VLDB 2026 Research / reviewers in the wild / expert
Christina Pöpper
dblp:11/3019
· DBLP profile ↗
48ranked-venue papers
4as first author
17since 2021 · last 2025
0000-0002-2814-962XORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 44 · 3 first-author · 16 since 2021Computer networks · 3 · 1 first-authorArtificial intelligence and machine learning · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | GridNet: Vision-based Mitigation of GPS Attacks for Aerial VehiclesabstractNavigation services based on Global Navigation Satellite Systems (GNSS) are essential for a wide range of global applications, including ensuring the safety of aerial vehicles. However, these GNSS signals (e. g., civilian GPS) are vulnerable to jamming and spoofing attacks. To mitigate such threats, we propose GridNet, a vision-based deep-learning technique to counter GPS jamming and spoofing attacks on aerial vehicles. GridNet uses visual devices (e.g., cameras) to determine geolocation during such attacks by extracting geolocation from aerial photos via a pre-trained neural network model. This non-invasive approach does not modify existing GPS infrastructure, merely relying on real-time visual data. Unlike other methods that focus solely on attack detection, GridNet provides a countermeasure, calculating geolocation data without GPS. We analyze the potential applications and discuss the performance in different flight environments. Experimental results show that GridNet can extract geolocation data from real aerial photos, achieving nearly 93% spoofing detection accuracy with a minimum average geolocation error of 7.33 meters within 4ms on a ground station server and 2.7ms on a typical UAV, respectively, offering a practical anti-spoofing solution. Nian Xue, Zhen Li 0047, Xianbin Hong, Christina Pöpper |
IJCNN | 4 |
| 2025 | Exposing the Guardrails: Reverse-Engineering and Jailbreaking Safety Filters in DALL·E Text-to-Image Pipelines
Corban Villa, Muhammad Shujaat Mirza, Christina Pöpper |
USENIX Security Symposium | 3 |
| 2024 | ASTRA-5G: Automated Over-the-Air Security Testing and Research Architecture for 5G SA DevicesabstractDespite the widespread deployment of 5G technologies, there exists a critical gap in security testing for 5G Standalone (SA) devices. Existing methods, largely manual and labor-intensive, are ill-equipped to fully uncover the state of security in the implementations of 5G SA protocols and standards on devices, severely limiting the ability to conduct comprehensive evaluations. To address this issue, in this work, we introduce a novel, open-source framework that automates the security testing process for 5G SA devices. By leveraging enhanced functionalities of 5G SA core and Radio Access Network (RAN) software, our framework offers a streamlined approach to generating, executing, and evaluating test cases, specifically focusing on the Non-Access Stratum layer. Our application of this framework across multiple 5G SA devices provides in-depth security insights, significantly improving testing efficiency and breadth. Syed Khandker, Michele Guerra, Evangelos Bitsikas, Roger Piqueras Jover, Aanjhan Ranganathan, Christina Pöpper |
WISEC | 6 |
| 2024 | Media talks Privacy: Unraveling a Decade of Privacy Discourse around the WorldabstractOur increasingly digital world has heightened concerns about privacy. Newspaper and media reporting influences and shapes public opinion, which impacts the strategic and operational decisions of a variety of stakeholders, making it crucial to understand how privacy-related issues are portrayed in the media. Leveraging time-series analysis, topic modeling, and sentiment analysis, this paper presents a comprehensive study on the coverage of privacy-related issues in newspapers from 2010 to 2022 across six regions of the world. Temporal trends in privacy coverage reveal a gradual increase in attention to privacy issues globally, with a notable surge observed in newspapers from the Global South, complementing the historically prominent Global North coverage. Topic modeling uncovers dominant themes in privacy reporting, revealing shifts in media focus from government surveillance to data breaches and tech corporations' role. Notably, the majority of privacy reporting carries a negative sentiment, emphasizing the widespread unease that pervades discussions surrounding privacy matters. Muhammad Shujaat Mirza, Corban Villa, Christina Pöpper |
Proc. Priv. Enhancing Technol. | 3 |
| 2023 | Tactics, Threats & Targets: Modeling Disinformation and its Mitigation
Muhammad Shujaat Mirza, Labeeba Begum, Liang Niu, Sarah Pardo, Azza Abouzeid, Paolo Papotti, Christina Pöpper |
NDSS | 7 |
| 2023 | Hope of Delivery: Extracting User Locations From Mobile Instant Messengers
Theodor Schnitzler, Katharina Kohls, Evangelos Bitsikas, Christina Pöpper |
NDSS | 4 |
| 2023 | Freaky Leaky SMS: Extracting User Locations by Analyzing SMS Timings
Evangelos Bitsikas, Theodor Schnitzler, Christina Pöpper, Aanjhan Ranganathan |
USENIX Security Symposium | 3 |
| 2023 | CodexLeaks: Privacy Leaks from Code Generation Language Models in GitHub Copilot
Liang Niu, Muhammad Shujaat Mirza, Zayd Maradni, Christina Pöpper |
USENIX Security Symposium | 4 |
| 2023 | Bypassing Tunnels: Leaking VPN Client Traffic by Abusing Routing Tables
Nian Xue, Yashaswi Malla, Zihang Xia, Christina Pöpper, Mathy Vanhoef |
USENIX Security Symposium | 4 |
| 2023 | UE Security Reloaded: Developing a 5G Standalone User-Side Security Testing FrameworkabstractSecurity flaws and vulnerabilities in cellular networks lead to severe security threats given the data-plane services that are involved, from calls to messaging and Internet access. While the 5G Standalone (SA) system is currently being deployed worldwide, practical security testing of User Equipment (UE) has only been conducted and reported publicly for 4G/LTE and earlier network generations. In this paper, we develop and present the first open-source based security testing framework for 5G SA User Equipment. To that end, we modify the functionality of open-source suites (Open5GS and srsRAN) and develop a broad set of test cases for the 5G NAS and RRC layers. We apply our testing framework in a proof-of-concept manner to 5G SA mobile phones and provide detailed insights from our experiments. While being a framework in development, the results of our experiments presented in this paper can assist other researchers in the field and have the potential to improve 5G SA security. Evangelos Bitsikas, Syed Khandker, Ahmad Salous, Aanjhan Ranganathan, Roger Piqueras Jover, Christina Pöpper |
WISEC | 6 |
| 2022 | You have been warned: Abusing 5G's Warning and Emergency SystemsabstractThe Public Warning System (PWS) is an essential part of cellular networks and a country’s civil protection. Warnings can notify users of hazardous events (e. g., floods, earthquakes) and crucial national matters that require immediate attention. PWS attacks disseminating fake warnings or concealing precarious events can have a serious impact, causing fraud, panic, physical harm, or unrest to users within an affected area. In this work, we conduct the first comprehensive investigation of PWS security in 5G networks. We demonstrate five practical attacks that may impact the security of 5G-based Commercial Mobile Alert System (CMAS) as well as Earthquake and Tsunami Warning System (ETWS) alerts. Additional to identifying the vulnerabilities, we investigate two PWS spoofing and three PWS suppression attacks, with or without a man-in-the-middle (MitM) attacker. We discover that MitM-based attacks have more severe impact than their non-MitM counterparts. Our PWS barring attack is an effective technique to eliminate legitimate warning messages. We perform a rigorous analysis of the roaming aspect of the PWS, incl. its potentially secure version, and report the implications of our attacks on other emergency features (e. g., 911 SIP calls). We discuss possible countermeasures and note that eradicating the attacks necessitates a scrupulous reevaluation of the PWS design and a secure implementation. Evangelos Bitsikas, Christina Pöpper |
ACSAC | 2 |
| 2022 | Towards Security-Optimized Placement of ADS-B SensorsabstractAutomatic Dependent Surveillance Broadcast (ADS-B) sensors deployed on the ground are central to observing aerial movements of aircraft. Their unsystematic placement, however, results in over-densification of sensor coverage in some areas and insufficient sensor coverage in other areas. ADS-B sensor coverage has so far been recognized and analyzed as an availability problem; it was tackled by sensor placement optimization techniques that aim for covering large enough areas. In this paper, we demonstrate that the unsystematic placement of ADS-B sensors leads to a security problem, since the realization and possible deployment of protective mechanisms is closely linked to aspects of redundancy in ADS-B sensor coverage. In particular, we model ADS-B sensor coverage as a multi-dimensional security problem. We then use multi-objective optimization techniques to tackle this problem and derive security-optimized near-optimal placement solutions. Our results show how the location of sensors play a significant role in reducing the success rate of attackers by providing a sufficient number of sensors within a specific geographical area to verify location claims and reducing the exposure to jamming attacks. Ala Darabseh, Christina Pöpper |
WISEC | 2 |
| 2021 | Don't hand it Over: Vulnerabilities in the Handover Procedure of Cellular TelecommunicationsabstractMobility management in the cellular networks plays a significant role in preserving mobile services with minimal latency while a user is moving. To support this essential functionality the cellular networks rely on the handover procedure. Most often, the User Equipment (UE) provides signal measurements to the network via reports to facilitate the handover decision when it discovers a more suitable base station. These measurement reports are cryptographically protected. In this paper, we examine the cellular specification and illustrate that this crucial functionality has critical security implications. To the best of our knowledge, this is the first work on cellular Man-In-The-Middle attacks based on the handover procedure. In particular, we demonstrate a new type of fake base station attacks in which the handover procedures, based on the encrypted measurement reports and signal power thresholds, are vulnerable. An attacker who sets up a false base station mimicking a legitimate one can utilize the vulnerabilities in the handover procedure to cause Denial-Of-Service attacks, Man-In-The-Middle attacks, and information disclosure affecting the user as well as the operator. Therefore, users’ privacy and service availability are jeopardized. Through rigorous experimentation, we uncover the vulnerable parts of the handover procedure, a comprehensive attacker methodology, and attack requirements. We largely focus on the 5G network showing that handover vulnerabilities remain unmitigated to date. Finally, we assess the impact of the handover attacks, and carefully present potential countermeasures that can be used against them. Evangelos Bitsikas, Christina Pöpper |
ACSAC | 2 |
| 2021 | We Built This Circuit: Exploring Threat Vectors in Circuit Establishment in TorabstractTraffic analysis attacks against the Tor network are a persisting threat to the anonymity of its users. The technical capabilities of attacks against encrypted Internet traffic have come a long way. Although the current state-of-the-art predicts high precision and accuracy for website fingerprinting and end-to-end confirmation, the concepts of these attacks often solely focus on their technical capabilities and ignore the operational requirements that are mandatory to get access to transmissions. In this work, we introduce three novel stepping-stone attacks that enable an adversary to (i) gain additional information about monitored connections, (ii) manipulate the Tor connection build-up, and (iii) conduct a targeted Denial-of-Service attack within the Tor infrastructure. All attacks exploit core defensive features of Tor and, consequently, are hard to patch. At the same time, our attacks are in line with standard attacker models for traffic analysis attacks. We demonstrate the feasibility of all three attacks in simulations and empirical case studies and emphasize their pivotal role in preparing a realistic setting for end-to-end confirmation attacks. Theodor Schnitzler, Christina Pöpper, Markus Dürmuth, Katharina Kohls |
EuroS&P | 2 |
| 2021 | Trust the Crowd: Wireless Witnessing to Detect Attacks on ADS-B-Based Air-Traffic Surveillance
Kai Jansen, Liang Niu, Nian Xue, Ivan Martinovic, Christina Pöpper |
NDSS | 5 |
| 2021 | 5G SUCI-catchers: still catching them all?abstractIn mobile networks, IMSI-Catchers identify and track users simply by requesting all users' permanent identities (IMSI) in range. The 5G standard attempts to fix this issue by encrypting the permanent identifier (now SUPI) and transmitting the SUCI. Since the encrypted SUCI is re-generated with an ephemeral key for each use, an attacker can no longer derive the user's identity. However, this scheme does not prevent all tracking and linking: if the identity of a user is already known, an attacker can probe users for that identity. Merlin Chlosta, David Rupprecht, Christina Pöpper, Thorsten Holz |
WISEC | 3 |
| 2021 | SoK: Managing Longitudinal Privacy of Publicly Shared Personal Online DataabstractAbstract Over the past decade, research has explored managing the availability of shared personal online data, with particular focus on longitudinal aspects of privacy. Yet, there is no taxonomy that takes user perspective and technical approaches into account. In this work, we systematize research on longitudinal privacy management of publicly shared personal online data from these two perspectives: user studies capturing users’ interactions related to the availability of their online data and technical proposals limiting the availability of data. Following a systematic approach, we derive conflicts between these two sides that have not yet been addressed appropriately, resulting in a list of challenging open problems to be tackled by future research. While limitations of data availability in proposed approaches and real systems are mostly time-based, users’ desired models are rather complex, taking into account content, audience, and the context in which data has been shared. Our systematic evaluation reveals interesting challenges broadly categorized by expiration conditions, data co-ownership, user awareness, and security and trust. Theodor Schnitzler, Muhammad Shujaat Mirza, Markus Dürmuth, Christina Pöpper |
Proc. Priv. Enhancing Technol. | 4 |
| 2020 | DeepSIM: GPS Spoofing Detection on UAVs using Satellite Imagery MatchingabstractUnmanned Aerial Vehicles (UAVs), better known as drones, have significantly advanced fields such as aerial surveillance, military reconnaissance, cadastral surveying, disaster monitoring, and delivery services. However, UAVs rely on civilian (unauthenticated) GPS for navigation which can be trivially spoofed. Nian Xue, Liang Niu, Xianbin Hong, Zhen Li 0047, Larissa Hoffaeller, Christina Pöpper |
ACSAC | 6 |
| 2020 | IMP4GT: IMPersonation Attacks in 4G NeTworks
David Rupprecht, Katharina Kohls, Thorsten Holz, Christina Pöpper |
NDSS | 4 |
| 2020 | Timeless Timing Attacks: Exploiting Concurrency to Leak Secrets over Remote Connections
Tom van Goethem, Christina Pöpper, Wouter Joosen, Mathy Vanhoef |
USENIX Security Symposium | 2 |
| 2020 | Call Me Maybe: Eavesdropping Encrypted LTE Calls With ReVoLTE
David Rupprecht, Katharina Kohls, Thorsten Holz, Christina Pöpper |
USENIX Security Symposium | 4 |
| 2020 | MAVPro: ADS-B message verification for aviation security with minimal numbers of on-ground sensorsabstractAutomatic Dependent Surveillance Broadcast (ADS-B) centrally contributes to aircraft traffic control in the US and Europe since 2020. ADS-B messages contain information about aircraft location and tracks to provide better real-time traceability of aircraft in space. However, the lack of security mechanisms will be an obstacle for trusting the ADS-B technology. Thus, countermeasures should be integrated to secure the communication and evaluate the integrity and trustworthiness of received messages. In this paper, we design a message verification protocol called MAVPro to evaluate the trustworthiness of received ADS-B messages whose authenticity and integrity could otherwise not be verified. The main idea behind MAVPro is to compare location claims in received ADS-B messages with expected aircraft locations, which are computed using predicted trajectory information (e. g., velocity, elapsed time, aircraft acceleration, heading information) and a set of pre-trusted, continuously updated anchors. Our protocol is able to evaluate the trustworthiness of received messages if as little as one ADS-B receiver obtains a message --- as opposed to four receivers required for using multilateration-based techniques to verify position claims. Thus we are able to considerably extend the coverage area where security checks can be applied compared to existing solutions. We evaluate MAVPro based on real-time data from the OpenSky network, analyze its performance, and verify its applicability to address ADS-B security concerns. MAVPro is backwards compatible and does not require changes to the ADS-B infrastructure. Ala Darabseh, Hoda Alkhzaimi, Christina Pöpper |
WISEC | 3 |
| 2020 | Protecting wi-fi beacons from outsider forgeriesabstractAll Wi-Fi networks periodically broadcast beacons to announce their presence to nearby clients. These beacons contain various properties of the network, including dynamic information to manage the behavior of clients. We first show that an adversary can forge beacons to carry out various known as well as novel attacks. Motivated by these attacks, we propose a scheme to authenticate beacon frames that is efficient and has low bandwidth overhead. We evaluate the security properties of this scheme, and discuss its current implementation in Linux. By collaborating with industry partners, our scheme also got incorporated into the draft 802.11 standard, increasing the chance of it being implemented by vendors. Mathy Vanhoef, Prasant Adhikari, Christina Pöpper |
WISEC | 3 |
| 2019 | On the Challenges of Geographical Avoidance for Tor
Katharina Kohls, Kai Jansen, David Rupprecht, Thorsten Holz, Christina Pöpper |
NDSS | 5 |
| 2019 | Towards Contractual Agreements for Revocation of Online Data
Theodor Schnitzler, Markus Dürmuth, Christina Pöpper |
SEC | 3 |
| 2019 | Breaking LTE on Layer TwoabstractLong Term Evolution (LTE) is the latest mobile communication standard and has a pivotal role in our information society: LTE combines performance goals with modern security mechanisms and serves casual use cases as well as critical infrastructure and public safety communications. Both scenarios are demanding towards a resilient and secure specification and implementation of LTE, as outages and open attack vectors potentially lead to severe risks. Previous work on LTE protocol security identified crucial attack vectors for both the physical (layer one) and network (layer three) layers. Data link layer (layer two) protocols, however, remain a blind spot in existing LTE security research. In this paper, we present a comprehensive layer two security analysis and identify three attack vectors. These attacks impair the confidentiality and/or privacy of LTE communication. More specifically, we first present a passive identity mapping attack that matches volatile radio identities to longer lasting network identities, enabling us to identify users within a cell and serving as a stepping stone for follow-up attacks. Second, we demonstrate how a passive attacker can abuse the resource allocation as a side channel to perform website fingerprinting that enables the attacker to learn the websites a user accessed. Finally, we present the A LTE R attack that exploits the fact that LTE user data is encrypted in counter mode (AES-CTR) but not integrity protected, which allows us to modify the message payload. As a proof-of-concept demonstration, we show how an active attacker can redirect DNS requests and then perform a DNS spoofing attack. As a result, the user is redirected to a malicious website. Our experimental analysis demonstrates the real-world applicability of all three attacks and emphasizes the threat of open attack vectors on LTE layer two protocols. David Rupprecht, Katharina Kohls, Thorsten Holz, Christina Pöpper |
IEEE Symposium on Security and Privacy | 4 |
| 2019 | LTE security disabled: misconfiguration in commercial networksabstractLong Term Evolution (LTE) is the de-facto standard for mobile communication. It provides effective security features but leaves room for misunderstandings in its configuration and implementation. In particular, providers face difficulties when maintaining network configurations. Merlin Chlosta, David Rupprecht, Thorsten Holz, Christina Pöpper |
WiSec | 4 |
| 2019 | Lost traffic encryption: fingerprinting LTE/4G traffic on layer twoabstractLong Term Evolution (LTE) provides the communication infrastructure for both professional and private use cases and has become an integral part of our everyday life. Even though LTE/4G overcomes many security issues of previous standards, recent work demonstrates several attack vectors on the physical and network layers of the LTE stack. We do, however, have only limited insights into the security and privacy aspects of the second layer. Katharina Kohls, David Rupprecht, Thorsten Holz, Christina Pöpper |
WiSec | 4 |
| 2018 | Forgetting with Puzzles: Using Cryptographic Puzzles to support Digital ForgettingabstractDigital forgetting deals with the unavailability of content uploaded to web and storage servers after the data has served its purpose. The content on the servers can be deleted manually, but this does not prevent data archival and access at different storage locations. This is problematic since then the data may be accessed for unintended or even malicious purposes long after the owners have decided to abandon the public availability of their data. Approaches which assign a lifetime value to data or use heuristics like interest in data to make it inaccessible after some time have been proposed, but digital forgetting is still in its infancy and there are a number of open problems with the proposed approaches. Ghous Amjad, Muhammad Shujaat Mirza, Christina Pöpper |
CODASPY | 3 |
| 2018 | DigesTor: Comparing Passive Traffic Analysis Attacks on Tor
Katharina Kohls, Christina Pöpper |
ESORICS (1) | 2 |
| 2018 | Crowd-GPS-Sec: Leveraging Crowdsourcing to Detect and Localize GPS Spoofing AttacksabstractThe aviation industry's increasing reliance on GPS to facilitate navigation and air traffic monitoring opens new attack vectors with the purpose of hijacking UAVs or interfering with air safety. We propose Crowd-GPS-Sec to detect and localize GPS spoofing attacks on moving airborne targets such as UAVs or commercial airliners. Unlike previous attempts to secure GPS, Crowd-GPS-Sec neither requires any updates of the GPS infrastructure nor of the airborne GPS receivers, which are both unlikely to happen in the near future. In contrast, Crowd-GPS-Sec leverages crowdsourcing to monitor the air traffic from GPS-derived position advertisements that aircraft periodically broadcast for air traffic control purposes. Spoofing attacks are detected and localized by an independent infrastructure on the ground which continuously analyzes the contents and the times of arrival of these advertisements. We evaluate our system with real-world data from a crowdsourced air traffic monitoring sensor network and by simulations. We show that Crowd-GPS-Sec is able to globally detect GPS spoofing attacks in less than two seconds and to localize the attacker up to an accuracy of 150 meters after 15 minutes of monitoring time. Kai Jansen, Matthias Schäfer 0002, Daniel Moser, Vincent Lenders, Christina Pöpper, Jens B. Schmitt |
IEEE Symposium on Security and Privacy | 5 |
| 2017 | Localization of Spoofing Devices using a Large-scale Air Traffic Surveillance SystemabstractSystems relying on satellite positioning techniques such as GPS can be targeted by spoofing attacks, where attackers try to inject fake positioning information. With the growing spread of flying drones and their usage of GPS for localization, these systems become interesting targets of attacks with the purpose of hijacking or to distract air safety surveillance. The most recent development in air traffic surveillance is the automatic dependent surveillance -- broadcast (ADS-B). Aircraft periodically broadcast their location, speed, or environmental measurements via ADS-B. The open research project OpenSky Network collects ADS-B reports and makes them available for research purposes. This poster presents a concept to detect and localize spoofing devices by utilizing the information provided by a large-scale air traffic surveillance system. We utilize ADS-B reports collected by the OpenSky Network and provide first results on the effectiveness of localizing spoofing sources. Kai Jansen, Matthias Schäfer 0002, Vincent Lenders, Christina Pöpper, Jens B. Schmitt |
AsiaCCS | 4 |
| 2017 | Traffic Analysis Attacks in Anonymity NetworksabstractWith more than 1.7 million daily users, Tor is a large-scale anonymity network that helps people to protect their identities in the Internet. Tor provides low-latency transmissions that can serve a wide range of applications including web browsing, which renders it an easily accessible tool for a large user base. Unfortunately, its wide adoption makes Tor a valuable target for de-anonymization attacks. Recent work proved that powerful traffic analysis attacks exist which enable an adversary to relate traffic streams in the network and identify users and accessed contents. One open research question in the field of anonymity networks therefore addresses efficient countermeasures to the class of traffic analysis attacks. Defensive techniques must improve the security features of existing networks while still providing an acceptable performance that can maintain the wide acceptance of a system. The proposed work presents an analysis of mixing strategies as a countermeasure to traffic analysis attacks in Tor. First simulation results indicate the security gains and performance impairments of three main mixing strategies. Katharina Kohls, Christina Pöpper |
AsiaCCS | 2 |
| 2017 | Advancing attacker models of satellite-based localization systems: the case of multi-device attackersabstractIn this paper, we report on recent advancements in attacking satellite-based positioning systems and on shortcomings of proposed countermeasures. Applications based on satellite positioning and navigation systems make use of a deployed infrastructure that is challenging to protect and secure against attacks. Many of the proposed protection mechanisms and solutions in the wild are based on and analyzed with respect to single-antenna attacker models that should in the meantime be considered outdated as they are no longer appropriate. Due to a significant drop in complexity and cost to perform multi-device attacks on these systems, the attacker models need to be adjusted to comprise more powerful adversaries that have recently become a reality. By demonstrating the implementation of a simple yet effective multi-antenna setup, we outline possible attacks against systems that are otherwise considered secure. Kai Jansen, Christina Pöpper |
WISEC | 2 |
| 2016 | Multi-receiver GPS spoofing detection: error models and realization
Kai Jansen, Nils Ole Tippenhauer, Christina Pöpper |
ACSAC | 3 |
| 2016 | SkypeLine: Robust Hidden Data Transmission for VoIPabstractInternet censorship is used in many parts of the world to prohibit free access to online information. Different techniques such as IP address or URL blocking, DNS hijacking, or deep packet inspection are used to block access to specific content on the Internet. In response, several censorship circumvention systems were proposed that attempt to bypass existing filters. Especially systems that hide the communication in different types of cover protocols attracted a lot of attention. However, recent research results suggest that this kind of covert traffic can be easily detected by censors. In this paper, we present SkypeLine, a censorship circumvention system that leverages Direct-Sequence Spread Spectrum (DSSS) based steganography to hide information in Voice-over-IP (VoIP) communication. SkypeLine introduces two novel modulation techniques that hide data by modulating information bits on the voice carrier signal using pseudo-random, orthogonal noise sequences and repeating the spreading operation several times. Our design goals focus on undetectability in presence of a strong adversary and improved data rates. As a result, the hiding is inconspicuous, does not alter the statistical characteristics of the carrier signal, and is robust against alterations of the transmitted packets. We demonstrate the performance of SkypeLine based on two simulation studies that cover the theoretical performance and robustness. Our measurements demonstrate that the data rates achieved with our techniques substantially exceed existing DSSS approaches. Furthermore, we prove the real-world applicability of the presented system with an exemplary prototype for Skype. Katharina Kohls, Thorsten Holz, Dorothea Kolossa, Christina Pöpper |
AsiaCCS | 4 |
| 2016 | Neuralyzer: Flexible Expiration Times for the Revocation of Online DataabstractOnce data is released to the Internet, there is little hope to successfully delete it, as it may have been duplicated, reposted, and archived in multiple places. This poses a significant threat to users' privacy and their right to permanently erase their very own data. One approach to control the implications on privacy is to assign a lifetime value to the published data and ensure that the data is no longer accessible after this point in time. However, such an approach suffers from the inability to successfully predict the right time when the data should vanish. Consequently, the author of the data can only estimate the correct time, which unfortunately can cause the premature or belated deletion of data. Apostolis Zarras, Katharina Kohls, Markus Dürmuth, Christina Pöpper |
CODASPY | 4 |
| 2015 | A practical investigation of identity theft vulnerabilities in EduroamabstractEduroam offers secure access to the Internet at participating institutions, using authentication via IEEE 802.1X and secure forwarding of authentication data to the authentication server of the user's institution. Due to erroneous configuration manuals and a lack of knowledge on the user side, though, a big share of client devices lack the required root CA certificate to authenticate the Eduroam network, yet still being able to access the network. Moreover, deficient software implementations on client devices prevent users from the secure execution of the authentication process. Sebastian Brenza, Andre Pawlowski, Christina Pöpper |
WISEC | 3 |
| 2014 | Enabling Short Fragments for Uncoordinated Spread Spectrum Communication
Christina Pöpper, Srdjan Capkun |
ESORICS (1) | 2 |
| 2011 | On the requirements for successful GPS spoofing attacksabstractAn increasing number of wireless applications rely on GPS signals for localization, navigation, and time synchronization. However, civilian GPS signals are known to be susceptible to spoofing attacks which make GPS receivers in range believe that they reside at locations different than their real physical locations. In this paper, we investigate the requirements for successful GPS spoofing attacks on individuals and groups of victims with civilian or military GPS receivers. In particular, we are interested in identifying from which locations and with which precision the attacker needs to generate its signals in order to successfully spoof the receivers. We will show, for example, that any number of receivers can easily be spoofed to one arbitrary location; however, the attacker is restricted to only few transmission locations when spoofing a group of receivers while preserving their constellation. In addition, we investigate the practical aspects of a satellite-lock takeover, in which a victim receives spoofed signals after first being locked on to legitimate GPS signals. Using a civilian GPS signal generator, we perform a set of experiments and find the minimal precision of the attacker's spoofing signals required for covert satellite-lock takeover. Nils Ole Tippenhauer, Christina Pöpper, Kasper Bonne Rasmussen, Srdjan Capkun |
CCS | 2 |
| 2011 | Investigation of Signal and Message Manipulations on the Wireless Channel
Christina Pöpper, Nils Ole Tippenhauer, Boris Danev, Srdjan Capkun |
ESORICS | 1 |
| 2010 | Keeping data secret under full compromise using porter devicesabstractWe address the problem of confidentiality in scenarios where the attacker is not only able to observe the communication between principals, but can also fully compromise the communicating parties (their devices, not only their long term secrets) after the confidential data has been exchanged. We formalize this problem and explore solutions that provide confidentiality after the full compromise of devices and user passwords. We propose two new solutions that use explicit key deletion and forward-secret protocols combined with key storage on porter devices. Our solutions provide the users with control over their privacy. We analyze the proposed solutions using an automatic verification tool. We also implement a prototype using a mobile phone as a porter device to illustrate how the solution can be realized on modern platforms. Christina Pöpper, David A. Basin, Srdjan Capkun, Cas Cremers |
ACSAC | 1 |
| 2010 | Anti-jamming broadcast communication using uncoordinated spread spectrum techniquesabstractJamming-resistant communication is crucial for safety-critical applications such as emergency alert broadcasts or the dissemination of navigation signals in adversarial settings. In such applications, mission-critical messages are broadcast to a large and unknown number of (potentially untrusted) receivers that rely on the availability, integrity, and authenticity of the messages; here, availability primarily refers to the ability to communicate in the presence of jamming. Common techniques to counter jamming-based denial-of-service attacks such as Frequency Hopping (FH) and Direct Sequence Spread Spectrum (DSSS) cannot be applied in such settings because they depend on secret pairwise or group keys shared between the sender and the receivers before the communication. This dependency entails serious or unsolvable scalability and keysetup problems or weak jamming-resistance (a single malicious receiver can compromise the whole system). As a solution, in this work, we propose uncoordinated spread spectrum techniques that enable anti-jamming broadcast communication without shared secrets. Uncoordinated spread spectrum techniques can handle an unlimited amount of (malicious) receivers. We present two instances (Uncoordinated FH and Uncoordinated DSSS) and analyze differences in their performance as well as their combination. We further discuss the applications of these techniques to anti-jamming navigation broadcast, bootstrapping of coordinated spread spectrum communication, and anti-jamming emergency alerts. Christina Pöpper, Mario Strasser, Srdjan Capkun |
IEEE J. Sel. Areas Commun. | 1 |
| 2009 | Efficient uncoordinated FHSS anti-jamming communicationabstractWe address the problem of jamming-resistant communication in scenarios in which the communicating parties do not share secret keys. This includes scenarios where the communicating parties are not known in advance or where not all parties can be trusted (e.g., jamming-resistant key establishment or anti-jamming broadcast to a large set of unknown receivers). In these cases, the deployment of shared secret keys is unrealistic, and therefore this problem cannot be solved using existing anti-jamming solutions like FHSS and DSSS that depend on pre-shared keys. Recently, a solution to this problem has been proposed that introduces Uncoordinated Frequency Hopping (UFH), a new spread-spectrum anti-jamming technique that does not rely on secret keys. In this work, we investigate the efficiency of UFH-based communication: we identify optimal strategies for the UFH frequency channel selection and we propose a set of new UFH-based anti-jamming schemes that, compared to the original UFH proposal, reduce the communication latency up to one-half (i.e., increase UFH communication throughput up to two times). Mario Strasser, Christina Pöpper, Srdjan Capkun |
MobiHoc | 2 |
| 2009 | Attacks on public WLAN-based positioning systemsabstractIn this work, we study the security of public WLAN-based positioning systems. Specifically, we investigate the Skyhook positioning system, available on PCs and used on a number of mobile platforms, including Apple's iPod touch and iPhone. By implementing and analyzing several kinds of attacks, we demonstrate that this system is vulnerable to location spoofing and location database manipulation. In both, the attacker can arbitrarily change the result of the localization at the victim device, by either impersonating remote infrastructure or by tampering with the service database. Our attacks can easily be replicated and we conjecture that--without appropriate countermeasures--public WLAN-based positioning should therefore be used with caution in safety-critical contexts. We further discuss several approaches for securing WLAN-based positioning systems. Nils Ole Tippenhauer, Kasper Bonne Rasmussen, Christina Pöpper, Srdjan Capkun |
MobiSys | 3 |
| 2009 | Jamming-resistant Broadcast Communication without Shared Keys
Christina Pöpper, Mario Strasser, Srdjan Capkun |
USENIX Security Symposium | 1 |
| 2008 | Jamming-resistant Key Establishment using Uncoordinated Frequency HoppingabstractWe consider the following problem: how can two devices that do not share any secrets establish a shared secret key over a wireless radio channel in the presence of a communication jammer? An inherent challenge in solving this problem is that known anti-jamming techniques (e.g.,frequency hopping or direct-sequence spread spectrum) which should support device communication during the key establishment require that the devices share a secret spreading key (or code) prior to the start of their communication. This requirement creates a circular dependency between anti-jamming spread-spectrum communication and key establishment, which has so far not been addressed. In this work, we propose an Uncoordinated Frequency Hopping (UFH) scheme that breaks this dependencyand enables key establishment in the presence of a communication jammer. We perform a detailed analysis of our UFH scheme and show its feasibility, both in terms of execution time and resource requirements. Mario Strasser, Christina Pöpper, Srdjan Capkun, Mario Cagalj |
SP | 2 |
| 2008 | Secure Time Synchronization in Sensor NetworksabstractTime synchronization is critical in sensor networks at many layers of their design. It enables better duty-cycling of the radio, accurate and secure localization, beamforming, and other collaborative signal processing tasks. These benefits make time-synchronization protocols a prime target of malicious adversaries who want to disrupt the normal operation of a sensor network. In this article, we analyze attacks on existing time synchronization protocols for wireless sensor networks and we propose a secure time synchronization toolbox to counter these attacks. This toolbox includes protocols for secure pairwise and group synchronization of nodes that either lie in the neighborhood of each other or are separated by multiple hops. We provide an in-depth analysis of the security and the energy overhead of the proposed protocols. The efficiency of these protocols has been tested through an experimental study on Mica2 motes. Saurabh Ganeriwal, Christina Pöpper, Srdjan Capkun, Mani Srivastava 0001 |
ACM Trans. Inf. Syst. Secur. | 2 |