TopVenues: A Reproducible Corpus and Tooling Substrate for Cybersecurity Literature Reviews

  • Sidnei Barbieri ITA
  • Ágney Lopes Roth Ferraz ITA
  • Lourenço Alves Pereira Júnior ITA

Resumo


Cybersecurity literature reviews require a reproducible denominator: the set of papers that a protocol includes before screening and synthesis begin. Today, that denominator is often reconstructed from publisher portals, bibliographic indices, and scholarly application programming interfaces (APIs) whose coverage, formats, and query semantics change over time. This paper presents TopVenues, an open-source system that materializes corpus construction as a versioned research artifact. TopVenues declares a venue and year scope, uses the DBLP Computer Science Bibliography (DBLP) as its primary metadata source, enriches records with abstracts and BibTeX entries via open scholarly APIs and publisher-specific extractors, and stores the results in a monotonic SQLite snapshot, accessible via a command-line interface (CLI), a web interface, and export paths for review workflows. The May 2026 snapshot contains 9,925 bibliographic records from 11 configured security-focused, security-relevant adjacent, and survey venues, with 99.86% abstract coverage and 99.99% BibTeX coverage; keyword search over the full corpus completes in under 31 ms, and a 252-test suite validates the data-integrity invariants. The fixed denominator also enables repeatable measurement: 29.2% of 2024 to 2025 papers from the four top-ranked security conferences in our scope appear as arXiv preprints, with a median of five months before publication, and a prior-author-track-record filter yields a 16.5× relative risk (2.5× conventional lift) at 90% recall for triaging preprints that later appear in the same venue set. TopVenues links corpus construction to auditable cybersecurity measurement by making the corpus itself executable, inspectable, and citable. The artifact is available at https://github.com/sidneibarbieri/topVenues.

Referências

Ammar, W. et al. (2018). Construction of the literature graph in Semantic Scholar. In Proceedings of the 2018 Conference of the North American Chapter of the Association for Computational Linguistics: Human Language Technologies (NAACL-HLT), pages 84–91, New Orleans, Louisiana. Association for Computational Linguistics.

arXiv (2024). arxiv API access and user’s manual. Accessed 2026-05-19. Thank you to arXiv for use of its open access interoperability.

Barbieri, S., De Souza, F. L. D. S., Teixeira, M. A., Marcondes, C. A. C., and Pereira, L. A. (2025). Searching for diamonds: Cross-domain opportunities in cyber threat intelligence. IEEE Access, 13:189554–189588.

Bouwman, X. et al. (2022). Helping hands: Measuring the impact of a large threat intelligence sharing community. In 31st USENIX Security Symposium, pages 1149–1165. USENIX Association.

Bouwman, X., Griffioen, H., Egbers, J., Doerr, C., Klievink, B., and van Eeten, M. (2020). A different cup of TI? the added value of commercial threat intelligence. In 29th USENIX Security Symposium, pages 433–450. USENIX Association.

Center for History and New Media (2006). Zotero: A free, easy-to-use research tool. Available: [link].

CORE (2023). CORE – computing research and education: Conference rankings. Available: [link].

Crowder, A., Lu, A., Childs, K., Stillman, C., Traynor, P., and Butler, K. R. B. (2025). Data to infinity and beyond: Examining data sharing and reuse practices in the computer security community. In 2025 IEEE Symposium on Security and Privacy, pages 2678–2696. IEEE.

Khraisat, A., Gondal, I., Vamplew, P., and Kamruzzaman, J. (2019). Survey of intrusion detection systems: Techniques, datasets and challenges. Cybersecurity, 2(1):20.

Kitchenham, B. and Charters, S. (2007). Guidelines for performing systematic literature reviews in software engineering. Technical Report EBSE 2007-001, Keele University and Durham University Joint Report.

Ley, M. (2002). The DBLP computer science bibliography: Evolution, research issues, perspectives. In Proceedings of the 9th International Symposium on String Processing and Information Retrieval (SPIRE), pages 1–10, Lisbon, Portugal. Springer.

Ley, M. (2009). DBLP: Some lessons learned. Proceedings of the VLDB Endowment, 2(2):1493–1500.

Li, V. G., Dunn, M., Pearce, P., McCoy, D., Voelker, G. M., and Savage, S. (2019). Reading the tea leaves: A comparative analysis of threat intelligence. In 28th USENIX Security Symposium, pages 851–867. USENIX Association.

Linnenluecke, M. K., Marrone, M., and Singh, A. K. (2020). Conducting systematic literature reviews and bibliometric analyses. Australian Journal of Management, 45(2):175–194.

Lo, K., Wang, L. L., Neumann, M., Kinney, R., and Weld, D. S. (2020). S2ORC: The semantic scholar open research corpus. In Proceedings of the 58th Annual Meeting of the Association for Computational Linguistics, pages 4969–4983.

Luh, R., Marschalek, S., Kaiser, M., Janicke, H., and Schrittwieser, S. (2017). Semantics-aware detection of targeted attacks: A survey. Journal of Computer Virology and Hacking Techniques, 13(1):47–85.

Olszewski, D. et al. (2023). “get in researchers; we’re measuring reproducibility”: A reproducibility study of machine learning papers in tier 1 security conferences. In Proceedings of the 2023 ACM SIGSAC Conference on Computer and Communications Security, pages 3433–3459. ACM.

Olszewski, D., Tucker, T., Butler, K. R. B., and Traynor, P. (2025). SoK: Towards a unified approach to applied replicability for computer security. In 34th USENIX Security Symposium, pages 469–488. USENIX Association.

Ouzzani, M., Hammady, H., Fedorowicz, Z., and Elmagarmid, A. (2016). Rayyan-a web and mobile app for systematic reviews. Systematic Reviews, 5(1):210.

Page, M. J. et al. (2021). The PRISMA 2020 statement: An updated guideline for reporting systematic reviews. BMJ, 372:n71.

Priem, J., Piwowar, H., and Orr, R. (2022). OpenAlex: A fully-open index of scholarly works, authors, venues, institutions, and concepts. arXiv preprint arXiv:2205.01833.

Rethlefsen, M. L. et al. (2021). PRISMA-S: An extension to the PRISMA statement for reporting literature searches in systematic reviews. Systematic Reviews, 10(1):39.

Shu, X. et al. (2018). Threat intelligence computing. In Proceedings of the 2018 ACM SIGSAC Conference on Computer and Communications Security, pages 1883–1898. ACM.

van de Schoot, R. et al. (2021). An open source machine learning framework for efficient and transparent systematic reviews. Nature Machine Intelligence, 3:125–133.

Van Dinter, R., Tekinerdogan, B., and Catal, C. (2021). Automation of systematic literature reviews: A systematic literature review. Information and Software Technology, 136:106589.

Wilkinson, M. D. et al. (2016). The FAIR guiding principles for scientific data management and stewardship. Scientific Data, 3:160018.
Publicado
01/09/2026
BARBIERI, Sidnei; FERRAZ, Ágney Lopes Roth; PEREIRA JÚNIOR, Lourenço Alves. TopVenues: A Reproducible Corpus and Tooling Substrate for Cybersecurity Literature Reviews. In: SIMPÓSIO BRASILEIRO DE CIBERSEGURANÇA (SBSEG), 26. , 2026, Armação dos Búzios/RJ. Anais [...]. Porto Alegre: Sociedade Brasileira de Computação, 2026 . p. 1150-1165. DOI: https://doi.org/10.5753/sbseg.2026.29056.

Artigos mais lidos do(s) mesmo(s) autor(es)