use it together with an outlier detection-based traffic classifier. Initial performance results reveal that the proposed solution has potential but it needs to be further evaluated in more realistic scenarios. Piotr Nowakowski, Piotr Zórawski, Krzysztof Cabaj, Wojciech Mazurczyk |
ARES | 3 |
| 2020 | Special issue on Advancements in 5G Networks Security
Wojciech Mazurczyk, Pascal Bisson, Roger Piqueras Jover, Koji Nakao, Krzysztof Cabaj |
Future Gener. Comput. Syst. | 5 |
| 2019 | Sniffing Detection within the Network: Revisiting Existing and Proposing Novel ApproachesabstractSniffing is a crucial part of the network attack where an intruder tries to gather as much information as possible on the devices, protocols and applications residing within the targeted network in order to discover their vulnerabilities. It is typically performed using dedicated software called sniffers and it is based on passively analyzing the traffic exchanged within the network. Due to its passive nature such malicious actions are quite hard to be discovered. That is why, in this paper we first revisit existing approaches and tools known from the state-of-the-art. Then we introduce a novel detection method which is able to identify suspicious machine using specially crafted network traffic and based on its reaction is able to infer whether sniffer is running or not. Krzysztof Cabaj, Marcin Gregorczyk, Wojciech Mazurczyk, Piotr Nowakowski, Piotr Zórawski |
ARES | 1 |
| 2019 | Fine-tuning of Distributed Network Covert Channels Parameters and Their Impact on UndetectabilityabstractCurrently the usage of various information hiding techniques for nefarious purposes becomes a major issue. Especially when the attackers, in order to stay under the radar, utilize increasingly sophisticated ways to conceal data. One of such advanced techniques is the use of distributed network covert channels (DNCC) where the secrets are spread among a number of available covert channels and transmitted in parallel. Taking above into consideration, in this paper we investigate how the data hiding techniques forming a DNCC can be configured to achieve an improved undetectability and how this impacts the DNCC performance and its detection susceptibility. Based on the presented results it can be concluded that if the utilized steganographic techniques forming a DNCC are used in a balanced manner then this may pose difficulties from the detection perspective although this typically also means significant limitation of the overall secret data rate. Krzysztof Cabaj, Wojciech Mazurczyk, Piotr Nowakowski, Piotr Zórawski |
ARES | 1 |
| 2019 | Network Threats Mitigation Using Software-Defined Networking for the 5G Internet of Radio Light SystemabstractCurrently 5G communication networks are envisioned to offer in a near future a wide range of high-quality services and unfaltering user experiences. In order to achieve this, several issues including security, privacy, and trust aspects need to be solved so that the 5G networks can be widely welcomed and accepted. Considering above, in this paper, we take a step towards these requirements by proposing a dedicated SDN-based integrated security framework for the Internet of Radio Light (IoRL) system that is following 5G architecture design. In particular, we present how TCP SYN-based scanning activities and DHCP-related network threats like Denial of Service (DoS), traffic eavesdropping, etc. can be detected and mitigated using such an approach. Enclosed experimental results prove that the proposed security framework is effective and efficient and thus can be considered as a promising defensive solution. Krzysztof Cabaj, Marcin Gregorczyk, Wojciech Mazurczyk, Piotr Nowakowski, Piotr Zórawski |
Secur. Commun. Networks | 1 |
| 2018 | SDN-based Mitigation of Scanning Attacks for the 5G Internet of Radio Light SystemabstractCurrently 5G communication networks are gaining on importance among industry, academia, and governments worldwide as they are envisioned to offer wide range of high-quality services and unfaltering user experiences. However, certain security, privacy and trust challenges need to be addressed in order for the 5G networks to be widely welcomed and accepted. That is why in this paper, we take a step towards these requirements and we introduce a dedicated SDN-based integrated security framework for the Internet of Radio Light (IoRL) system that is following 5G architecture design. In particular, we present how TCP SYN-based scanning activities which typically comprise the first phase of the attack chain can be detected and mitigated using such an approach. Enclosed experimental results prove that the proposed security framework has potential to become an effective defensive solution. Krzysztof Cabaj, Marcin Gregorczyk, Wojciech Mazurczyk, Piotr Nowakowski, Piotr Zórawski |
ARES | 1 |
| 2018 | Towards Distributed Network Covert Channels Detection Using Data Mining-based ApproachabstractCurrently, due to improvements in defensive systems network covert channels are increasingly drawing attention of cybercriminals and malware developers as they can provide stealthiness of the malicious communication and thus to bypass existing security solutions. On the other hand, the utilized data hiding methods are getting increasingly sophisticated as the attackers, in order to stay under the radar, distribute the covert data among many connections, protocols, etc. That is why, the detection of such threats becomes a pressing issue. In this paper we make an initial step in this direction by presenting a data mining-based detection of such advanced threats which relies on pattern discovery technique. The obtained, initial experimental results indicate that such solution has potential and should be further investigated. Krzysztof Cabaj, Wojciech Mazurczyk, Piotr Nowakowski, Piotr Zórawski |
ARES | 1 |
| 2018 | Towards Deriving Insights into Data Hiding Methods Using Pattern-based ApproachabstractIn network information hiding, hiding patterns are used to describe hiding methods and their taxonomy. In this paper, we analyze the current state of hiding patterns and we further improve their taxonomy. In order to more thoroughly characterize and understand data hiding methods applied to communication networks we propose to distinguish between sender-side and receiver-side patterns. Additionally, we show how information hiding patterns can be utilized to conveniently describe the realization of the distributed network covert channels. Wojciech Mazurczyk, Steffen Wendzel, Krzysztof Cabaj |
ARES | 3 |
| 2018 | Cybersecurity education: Evolution of the discipline and analysis of master programs
Krzysztof Cabaj, Dulce Domingos, Zbigniew Kotulski, Ana Respício |
Comput. Secur. | 1 |
| 2018 | Cybersecurity: trends, issues, and challenges
Krzysztof Cabaj, Zbigniew Kotulski, Bogdan Ksiezopolski, Wojciech Mazurczyk |
EURASIP J. Inf. Secur. | 1 |
| 2017 | The impact of malware evolution on the analysis methods and infrastructureabstractThe huge number of malware introduced each day demands methods and tools for their automated analyses.Complex and distributed infrastructure of malicious software and new sophisticated techniques used to obstruct the analyses are discussed in the paper based on real-life malware evolution observed for a long time.Their impact on both toolsets and methods are presented based on practical development of systems for malware analyses and new features for existing tools. Krzysztof Cabaj, Piotr Gawkowski, Konrad Grochowski, Alexis Nowikowski, Piotr Zórawski |
FedCSIS | 1 |
| 2016 | Developing malware evaluation infrastructureabstractMalware evaluation is a key factor in security.It supposed to be safe and accurate.The contemporary malware is very sophisticated.Usually it uses complex distributed infrastructure an investigation of which is a very challenging task.In the paper, the development of the testbeds toward malware and its infrastructure evaluation is presented.Based on the real-life experience with the subsequent CryptoWall generations analysis, the MESS evaluation system is introduced.A rich set of analytical results is discussed.A new methods of visualization for malware artefacts analysis are given. Krzysztof Cabaj, Piotr Gawkowski, Konrad Grochowski, Amadeusz Kosik |
FedCSIS | 1 |
| 2012 | What are suspicious VoIP delays?
Wojciech Mazurczyk, Krzysztof Cabaj, Krzysztof Szczypiorski |
Multim. Tools Appl. | 2 |