Martin Gergeleit

dblp:11/5971 · DBLP profile ↗
← Back
14ranked-venue papers
0as first author
5since 2021 · last 2026
0009-0003-3799-4010ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Systems, architecture and hardware · 8 · 3 since 2021Security and privacy · 2 · 2 since 2021Software engineering, systems software and programming languages · 1
YearPublicationVenuePosition
2026 Identifying Control and Monitoring Data for Forensics of Safety-Critical Attacks on Control Room Operations
Alexios Karagiozidis, Martin Gergeleit
SAFECOMP2
2025 Evaluating Advanced Anomaly Detection Models for Time Series Data of Refrigeration Systems
abstract
Reliable cold chain monitoring in supermarkets is essential, yet current anomaly detection often relies on fixed expert-defined thresholds and raw data, limiting flexibility. This study evaluates different advanced anomaly detection on real-world refrigeration time series data, focusing on generalization across similar refrigeration units with varying configurations. It examines model performance on both seen and unseen units and explores calibration methods, including data scaling and individual anomaly threshold determination. Results show that Transformer-based models and state-space models outperform traditional baselines and generalize well, even across differing systems. Tailored thresholds and calibration improve detection, offering a scalable approach for industrial deployment.
Melina Meyer, Julian Eversheim, Johannes Pitterle, Martin Gergeleit, Dirk Krechel
ETFA4
2023 A Forensic I/O Recorder for Industrial Control Systems Using PLCs and OPC UA
abstract
The increasing network connectivity of automation or industrial control systems (ICS) through Industrie 4.0 has led to higher risks of attacks, where remote attackers can compromise industrial devices or networks to maliciously change or inject data, as well as send malicious commands that can damage machines or impair production efficiency. However, evidence gathering for such attacks can be challenging due to the lack of forensic compliant logging capabilities, as well as the high heterogeneity of these devices that makes it difficult to find generalized approaches for collecting evidence or artifacts from an ICS system. Furthermore industrial devices have limited hardware and CPU resources making established IT forensics not applicable to these devices.
Alexios Karagiozidis, Martin Gergeleit
ARES2
2023 Development of Anomaly Detection with Variable Contexts on Refrigeration Data
abstract
Anomaly detection in time series data is a well-known research topic and of great interest to the industry. However, industrial systems are complex due to the nature of real world plants and their interrelationships in the overall system. Industrial plants often cannot be considered in isolation because their environment affects them. Thus, industrial plants have variable contexts in which they are embedded. The combination of a variable context with the information of the plant poses a challenge in modeling AI approaches for anomaly detection.In the field of refrigeration, machine learning approaches are still in their early stages. In live systems, simple threshold values are often still used. There are only a few published approaches to detect error situations using machine learning on such data.In this work, the challenges to such a model architecture are analyzed and a dataset of real refrigeration plants is built. Then, models for detection and classification are explored and their applicability to this type of data is evaluated. Furthermore, models are combined to add context to improve the results compared to models without context information.
Melina Meyer, Martin Gergeleit, Dirk Krechel
ETFA2
2022 An OT Forensic Model Based on Established IT Forensics Using IIRA
abstract
Through Industrie 4.0, the connectivity of automation or industrial control systems (ICS) is increasing. Simultaneously the frequency and aggressiveness of remote attacks have increased, impacting the risk and vulnerabilities of ICS [1]. For example, a remote attacker can now damage industrial machines or impair the efficiency of production facilities over the Internet. To find evidence and protect oneself against future attacks as well as to minimize risks, it is necessary to be able to investigate or trace down such incidents by performing forensics within ICS. In this paper, we developed a forensic model to plan and perform forensic investigations within Internet-based ICS. For this purpose, we use established classic IT forensic processes as well as existing forensic research for Operational Technology (OT). Our model is compliant with the Industrial Internet Reference Architecture (IIRA) so it can be integrated or applied to existing Internet-based ICS.The approach is validated by showing that it is suitable to detect and analyze a recently published, more sophisticated attack on the OT specific components of typical ICS architectures.
Alexios Karagiozidis, Martin Gergeleit
ETFA2
2020 Towards Automated Security Evaluation within the Industrial Reference Architecture
abstract
The current developments towards the visions of Industrie 4.0 will create open and dynamic architectures being supervised by Industrial Automation and Control Systems. Due to this new connectivity and flexibility, future industrial production systems need to be inspected during all phases of the whole lifecycle from a security point of view as well. Frequent reconfiguration and adaptation based on smart services impose advanced requirements on the audits and certification with regard to security. To facilitate that, this work presents an approach for the modeling of security requirements and capabilities within the Industrial Reference Architecture and evaluates it based on the concrete system architectures of a number of industrial use cases. The result is the Sec4ICS tooling-based concept for the automated assessment of security-related functionalities within industrial systems.
Marco Ehrlich, Martin Gergeleit, Henning Trsek, Georg Lukas
ETFA2
2019 Secure and Flexible Deployment of Industrial Applications inside Cloud-Based Environments
abstract
Future industrial production systems following the paradigms of Industrie 4.0 will be reconfigured frequently and new system configurations will be deployed automatically as part of the engineering processes. In order to keep pace with this requirement of increased flexibility, it will be needed to achieve the adequate security levels in an automated way and to reduce the current static procedures and manual efforts as much as possible. Therefore, a modelling of all security-related functionalities and capabilities is mandatory. This paper further describes an approach for such a modelling based on the IEC 62443 security standard and an implementation of an automated deployment of components inside an industrial environment established with the OASIS Tosca and Ansible tools. The first results of the whole tool chain are evaluated with a real-world use case of software deployment in a suitable lab environment.
Marco Ehrlich, Henning Trsek, Martin Gergeleit, Julius Paffrath, Kostyantyn Simkin, Jürgen Jasperneite
ETFA3
2005 Robust scheduling in team-robotics
Leandro Buss Becker, Edgar Nett, Stefan Schemmer, Martin Gergeleit
J. Syst. Softw.4
2003 Using a flexible real-time scheduling strategy in a distributed embedded application
abstract
The increasing complexity of current real-time applications demands systems to make good use of the available computational resources. Guaranteeing timing behavior using traditional real-time scheduling policies is turning to be unfeasible, as these policies are based in pessimistic worst-case assumptions that pre-allocate resources even though they will be rarely used. The time-aware fault-tolerant (TAFT) scheduler presents a flexible scheduling strategy that allows the construction of schedules maximizing the CPU utilization. This work presents the use of the TAFT scheduler with computational intensive distributed embedded applications, in order to keep a high ratio of successful tasks completion and so guaranteeing its computational progress. More specifically, the paper sketches a "TAFT-based" fusion algorithm for laser-scanner data and derives the requirements that the execution of this algorithm has on the CPU-scheduling.
Leandro Buss Becker, Martin Gergeleit, Stefan Schemmer, Edgar Nett
ETFA (2)2
2001 Enhancing O-O Middleware to Become Time-Aware
Edgar Nett, Martin Gergeleit, Michael Mock
Real Time Syst.2
2000 Monitoring Distributed Real-Time Activities in DCOM
abstract
Object-oriented frameworks have become a key element in the design of distribution systems. They make the existence of the physical and operating system level resources transparent to the designer and provide the abstract view of the distributed systems as a set of objects that interact by invoking well-defined interfaces of each other. Easy reuse of existing components, location transparency and implementation hiding are the main ingredients of such frameworks that simplify the task of designing distributed systems drastically. It is desirable to take advantage of these benefits when designing distributed real-time systems, too. However, this goal conflicts with the essential need to consider the allocation of system resources when real-time requirements must be met. Here, system level resource issues such as execution times on CPUs, thread switches, occurrence of interrupts, and message delays are of primary interest. Our approach to solve this dilemma is to allow and support the designer of distributed real-time object-oriented applications to become aware of system level resources. We present a monitoring tool JewelDC that allows monitoring of distribution activities (i.e. nested sequences of object invocations) in a distributed object-oriented framework. Distributed activities are visualized at the abstract object level while simultaneously revealing their use of system level resources. The tool has been implemented for DCOM on Microsoft Windows NT 4.0.
Michael Mock, Martin Gergeleit, Edgar Nett
ISORC2
1999 An Integrated Environment for the Complete Development Cycle of an Object-Oriented Distributed Real-Time System
abstract
This paper describes a powerful integrated development environment that covers all steps of the development of an object-oriented real-time application from initial design to the final evaluation. The system consists of a set of integrated tools for modeling, simulation, implementation, instrumentation, monitoring, and visualization that all work on the same OO system model. As all steps of creating a running implementation with visualized monitoring output from the design model are automatic, the environment encourages an iterative approach to the design of complex real-time control applications. This complete environment has been accomplished by integrating the SIMOO-RT modeling, simulation and implementation environment, developed at the Federal University of Rio Grande do Sul, with the Jewel++ object-oriented instrumentation and monitoring tool from GMD, St. Augustin, Germany. The work has been done in the context of the ADOORATA project (A Distributed Object-Oriented Architecture for Real-Time Automation), a Brazilian-German cooperation.
Carlos Eduardo Pereira, Leandro Buss Becker, Martin Gergeleit, Edgar Nett
ISORC3
1998 An Adaptive Approach to Object-Oriented Real-Time Computing
abstract
Real time computing is becoming an enabling technology for many important distributed applications such as flexible manufacturing, multimedia, robotics and process control. Traditionally, real time systems have been realized as isolated embedded systems. Unfortunately, this approach no longer suffices for future complex systems in the application scenarios mentioned above. In this situation, the use of an object oriented design paradigm greatly reduces the complexity of the system while improving reusability and manageability. Furthermore, the surrounding IT infrastructure is more and more accessible through object oriented interfaces (e.g. CORBA). In addition, object oriented modeling allows reflection of the dynamic characteristics of the applications mentioned above by instantiating objects dynamically. In order to meet the real time requirements in such an environment, static scheduling is not sufficient since many non predictable resource conflicts influence execution times. Therefore, the most distinguishing requirement of these complex heterogeneous systems is the need of the computing system to dynamically adapt to dynamically changing conditions. Little work has been done on integrating object oriented system design with resource allocation algorithms that are flexible enough to cope with this new requirement. The paper presents an approach for an adaptive object oriented system with integrated monitoring, dynamic execution time prediction and scheduling. It explains how this approach is applied to CORBA and C++.
Edgar Nett, Martin Gergeleit, Michael Mock
ISORC2
1992 JEWEL: Design and Implementation of a Distributed Measurement System
abstract
The distributed measurement system JEWEL, developed within project RelaX, is described. JEWEL consists of a flexible toolkit for low-interference online performance measurement integrated with a powerful adaptable graphical presentation facility and a generic interactive experiment control system. JEWEL supports a large set of different system models as well as a wide variety of interfaces to the observed system. Two examples are presented in order to demonstrate its flexibility.>
Frank Lange, Reinhold Kröger, Martin Gergeleit
IEEE Trans. Parallel Distributed Syst.3