Pith. sign in

REVIEW 3 major objections 4 minor 61 references

A Guide to Stakeholder Analysis for Cybersecurity Researchers

T0 review · 3 major / 4 minor · reviewed 2026-08-05 · deepseek-v4-flash

Pith's one-line read This paper argues that stakeholder-based ethics analysis for cybersecurity can be reduced to a two-step procedure: use a canonical stakeholder table, then use a research-method-to-stakeholder map, demonstrated on four real studies.

desk verdict A useful, clearly written guide for a real upcoming ethics requirement, but its central direct/indirect stakeholder distinction is internally inconsistent and the mapping needs justification before it can be trusted as a community reference. read the letter →

arxiv 2508.14796 v1 pith:2DZS7OPC submitted 2025-08-20 cs.CR cs.SE

classification cs.CRcs.SE
keywords stakeholderanalysisresearchethicscybersecurityempiricalmethodsstatementsdirectandindirectstakeholdersUSENIXSecurity2026standards
verification ladder T0 review T1 audit T2 compute T3 formal

The pith

A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.

The reading

The paper is a practical guide, not an empirical study. It argues that the stakeholder-based ethics analysis now required by top cybersecurity venues, including USENIX Security 2026, can be started from a reusable taxonomy instead of a blank page. It defines direct and indirect stakeholders, maps common empirical research methods to the kinds of direct stakeholders those methods typically expose, and shows the mapping on four worked examples from the authors' own lab. If the mapping is sound, a research team can draft a reasonably complete stakeholder section quickly and reviewers gain a shared vocabulary for checking completeness.

What carries the argument

The load-bearing machinery is a pair of tables and a two-way distinction. Table 1 lists twelve stakeholder categories separated into direct and indirect. Table 2 groups common cybersecurity research methods—controlled experiments, interviews, case studies, repository mining and corpus analysis, tool evaluation and benchmarking, simulation, longitudinal and meta-science studies, systematic review and replication—and asserts the typical direct stakeholders for each cluster. The direct/indirect distinction separates stakeholders reached through short, observable causal links from those affected through diffuse or downstream effects. The Menlo Report's four principles supply the ethical baseline

What would settle it

Take a cohort of published cybersecurity papers spanning Table 2's method clusters, apply the guide's tables to predict each paper's direct and indirect stakeholders, then compare those predictions with the harms, complaints, or retractions the papers later attract. If a substantial share of realized harms involves stakeholder categories absent from Table 1 or absent from that cluster's row in Table 2, the mapping is incomplete.

Watch

Extended reading notes

Core claim

The guide's central claim is that stakeholder identification in cybersecurity research is a method-driven enumeration task. Step one is to use Table 1's canonical list of direct stakeholders (participants, system operators, software maintainers, data subjects, the research team) and indirect stakeholders (end users, vulnerable populations, adversaries, broader public, institutions). Step two is to use Table 2, whose rows are clusters of empirical research methods derived from the empirical standards cited in the paper, to see which stakeholders a project's method most likely exposes. The paper further claims that problem domain determines who is exposed, while research method determines how

Load-bearing premise

The load-bearing premise is that Table 2's mapping from research methods to typical direct stakeholders is complete and correct, a claim the paper asserts from the empirical standards without showing its derivation; a secondary premise is that the four worked examples, all from the authors' own lab, are representative enough to demonstrate the procedure.

Editorial extensions

If this is right

  • A research team preparing a USENIX Security 2026 ethics statement can begin with Table 1 as a checklist and use Table 2 to focus on the stakeholders its research method most likely exposes.
  • Because a single study can fall into several method clusters, the guide implies stakeholder lists should be unioned across clusters rather than read as mutually exclusive.
  • Reviewers and IRB reviewers can use the same two tables to test whether an ethics statement's coverage is plausible, instead of relying on intuition about who might be harmed.
  • The worked examples show that changing the research method while keeping the problem domain can change the exposed stakeholder set, so ethics analysis must track methodology, not just topic.

Reading between the lines

Editorial extensions of the paper, not claims the author makes directly.

  • My inference: Table 2 would be strongest if validated empirically—for each method cluster, one could collect post-publication harm reports, retractions, or public controversies and check whether Table 2 would have named the affected parties.
  • My inference: the paper leaves implicit how a multi-method study should weigh competing harms across clusters; a practical extension would be a prioritization rule for merging conflicting stakeholder exposures.
  • My inference: because all four worked examples are drawn from the authors' own research, transferability to human-subjects-heavy or large-scale measurement studies outside that setting is untested but directly testable by applying the tables to other published papers.
Share X Bluesky LinkedIn Reddit HN

Signed reviews

No signed human review yet.

Editorial analysis

A structured set of objections, weighed in public.

Desk editor's note, referee report, and a circularity audit.

Referee Report

3 major / 4 minor

Summary. The paper is a practical guide to stakeholder-based ethics analysis for cybersecurity research, motivated by the USENIX Security 2026 requirement that submissions include a stakeholder analysis. It defines direct and indirect stakeholders, proposes a mapping from research method clusters to typical direct stakeholders (Table 2, claimed to be derived from the SIGSOFT Empirical Standards), and presents four worked examples drawn exclusively from the authors' own prior publications (Section 4). The paper's central claim is that a researcher following this guide can enumerate relevant stakeholders for a project and draft an ethics statement with reasonable completeness.

Significance. The guide addresses a timely and genuine need: many cybersecurity researchers are now required to perform stakeholder analysis but may lack a concrete procedure. The paper is clearly written, well structured, and offers useful baseline categories in Table 1. The worked examples, though self-referential, illustrate the intended workflow and surface realistic ethical concerns. If the method-to-stakeholder mapping were properly warranted and internally consistent, the guide would be a valuable community resource. However, the load-bearing mapping and the examples are not currently validated, and the central classification has an internal inconsistency with the paper's own definition of direct stakeholders.

major comments (3)
  1. [§2.2 and Table 2] The definition in §2.2 states that direct stakeholders 'interact with, or are explicitly involved in, the research process (e.g., as participants or collaborators).' Table 2, however, lists 'OSS maintainers, contributors, downstream users' as typical direct stakeholders for Repository Mining/Corpus Analysis, and 'Original study authors' as direct for Systematic Review/Replication. These actors do not interact with or participate in the research; they are affected through publication or use of results, which matches the paper's own indirect-stakeholder definition. Because Table 2 is the core deliverable enabling stakeholder identification, this inconsistency undermines the guide's central promise. The definition or the table must be revised and made mutually consistent.
  2. [§3, Table 2] The paper asserts that the method clusters in Table 2 are 'derived from the SIGSOFT Empirical Standards' but provides no derivation. The reader cannot verify which standards categories map to which clusters, why these particular stakeholder sets are associated, or why the lists are complete. This makes the central mapping an unsubstantiated assertion. Please provide a traceable mapping from the standards' method categories to the clusters, or explicitly reframe the table as an untested heuristic. The current presentation overstates the evidence base.
  3. [§4, Table 3, Examples A–D] The worked examples are explicitly restricted to papers whose authors are on the present author list, 'to mitigate concerns about bias or blame.' This means the examples cannot serve as validation of the framework's completeness or representativeness; they are self-selected illustrations from a single lab. Moreover, the classifications are internally inconsistent across examples: Table 3 lists Adversaries as a direct stakeholder in Examples A, C, and D, but as an indirect stakeholder in Example B, despite A, B, and D all combining corpus analysis with tool evaluation. The paper needs explicit criteria for direct/indirect assignment and at least one independent worked example outside the authors' own corpus.
minor comments (4)
  1. [§5.1] The paper cites reference [19] for the 'USENIX Security 2026 Call for Papers,' but [19] is the USENIX Security 2025 CFP. The 2026 CFP is [3]. Please correct the citation.
  2. [§4.1.2, §4.2.2] The text contains the typo 'e.g.,, IoT' in both examples; delete the extra comma.
  3. [Table 2] The note says 'Citations in bold are included in the analysis in §4.' Ensure the bold formatting is applied consistently to all four papers analyzed in §4 ([32], [34], [28], [37]) or remove the note if formatting is not meaningfully rendered.
  4. [§4.3] The text says 'published in USENIX 2025'; referring to the venue as 'USENIX Security 2025' would be more precise and consistent with the reference list.

Circularity Check

0 steps flagged · score 1.0 of 10

No significant circularity: the guide's taxonomy and mapping rest on external sources and asserted judgments, not on fitting or re-deriving its own examples; the only self-referential element is the choice of worked examples, which is a generalizability limitation rather than a circular derivation.

full rationale

This is a practical guide, not a derivation with fitted parameters or predictions. The stakeholder definition in §2.2 is imported from external requirements-engineering literature (Sharp et al. [12]; Freeman [13]), and the method clusters in Table 2 are explicitly attributed to the SIGSOFT Empirical Standards [27], an external source. The mapping from methods to typical direct stakeholders is presented as an asserted judgment, not as something derived from the worked examples. The worked examples in §4 are all drawn from the authors' own papers ('To mitigate concerns about bias or blame, we only discuss papers whose authors are represented on the author list of the present guide'), which is a real self-selection limitation for demonstrating generalizability, but the examples are applications of the framework, not the inputs from which the framework is fitted or defined. No equation, parameter, or 'prediction' reduces to its own input by construction. Section 3 says the method clusters are 'derived from the SIGSOFT Empirical Standards' but does not show the derivation; that is missing support, not circularity. Similarly, the internal inconsistency between §2.2's definition of direct stakeholders (interact with, or are explicitly involved in, the research process) and Table 2's classification of OSS maintainers and downstream users as direct for repository mining is a correctness/consistency concern, not a circularity concern. Overall, no load-bearing self-citation chain or definitional equivalence exists; the central claims remain independent of the examples used to illustrate them.

Assumptions & free parameters 0 free parameters · 5 assumptions · 0 invented entities

No free parameters (the paper fits nothing) and no invented entities (the taxonomy is drawn from prior work). The axioms are the framework's premises: the Menlo principles as ethical baseline, the venue-policy fact underlying the motivation, the asserted necessity of stakeholder identification, the unvalidated Table 2 mapping that carries the guide's practical weight, and the representativeness of the self-authored examples.

assumptions (5)
  • domain assumption The Menlo Report's four principles (respect for persons, beneficence, justice, respect for law and public interest) are a valid baseline for computing research ethics.
    Adopted from cited prior work [4,5] in §2.1; the paper builds its definition of ethics analysis on these principles without independent justification.
  • domain assumption USENIX Security 2026 requires a stakeholder-based ethics analysis in all submissions.
    Factual claim about venue policy cited to [3]; the plural claim about 'top venues' in the abstract rests on this single CFP.
  • domain assumption Stakeholder identification is a necessary prerequisite for ethical analysis.
    The paper's central premise in §2.1-2.2: 'a common starting point is the identification of stakeholders'; asserted rather than argued.
  • ad hoc to paper The method clusters in Table 2, with their typical direct stakeholders, are a valid grouping derived from the SIGSOFT Empirical Standards.
    §3 states the clusters are 'derived from the SIGSOFT Empirical Standards' but no derivation or validation is given; the stakeholder assignments are the authors' judgments.
  • ad hoc to paper The four worked examples (papers authored by members of this guide's author list) are representative of the method categories and illustrate typical stakeholder exposures.
    §4 restricts examples to the authors' own papers to 'mitigate concerns about bias or blame'; representativeness is assumed, not demonstrated.

how reviews work

0 comments
Cite this review

Pith. "Pith review of A Guide to Stakeholder Analysis for Cybersecurity Researchers." pith.science (2026). https://pith.science/paper/2DZS7OPC

@misc{pith2026250814796,
  author       = {Pith},
  title        = {Pith review of: A Guide to Stakeholder Analysis for Cybersecurity Researchers},
  year         = {2026},
  howpublished = {\url{https://pith.science/paper/2DZS7OPC}},
  note         = {Machine review of arXiv:2508.14796}
}
read the original abstract

Stakeholder-based ethics analysis is now a formal requirement for submissions to top cybersecurity research venues. This requirement reflects a growing consensus that cybersecurity researchers must go beyond providing capabilities to anticipating and mitigating the potential harms thereof. However, many cybersecurity researchers may be uncertain about how to proceed in an ethics analysis. In this guide, we provide practical support for that requirement by enumerating stakeholder types and mapping them to common empirical research methods. We also offer worked examples to demonstrate how researchers can identify likely stakeholder exposures in real-world projects. Our goal is to help research teams meet new ethics mandates with confidence and clarity, not confusion.

Figures

Figures reproduced from arXiv: 2508.14796 by the authors.

Figure 1
Figure 1. Parallel processes of research planning and ethics [PITH_FULL_IMAGE:figures/full_fig_p002_1.png] view at source ↗

Discussion (0). Continue with ORCID to comment.

Reference graph

Works this paper leans on

61 extracted references · 1 linked inside Pith

  1. [6]

    Ethical frameworks and computer security trolley problems: foundations for conversations,

    T. Kohno, Y . Acar, and W. Loh, “Ethical frameworks and computer security trolley problems: foundations for conversations,” in2023 Proceedings of the 32th USENIX Security Symposium, 2023, pp. 5145–5162

  2. [1]

    The moral character of cryptographic work,

    P. Rogaway, “The moral character of cryptographic work,” Cryptology ePrint Archive, 2015

  3. [2]

    Message from the usenix security ’25 program co-chairs,

    USENIX Security Symposium 2025 Program Co- Chairs, “Message from the usenix security ’25 program co-chairs,” 2025, accessed: 2025-08-14. [Online]. Avail- able: https://www.usenix.org/sites/default/files/sec25_ message.pdf

  4. [3]

    USENIX Security ’26 Call for Papers,

    USENIX Security Symposium 2026 Program Committee, “USENIX Security ’26 Call for Papers,” 2025, accessed: 2025-07-31. [On- line]. Available: https://www.usenix.org/conference/ usenixsecurity26/call-for-papers

  5. [4]

    The menlo report: Ethical principles guiding information and commu- nication technology research,

    D. Dittrich and E. Kenneally, “The menlo report: Ethical principles guiding information and commu- nication technology research,” U.S. Department of Homeland Security, Tech. Rep., 2012. [Online]. Avail- able: https://www.caida.org/publications/papers/2012/ menlo_report_actual_formatted/

  6. [5]

    T. L. Beauchamp and J. F. Childress, Principles of Biomedical Ethics, 8th ed. Oxford University Press, 2019

  7. [7]

    Friedman, P

    B. Friedman, P. H. Kahn Jr., and A. Borning, Value Sensitive Design and Information Systems . John Wiley & Sons, Ltd, 2008, ch. 4, pp. 69–101. [Online]. Available: https://onlinelibrary.wiley.com/doi/abs/10. 1002/9780470281819.ch4

  8. [8]

    J. S. Mill, Utilitarianism. Parker, Son, and Bourn, 1863

Show all 61 references
  1. [9]

    Kant,Groundwork of the Metaphysics of Morals, 1785, translated by Mary Gregor (Cambridge Unviersity Press, 2nd ed., 2012)

    I. Kant,Groundwork of the Metaphysics of Morals, 1785, translated by Mary Gregor (Cambridge Unviersity Press, 2nd ed., 2012)

  2. [10]

    Modern moral philosophy,

    G. Anscombe, “Modern moral philosophy,” Philosophy, vol. 33, no. 124, pp. 1–19, 1958

  3. [11]

    Shostack, Threat Modeling: Designing for Security

    A. Shostack, Threat Modeling: Designing for Security. Wiley, 2014

  4. [12]

    Stakeholder identification in the requirements engineering pro- cess,

    H. Sharp, A. Finkelstein, and G. Galal, “Stakeholder identification in the requirements engineering pro- cess,” in Proceedings. Tenth International Workshop on Database and Expert Systems Applications. DEXA 99, 1999, pp. 387–391

  5. [13]

    R. E. Freeman, Strategic Management: A Stakeholder Approach. Pitman Publishing, 1984

  6. [14]

    N. G. Leveson, Engineering a Safer World: Systems Thinking Applied to Safety. MIT Press, 2012

  7. [15]

    Sommerville and P

    I. Sommerville and P. Sawyer,Requirements Engineer- ing: A Good Practice Guide, 1st ed. USA: John Wiley & Sons, Inc., 1997

  8. [16]

    Viewpoints: principles, problems and a practi- cal approach to requirements engineering,

    ——, “Viewpoints: principles, problems and a practi- cal approach to requirements engineering,” Annals of software engineering, vol. 3, no. 1, pp. 101–130, 1997

  9. [17]

    Com- puter security resource center glossary: Cybersecurity,

    National Institute of Standards and Technology, “Com- puter security resource center glossary: Cybersecurity,” 2024, accessed: 2025-07-31. [Online]. Available: https://csrc.nist.gov/glossary/term/cybersecurity

  10. [18]

    Call for Papers,

    IEEE S&P 2025 Program Committee, “Call for Papers,” 2024, accessed: 2025-07-31. [Online]. Available: https://sp2025.ieee-security.org/cfpapers.html

  11. [19]

    USENIX Security ’25 Call for Papers,

    USENIX Security Symposium 2025 Program Committee, “USENIX Security ’25 Call for Papers,” 2024, accessed: 2025-07-31. [On- line]. Available: https://www.usenix.org/conference/ usenixsecurity25/call-for-papers

  12. [20]

    NDSS Symposium 2025 Call for Pa- pers,

    NDSS Symposium 2025 Program Commit- tee, “NDSS Symposium 2025 Call for Pa- pers,” 2024, accessed: 2025-07-31. [Online]. Available: https://www.ndss-symposium.org/ndss2025/ submissions/call-for-papers/

  13. [21]

    Call for Papers,

    ACM CCS 2025 Program Committee, “Call for Papers,” 2024, accessed: 2025-07-31. [Online]. Available: https://www.sigsac.org/ccs/CCS2025/call-for-papers/

  14. [22]

    Robust de- anonymization of large sparse datasets,

    A. Narayanan and V . Shmatikov, “Robust de- anonymization of large sparse datasets,” in Proceedings of the IEEE Symposium on Security and Privacy . IEEE, 2008, pp. 111–125

  15. [23]

    Ethics in emerg- ing technology: A particular focus on data and privacy,

    J. Metcalf, E. Keller, and d. boyd, “Ethics in emerg- ing technology: A particular focus on data and privacy,” Journal of Information, Communication and Ethics in Society, vol. 14, no. 2, pp. 77–92, 2016

  16. [24]

    Au- tomatic patch-based exploit generation is possible: Tech- niques and implications,

    D. Brumley, P. Poosankam, D. Song, and J. Zheng, “Au- tomatic patch-based exploit generation is possible: Tech- niques and implications,” in 2008 IEEE Symposium on Security and Privacy (sp 2008). IEEE, 2008, pp. 143– 157

  17. [25]

    Dual-use and dilemmas for cybersecurity, peace and technology assessment,

    T. Riebe and C. Reuter, “Dual-use and dilemmas for cybersecurity, peace and technology assessment,” inIn- formation Technology for Peace and Security: IT Ap- plications and Infrastructures in Conflicts, Crises, War, and Peace. Springer, 2019, pp. 165–183. 10

  18. [26]

    Rowhammer: A retrospec- tive,

    O. Mutlu and J. S. Kim, “Rowhammer: A retrospec- tive,” IEEE Transactions on Computer-Aided Design of Integrated Circuits and Systems, vol. 39, no. 8, pp. 1555–1571, 2019

  19. [27]

    Empirical Standards for Software Engi- neering Research,

    P. Ralph et al., “Empirical Standards for Software Engi- neering Research,” arXiv:2010.03525 [cs.SE], 2021

  20. [28]

    An industry interview study of software signing for supply chain security,

    K. G. Kalu, T. Singla, C. Okafor, S. Torres-Arias, and J. C. Davis, “An industry interview study of software signing for supply chain security,” in 2025 Proceedings of the 34th USENIX Security Symposium, 2025, pp. 81– 100

  21. [29]

    "all of them claim to be the best

    R. Ramesh, A. Vyas, and R. Ensafi, “"all of them claim to be the best": Multi-perspective study of VPN users and VPN providers,” in 32nd USENIX Security Symposium (USENIX Security 23) . Anaheim, CA: USENIX Association, Aug. 2023, pp. 5773–5789. [Online]. Available: https://www...

  22. [30]

    Tracking you from a thousand miles away! turning a bluetooth device into an apple airtag without root privileges,

    J. Chen, X. Ma, L. Luo, and Q. Zeng, “Tracking you from a thousand miles away! turning a bluetooth device into an apple airtag without root privileges,” in 2025 Proceedings of the 34th USENIX Security Symposium, 2025, pp. 4345–4362

  23. [31]

    Exposing the guardrails: Reverse-engineering and jailbreaking safety filters in dall ·e text-to-image pipelines,

    C. Villa, S. Mirza, and C. Pöpper, “Exposing the guardrails: Reverse-engineering and jailbreaking safety filters in dall ·e text-to-image pipelines,” in 2025 Pro- ceedings of the 34th USENIX Security Symposium, 2025, pp. 897–916

  24. [32]

    Systematically detecting packet validation vulnerabilities in embedded network stacks,

    P. C. Amusuo, R. A. C. Méndez, Z. Xu, A. Machiry, and J. C. Davis, “Systematically detecting packet validation vulnerabilities in embedded network stacks,” in 2023 38th IEEE/ACM International Conference on Automated Software Engineering (ASE), 2023, pp. 926–938

  25. [33]

    Catch-22: Uncovering compromised hosts using ssh public keys,

    C. Munteanu, G. Smaragdakis, A. Feldmann, and T. Fiebig, “Catch-22: Uncovering compromised hosts using ssh public keys,” in 2025 Proceedings of the 34th USENIX Security Symposium, 2025, pp. 861–878

  26. [34]

    Do unit proofs work? an empirical study of compositional bounded model checking for memory safety verification,

    P. C. Amusuo, O. Cochell, T. L. Lievre, P. V . Patil, A. Machiry, and J. C. Davis, “Do unit proofs work? an empirical study of compositional bounded model checking for memory safety verification,”arXiv preprint arXiv:2503.13762, 2025

  27. [35]

    Smudged finger- prints: Characterizing and improving the performance of web application fingerprinting,

    B. Kondracki and N. Nikiforakis, “Smudged finger- prints: Characterizing and improving the performance of web application fingerprinting,” in 33rd USENIX Se- curity Symposium (USENIX Security 24). Philadelphia, PA: USENIX Association, Aug. 2024, pp. 4625–4640. [Online]. Availa...

  28. [36]

    Llms cannot reliably identify and reason about security vulnerabilities (yet?): A comprehensive evaluation, framework, and benchmarks,

    S. Ullah, M. Han, S. Pujar, H. Pearce, A. Coskun, and G. Stringhini, “Llms cannot reliably identify and reason about security vulnerabilities (yet?): A comprehensive evaluation, framework, and benchmarks,” in2024 IEEE Symposium on Security and Privacy (SP), 2024, pp. 862– 880

  29. [37]

    ZTDjava: Mitigating software supply chain vulnerabil- ities via zero-trust dependencies,

    P. C. Amusuo, K. A. Robinson, T. Singla, H. Peng, A. Machiry, S. Torres-Arias, L. Simon, and J. C. Davis, “ZTDjava: Mitigating software supply chain vulnerabil- ities via zero-trust dependencies,” in 2025 IEEE/ACM 47th International Conference on Software Engineering (ICSE), 2...

  30. [38]

    ENG25519: Faster TLS 1.3 handshake using optimized x25519 and ed25519,

    J. Zhang, J. Huang, L. Zhao, D. Chen, and Ç. K. Koç, “ENG25519: Faster TLS 1.3 handshake using optimized x25519 and ed25519,” in 33rd USENIX Security Symposium (USENIX Security 24). Philadelphia, PA: USENIX Association, Aug. 2024, pp. 6381–6398. [Online]. Available: https://ww...

  31. [39]

    Fourteen years in the life: A root Server’s perspective on DNS resolver security,

    A. Hilton, C. Deccio, and J. Davis, “Fourteen years in the life: A root Server’s perspective on DNS resolver security,” in 32nd USENIX Security Symposium (USENIX Security 23) . Anaheim, CA: USENIX Association, Aug. 2023, pp. 3171–3186. [Online]. Available: https://www.usenix.o...

  32. [40]

    Sok: Digging into the digital underworld of stolen data markets,

    T. Marjanov and A. Hutchings, “Sok: Digging into the digital underworld of stolen data markets,” in2025 IEEE Symposium on Security and Privacy (SP), 2025, pp. 1– 18

  33. [41]

    Sok: A privacy framework for security research using social media data,

    K. Beadle, K. I. Turk, A. Eusebi, M. Tran, M. Ordekian, E. Mariconti, Y . Zou, and M. Vasek, “Sok: A privacy framework for security research using social media data,” in 2025 IEEE Symposium on Security and Privacy (SP), 2025, pp. 1178–1196

  34. [42]

    Sok: Security and privacy of blockchain interoperability,

    A. Augusto, R. Belchior, M. Correia, A. Vasconcelos, L. Zhang, and T. Hardjono, “Sok: Security and privacy of blockchain interoperability,” in 2024 IEEE Sympo- sium on Security and Privacy (SP) , 2024, pp. 3840– 3865

  35. [43]

    Sok: Understanding zk-snarks: The gap between re- search and practice,

    J. Liang, D. Hu, P. Wu, Y . Yang, Q. Shen, and Z. Wu, “Sok: Understanding zk-snarks: The gap between re- search and practice,” in 2025 Proceedings of the 34th USENIX Security Symposium, 2025, pp. 2085–2104

  36. [44]

    We really need to talk about session tickets: A Large-Scale analy- sis of cryptographic dangers with TLS session tickets,

    S. Hebrok, S. Nachtigall, M. Maehren, N. Erinola, R. Merget, J. Somorovsky, and J. Schwenk, “We really need to talk about session tickets: A Large-Scale analy- sis of cryptographic dangers with TLS session tickets,” in 32nd USENIX Security Symposium (USENIX Security 11 23). An...

  37. [45]

    Where urls become weapons: Automated discovery of ssrf vulnerabilities in web applications,

    E. Wang, J. Chen, W. Xie, C. Wang, Y . Gao, Z. Wang, H. Duan, Y . Liu, and B. Wang, “Where urls become weapons: Automated discovery of ssrf vulnerabilities in web applications,” in2024 IEEE Symposium on Security and Privacy (SP), 2024, pp. 239–257

  38. [46]

    Spill the TeA: An empirical study of trusted application rollback preven- tion on android smartphones,

    M. Busch, P. Mao, and M. Payer, “Spill the TeA: An empirical study of trusted application rollback preven- tion on android smartphones,” in 33rd USENIX Security Symposium (USENIX Security 24). Philadelphia, PA: USENIX Association, Aug. 2024, pp. 5071–5088. [Online]. Available:...

  39. [47]

    Fledg- ing will continue until privacy improves: Empirical analysis of google’s Privacy-Preserving targeted advertising,

    G. Calderonio, M. M. Ali, and J. Polakis, “Fledg- ing will continue until privacy improves: Empirical analysis of google’s Privacy-Preserving targeted advertising,” in 33rd USENIX Security Sympo- sium (USENIX Security 24) . Philadelphia, PA: USENIX Association, Aug. 2024, pp. ...

  40. [48]

    Back to school: On the (In)Security of academic VPNs,

    K. L. Wu, M. H. Hue, N. M. Poon, K. M. Leung, W. Y . Po, K. T. Wong, S. H. Hui, and S. Y . Chau, “Back to school: On the (In)Security of academic VPNs,” in 32nd USENIX Security Symposium (USENIX Security 23) . Anaheim, CA: USENIX Association, Aug. 2023, pp. 5737–5754. [Online]...

  41. [49]

    Speedrunning the maze: Meeting regulatory patching deadlines in a large enterprise environment,

    G. t. Napel, M. van Eeten, and S. Parkin, “Speedrunning the maze: Meeting regulatory patching deadlines in a large enterprise environment,” in2025 IEEE Symposium on Security and Privacy (SP), 2025, pp. 504–521

  42. [50]

    Learning with seman- tics: Towards a Semantics-Aware routing anomaly detection system,

    Y . Chen, Q. Yin, Q. Li, Z. Liu, K. Xu, Y . Xu, M. Xu, Z. Liu, and J. Wu, “Learning with seman- tics: Towards a Semantics-Aware routing anomaly detection system,” in 33rd USENIX Security Sym- posium (USENIX Security 24) . Philadelphia, PA: USENIX Association, Aug. 2024, pp. 51...

  43. [51]

    TreeSync: Authenticated group management for messaging layer security,

    T. Wallez, J. Protzenko, B. Beurdouche, and K. Bharga- van, “TreeSync: Authenticated group management for messaging layer security,” in 32nd USENIX Security Symposium (USENIX Security 23) . Anaheim, CA: USENIX Association, Aug. 2023, pp. 1217–1233. [Online]. Available: https:/...

  44. [52]

    Kairos: Practical intrusion detection and investigation using whole-system provenance,

    Z. Cheng, Q. Lv, J. Liang, Y . Wang, D. Sun, T. Pasquier, and X. Han, “Kairos: Practical intrusion detection and investigation using whole-system provenance,” in2024 IEEE Symposium on Security and Privacy (SP), 2024, pp. 3533–3551

  45. [53]

    Hofstede, G

    G. Hofstede, G. J. Hofstede, and M. Minkov, Cul- tures and Organizations: Software of the Mind, 3rd ed. McGraw-Hill, 2010

  46. [54]

    Engineering ethics in global context: Four fundamental approaches,

    Q. Zhu and B. K. Jesiek, “Engineering ethics in global context: Four fundamental approaches,” in 2017 ASEE Annual Conference & Exposition, 2017

  47. [55]

    Practicing engineering ethics in global context: A comparative study of expert and novice approaches to cross-cultural ethical situations,

    ——, “Practicing engineering ethics in global context: A comparative study of expert and novice approaches to cross-cultural ethical situations,” Science and Engi- neering Ethics, vol. 26, no. 4, pp. 2097–2120, 2020

  48. [56]

    On the feasibility of stealthily in- troducing vulnerabilities in open-source software via hypocrite commit,

    Y . Wu and K. Lu, “On the feasibility of stealthily in- troducing vulnerabilities in open-source software via hypocrite commit,” in 2021 IEEE Symposium on Secu- rity and Privacy (SP), 2021, retracted

  49. [57]

    Russian Foreign Intelligence Service (SVR) Exploiting JetBrains TeamCity CVE Globally,

    Cybersecurity and Infrastructure Security Agency, “Russian Foreign Intelligence Service (SVR) Exploiting JetBrains TeamCity CVE Globally,” 2023, accessed: 2025-07-31. [Online]. Available: https://www.cisa.gov/ news-events/cybersecurity-advisories/aa23-347a

  50. [58]

    Mandiant Exposes APT1 – One of China’s Cyber Espionage Units – and Releases 3,000 Indicators,

    D. Mcwhorter, “Mandiant Exposes APT1 – One of China’s Cyber Espionage Units – and Releases 3,000 Indicators,” 2013, accessed: 2025-07-31. [On- line]. Available: https://www.mandiant.com/resources/ apt1-exposing-one-of-chinas-cyber-espionage-units

  51. [59]

    Documents Reveal Top NSA Hacking Unit,

    V on SPIEGEL Staff, “Documents Reveal Top NSA Hacking Unit,” 2013, accessed: 2025-07-31. [Online]. Available: https://www.spiegel.de/international/world/ a-940969.html

  52. [60]

    Unit 8200,

    “Unit 8200,” accessed: 2025-08-19. [Online]. Available: https://en.wikipedia.org/wiki/Unit_8200

  53. [61]

    Internet organised crime threat assessment (iocta),

    “Internet organised crime threat assessment (iocta),” Europol, Tech. Rep., 2023. [Online]. Avail- able: https://www.europol.europa.eu/cms/sites/default/ files/documents/IOCTA%202023%20-%20EN_0.pdf 12

Pith tools

Reviewed August 5, 2026 · model on record in the stance chip above.