Daniel Weber 0007

dblp:04/5465-7 · DBLP profile ↗
← Back
13ranked-venue papers
6as first author
13since 2021 · last 2026
0009-0008-0213-5773ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 13 · 6 first-author · 13 since 2021
YearPublicationVenuePosition
2026 Trevex: A Black-Box Detection Framework for Data-Flow Transient Execution Vulnerabilities
Daniel Weber 0007, Fabian Thomas, Leon Trampert, Ruiyi Zhang 0001, Michael Schwarz 0001
SP1
2025 RISCover: Automatic Discovery of User-exploitable Architectural Security Vulnerabilities in Closed-Source RISC-V CPUs
abstract
The open and extensible RISC-V instruction set has enabled many new CPU vendors and implementations, but most commercial CPUs are closed-source, significantly hindering vulnerability analysis—especially for bugs exploitable from unprivileged user space.
Fabian Thomas, Eric García Arribas, Lorenz Hetterich, Daniel Weber 0007, Lukas Gerlach 0001, Ruiyi Zhang 0001, Michael Schwarz 0001
CCS4
2025 Styled to Steal: The Overlooked Attack Surface in Email Clients
abstract
Email is still a widely used communication medium, particularly in professional contexts. Standards such as OpenPGP and S/MIME offer encryption while maintaining compatibility with existing infrastructure. Within the end-to-end encryption threat model, email servers are untrusted, which creates opportunities for attackers to inject malicious HTML or CSS into encrypted emails---either live during email transport, or by re-sending leaked emails.
Leon Trampert, Daniel Weber 0007, Christian Rossow, Michael Schwarz 0001
CCS2
2025 Cascading Spy Sheets: Exploiting the Complexity of Modern CSS for Email and Browser Fingerprinting
Leon Trampert, Daniel Weber 0007, Lukas Gerlach 0001, Christian Rossow, Michael Schwarz 0001
NDSS2
2025 SCASE: Automated Secret Recovery via Side-Channel-Assisted Symbolic Execution
Daniel Weber 0007, Lukas Gerlach 0001, Leon Trampert, Youheng Lü, Jo Van Bulck, Michael Schwarz 0001
USENIX Security Symposium1
2024 No Leakage Without State Change: Repurposing Configurable CPU Exceptions to Prevent Microarchitectural Attacks
abstract
Microarchitectural side-channel attacks have become significant threats to computer system security. While writing side-channel-resistant code can mitigate these attacks, it is time-consuming and error-prone. Detection approaches provide an alternative by monitoring the system for signs of ongoing attacks. However, distinguishing between malicious and benign processes is complex, error-prone, and ineffective against sophisticated attacks.In this paper, we propose a novel approach, IRQGuard, which shifts the focus to proactive mitigation. IRQGuard enables the victim to monitor its own microarchitectural events resulting from microarchitectural state changes. Leveraging existing CPU features, IRQGuard uses interrupt requests (IRQs) triggered by victim-specific microarchitectural state changes within predefined code regions. This self-monitoring eliminates noise of unrelated applications, enabling immediate detection and response to potential attacks. Our proof-of-concept implementation demonstrates that IRQGuard stops information leakage in under 200 CPU cycles, outperforming current methods significantly. We evaluate IRQGuard on both cryptographic (OpenSSL) and non-cryptographic (toilet command-line utility) applications. We demonstrate IRQGuard’s real-world viability by protecting an OpenSSH server from cache attacks. IRQGuard offers a practical, low-overhead solution for mitigating a wide range of microarchitectural attacks on Intel, AMD, and Arm CPUs.
Daniel Weber 0007, Leonard Niemann, Lukas Gerlach 0001, Jan Reineke 0001, Michael Schwarz 0001
ACSAC1
2024 CacheWarp: Software-based Fault Injection using Selective State Reset
Ruiyi Zhang 0001, Lukas Gerlach 0001, Daniel Weber 0007, Lorenz Hetterich, Youheng Lü, Andreas Kogler, Michael Schwarz 0001
USENIX Security Symposium3
2023 Indirect Meltdown: Building Novel Side-Channel Attacks from Transient-Execution Attacks
Daniel Weber 0007, Fabian Thomas, Lukas Gerlach 0001, Ruiyi Zhang 0001, Michael Schwarz 0001
ESORICS (3)1
2023 Reviving Meltdown 3a
Daniel Weber 0007, Fabian Thomas, Lukas Gerlach 0001, Ruiyi Zhang 0001, Michael Schwarz 0001
ESORICS (3)1
2023 A Security RISC: Microarchitectural Attacks on Hardware RISC-V CPUs
abstract
Microarchitectural attacks threaten the security of computer systems even in the absence of software vulnerabilities. Such attacks are well explored on x86 and ARM CPUs, with a wide range of proposed but not-yet deployed hardware countermeasures. With the standardization of the RISC-V instruction set architecture and the announcement of support for the architecture by major processor vendors, RISC-V CPUs are on the verge of becoming ubiquitous. However, the microarchitectural attack surface of the first commercially-available RISC-V hardware CPUs still needs to be explored.This paper analyzes the two commercially-available off-the-shelf 64-bit RISC-V (hardware) CPUs used in most RISC-V systems running a full-fledged commodity Linux system. We evaluate the microarchitectural attack surface and introduce 3 new microarchitectural attack techniques: Cache+Time, a novel cache-line-granular cache attack without shared memory, Flush+Fault exploiting the Harvard cache architecture for Flush+Reload, and CycleDrift exploiting unprivileged access to instruction-retirement information. We also show that many known attacks apply to these RISC-V CPUs, mainly due to non-existing hardware countermeasures and instruction-set subtleties that do not consider the microarchitectural attack surface. We demonstrate our attacks in 6 case studies, including the first RISC-V-specific microarchitectural KASLR break and a CycleDrift-based method for detecting kernel activity. Based on our analysis, we stress the need to consider the microarchitectural attack surface during every step of a CPU design, including custom ISA extensions.
Lukas Gerlach 0001, Daniel Weber 0007, Ruiyi Zhang 0001, Michael Schwarz 0001
SP2
2023 (M)WAIT for It: Bridging the Gap between Microarchitectural and Architectural Side Channels
Ruiyi Zhang 0001, Daniel Weber 0007, Michael Schwarz 0001
USENIX Security Symposium3
2022 Finding and Exploiting CPU Features using MSR Templating
abstract
To ensure backward compatibility while adding new features to CPUs, CPU vendors enable a limited CPU configuration via so-called model-specific registers (MSRs). These MSRs have been introduced for various features, such as debugging, performance monitoring, or security. While many MSRs are documented, there is still a plethora of undocumented or sparsely documented MSRs in modern CPUs. Furthermore, with multiple hundred MSRs, each providing up to 64 configuration bits, it is tedious to find specific configuration options. In this paper, we show that MSRs and their configuration bits can be detected automatically on Intel and AMD CPUs. We introduce MSRevelio, a framework to automatically detect bits that influence the behavior of instructions and semi-automatically find bits controlled by BIOS settings. We show that previously overlooked bits can harden systems against microarchitectural attacks such as Medusa, CrossTalk, and software-prefetch attacks. Additionally, we show that an undocumented lock bit allows disabling AES-NI at runtime, forcing mbedTLS to fall back to an AES implementation vulnerable to cache attacks. Exploiting this fallback inside an SGX enclave, we fully recover the AES key used by the enclave. With our detection approach, we show that security features retrofitted with microcode updates can be easily detected, even before the public documentation of the underlying vulnerability. In our analysis of the Xen hypervisor, we show that Xen’s handling of MSRs was flawed for a long time, allowing guests to access undocumented and unhandled MSRs and fingerprint specific Xen versions. Using automated correlation analysis between documented and undocumented MSRs, we discover a previously undocumented MSR correlating with the CPU’s timestamp counter. This MSR is also accessible from Xen guests, and we demonstrate a Foreshadow attack when all other timers are unavailable or artificially deteriorated. Our results highlight that transparency is crucial for features interacting closely with CPU internals.
Andreas Kogler, Daniel Weber 0007, Martin Haubenwallner, Moritz Lipp, Daniel Gruss, Michael Schwarz 0001
SP2
2021 Osiris: Automated Discovery of Microarchitectural Side Channels
Daniel Weber 0007, Ahmad Ibrahim 0002, Hamed Nemati, Michael Schwarz 0001, Christian Rossow
USENIX Security Symposium1