REVIEW 3 major objections 4 minor 61 references
A Guide to Stakeholder Analysis for Cybersecurity Researchers
T0 review · 3 major / 4 minor · reviewed 2026-08-05 · deepseek-v4-flash
Pith's one-line read This paper argues that stakeholder-based ethics analysis for cybersecurity can be reduced to a two-step procedure: use a canonical stakeholder table, then use a research-method-to-stakeholder map, demonstrated on four real studies.
desk verdict A useful, clearly written guide for a real upcoming ethics requirement, but its central direct/indirect stakeholder distinction is internally inconsistent and the mapping needs justification before it can be trusted as a community reference. read the letter →
The pith
A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.
The reading
What carries the argument
The load-bearing machinery is a pair of tables and a two-way distinction. Table 1 lists twelve stakeholder categories separated into direct and indirect. Table 2 groups common cybersecurity research methods—controlled experiments, interviews, case studies, repository mining and corpus analysis, tool evaluation and benchmarking, simulation, longitudinal and meta-science studies, systematic review and replication—and asserts the typical direct stakeholders for each cluster. The direct/indirect distinction separates stakeholders reached through short, observable causal links from those affected through diffuse or downstream effects. The Menlo Report's four principles supply the ethical baseline
What would settle it
Take a cohort of published cybersecurity papers spanning Table 2's method clusters, apply the guide's tables to predict each paper's direct and indirect stakeholders, then compare those predictions with the harms, complaints, or retractions the papers later attract. If a substantial share of realized harms involves stakeholder categories absent from Table 1 or absent from that cluster's row in Table 2, the mapping is incomplete.
Extended reading notes
Core claim
The guide's central claim is that stakeholder identification in cybersecurity research is a method-driven enumeration task. Step one is to use Table 1's canonical list of direct stakeholders (participants, system operators, software maintainers, data subjects, the research team) and indirect stakeholders (end users, vulnerable populations, adversaries, broader public, institutions). Step two is to use Table 2, whose rows are clusters of empirical research methods derived from the empirical standards cited in the paper, to see which stakeholders a project's method most likely exposes. The paper further claims that problem domain determines who is exposed, while research method determines how
Load-bearing premise
The load-bearing premise is that Table 2's mapping from research methods to typical direct stakeholders is complete and correct, a claim the paper asserts from the empirical standards without showing its derivation; a secondary premise is that the four worked examples, all from the authors' own lab, are representative enough to demonstrate the procedure.
Editorial extensions
If this is right
- A research team preparing a USENIX Security 2026 ethics statement can begin with Table 1 as a checklist and use Table 2 to focus on the stakeholders its research method most likely exposes.
- Because a single study can fall into several method clusters, the guide implies stakeholder lists should be unioned across clusters rather than read as mutually exclusive.
- Reviewers and IRB reviewers can use the same two tables to test whether an ethics statement's coverage is plausible, instead of relying on intuition about who might be harmed.
- The worked examples show that changing the research method while keeping the problem domain can change the exposed stakeholder set, so ethics analysis must track methodology, not just topic.
Reading between the lines
- My inference: Table 2 would be strongest if validated empirically—for each method cluster, one could collect post-publication harm reports, retractions, or public controversies and check whether Table 2 would have named the affected parties.
- My inference: the paper leaves implicit how a multi-method study should weigh competing harms across clusters; a practical extension would be a prioritization rule for merging conflicting stakeholder exposures.
- My inference: because all four worked examples are drawn from the authors' own research, transferability to human-subjects-heavy or large-scale measurement studies outside that setting is untested but directly testable by applying the tables to other published papers.
Signed reviews
Editorial analysis
A structured set of objections, weighed in public.
Referee Report
Summary. The paper is a practical guide to stakeholder-based ethics analysis for cybersecurity research, motivated by the USENIX Security 2026 requirement that submissions include a stakeholder analysis. It defines direct and indirect stakeholders, proposes a mapping from research method clusters to typical direct stakeholders (Table 2, claimed to be derived from the SIGSOFT Empirical Standards), and presents four worked examples drawn exclusively from the authors' own prior publications (Section 4). The paper's central claim is that a researcher following this guide can enumerate relevant stakeholders for a project and draft an ethics statement with reasonable completeness.
Significance. The guide addresses a timely and genuine need: many cybersecurity researchers are now required to perform stakeholder analysis but may lack a concrete procedure. The paper is clearly written, well structured, and offers useful baseline categories in Table 1. The worked examples, though self-referential, illustrate the intended workflow and surface realistic ethical concerns. If the method-to-stakeholder mapping were properly warranted and internally consistent, the guide would be a valuable community resource. However, the load-bearing mapping and the examples are not currently validated, and the central classification has an internal inconsistency with the paper's own definition of direct stakeholders.
major comments (3)
- [§2.2 and Table 2] The definition in §2.2 states that direct stakeholders 'interact with, or are explicitly involved in, the research process (e.g., as participants or collaborators).' Table 2, however, lists 'OSS maintainers, contributors, downstream users' as typical direct stakeholders for Repository Mining/Corpus Analysis, and 'Original study authors' as direct for Systematic Review/Replication. These actors do not interact with or participate in the research; they are affected through publication or use of results, which matches the paper's own indirect-stakeholder definition. Because Table 2 is the core deliverable enabling stakeholder identification, this inconsistency undermines the guide's central promise. The definition or the table must be revised and made mutually consistent.
- [§3, Table 2] The paper asserts that the method clusters in Table 2 are 'derived from the SIGSOFT Empirical Standards' but provides no derivation. The reader cannot verify which standards categories map to which clusters, why these particular stakeholder sets are associated, or why the lists are complete. This makes the central mapping an unsubstantiated assertion. Please provide a traceable mapping from the standards' method categories to the clusters, or explicitly reframe the table as an untested heuristic. The current presentation overstates the evidence base.
- [§4, Table 3, Examples A–D] The worked examples are explicitly restricted to papers whose authors are on the present author list, 'to mitigate concerns about bias or blame.' This means the examples cannot serve as validation of the framework's completeness or representativeness; they are self-selected illustrations from a single lab. Moreover, the classifications are internally inconsistent across examples: Table 3 lists Adversaries as a direct stakeholder in Examples A, C, and D, but as an indirect stakeholder in Example B, despite A, B, and D all combining corpus analysis with tool evaluation. The paper needs explicit criteria for direct/indirect assignment and at least one independent worked example outside the authors' own corpus.
minor comments (4)
- [§5.1] The paper cites reference [19] for the 'USENIX Security 2026 Call for Papers,' but [19] is the USENIX Security 2025 CFP. The 2026 CFP is [3]. Please correct the citation.
- [§4.1.2, §4.2.2] The text contains the typo 'e.g.,, IoT' in both examples; delete the extra comma.
- [Table 2] The note says 'Citations in bold are included in the analysis in §4.' Ensure the bold formatting is applied consistently to all four papers analyzed in §4 ([32], [34], [28], [37]) or remove the note if formatting is not meaningfully rendered.
- [§4.3] The text says 'published in USENIX 2025'; referring to the venue as 'USENIX Security 2025' would be more precise and consistent with the reference list.
Circularity Check
No significant circularity: the guide's taxonomy and mapping rest on external sources and asserted judgments, not on fitting or re-deriving its own examples; the only self-referential element is the choice of worked examples, which is a generalizability limitation rather than a circular derivation.
full rationale
This is a practical guide, not a derivation with fitted parameters or predictions. The stakeholder definition in §2.2 is imported from external requirements-engineering literature (Sharp et al. [12]; Freeman [13]), and the method clusters in Table 2 are explicitly attributed to the SIGSOFT Empirical Standards [27], an external source. The mapping from methods to typical direct stakeholders is presented as an asserted judgment, not as something derived from the worked examples. The worked examples in §4 are all drawn from the authors' own papers ('To mitigate concerns about bias or blame, we only discuss papers whose authors are represented on the author list of the present guide'), which is a real self-selection limitation for demonstrating generalizability, but the examples are applications of the framework, not the inputs from which the framework is fitted or defined. No equation, parameter, or 'prediction' reduces to its own input by construction. Section 3 says the method clusters are 'derived from the SIGSOFT Empirical Standards' but does not show the derivation; that is missing support, not circularity. Similarly, the internal inconsistency between §2.2's definition of direct stakeholders (interact with, or are explicitly involved in, the research process) and Table 2's classification of OSS maintainers and downstream users as direct for repository mining is a correctness/consistency concern, not a circularity concern. Overall, no load-bearing self-citation chain or definitional equivalence exists; the central claims remain independent of the examples used to illustrate them.
Assumptions & free parameters
assumptions (5)
- domain assumption The Menlo Report's four principles (respect for persons, beneficence, justice, respect for law and public interest) are a valid baseline for computing research ethics.
- domain assumption USENIX Security 2026 requires a stakeholder-based ethics analysis in all submissions.
- domain assumption Stakeholder identification is a necessary prerequisite for ethical analysis.
- ad hoc to paper The method clusters in Table 2, with their typical direct stakeholders, are a valid grouping derived from the SIGSOFT Empirical Standards.
- ad hoc to paper The four worked examples (papers authored by members of this guide's author list) are representative of the method categories and illustrate typical stakeholder exposures.
Cite this review
Pith. "Pith review of A Guide to Stakeholder Analysis for Cybersecurity Researchers." pith.science (2026). https://pith.science/paper/2DZS7OPC
@misc{pith2026250814796,
author = {Pith},
title = {Pith review of: A Guide to Stakeholder Analysis for Cybersecurity Researchers},
year = {2026},
howpublished = {\url{https://pith.science/paper/2DZS7OPC}},
note = {Machine review of arXiv:2508.14796}
}
read the original abstract
Stakeholder-based ethics analysis is now a formal requirement for submissions to top cybersecurity research venues. This requirement reflects a growing consensus that cybersecurity researchers must go beyond providing capabilities to anticipating and mitigating the potential harms thereof. However, many cybersecurity researchers may be uncertain about how to proceed in an ethics analysis. In this guide, we provide practical support for that requirement by enumerating stakeholder types and mapping them to common empirical research methods. We also offer worked examples to demonstrate how researchers can identify likely stakeholder exposures in real-world projects. Our goal is to help research teams meet new ethics mandates with confidence and clarity, not confusion.
Figures
Reference graph
Works this paper leans on
-
[6]
Ethical frameworks and computer security trolley problems: foundations for conversations,
T. Kohno, Y . Acar, and W. Loh, “Ethical frameworks and computer security trolley problems: foundations for conversations,” in2023 Proceedings of the 32th USENIX Security Symposium, 2023, pp. 5145–5162
2023
-
[1]
The moral character of cryptographic work,
P. Rogaway, “The moral character of cryptographic work,” Cryptology ePrint Archive, 2015
2015
-
[2]
Message from the usenix security ’25 program co-chairs,
USENIX Security Symposium 2025 Program Co- Chairs, “Message from the usenix security ’25 program co-chairs,” 2025, accessed: 2025-08-14. [Online]. Avail- able: https://www.usenix.org/sites/default/files/sec25_ message.pdf
2025
-
[3]
USENIX Security ’26 Call for Papers,
USENIX Security Symposium 2026 Program Committee, “USENIX Security ’26 Call for Papers,” 2025, accessed: 2025-07-31. [On- line]. Available: https://www.usenix.org/conference/ usenixsecurity26/call-for-papers
2026
-
[4]
The menlo report: Ethical principles guiding information and commu- nication technology research,
D. Dittrich and E. Kenneally, “The menlo report: Ethical principles guiding information and commu- nication technology research,” U.S. Department of Homeland Security, Tech. Rep., 2012. [Online]. Avail- able: https://www.caida.org/publications/papers/2012/ menlo_report_actual_formatted/
2012
-
[5]
T. L. Beauchamp and J. F. Childress, Principles of Biomedical Ethics, 8th ed. Oxford University Press, 2019
2019
-
[7]
Friedman, P
B. Friedman, P. H. Kahn Jr., and A. Borning, Value Sensitive Design and Information Systems . John Wiley & Sons, Ltd, 2008, ch. 4, pp. 69–101. [Online]. Available: https://onlinelibrary.wiley.com/doi/abs/10. 1002/9780470281819.ch4
2008
-
[8]
J. S. Mill, Utilitarianism. Parker, Son, and Bourn, 1863
Show all 61 references
-
[9]
Kant,Groundwork of the Metaphysics of Morals, 1785, translated by Mary Gregor (Cambridge Unviersity Press, 2nd ed., 2012)
I. Kant,Groundwork of the Metaphysics of Morals, 1785, translated by Mary Gregor (Cambridge Unviersity Press, 2nd ed., 2012)
2012
-
[10]
Modern moral philosophy,
G. Anscombe, “Modern moral philosophy,” Philosophy, vol. 33, no. 124, pp. 1–19, 1958
1958
-
[11]
Shostack, Threat Modeling: Designing for Security
A. Shostack, Threat Modeling: Designing for Security. Wiley, 2014
2014
-
[12]
Stakeholder identification in the requirements engineering pro- cess,
H. Sharp, A. Finkelstein, and G. Galal, “Stakeholder identification in the requirements engineering pro- cess,” in Proceedings. Tenth International Workshop on Database and Expert Systems Applications. DEXA 99, 1999, pp. 387–391
1999
-
[13]
R. E. Freeman, Strategic Management: A Stakeholder Approach. Pitman Publishing, 1984
1984
-
[14]
N. G. Leveson, Engineering a Safer World: Systems Thinking Applied to Safety. MIT Press, 2012
2012
-
[15]
Sommerville and P
I. Sommerville and P. Sawyer,Requirements Engineer- ing: A Good Practice Guide, 1st ed. USA: John Wiley & Sons, Inc., 1997
1997
-
[16]
Viewpoints: principles, problems and a practi- cal approach to requirements engineering,
——, “Viewpoints: principles, problems and a practi- cal approach to requirements engineering,” Annals of software engineering, vol. 3, no. 1, pp. 101–130, 1997
1997
-
[17]
Com- puter security resource center glossary: Cybersecurity,
National Institute of Standards and Technology, “Com- puter security resource center glossary: Cybersecurity,” 2024, accessed: 2025-07-31. [Online]. Available: https://csrc.nist.gov/glossary/term/cybersecurity
2024
-
[18]
Call for Papers,
IEEE S&P 2025 Program Committee, “Call for Papers,” 2024, accessed: 2025-07-31. [Online]. Available: https://sp2025.ieee-security.org/cfpapers.html
2025
-
[19]
USENIX Security ’25 Call for Papers,
USENIX Security Symposium 2025 Program Committee, “USENIX Security ’25 Call for Papers,” 2024, accessed: 2025-07-31. [On- line]. Available: https://www.usenix.org/conference/ usenixsecurity25/call-for-papers
2025
-
[20]
NDSS Symposium 2025 Call for Pa- pers,
NDSS Symposium 2025 Program Commit- tee, “NDSS Symposium 2025 Call for Pa- pers,” 2024, accessed: 2025-07-31. [Online]. Available: https://www.ndss-symposium.org/ndss2025/ submissions/call-for-papers/
2025
-
[21]
Call for Papers,
ACM CCS 2025 Program Committee, “Call for Papers,” 2024, accessed: 2025-07-31. [Online]. Available: https://www.sigsac.org/ccs/CCS2025/call-for-papers/
2025
-
[22]
Robust de- anonymization of large sparse datasets,
A. Narayanan and V . Shmatikov, “Robust de- anonymization of large sparse datasets,” in Proceedings of the IEEE Symposium on Security and Privacy . IEEE, 2008, pp. 111–125
2008
-
[23]
Ethics in emerg- ing technology: A particular focus on data and privacy,
J. Metcalf, E. Keller, and d. boyd, “Ethics in emerg- ing technology: A particular focus on data and privacy,” Journal of Information, Communication and Ethics in Society, vol. 14, no. 2, pp. 77–92, 2016
2016
-
[24]
Au- tomatic patch-based exploit generation is possible: Tech- niques and implications,
D. Brumley, P. Poosankam, D. Song, and J. Zheng, “Au- tomatic patch-based exploit generation is possible: Tech- niques and implications,” in 2008 IEEE Symposium on Security and Privacy (sp 2008). IEEE, 2008, pp. 143– 157
2008
-
[25]
Dual-use and dilemmas for cybersecurity, peace and technology assessment,
T. Riebe and C. Reuter, “Dual-use and dilemmas for cybersecurity, peace and technology assessment,” inIn- formation Technology for Peace and Security: IT Ap- plications and Infrastructures in Conflicts, Crises, War, and Peace. Springer, 2019, pp. 165–183. 10
2019
-
[26]
Rowhammer: A retrospec- tive,
O. Mutlu and J. S. Kim, “Rowhammer: A retrospec- tive,” IEEE Transactions on Computer-Aided Design of Integrated Circuits and Systems, vol. 39, no. 8, pp. 1555–1571, 2019
2019
-
[27]
Empirical Standards for Software Engi- neering Research,
P. Ralph et al., “Empirical Standards for Software Engi- neering Research,” arXiv:2010.03525 [cs.SE], 2021
2010
-
[28]
An industry interview study of software signing for supply chain security,
K. G. Kalu, T. Singla, C. Okafor, S. Torres-Arias, and J. C. Davis, “An industry interview study of software signing for supply chain security,” in 2025 Proceedings of the 34th USENIX Security Symposium, 2025, pp. 81– 100
2025
-
[29]
"all of them claim to be the best
R. Ramesh, A. Vyas, and R. Ensafi, “"all of them claim to be the best": Multi-perspective study of VPN users and VPN providers,” in 32nd USENIX Security Symposium (USENIX Security 23) . Anaheim, CA: USENIX Association, Aug. 2023, pp. 5773–5789. [Online]. Available: https://www...
2023
-
[30]
Tracking you from a thousand miles away! turning a bluetooth device into an apple airtag without root privileges,
J. Chen, X. Ma, L. Luo, and Q. Zeng, “Tracking you from a thousand miles away! turning a bluetooth device into an apple airtag without root privileges,” in 2025 Proceedings of the 34th USENIX Security Symposium, 2025, pp. 4345–4362
2025
-
[31]
Exposing the guardrails: Reverse-engineering and jailbreaking safety filters in dall ·e text-to-image pipelines,
C. Villa, S. Mirza, and C. Pöpper, “Exposing the guardrails: Reverse-engineering and jailbreaking safety filters in dall ·e text-to-image pipelines,” in 2025 Pro- ceedings of the 34th USENIX Security Symposium, 2025, pp. 897–916
2025
-
[32]
Systematically detecting packet validation vulnerabilities in embedded network stacks,
P. C. Amusuo, R. A. C. Méndez, Z. Xu, A. Machiry, and J. C. Davis, “Systematically detecting packet validation vulnerabilities in embedded network stacks,” in 2023 38th IEEE/ACM International Conference on Automated Software Engineering (ASE), 2023, pp. 926–938
2023
-
[33]
Catch-22: Uncovering compromised hosts using ssh public keys,
C. Munteanu, G. Smaragdakis, A. Feldmann, and T. Fiebig, “Catch-22: Uncovering compromised hosts using ssh public keys,” in 2025 Proceedings of the 34th USENIX Security Symposium, 2025, pp. 861–878
2025
-
[34]
Do unit proofs work? an empirical study of compositional bounded model checking for memory safety verification,
P. C. Amusuo, O. Cochell, T. L. Lievre, P. V . Patil, A. Machiry, and J. C. Davis, “Do unit proofs work? an empirical study of compositional bounded model checking for memory safety verification,”arXiv preprint arXiv:2503.13762, 2025
2025 arXiv
-
[35]
Smudged finger- prints: Characterizing and improving the performance of web application fingerprinting,
B. Kondracki and N. Nikiforakis, “Smudged finger- prints: Characterizing and improving the performance of web application fingerprinting,” in 33rd USENIX Se- curity Symposium (USENIX Security 24). Philadelphia, PA: USENIX Association, Aug. 2024, pp. 4625–4640. [Online]. Availa...
2024
-
[36]
Llms cannot reliably identify and reason about security vulnerabilities (yet?): A comprehensive evaluation, framework, and benchmarks,
S. Ullah, M. Han, S. Pujar, H. Pearce, A. Coskun, and G. Stringhini, “Llms cannot reliably identify and reason about security vulnerabilities (yet?): A comprehensive evaluation, framework, and benchmarks,” in2024 IEEE Symposium on Security and Privacy (SP), 2024, pp. 862– 880
2024
-
[37]
ZTDjava: Mitigating software supply chain vulnerabil- ities via zero-trust dependencies,
P. C. Amusuo, K. A. Robinson, T. Singla, H. Peng, A. Machiry, S. Torres-Arias, L. Simon, and J. C. Davis, “ZTDjava: Mitigating software supply chain vulnerabil- ities via zero-trust dependencies,” in 2025 IEEE/ACM 47th International Conference on Software Engineering (ICSE), 2...
2025
-
[38]
ENG25519: Faster TLS 1.3 handshake using optimized x25519 and ed25519,
J. Zhang, J. Huang, L. Zhao, D. Chen, and Ç. K. Koç, “ENG25519: Faster TLS 1.3 handshake using optimized x25519 and ed25519,” in 33rd USENIX Security Symposium (USENIX Security 24). Philadelphia, PA: USENIX Association, Aug. 2024, pp. 6381–6398. [Online]. Available: https://ww...
2024
-
[39]
Fourteen years in the life: A root Server’s perspective on DNS resolver security,
A. Hilton, C. Deccio, and J. Davis, “Fourteen years in the life: A root Server’s perspective on DNS resolver security,” in 32nd USENIX Security Symposium (USENIX Security 23) . Anaheim, CA: USENIX Association, Aug. 2023, pp. 3171–3186. [Online]. Available: https://www.usenix.o...
2023
-
[40]
Sok: Digging into the digital underworld of stolen data markets,
T. Marjanov and A. Hutchings, “Sok: Digging into the digital underworld of stolen data markets,” in2025 IEEE Symposium on Security and Privacy (SP), 2025, pp. 1– 18
2025
-
[41]
Sok: A privacy framework for security research using social media data,
K. Beadle, K. I. Turk, A. Eusebi, M. Tran, M. Ordekian, E. Mariconti, Y . Zou, and M. Vasek, “Sok: A privacy framework for security research using social media data,” in 2025 IEEE Symposium on Security and Privacy (SP), 2025, pp. 1178–1196
2025
-
[42]
Sok: Security and privacy of blockchain interoperability,
A. Augusto, R. Belchior, M. Correia, A. Vasconcelos, L. Zhang, and T. Hardjono, “Sok: Security and privacy of blockchain interoperability,” in 2024 IEEE Sympo- sium on Security and Privacy (SP) , 2024, pp. 3840– 3865
2024
-
[43]
Sok: Understanding zk-snarks: The gap between re- search and practice,
J. Liang, D. Hu, P. Wu, Y . Yang, Q. Shen, and Z. Wu, “Sok: Understanding zk-snarks: The gap between re- search and practice,” in 2025 Proceedings of the 34th USENIX Security Symposium, 2025, pp. 2085–2104
2025
-
[44]
We really need to talk about session tickets: A Large-Scale analy- sis of cryptographic dangers with TLS session tickets,
S. Hebrok, S. Nachtigall, M. Maehren, N. Erinola, R. Merget, J. Somorovsky, and J. Schwenk, “We really need to talk about session tickets: A Large-Scale analy- sis of cryptographic dangers with TLS session tickets,” in 32nd USENIX Security Symposium (USENIX Security 11 23). An...
2023
-
[45]
Where urls become weapons: Automated discovery of ssrf vulnerabilities in web applications,
E. Wang, J. Chen, W. Xie, C. Wang, Y . Gao, Z. Wang, H. Duan, Y . Liu, and B. Wang, “Where urls become weapons: Automated discovery of ssrf vulnerabilities in web applications,” in2024 IEEE Symposium on Security and Privacy (SP), 2024, pp. 239–257
2024
-
[46]
Spill the TeA: An empirical study of trusted application rollback preven- tion on android smartphones,
M. Busch, P. Mao, and M. Payer, “Spill the TeA: An empirical study of trusted application rollback preven- tion on android smartphones,” in 33rd USENIX Security Symposium (USENIX Security 24). Philadelphia, PA: USENIX Association, Aug. 2024, pp. 5071–5088. [Online]. Available:...
2024
-
[47]
Fledg- ing will continue until privacy improves: Empirical analysis of google’s Privacy-Preserving targeted advertising,
G. Calderonio, M. M. Ali, and J. Polakis, “Fledg- ing will continue until privacy improves: Empirical analysis of google’s Privacy-Preserving targeted advertising,” in 33rd USENIX Security Sympo- sium (USENIX Security 24) . Philadelphia, PA: USENIX Association, Aug. 2024, pp. ...
2024
-
[48]
Back to school: On the (In)Security of academic VPNs,
K. L. Wu, M. H. Hue, N. M. Poon, K. M. Leung, W. Y . Po, K. T. Wong, S. H. Hui, and S. Y . Chau, “Back to school: On the (In)Security of academic VPNs,” in 32nd USENIX Security Symposium (USENIX Security 23) . Anaheim, CA: USENIX Association, Aug. 2023, pp. 5737–5754. [Online]...
2023
-
[49]
Speedrunning the maze: Meeting regulatory patching deadlines in a large enterprise environment,
G. t. Napel, M. van Eeten, and S. Parkin, “Speedrunning the maze: Meeting regulatory patching deadlines in a large enterprise environment,” in2025 IEEE Symposium on Security and Privacy (SP), 2025, pp. 504–521
2025
-
[50]
Learning with seman- tics: Towards a Semantics-Aware routing anomaly detection system,
Y . Chen, Q. Yin, Q. Li, Z. Liu, K. Xu, Y . Xu, M. Xu, Z. Liu, and J. Wu, “Learning with seman- tics: Towards a Semantics-Aware routing anomaly detection system,” in 33rd USENIX Security Sym- posium (USENIX Security 24) . Philadelphia, PA: USENIX Association, Aug. 2024, pp. 51...
2024
-
[51]
TreeSync: Authenticated group management for messaging layer security,
T. Wallez, J. Protzenko, B. Beurdouche, and K. Bharga- van, “TreeSync: Authenticated group management for messaging layer security,” in 32nd USENIX Security Symposium (USENIX Security 23) . Anaheim, CA: USENIX Association, Aug. 2023, pp. 1217–1233. [Online]. Available: https:/...
2023
-
[52]
Kairos: Practical intrusion detection and investigation using whole-system provenance,
Z. Cheng, Q. Lv, J. Liang, Y . Wang, D. Sun, T. Pasquier, and X. Han, “Kairos: Practical intrusion detection and investigation using whole-system provenance,” in2024 IEEE Symposium on Security and Privacy (SP), 2024, pp. 3533–3551
2024
-
[53]
Hofstede, G
G. Hofstede, G. J. Hofstede, and M. Minkov, Cul- tures and Organizations: Software of the Mind, 3rd ed. McGraw-Hill, 2010
2010
-
[54]
Engineering ethics in global context: Four fundamental approaches,
Q. Zhu and B. K. Jesiek, “Engineering ethics in global context: Four fundamental approaches,” in 2017 ASEE Annual Conference & Exposition, 2017
2017
-
[55]
Practicing engineering ethics in global context: A comparative study of expert and novice approaches to cross-cultural ethical situations,
——, “Practicing engineering ethics in global context: A comparative study of expert and novice approaches to cross-cultural ethical situations,” Science and Engi- neering Ethics, vol. 26, no. 4, pp. 2097–2120, 2020
-
[56]
On the feasibility of stealthily in- troducing vulnerabilities in open-source software via hypocrite commit,
Y . Wu and K. Lu, “On the feasibility of stealthily in- troducing vulnerabilities in open-source software via hypocrite commit,” in 2021 IEEE Symposium on Secu- rity and Privacy (SP), 2021, retracted
2021
-
[57]
Russian Foreign Intelligence Service (SVR) Exploiting JetBrains TeamCity CVE Globally,
Cybersecurity and Infrastructure Security Agency, “Russian Foreign Intelligence Service (SVR) Exploiting JetBrains TeamCity CVE Globally,” 2023, accessed: 2025-07-31. [Online]. Available: https://www.cisa.gov/ news-events/cybersecurity-advisories/aa23-347a
2023
-
[58]
Mandiant Exposes APT1 – One of China’s Cyber Espionage Units – and Releases 3,000 Indicators,
D. Mcwhorter, “Mandiant Exposes APT1 – One of China’s Cyber Espionage Units – and Releases 3,000 Indicators,” 2013, accessed: 2025-07-31. [On- line]. Available: https://www.mandiant.com/resources/ apt1-exposing-one-of-chinas-cyber-espionage-units
2013
-
[59]
Documents Reveal Top NSA Hacking Unit,
V on SPIEGEL Staff, “Documents Reveal Top NSA Hacking Unit,” 2013, accessed: 2025-07-31. [Online]. Available: https://www.spiegel.de/international/world/ a-940969.html
2013
-
[60]
Unit 8200,
“Unit 8200,” accessed: 2025-08-19. [Online]. Available: https://en.wikipedia.org/wiki/Unit_8200
2025
-
[61]
Internet organised crime threat assessment (iocta),
“Internet organised crime threat assessment (iocta),” Europol, Tech. Rep., 2023. [Online]. Avail- able: https://www.europol.europa.eu/cms/sites/default/ files/documents/IOCTA%202023%20-%20EN_0.pdf 12
2023
Reviewed August 5, 2026 · model on record in the stance chip above.
Discussion (0). Continue with ORCID to comment.