Sebastian Schrittwieser

dblp:09/8857 · DBLP profile ↗
← Back
49ranked-venue papers
9as first author
15since 2021 · last 2026
0000-0003-2115-2022ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 39 · 8 first-author · 13 since 2021Databases, data management, data science and information retrieval · 7 · 1 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 7 · 1 first-author · 1 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 since 2021
YearPublicationVenuePosition
2026 SaMBA: Increasing Mixed Boolean-Arithmetic Complexity Through Equality Saturation
Caroline König, Philip König, Patrick Felbauer, Sebastian Schrittwieser
AsiaCCS5
2026 Obfuscation detection using matrix complexity features of binary grayscale images
Sebastian Raubitzek, Sebastian Schrittwieser, Caroline König, Patrick Felbauer, Kevin Mallinger, Andreas Ekelhart, Edgar R. Weippl
Comput. Secur.2
2025 Leaky Apps: Large-scale Analysis of Secrets Distributed in Android and iOS Apps
abstract
Mobile apps store various types of secrets to support their functionalities. These include API keys, and cryptographic material to authenticate users and access backend services. Once distributed, attackers can reverse-engineer the apps, and these secrets become accessible, posing risks such as data leaks, and service abuse.
Sebastian Schrittwieser, Edgar R. Weippl
CCS2
2025 PenQuestEnv: A Reinforcement Learning Environment for Cyber Security
Sebastian Eresheim, Simon Gmeiner, Alexander Piglmann, Thomas Petelin, Robert Luh, Paul Tavolato, Sebastian Schrittwieser
ICISSP (1)7
2025 Gamifying information security: Adversarial risk exploration for IT/OT infrastructures
Robert Luh, Sebastian Eresheim, Paul Tavolato, Thomas Petelin, Simon Gmeiner, Andreas Holzinger, Sebastian Schrittwieser
Comput. Secur.7
2024 CheckMATE '24 - Research on Offensive and Defensive Techniques in the context of Man At The End (MATE) Attacks
abstract
MATE (Man-At-The-End) is an attacker model where an adversary has access to the target software and/or hardware environment of his victim and the ability to observe and modify it in order to extract secrets such as cryptographic keys or sensitive information, possibly with the subsequent goal of compromising code integrity or inserting backdoors, among others. A typical example of such a scenario is the case of an attack on a stolen smartphone or against software leveraging protection to offer premium content and/or features such as paid TV channels.
Sebastian Schrittwieser, Michele Ianni
CCS1
2024 Comparing the Effectivity of Planned Cyber Defense Controls in Order to Support the Selection Process
Paul Tavolato, Robert Luh, Sebastian Eresheim, Simon Gmeiner, Sebastian Schrittwieser
ICISSP5
2024 Attacking Graph Neural Networks with Bit Flips: Weisfeiler and Leman Go Indifferent
abstract
Prior attacks on graph neural networks have focused on graph poisoning and evasion, neglecting the network's weights and biases. For convolutional neural networks, however, the risk arising from bit flip attacks is well recognized. We show that the direct application of a traditional bit flip attack to graph neural networks is of limited effectivity. Hence, we discuss the Injectivity Bit Flip Attack, the first bit flip attack designed specifically for graph neural networks. Our attack targets the learnable neighborhood aggregation functions in quantized message passing neural networks, degrading their ability to distinguish graph structures and impairing the expressivity of the Weisfeiler-Leman test. We find that exploiting mathematical properties specific to certain graph neural networks significantly increases their vulnerability to bit flip attacks. The Injectivity Bit Flip Attack can degrade the maximal expressive Graph Isomorphism Networks trained on graph property prediction datasets to random output by flipping only a small fraction of the network's bits, demonstrating its higher destructive power compared to traditional bit flip attacks transferred from convolutional neural networks. Our attack is transparent, motivated by theoretical insights and confirmed by extensive empirical results.
Lorenz Kummer, Samir Moustafa, Sebastian Schrittwieser, Wilfried N. Gansterer, Nils M. Kriege
KDD3
2024 Code Obfuscation Classification Using Singular Value Decomposition on Grayscale Image Representations
Sebastian Raubitzek, Sebastian Schrittwieser, Caroline Lawitschka, Kevin Mallinger, Andreas Ekelhart, Edgar R. Weippl
SECRYPT2
2024 Safe or Scam? An Empirical Simulation Study on Trust Indicators in Online Shopping
Sebastian Schrittwieser, Andreas Ekelhart, Esther Seidl, Edgar R. Weippl
SECRYPT1
2024 Editorial: Special issue on ARES 2022
Emilio Coppa, Sebastian Schrittwieser
Comput. Secur.2
2024 Obfuscation undercover: Unraveling the impact of obfuscation layering on structural code patterns
Sebastian Raubitzek, Sebastian Schrittwieser, Elisabeth Wimmer, Kevin Mallinger
J. Inf. Secur. Appl.2
2023 Large Language Models for Code Obfuscation Evaluation of the Obfuscation Capabilities of OpenAI's GPT-3.5 on C Source Code
Patrick Kochberger, Maximilian Gramberger, Sebastian Schrittwieser, Caroline Lawitschka, Edgar R. Weippl
SECRYPT3
2022 PenQuest Reloaded: A Digital Cyber Defense Game for Technical Education
abstract
Today’s IT and OT infrastructure is threatened by a plethora of cyber-attacks conducted by actors with different motivations and means. Furthermore, the complexity of these exposed systems as well as the adversaries’ sophisticated technical arsenal makes it increasingly difficult to plan and implement an organization’s defense. Understanding the link between specific attacks and effective mitigating measures is particularly challenging – as is understanding the underlying information security concepts. To support the training of current, and more importantly, nascent security engineers, we propose PenQuest, a digital attack and defense game where an attacker attempts to compromise an abstracted IT infrastructure and the defender works to prevent or mitigate the threat. The game is based on MITRE ATT&CK, D3FEND, and the NIST SP 800-53 security standard and incorporates a multitude of concepts such as cyber kill chains, attack vectors, network segmentation, and more. PenQuest is built to support security education and risk assessment and was evaluated with a class of engineering students as well as independent security experts. Initial results show a significant increase in knowledge retention and attest to the game’s feasibility for educational use.
Robert Luh, Sebastian Eresheim, Stefanie Größbacher, Thomas Petelin, Florian Mayr, Paul Tavolato, Sebastian Schrittwieser
EDUCON7
2021 SoK: Automatic Deobfuscation of Virtualization-protected Applications
abstract
Malware authors often rely on code obfuscation to hide the malicious functionality of their software, making detection and analysis more difficult. One of the most advanced techniques for binary obfuscation is virtualization-based obfuscation, which converts the functionality of a program into the bytecode of a randomly generated virtual machine which is embedded into the protected program. To enable the automatic detection and analysis of protected malware, new deobfuscation techniques against virtualization-based obfuscation are constantly being developed and proposed in the literature.
Patrick Kochberger, Sebastian Schrittwieser, Stefan Schweighofer, Peter Kieseberg, Edgar R. Weippl
ARES2
2019 Large-Scale Analysis of Pop-Up Scam on Typosquatting URLs
abstract
Today, many different types of scams can be found on the internet. Online criminals are always finding new creative ways to trick internet users, be it in the form of lottery scams, downloading scam apps for smartphones or fake gambling websites. This paper presents a large-scale study on one particular delivery method of online scam: pop-up scam on typosquatting domains. Typosquatting describes the concept of registering domains which are very similar to existing ones while deliberately containing common typing errors; these domains are then used to trick online users while under the belief of browsing the intended website. Pop-up scam uses JavaScript alert boxes to present a message which attracts the user's attention very effectively, as they are a blocking user interface element.
Tobias Dam, Lukas Daniel Klausner, Damjan Buhov, Sebastian Schrittwieser
ARES4
2019 AIDIS: Detecting and classifying anomalous behavior in ubiquitous kernel processes
Robert Luh, Helge Janicke, Sebastian Schrittwieser
Comput. Secur.3
2018 The Other Side of the Coin: A Framework for Detecting and Analyzing Web-based Cryptocurrency Mining Campaigns
abstract
Mining for crypto currencies is usually performed on high-performance single purpose hardware or GPUs. However, mining can be easily parallelized and distributed over many less powerful systems. Cryptojacking is a new threat on the Internet and describes code included in websites that uses a visitor's CPU to mine for crypto currencies without the their consent. This paper introduces MiningHunter, a novel web crawling framework which is able to detect mining scripts even if they obfuscate their malicious activities. We scanned the Alexa Top 1 million websites for cryptojacking, collected more than 13,400,000 unique JavaScript files with a total size of 246 GB and found that 3,178 websites perform cryptocurrency mining without their visitors' consent. Furthermore, MiningHunter can be used to provide an in-depth analysis of cryptojacking campaigns. To show the feasibility of the proposed framework, three of such campaigns are examined in detail. Our results provide the most comprehensive analysis to date of the spread of cryptojacking on the Internet.
Julian Rauchberger, Sebastian Schrittwieser, Tobias Dam, Robert Luh, Damjan Buhov, Gerhard Pötzelsberger, Hyoungshick Kim
ARES2
2018 APT RPG: Design of a Gamified Attacker/Defender Meta Model
Robert Luh, Marlies Temper, Simon Tjoa, Sebastian Schrittwieser
ICISSP4
2017 LLR-Based Sentiment Analysis for Kernel Event Sequences
abstract
Behavior-based analysis of dynamically executed binaries has become a widely used technique for the identification of suspected malware. Most solutions rely on function call patterns to determine whether a sample is exhibiting malicious behavior. These system and API calls are usually regarded individually and do not consider contextual information or process inter-dependencies. In addition, the patterns are often fixed in nature and do not adapt to changing circumstances on the system environment level. To address these shortcomings, this paper proposes a sentiment extraction and scoring system capable of learning the maliciousness inherent to n-grams of kernel events captured by a real-time monitoring agent. The approach is based on calculating the log likelihood ratio (LLR) of all identified n-grams, effectively determining neighboring sequences as well as assessing whether certain event combinations incline towards the benign or malicious. The extraction component automatically compiles a WordNet-like sentiment dictionary of events, which is subsequently used to score unknown traces of either individual processes, or a session in its entirety. The system was evaluated using a large set of real-world event traces collected on live corporate workstations as well as raw API call traces created in a dedicated malware analysis environment. While applicable to both scenarios, the introduced solution performed best for our abstracted kernel events, generating both new insight into malware- system interaction and assisting with the scoring of hitherto unknown application behavior.
Robert Luh, Sebastian Schrittwieser, Stefan Marschalek
AINA2
2017 Real-Time Forensics Through Endpoint Visibility
Peter Kieseberg, Sebastian Neuner, Sebastian Schrittwieser, Martin Schmiedecker, Edgar R. Weippl
ICDF2C3
2017 Sequitur-based Inference and Analysis Framework for Malicious System Behavior
Robert Luh, Gregor Schramm, Markus Wagner 0008, Sebastian Schrittwieser
ICISSP4
2017 Design of an Anomaly-based Threat Detection & Explication System
Robert Luh, Sebastian Schrittwieser, Stefan Marschalek, Helge Janicke
ICISSP2
2017 Longkit - A Universal Framework for BIOS/UEFI Rootkits in System Management Mode
Julian Rauchberger, Robert Luh, Sebastian Schrittwieser
ICISSP3
2017 Hello, Facebook! Here Is the Stalkers' Paradise!: Design and Analysis of Enumeration Attack Using Phone Numbers on Facebook
Kuyju Kim, Junsung Cho, Hyoungshick Kim, Sebastian Schrittwieser
ISPEC5
2017 Poster: Design of an Anomaly-based Threat Detection & Explication System
abstract
The poster corresponding to this summary depicts a proposition of a system able to explain anomalous behavior within a user session by considering anomalies identified through their deviation from a set of baseline process graphs. We adapt star structures, a bipartite representation used to approximate the edit distance between two graphs. Relevant processes are selected from a dictionary of benign and malicious traces generated through a sentiment-like bigram extraction and scoring system based on the log likelihood ratio test. We prototypically implemented smart anomaly explication through a number of competency questions derived and evaluated by a decision tree. The determined key factors are ultimately mapped to a dedicated APT attack stage ontology that considers actions, actors, as well as target assets.
Robert Luh, Sebastian Schrittwieser, Stefan Marschalek, Helge Janicke, Edgar R. Weippl
SACMAT2
2016 TAON: an ontology-based approach to mitigating targeted attacks
abstract
Targeted attacks on IT systems are a rising threat against the confidentiality of sensitive data and the availability of systems and infrastructures. Planning for the eventuality of a data breach or sabotage attack has become an increasingly difficult task with the emergence of advanced persistent threats (APTs), a class of highly sophisticated cyber-attacks that are nigh impossible to detect using conventional signature-based systems.
Robert Luh, Sebastian Schrittwieser, Stefan Marschalek
iiWAS2
2015 Trust me, I'm a Root CA! Analyzing SSL Root CAs in Modern Browsers and Operating Systems
abstract
The security and privacy of our online communications heavily relies on the entity authentication mechanisms provided by SSL. Those mechanisms in turn heavily depend on the trustworthiness of a large number of companies and governmental institutions for attestation of the identity of SSL services providers. In order to offer a wide and unobstructed availability of SSL-enabled services and to remove the need to make a large amount of trust decisions from their users, operating systems and browser manufactures include lists of certification authorities which are trusted for SSL entity authentication by their products. This has the problematic effect that users of such browsers and operating systems implicitly trust those certification authorities with the privacy of their communications while they might not even realize it. The problem is further complicated by the fact that different software vendors trust different companies and governmental institutions, from a variety of countries, which leads to an obscure distribution of trust. To give insight into the trust model used by SSL this thesis explains the various entities and technical processes involved in establishing trust when using SSL communications. It furthermore analyzes the number and origin of companies and governmental institutions trusted by various operating systems and browser vendors and correlates the gathered information to a variety of indexes to illustrate that some of these trusted entities are far from trustworthy. Furthermore it points out the fact that the number of entities we trust with the security of our SSL communications keeps growing over time and displays the negative effects this might have as well as shows that the trust model of SSL is fundamentally broken.
Tariq Fadai, Sebastian Schrittwieser, Peter Kieseberg, Martin Mulazzani
ARES2
2015 Gradually Improving the Forensic Process
abstract
At the time of writing, one of the most pressing problems for forensic investigators is the huge amount of data to analyze per case. Not only the number of devices increases due to the advancing computerization of every days life, but also the storage capacity of each and every device raises into multi-terabyte storage requirements per case for forensic working images. In this paper we improve the standardized forensic process by proposing to use file deduplication across devices as well as file white listing rigorously in investigations, to reduce the amount of data that needs to be stored for analysis as early as during data acquisition. These improvements happen in an automatic fashion and completely transparent to the forensic investigator. They furthermore be added without negative effects to the chain of custody or artefact validity in court, and are evaluated in a realistic use case.
Sebastian Neuner, Martin Mulazzani, Sebastian Schrittwieser, Edgar R. Weippl
ARES3
2015 Classifying malicious system behavior using event propagation trees
abstract
Behavior-based analysis of dynamically executed software has become an established technique to identifying and analyzing potential malware. Most solutions rely on API or system call patterns to determine whether a sample is exhibiting malicious activity. Analysis is usually performed on demand and offers little insight into the current system state. In addition, the fixed nature of behavioral patterns is known to cause false-positives whenever a certain, potentially malicious action is used in a benign context.
Stefan Marschalek, Robert Luh, Manfred Kaiser, Sebastian Schrittwieser
iiWAS4
2015 Privacy and data protection in smartphone messengers
abstract
Ever since the Snowden revelations regarding mass surveillance, the role of privacy protection in commodity communication software has gained increasing awareness in the general public. Still, during the last years many new messengers were developed for Android, where often privacy was not considered to be a key issue. Due to the widespread use of these apps even in corporate environments this opens up attack vectors that can result in advanced persistent threats. In this paper we analyze the most prominent messenger apps with respect to privacy concepts, focusing not only on the transmission layer regarding the support of encrypted communication, but also attacks targeting the communication metadata, e.g. detecting the existence of communication between users, as well as providing an enumeration of all users of a service. Furthermore, device theft and loss is a major issue regarding the protection of user privacy. Thus, we also analyzed, whether the messages are stored in a secure way on the device itself, or if control over the physical device allows access to the message data. In order to analyze the possible usability of these messengers as means for targeted surveillance of users by the provider (or an entity controlling it), we also analyzed the rights and privileges the respective apps need in order to be able to install and work. Here, major differences could be detected, with several apps claiming privileges that could not be explained with the normal mode of operation, thus posing a serious risk for the privacy of the respective user base.
Christoph Rottermanner, Peter Kieseberg, Markus Huber 0001, Martin Schmiedecker, Sebastian Schrittwieser
iiWAS5
2014 AES-SEC: Improving Software Obfuscation through Hardware-Assistance
abstract
While the resilience of software-only code obfuscation remains unclear and ultimately depends only on available resources and patience of the attacker, hardware-based software protection approaches can provide a much higher level of protection against program analysis. Almost no systematic research has been done on the interplay between hardware and software based protection mechanism. In this paper, we propose modifications to Intel's AES-NI instruction set in order to make it suitable for application in software protection scenarios and demonstrate its integration into a control flow obfuscation scheme. Our novel approach provides strong hardware-software binding and restricts the attack context to pure dynamic analysis - two major limiting factors of reverse engineering - to delay a successful attack against a program.
Sebastian Schrittwieser, Stefan Katzenbeisser 0001, Georg Merzdovnik, Peter Kieseberg, Edgar R. Weippl
ARES1
2014 Towards Fully Automated Digital Alibis with Social Interaction
Stefanie Beyer, Martin Mulazzani, Sebastian Schrittwieser, Markus Huber 0001, Edgar R. Weippl
IFIP Int. Conf. Digital Forensics3
2014 What's new with WhatsApp & Co.? Revisiting the Security of Smartphone Messaging Applications
abstract
In recent years mobile messaging and VoIP applications for smartphones have seen a massive surge in popularity, which has also sparked the interest in research related to the security of these applications. Various security researchers and institutions have performed in-depth analyses of specific applications or vulnerabilities. This paper gives an overview of the status quo in terms of security for a number of selected applications in comparison to a previous evaluation conducted two years ago, as well as performing an analysis on some new applications. The evaluation methods mostly focus on known vulnerabilities in connection with authentication and validation mechanisms but also describe some newly identified attack vectors. The results show a predominantly positive trend for new applications, which are mostly being developed with robust security and privacy features, while some of the older applications have shown little to no progress in this regard or have even introduced new vulnerabilities in recent versions.
Robin Mueller, Sebastian Schrittwieser, Peter Frühwirt, Peter Kieseberg, Edgar R. Weippl
iiWAS2
2014 Spoiled Onions: Exposing Malicious Tor Exit Relays
Philipp Winter, Richard Köwer, Martin Mulazzani, Markus Huber 0001, Sebastian Schrittwieser, Stefan Lindskog, Edgar R. Weippl
Privacy Enhancing Technologies5
2014 Covert Computation - Hiding code in code through compile-time obfuscation
Sebastian Schrittwieser, Stefan Katzenbeisser 0001, Peter Kieseberg, Markus Huber 0001, Manuel Leithner, Martin Mulazzani, Edgar R. Weippl
Comput. Secur.1
2013 SHPF: Enhancing HTTP(S) Session Security with Browser Fingerprinting
abstract
Session hijacking has become a major problem in today's Web services, especially with the availability of free off-the-shelf tools. As major websites like Facebook, You tube and Yahoo still do not use HTTPS for all users by default, new methods are needed to protect the users' sessions if session tokens are transmitted in the clear. In this paper we propose the use of browser fingerprinting for enhancing current state-of-the-art HTTP(S) session management. Monitoring a wide set of features of the user's current browser makes session hijacking detectable at the server and raises the bar for attackers considerably. This paper furthermore identifies HTML5 and CSS features that can be used for browser fingerprinting and to identify or verify a browser without the need to rely on the User Agent string. We implemented our approach in a framework that is highly configurable and can be added to existing Web applications and server-side session management with ease.
Thomas Unger, Martin Mulazzani, Dominik Fruhwirt, Markus Huber 0001, Sebastian Schrittwieser, Edgar R. Weippl
ARES5
2013 Covert computation: hiding code in code for obfuscation purposes
abstract
As malicious software gets increasingly sophisticated and resilient to detection, new concepts for the identification of malicious behavior are developed by academia and industry alike. While today's malware detectors primarily focus on syntactical analysis (i.e., signatures of malware samples), the concept of semantic-aware malware detection has recently been proposed. Here, the classification is based on models that represent the underlying machine and map the effects of instructions on the hardware. In this paper, we demonstrate the incompleteness of these models and highlight the threat of malware, which exploits the gap between model and machine to stay undetectable. To this end, we introduce a novel concept we call covert computation, which implements functionality in side effects of microprocessors. For instance, the flags register can be used to calculate basic arithmetical and logical operations. Our paper shows how this technique could be used by malware authors to hide malicious code in a harmless-looking program. Furthermore, we demonstrate the resilience of covert computation against semantic-aware malware scanners.
Sebastian Schrittwieser, Stefan Katzenbeisser 0001, Peter Kieseberg, Markus Huber 0001, Manuel Leithner, Martin Mulazzani, Edgar R. Weippl
AsiaCCS1
2013 Quantifying Windows File Slack Size and Stability
Martin Mulazzani, Sebastian Neuner, Peter Kieseberg, Markus Huber 0001, Sebastian Schrittwieser, Edgar R. Weippl
IFIP Int. Conf. Digital Forensics5
2013 InnoDB database forensics: Enhanced reconstruction of data manipulation queries from redo logs
Peter Frühwirt, Peter Kieseberg, Sebastian Schrittwieser, Markus Huber 0001, Edgar R. Weippl
Inf. Secur. Tech. Rep.3
2012 InnoDB Database Forensics: Reconstructing Data Manipulation Queries from Redo Logs
abstract
InnoDB is a powerful open-source storage engine for MySQL that gained much popularity during the recent years. This paper proposes methods for forensic analysis of InnoDB databases by analyzing the redo logs, primarily used for crash recovery within the storage engine. This new method can be very useful in forensic investigations where the attacker got admin privileges, or was the admin himself. While such a powerful attacker could cover tracks by manipulating the log files intended for fraud detection, data cannot be changed easily in the redo logs. Based on a prototype implementation, we show methods for recovering Insert, Delete and Update statements issued against a database.
Peter Frühwirt, Peter Kieseberg, Sebastian Schrittwieser, Markus Huber 0001, Edgar R. Weippl
ARES3
2012 Digital forensics for enterprise rights management systems
abstract
Digital forensics is the application of techniques to recover, reconstruct and analyze data from a computer or a similar system in order to gather digital evidence (e.g. on a suspicious employee or for law enforcement). Guidelines and standards for forensic investigations exist (e.g. NIST SP800-86), but do not cover Enterprise Rights Management (ERM), where data is usually encrypted and therefore inaccessible without knowing the cryptographic key. This paper explores forensic techniques for ERM systems and develops application specific guidelines for forensic investigations targeting Microsoft Active Directory Rights Management Services (RMS) and Adobe LiveCycle Rights Management. Moreover, we illustrate the important role of database forensics for investigations in ERM systems and finally show that with Microsoft's ERM solution no secure, centrally-managed revocation of specific documents in order to prevent digital forensics is feasible.
Sebastian Schrittwieser, Peter Kieseberg, Edgar R. Weippl
iiWAS1
2012 Guess Who's Texting You? Evaluating the Security of Smartphone Messaging Applications
Sebastian Schrittwieser, Peter Frühwirt, Peter Kieseberg, Manuel Leithner, Martin Mulazzani, Markus Huber 0001, Edgar R. Weippl
NDSS1
2011 Using Generalization Patterns for Fingerprinting Sets of Partially Anonymized Microdata in the Course of Disasters
abstract
In the event of large natural and artificial disasters, it is of vital importance to provide all sorts of data to the relief organizations (fire department, red cross,...) to enhance their effectivity. Still, some of this data (e.g. regarding personal information on health status) may be considered private. k-anonymity can be utilized to mitigate the risks resulting from disclosure of such data, however, sometimes it is not possible to achieve a suitable size for k in order to completely anonymize the data without interfering with rescue operations. Still, this data will be sensitive after the disaster recovery is finished. Thus we aim at protecting the data by devising an intrinsic fingerprinting-scheme that allows to detect the source of eventually disclosed information afterwards. Our approach uses the properties directly derived from the anonymization process to generate unique fingerprints for every data set.
Sebastian Schrittwieser, Peter Kieseberg, Isao Echizen, Sven Wohlgemuth, Noboru Sonehara
ARES1
2011 Social snapshots: digital forensics for online social networks
abstract
Recently, academia and law enforcement alike have shown a strong demand for data that is collected from online social networks. In this work, we present a novel method for harvesting such data from social networking websites. Our approach uses a hybrid system that is based on a custom add-on for social networks in combination with a web crawling component. The datasets that our tool collects contain profile information (user data, private messages, photos, etc.) and associated meta-data (internal timestamps and unique identifiers). These social snapshots are significant for security research and in the field of digital forensics. We implemented a prototype for Facebook and evaluated our system on a number of human volunteers. We show the feasibility and efficiency of our approach and its advantages in contrast to traditional techniques that rely on application-specific web crawling and parsing. Furthermore, we investigate different use-cases of our tool that include consensual application and the use of sniffed authentication cookies. Finally, we contribute to the research community by publishing our implementation as an open-source project.
Markus Huber 0001, Martin Mulazzani, Manuel Leithner, Sebastian Schrittwieser, Gilbert Wondracek, Edgar R. Weippl
ACSAC4
2011 Using the structure of B+-trees for enhancing logging mechanisms of databases
abstract
Today's database management systems implement sophisticated access control mechanisms to prevent unauthorized access and modifications. This is, as an example, an important basic requirement for SOX (Sarbanes--Oxley Act) compliance, whereby every past transaction has to be traceable at any time. However, malicious database administrators may still be able to bypass the security mechanisms to make hidden modifications to the database.
Peter Kieseberg, Sebastian Schrittwieser, Lorcan Morgan, Martin Mulazzani, Markus Huber 0001, Edgar R. Weippl
iiWAS2
2011 An Algorithm for k-Anonymity-Based Fingerprinting
Sebastian Schrittwieser, Peter Kieseberg, Isao Echizen, Sven Wohlgemuth, Noboru Sonehara, Edgar R. Weippl
IWDW1
2011 Dark Clouds on the Horizon: Using Cloud Storage as Attack Vector and Online Slack Space
Martin Mulazzani, Sebastian Schrittwieser, Manuel Leithner, Markus Huber 0001, Edgar R. Weippl
USENIX Security Symposium2
2010 QR code security
abstract
This paper examines QR Codes and how they can be used to attack both human interaction and automated systems. As the encoded information is intended to be machine readable only, a human cannot distinguish between a valid and a maliciously manipulated QR code. While humans might fall for phishing attacks, automated readers are most likely vulnerable to SQL injections and command injections. Our contribution consists of an analysis of the QR Code as an attack vector, showing different attack strategies from the attackers point of view and exploring their possible consequences.
Peter Kieseberg, Manuel Leithner, Martin Mulazzani, Lindsay Munroe, Sebastian Schrittwieser, Mayank Sinha, Edgar R. Weippl
MoMM5