EDBT 2026 Demo / reviewers in the wild / expert
Jerry den Hartog
dblp:d/JerrydenHartog · also J. I. den Hartog
· DBLP profile ↗
32ranked-venue papers
3as first author
5since 2021 · last 2024
0009-0001-3846-9045ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 23 · 1 first-author · 4 since 2021Artificial intelligence and machine learning · 3 · 1 since 2021Computer networks · 2Theory of computation · 2 · 1 first-authorApplied, interdisciplinary, general and emerging computing · 2 · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 first-authorDatabases, data management, data science and information retrieval · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | Using DNS Patterns for Automated Cyber Threat AttributionabstractLinking attacks to the actors responsible is a critical part of threat analysis. Threat attribution, however, is challenging. Attackers try to avoid detection and avert attention to mislead investigations. The trend of attackers using malicious services provided by third parties also makes it difficult to discern between attackers and providers. Besides that, having a security team doing manual-only analysis might overwhelm analysts. As a result, the effective use of any trustworthy information for attribution is paramount, and automating this process is valuable. For this purpose, we propose an approach to perform automated attribution with a source of reliable information currently underutilised, the DNS patterns used by attackers. Our method creates recommendations based on similar patterns observed between a new incident and already attributed attacks and then generates a list of the most similar attacks. We show that our approach can, at ten recommendations, achieve 0.8438 precision and 0.7378 accuracy. We also show that DNS patterns have a short lifespan, allowing their utility even in more recent knowledge bases. Cristoffer Leite, Jerry den Hartog, Daniel Ricardo dos Santos |
ARES | 2 |
| 2024 | From Power to Water: Dissecting SCADA Networks Across Different Critical Infrastructures
Neil Ortiz Silva, Martin Rosso, Emmanuele Zambon, Jerry den Hartog, Alvaro A. Cárdenas |
PAM (1) | 4 |
| 2024 | WiP: Enhancing the Comprehension of XACML PoliciesabstractPolicy comprehension is crucial for ensuring data protection. Yet, policies written in flexible and expressive languages such as XACML are not easy to comprehend. In this work, we propose a visualization framework to facilitate the comprehension of XACML policies and their evaluation. Our framework shows a tree representation of the XACML policies to be enforced and highlights the contribution of its policy elements to the overall access decision, thus supporting the understanding of how this decision resulted from the interplay between possibly conflicting access requirements. We implemented our visualization framework as an extension to SAFAX, an XACML-based framework that offers authorization as a service. Gelareh Hasel Mehri, Tien-Dung Le, Bram C. M. Cappers, Jerry den Hartog, Nicola Zannone |
SACMAT | 4 |
| 2023 | Automated Cyber Threat Intelligence Generation on Multi-Host Network IncidentsabstractThe lack of automation is one of the main issues hindering the broad usage of high-level Cyber Threat Intelligence (CTI). Creating and using such information by capturing Tactics, Techniques and Procedures (TTPs) is currently an arduous manual task for Cyber Security Incident Response Teams (CSIRT). For CSIRTs, a Network Intrusion Detection System (NIDS) automates the detection of cyber threats. It provides relevant information about alerts to the analysts. This information could generate CTI reports to help others better protect themselves from similar attacks. Due to the demanding work involved in manually creating high-level CTI reports for multi-host incidents, automating this process has become increasingly important.In this paper, a solution is presented to automate the creation of verifiable high-level cyber threat intelligence reports by mapping chains of alerts to TTPs. The solution enables visualisation of attack chains and tactics used, but also manual analysis and validation of the reports created. The proposed approach is evaluated by comparing generating reports with existing CTI, validating any additional TTPs found. The evaluation shows that, not only it was able to match existing reports, but it was also able to improve the knowledge about these threats. Cristoffer Leite, Jerry den Hartog, Daniel Ricardo dos Santos, Elisa Costante |
IEEE Big Data | 2 |
| 2023 | A Framework for Privacy-Preserving White-Box Anomaly Detection using a Lattice-Based Access ControlabstractPrivacy concerns are amongst the core issues that will constrain the adoption of distributed anomaly detection. Indeed, when outsourcing anomaly detection, i.e. with a party other than the data owner running the detection, confidential or private aspects of the observed data may need protection. Some privacy-enhancing function is usually employed. Because of the impact that this restriction causes in the creation of explainable alerts, finding mechanisms to balance the trade-off between privacy and usefulness has become increasingly important. Due to this motivation, in this paper, a privacy-preserving white-box anomaly detection framework is presented to facilitate matching the compatibility between service requirements and privacy restrictions of an user by using an access control based on a lattice of privacy protection levels. Our framework allows entities to verify these trade-offs by specifying required protection at the level of features. We evaluate the framework in a real-world scenario within the e-health setting. The results point out that it can generate interpretable alerts while protecting the confidentiality of the data. Cristoffer Leite, Jerry den Hartog, Paul Koster |
SACMAT | 2 |
| 2020 | A Matter of Life and Death: Analyzing the Security of Healthcare Networks
Guillaume Dupont, Daniel Ricardo dos Santos, Elisa Costante, Jerry den Hartog, Sandro Etalle |
SEC | 4 |
| 2019 | Role Inference + Anomaly Detection = Situational Awareness in BACnet Networks
Davide Fauri, Michail Kapsalakis, Daniel Ricardo dos Santos, Elisa Costante, Jerry den Hartog, Sandro Etalle |
DIMVA | 5 |
| 2019 | Using Provenance for Secure Data Fusion in Cooperative SystemsabstractIn the context of cooperative systems, data coming from multiple, autonomous, heterogeneous information sources, is processed and fused into new pieces of information that can be further processed by other entities participating in the cooperation. Controlling the access to such evolving and variegated data, often under the authority of different entities, is challenging. In this work, we identify a set of access control requirements for multi-source cooperative systems and propose an attribute-based access control model where provenance information is used to specify access constraints that account for both the evolution of data objects and the process of data fusion. We demonstrate the feasibility of the proposed model by showing how it can be implemented within existing access control mechanisms with minimal changes. Clara Bertolissi, Jerry den Hartog, Nicola Zannone |
SACMAT | 2 |
| 2018 | Leveraging Semantics for Actionable Intrusion Detection in Building Automation Systems
Davide Fauri, Michail Kapsalakis, Daniel Ricardo dos Santos, Elisa Costante, Jerry den Hartog, Sandro Etalle |
CRITIS | 5 |
| 2018 | Security and privacy for innovative automotive applications: A survey
Van Huynh Le, Jerry den Hartog, Nicola Zannone |
Comput. Commun. | 2 |
| 2017 | Formal analysis of XACML policies using SMT
Fatih Turkmen, Jerry den Hartog, Silvio Ranise, Nicola Zannone |
Comput. Secur. | 2 |
| 2017 | A white-box anomaly-based framework for database leakage detection
Elisa Costante, Jerry den Hartog, Milan Petkovic, Sandro Etalle, Mykola Pechenizkiy |
J. Inf. Secur. Appl. | 2 |
| 2016 | An Authorization Service for Collaborative Situation AwarenessabstractIn international military coalitions, situation awareness is achieved by gathering critical intel from different authorities. Authorities want to retain control over their data, as they are sensitive by nature, and, thus, usually employ their own authorization solutions to regulate access to them. In this paper, we highlight that harmonizing authorization solutions at the coalition level raises many challenges. We demonstrate how we address authorization challenges in the context of a scenario defined by military experts using a prototype implementation of SAFAX, an XACML-based architectural framework tailored to the development of authorization services for distributed systems. Alexandru Ionut Egner, Duc Luu, Jerry den Hartog, Nicola Zannone |
CODASPY | 3 |
| 2016 | Data Governance and Transparency for Collaborative Systems
Rauf Mahmudlu, Jerry den Hartog, Nicola Zannone |
DBSec | 2 |
| 2016 | Towards Creating Believable Decoy Project Folders for Detecting Data Theft
Stefan Thaler, Jerry den Hartog, Milan Petkovic |
DBSec | 2 |
| 2015 | Cross-Domain Attribute Conversion for Authentication and AuthorizationabstractIn bio-security emergencies, such as an outbreak of an exotic animal disease, it is essential that the organizations involved in combating this outbreak collaborate effectively and efficiently. To achieve such a collaboration potentially confidential infrastructure and resources need to be shared amongst members of the participating organizations. In AU2EU we demonstrate the combination of existing data minimizing authentication, attribute-based authorization technologies to dynamically enable collaborations between these organization. However, a key problem that occurs during the establishment of such collaboration is different terminologies for similar authorization attributes. To overcome these differences and to minimize the overhead for new organizations to join an existing consortium we propose an ontology-based solution for converting attributes from one domain vocabulary to another. Additionally, we propose a methodology to construct a shared domain vocabulary. Using a shared domain vocabulary in the conversion process decreases the amount of alignments required for collaborating. We integrate and demonstrate the feasibility of this approach in a real-life scenario within the scope of AU2EU. This paper presents preliminary work, which is currently being deployed and will be evaluated in the upcoming months. Stefan Thaler, Jerry den Hartog, Dhouha Ayed, Dieter Sommer, Michael Hitchens |
ARES | 2 |
| 2015 | Understanding Perceived Trust to Reduce RegretabstractTrust is fundamental for promoting the use of online services, such as e‐commerce or e‐health. Understanding how users perceive trust online is a precondition to create trustworthy marketplaces. In this article, we present a domain‐independent general trust perception model that helps us to understand how users make online trust decisions and how we can help them in making the right decisions, which minimize future regret. We also present the results of a user study describing the weight that different factors in the model (e.g.,security,look&feel, andprivacy) have on perceived trust. The study identifies the existence of a positive correlation between the user's knowledge and the importance placed on factors such as security and privacy. This indicates that the impact factors as security and privacy have on perceived trust is higher in users with higher knowledge. Elisa Costante, Jerry den Hartog, Milan Petkovic |
Comput. Intell. | 2 |
| 2014 | POSTER: Analyzing Access Control Policies with SMTabstractThe flexibility and expressiveness of eXtensible Access Control Markup Language (XACML) allows the specification of a wide range of policies in different access control models. However, XACML policies are often verbose and, thus, prone to errors. Several tools have been developed to assist policy authors for the verification and analysis of policies, but most of them are limited in the types of analysis they can perform. In particular, they are not able to reason about predicates of non-boolean variables and, even if they do, they do it inefficiently. In this paper, we present the X2S framework, a formal framework for the analysis of XACML policies that employs Satisfiability Modulo Theories (SMT) as the underlying reasoning mechanism. The use of SMT not only allows more fine-grained analysis of policies, but it also improves the performance of policy analysis significantly. Fatih Turkmen, Jerry den Hartog, Nicola Zannone |
CCS | 2 |
| 2014 | Hunting the Unknown - White-Box Database Leakage Detection
Elisa Costante, Jerry den Hartog, Milan Petkovic, Sandro Etalle, Mykola Pechenizkiy |
DBSec | 2 |
| 2013 | TRIPLEX: verifying data minimisation in communication systemsabstractSystems dealing with personal information are legally required to satisfy the principle of data minimisation. Privacy-enhancing protocols use cryptographic primitives to minimise the amount of personal information exposed by communication. However, the complexity of these primitives and their interplay makes it hard for non-cryptography experts to understand the privacy implications of their use. In this paper, we present TRIPLEX, a framework for the analysis of data minimisation in privacy-enhancing protocols. Meilof Veeningen, Mayla Brusò, Jerry den Hartog, Nicola Zannone |
CCS | 3 |
| 2013 | Database Anomalous Activities - Detection and Quantification
Elisa Costante, Sokratis Vavilis, Sandro Etalle, Jerry den Hartog, Milan Petkovic, Nicola Zannone |
SECRYPT | 4 |
| 2011 | My Private Cloud Overview: A Trust, Privacy and Security Infrastructure for the CloudabstractBased on the assumption that cloud providers can be trusted (to a certain extent) we define a trust, security and privacy preserving infrastructure that relies on trusted cloud providers to operate properly. Working in tandem with legal agreements, our open source software supports: trust and reputation management, sticky policies with fine grained access controls, privacy preserving delegation of authority, federated identity management, different levels of assurance and configurable audit trails. Armed with these tools, cloud service providers are then able to offer a reliable privacy preserving infrastructure-as-a-service to their clients. David W. Chadwick, Stijn F. Lievens, Jerry den Hartog, Andreas Pashalidis, Joseph Alhadeff |
IEEE CLOUD | 3 |
| 2011 | Preface of Special Issue on "Computer Security: Foundations and Automated Reasoning"
Lujo Bauer, Sandro Etalle, Jerry den Hartog, Luca Viganò 0001 |
J. Autom. Reason. | 3 |
| 2010 | Principles on the Security of AES against First and Second-Order Differential Power Analysis
Jiqiang Lu, Jerry den Hartog |
ACNS | 3 |
| 2010 | Formal Verification of Privacy for RFID SystemsabstractRFID tags are being widely employed in a variety of applications, ranging from barcode replacement to electronic passports. Their extensive use, however, in combination with their wireless nature, introduces privacy concerns as a tag could leak information about the owner's behaviour. In this paper we define two privacy notions, unlinkability and forward privacy, using a formal model based on the applied pi calculus, and we show the relationship between them. Then we focus on a generic class of simple privacy protocols, giving sufficient and necessary conditions for unlinkability and forward privacy for this class. These conditions are based on the concept of frame independence that we develop in this paper. Finally, we apply our techniques to two identification protocols, formally proving their privacy guarantees. Mayla Brusò, Konstantinos Chatzikokolakis 0001, Jerry den Hartog |
CSF | 3 |
| 2010 | Towards Static Flow-Based Declassification for Legacy and Untrusted ProgramsabstractSimple non-interference is too restrictive for specifying and enforcing information flow policies in most programs. Exceptions to non-interference are provided using declassification policies. Several approaches for enforcing declassification have been proposed in the literature. In most of these approaches, the declassification policies are embedded in the program itself or heavily tied to the variables in the program being analyzed, thereby providing little separation between the code and the policy. Consequently, the previous approaches essentially require that the code be trusted, since to trust that the correct policy is being enforced, we need to trust the source code. In this paper, we propose a novel framework in which declassification policies are related to the source code being analyzed via its I/O channels. The framework supports many of the of declassification policies identified in the literature. Based on flow-based static analysis, it represents a first step towards a new approach that can be applied to untrusted and legacy source code to automatically verify that the analyzed program complies with the specified declassification policies. The analysis works by constructing a conservative approximation of expressions over input channel values that could be output by the program, and by determining whether all such expressions satisfy the declassification requirements stated in the policy. We introduce a representation of such expressions that resembles tree automata. We prove that if a program is considered safe according to our analysis then it satisfies a property we call Policy Controlled Release, which formalizes information-flow correctness according to our notion of declassification policy. We demonstrate, through examples, that our approach works for several interesting and useful declassification policies, including one involving declassification of the average of several confidential values. Bruno P. S. Rocha, Sruthi Bandhakavi, Jerry den Hartog, William H. Winsborough, Sandro Etalle |
IEEE Symposium on Security and Privacy | 3 |
| 2008 | An Operation-Based Metric for CPA Resistance
Jerry den Hartog, Erik P. de Vink |
SEC | 2 |
| 2008 | Towards mechanized correctness proofs for cryptographic algorithms: Axiomatization of a probabilistic Hoare style logic
Jerry den Hartog |
Sci. Comput. Program. | 1 |
| 2006 | A Probabilistic Hoare-style Logic for Game-Based Cryptographic Proofs
Ricardo Corin, Jerry den Hartog |
ICALP (2) | 2 |
| 2005 | Functional Principles of Registry-based Service DiscoveryabstractAs Service Discovery Protocols (SDP) are becoming increasingly important for ubiquitous computing, they must behave according to predefined principles. We present the functional Principles of Service Discovery for robust, registry-based service discovery. A methodology to guarantee adherence to these principles is provided and illustrated by formal verification of the principles against FRODO, an SDP built for the home environment. We show that, to make behavioral guarantees, an SDP has to be robust against network disturbances, and cannot rely only on the network layer. Vasughi Sundramoorthy, Pieter H. Hartel, Jerry den Hartog, Hans Scholten |
LCN | 3 |
| 2003 | PINPAS: A Tool for Power Analysis of Smartcards
Jerry den Hartog, Jan Verschuren, Erik P. de Vink, Jaap de Vos, W. Wiersma |
SEC | 1 |
| 1999 | Full Abstractness of a Metric Semantics for Action RefinementabstractFor a process language with action refinement and synchronization both an operational and a denotational semantics are given. The operational semantics is based on an SOS-style transition system specification involving syntactical refinement sequences. The denotational semantics is an interleaving model which uses semantical refinement ‘environments'. It identifies those statements which are equal under all refinements. The denotational model is shown to be fully abstract with respect to the operational one. The underlying metric machinery is exploited to obtain this full abstractness result. Usually, action refinement is treated either in a model with some form of true concurrency, or, when an interleaving model is applied, by assuming that the refining statements are atomized. We argue that an interleaving model without such atomization is attractive as well. Jerry den Hartog, Erik P. de Vink, J. W. de Bakker |
Fundam. Informaticae | 1 |