Martin Serror

dblp:128/8267 · DBLP profile ↗
← Back
22ranked-venue papers
7as first author
10since 2021 · last 2025
0000-0002-6925-5744ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 13 · 3 first-author · 3 since 2021Security and privacy · 7 · 2 first-author · 6 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2025 Sherlock: A Dataset for Process-aware Intrusion Detection Research on Power Grid Networks: Dataset Paper
abstract
419
Eric Wagner 0003, Lennart Bader, Konrad Wolsing, Martin Serror
CODASPY4
2025 MAC Aggregation over Lossy Channels in DTLS 1.3
abstract
Aggregating Message Authentication Codes (MACs) promises to save valuable bandwidth in resource-constrained environments. The idea is simple: Instead of appending an authentication tag to each message in a communication stream, the integrity protection of multiple messages is aggregated into a single tag. Recent studies postulate, e.g., based on simulations, that these benefits also spread to wireless, and thus lossy, scenarios despite each lost packet typically resulting in the loss of integrity protection information for multiple messages. In this paper, we investigate these claims in a real deployment. Therefore, we first design a MAC aggregation extension for the Datagram Transport Layer Security (DTLS) 1.3 protocol. Afterward, we extensively evaluate the performance of MAC aggregation on a complete communication protocol stack on embedded hardware. We find that MAC aggregation can indeed increase goodput by up to 50 % and save up to 17 % of energy expenditure for the transmission of short messages, even in lossy channels.
Eric Wagner 0003, David Heye, Klaus Wehrle, Martin Serror
ICNP5
2025 P4Ward: Fine-Grained Behavioral Policy Enforcement for Industrial Networks
abstract
Industrial Control Systems (ICS) are increasingly targeted by cyber-attacks, yet often lack cryptographic protections due to legacy devices and protocols. Network-based defenses— particularly the enforcement of behavioral policies—offer an effective means of reducing the attack surface. However, such approaches must support industrial protocols and payload inspection while maintaining scalability and low-latency overhead. In this paper, we present P4Ward, a framework that leverages Manufacturer Usage Description (MUD) for scalable, device-specific policy specification and uses P4-programmable hardware switches to enforce these policies at line rate, in conjunction with authentication where feasible. We implement a proof-of-concept supporting multiple industrial protocols, including Modbus and OPC UA, and evaluate its performance and security impact. Our results show that P4Ward achieves latency comparable to industrial-grade switches while enabling precise enforcement of flexible access control rules—such as validating application layer fields (e.g., function codes) and explicitly restricting write operations to authorized endpoints.
Ina Berenice Fink, William Köhler, Martin Serror, Klaus Wehrle
LCN3
2024 When and How to Aggregate Message Authentication Codes on Lossy Channels?
Eric Wagner 0003, Martin Serror, Klaus Wehrle, Martin Henze
ACNS (2)2
2024 Madtls: Fine-grained Middlebox-aware End-to-end Security for Industrial Communication
abstract
Industrial control systems increasingly rely on middlebox functionality such as intrusion detection or in-network processing. However, traditional end-to-end security protocols interfere with the necessary access to in-flight data. While recent work on middlebox-aware end-to-end security protocols for the traditional Internet promises to address the dilemma between end-to-end security guarantees and middleboxes, the current state-of-the-art lacks critical features for industrial communication. Most importantly, industrial settings require fine-grained access control for middleboxes to truly operate in a least-privilege mode. Likewise, advanced applications even require that middleboxes can inject specific messages (e.g., emergency shutdowns). Meanwhile, industrial scenarios often expose tight latency and bandwidth constraints not found in the traditional Internet. As the current state-of-the-art misses critical features, we propose Middlebox-aware DTLS (Madtls), a middlebox-aware end-to-end security protocol specifically tailored to the needs of industrial networks. Madtls provides bit-level read and write access control of middleboxes to communicated data with minimal bandwidth and processing overhead, even on constrained hardware.
Eric Wagner 0003, David Heye, Martin Serror, Ike Kunze, Klaus Wehrle, Martin Henze
AsiaCCS3
2023 Comprehensively Analyzing the Impact of Cyberattacks on Power Grids
abstract
The increasing digitalization of power grids and especially the shift towards IP-based communication drastically increase the susceptibility to cyberattacks, potentially leading to blackouts and physical damage. Understanding the involved risks, the interplay of communication and physical assets, and the effects of cyberattacks are paramount for the uninterrupted operation of this critical infrastructure. However, as the impact of cyberattacks cannot be researched in real-world power grids, current efforts tend to focus on analyzing isolated aspects at small scales, often covering only either physical or communication assets. To fill this gap, we present Wattson, a comprehensive research environment that facilitates reproducing, implementing, and analyzing cyberattacks against power grids and, in particular, their impact on both communication and physical processes. We validate Wattson’s accuracy against a physical testbed and show its scalability to realistic power grid sizes. We then perform authentic cyberattacks, such as Industroyer, within the environment and study their impact on the power grid’s energy and communication side. Besides known vulnerabilities, our results reveal the ripple effects of susceptible communication on complex cyber-physical processes and thus lay the foundation for effective countermeasures.
Lennart Bader, Martin Serror, Olav Lamberts, Ömer Sen, Dennis van der Velde, Immanuel Hacker, Julian Filter, Elmar Gerhards-Padilla, Martin Henze
EuroS&P2
2022 Poster: INSIDE - Enhancing Network Intrusion Detection in Power Grids with Automated Facility Monitoring
abstract
Advances in digitalization and networking of power grids have increased the risks of cyberattacks against such critical infrastructures, where the attacks often originate from within the power grid's network. Adequate detection must hence consider both physical access violations and network anomalies to identify the attack's origin. Therefore, we propose INSIDE, combining network intrusion detection with automated facility monitoring to swiftly detect cyberattacks on power grids based on unauthorized access. Besides providing an initial design for INSIDE, we discuss potential use cases illustrating the benefits of such a comprehensive methodology.
Martin Serror, Lennart Bader, Martin Henze, Arne Schwarze, Kai Nürnberger
CCS1
2022 BP-MAC: Fast Authentication for Short Messages
abstract
Resource-constrained devices increasingly rely on wireless communication for the reliable and low-latency transmission of short messages. However, especially the implementation of adequate integrity protection of time-critical messages places a significant burden on these devices. We address this issue by proposing BP-MAC, a fast and memory-efficient approach for computing message authentication codes based on the well-established Carter-Wegman construction. Our key idea is to offload resource-intensive computations to idle phases and thus save valuable time in latency-critical phases, i.e., when new data awaits processing. Therefore, BP-MAC leverages a universal hash function designed for the bitwise preprocessing of integrity protection to later only require a few XOR operations during the latency-critical phase. Our evaluation on embedded hardware shows that BP-MAC outperforms the state-of-the-art in terms of latency and memory overhead, notably for small messages, as required to adequately protect resource-constrained devices with stringent security and latency requirements.
Eric Wagner 0003, Martin Serror, Klaus Wehrle, Martin Henze
WISEC2
2021 DEMONS: Extended Manufacturer Usage Description to Restrain Malicious Smartphone Apps
abstract
The growing popularity of the consumer IoT intensifies the risks for security and privacy breaches. It typically suffices to successfully attack a single IoT device to access the home network illicitly. This observation emphasizes the need for in-network security, complementing each device’s security mechanisms with additional network-layer protection. Recently, the IETF proposed Manufacturer Usage Description (MUD) to limit network traffic of IoT devices to their required minimum. However, the tangled communication of IoT devices, e.g., connections to smartphones and smart speakers, is not covered by MUD. We propose Distributed Enforcement of MUD on Smartphones (DEMONS), extending central enforcement of MUD with distributed enforcement at authenticated smartphones to mitigate the threats of malicious apps and IoT devices by filtering malicious traffic close to its origin and preventing further spread. We discuss the security gains and demonstrate that the introduced overhead regarding latency, bandwidth, and power consumption has a negligible performance impact.
Ina Berenice Fink, Martin Serror, Klaus Wehrle
LCN2
2021 Challenges and Opportunities in Securing the Industrial Internet of Things
abstract
Given the tremendous success of the Internet of Things in interconnecting consumer devices, we observe a natural trend to likewise interconnect devices in industrial settings, referred to as industrial Internet of Things or Industry 4.0. While this coupling of industrial components provides many benefits, it also introduces serious security challenges. Although sharing many similarities with the consumer Internet of Things, securing the industrial Internet of Things introduces its own challenges but also opportunities, mainly resulting from a longer lifetime of components and a larger scale of networks. In this article, we identify the unique security goals and challenges of the industrial Internet of Things, which, unlike consumer deployments, mainly follow from safety and productivity requirements. To address these security goals and challenges, we provide a comprehensive survey of research efforts to secure the industrial Internet of Things, discuss their applicability, and analyze their security benefits.
Martin Serror, Sacha Hack, Martin Henze, Marko Schuba, Klaus Wehrle
IEEE Trans. Ind. Informatics1
2020 Extending MUD to Smartphones
abstract
The tremendous success of the IoT is overshadowed by severe security risks introduced by IoT devices and smartphone apps to control them. Therefore, academia and industry increasingly acknowledge the use of in-network security approaches, such as IETF Manufacturer Usage Description (MUD), to restrict undesired communication. However, actual communication patterns of smart homes are not sufficiently covered by such policy-based approaches. In this paper, we propose to enforce MUD on authenticated smartphones to efficiently filter malicious traffic close to its origin and hinder further spreading. Such enforcement allows us to successfully mitigate the threat of malicious apps and IoT devices in smart home networks.
Ina Berenice Fink, Martin Serror, Klaus Wehrle
LCN2
2020 QWIN: Facilitating QoS in Wireless Industrial Networks Through Cooperation
Martin Serror, Eric Wagner 0003, René Glebke, Klaus Wehrle
Networking1
2020 Improving MAC Protocols for Wireless Industrial Networks via Packet Prioritization and Cooperation
abstract
Stations in Cyber-Physical Systems (CPSs) and especially Industrial Internet of Things applications often work towards a common goal, but not all their tasks may be equally important to reach this goal. Hence, stations need to prioritize traffic because network resources are limited. To increase the service quality by utilizing otherwise unused network resources, stations may also opt to use cooperation instead of contention. Many existing standards and academic approaches focus on implementing either cooperation or Quality of Service (QoS) mechanisms. In this paper, we evaluate how to leverage cooperation to improve QoS. Since stations in wireless industrial applications often communicate locally, we focus on the MAC layer. We identify a set of useful cooperation mechanisms that increase the packet delivery ratio, and then extend them by several packet prioritization strategies and evaluate in multiple simulated industrial scenarios. As a result, we provide a set of guidelines for protocol designers to combine different mechanisms depending on the requirements imposed by industrial applications. Moreover, we provide and evaluate an exemplary combination of mechanisms derived from our results aiming at high reliability and low latency.
Jörg Christian Kirchhof, Martin Serror, René Glebke, Klaus Wehrle
WoWMoM2
2018 Towards In-Network Security for Smart Homes
abstract
The proliferation of the Internet of Things (IoT) in the context of smart homes entails new security risks threatening the privacy and safety of end users. In this paper, we explore the design space of in-network security for smart home networks, which automatically complements existing security mechanisms with a rule-based approach, i. e., every IoT device provides a specification of the required communication to fulfill the desired services. In our approach, the home router as the central network component then enforces these communication rules with traffic filtering and anomaly detection to dynamically react to threats. We show that in-network security can be easily integrated into smart home networks based on existing approaches and thus provides additional protection for heterogeneous IoT devices and protocols. Furthermore, in-network security relieves users of difficult home network configurations, since it automatically adapts to the connected devices and services.
Martin Serror, Martin Henze, Sacha Hack, Marko Schuba, Klaus Wehrle
ARES1
2018 Secure Low Latency Communication for Constrained Industrial IoT Scenarios
abstract
The emerging Internet of Things (IoT) promises value-added services for private and business applications. However, especially the industrial IoT often faces tough communication latency boundaries, e.g., to react to production errors, realize human-robot interaction, or counter fluctuations in smart grids. Simultaneously, devices must apply security measures such as encryption and integrity protection to guard business secrets and prevent sabotage. As security processing requires significant time, the goals of secure communication and low latency contradict each other. Especially on constrained IoT devices, which are equipped with cheap, low-power processors, the overhead for security processing aggregates to a primary source of latency. We show that antedated encryption and data authentication with templates enables IoT devices to meet both, security and low latency requirements. These mechanisms offload significant security processing to a preprocessing phase and thus decrease latency during actual transmission by up to 75.9 %. Thereby they work for well-established security-proven standard ciphers.
Jens Hiller, Martin Henze, Martin Serror, Eric Wagner 0003, Jan Niklas Richter, Klaus Wehrle
LCN3
2018 Practical Evaluation of Cooperative Communication for Ultra-Reliability and Low-Latency
abstract
Existing wireless communication systems are not able to meet the stringent requirements for critical machine-to-machine communications regarding ultra-reliability and low-latency. Since increasing the communication reliability often comes at the price of increasing the latency as well, new mechanisms must be proposed that consider both challenges together. A promising approach, according to analytical work, is to increase the reliability by using cooperative diversity, where all stations within range help each other in the transmission process. Theoretical analyses, however, only provide a limited insight regarding the actual performance due to the strong assumptions they make to model such complex systems. In this paper, we thus evaluate the practical feasibility of ultra-reliable low-latency communication through cooperation by designing a data link protocol that incorporates a best relay selection mechanism. We implement our protocol in a real-world testbed, consisting of software-defined radios, to gain a better understanding of how future ultra-reliable low-latency systems should be designed and implemented. Our measurement campaigns show that at a given low target latency of 1 ms, we achieve a packet error rate between 10−5 and 10−7 with a standard 802.11a physical layer.
Martin Serror, Sebastian Vaaben, Klaus Wehrle, James Gross
WOWMOM1
2017 Code-transparent Discrete Event Simulation for Time-accurate Wireless Prototyping
abstract
Exhaustive testing of wireless communication protocols on prototypical hardware is costly and time-consuming. An alternative approach is network simulation, which, however, often strongly abstracts from the actual hardware. Especially in the wireless domain, such abstractions often lead to inaccurate simulation results. Therefore, we propose a code-transparent discrete event simulator that enables a direct simulation of existing code for wireless prototypes. With a focus on lower layers of the communication stack, we enable a parametrization of the simulation timings based on real-world measurements to increase the simulation accuracy. Our evaluation shows that we achieve close results for throughput (deviation below 3% for UDP and latency (corrected deviation about 13% compared to real-world setups, while providing the benefits of code-transparent simulation, i.e., to flexibly simulate large topologies with existing prototype code. Moreover, we demonstrate that our approach finds implementation defects in existing hardware prototype software, which are otherwise difficult to track down in real deployments.
Martin Serror, Jörg Christian Kirchhof, Mirko Stoffers, Klaus Wehrle, James Gross
SIGSIM-PADS1
2016 Performance analysis of cooperative ARQ systems for wireless industrial networks
abstract
The proliferation of wireless communications has lead to a high interest to establish this technology in industrial settings. The main arguments in favor of wireless are reduced costs in deployment and maintenance, as well as increased flexibility. In contrast to home and office environments, industrial settings include mission-critical machine-to-machine applications, demanding stringent requirements for reliability and latency in the area of 1–10−9 PDR and 1ms, respectively. One way to achieve both is cooperative Automatic Repeat reQuest (ARQ), which leverages spatial diversity. This paper presents a wireless multi-user Time Division Multiple Access system with cooperative ARQ for mission-critical communication. We evaluate two design options analytically, using an outage-capacity model, to investigate whether the relaying of messages should be performed centrally at a multi-antenna AP with perfect Channel State Information (CSI) or decentrally at simultaneously transmitting stations with average CSI. Results indicate that both options are able to achieve the targeted communication guarantees when a certain degree of diversity is implemented, showing a stable system performance even with an increasing number of stations.
Martin Serror, Yulin Hu, Christian Dombrowski, Klaus Wehrle, James Gross
WoWMoM1
2015 Collaborative On-demand Wi-Fi sharing
abstract
While users can ubiquitously access the Internet via their Wi-Fi network or their mobile carrier network, access to foreign private Wi-Fi networks is mostly prohibited. This is because private APs have no means of authenticating foreign mobile users prior to granting access to their network, entailing severe security and liability risks. However, such Wi-Fi roaming would make the vast network resources of private users available on a collaborative basis. We propose Collaborative On-demand Wi-Fi Sharing (COWS), offering 802.1×-equivalent authentication of foreign users at private APs without the need for elaborate, hierarchical authentication infrastructures. COWS embeds authentication credentials into 802.11 association requests, enabling APs to establish 802.11 AP networks exclusively on-demand and after an authentication of the mobile user at her home network provider. Our evaluation using Android smartphones and various authentication provider instances shows the real-life applicability of COWS, enabling lightweight, collaborative Wi-Fi roaming at the APs of private users.
Hanno Wirtz, Torsten Zimmermann, Martin Serror, Klaus Wehrle
LCN3
2015 Enabling ubiquitous interaction with smart things
abstract
Within the Internet of Things (IoT), Smart Things (STs) promise to permeate all contexts of daily life, offering digital access to their physical functionality. Mobile users then would be able to ubiquitously and spontaneously interact with things they encounter, enabling a wealth of diverse usage scenarios and applications. Currently, however, ST interaction requires a pre-controlled Internet or network connection as well as the prior installation of the ST-specific interaction interface, i.e., smartphone app. Users can thus only interact with known things, in contrast to the vision of spontaneous, ubiquitous discovery and interaction. We thus propose STIF (Smart Things Interaction Framework), enabling local wireless discovery of STs spontaneously via Wi-Fi, Bluetooth Low Energy, Visible Light Communication, or Acoustic Communication. STIF allows STs to transmit their interaction interface directly to users and supports interaction based on user input via touch and AR GUIs as well as motion and speech recognition. We implement STIF for Android phones as well as Arduino and Raspberry Pi things and demonstrate the real-life applicability of the supported communication and interaction techniques.
Hanno Wirtz, Jan Rüth, Martin Serror, Torsten Zimmermann, Klaus Wehrle
SECON3
2015 WARPsim: A code-transparent network simulator for WARP devices
abstract
Analyzing a communication protocol by means of simulation and real-world experimentation requires careful protocol implementation in both domains. Differences in the implementation may lead to significantly diverging performance results, which may affect the protocol design process adversely. A code-transparent simulation and experimentation framework for Wireless Access Research Platform (WARP) devices is proposed, which is called WARPsim. By extending the simulation engine appropriately, the same application code that runs on WARP devices can be used for simulation. This work studies the implications of this approach using the example of implementing time-critical Medium Access Control Layer (MAC) protocols on WARP devices. In the demonstration, various MAC protocols will be simulated using WARPsim, while changing protocol parameters, but also crucial aspects of the emulated hardware. A graphical representation integrated into the framework allows for an intuitive examination of the protocol behavior.
Andreas Schumacher, Martin Serror, Christian Dombrowski, James Gross
WOWMOM2
2012 DHT-based localized service discovery in wireless mesh networks
abstract
Wireless mesh networks (WMNs) provide high-bandwidth wireless network access to mobile clients in extensible, robust multi-hop networks. WMNs support distributed service provision and data storage, catering to the advanced capabilities of current mobile devices. Services and data discovery using undirected broadcast or multicast messages, as in traditional discovery protocols, significantly harms network performance due to interference and collisions. In contrast, distributed hash tables (DHTs) offer consistent mapping of service and data identifiers to the providing devices and therefore allow a directed unicast discovery and access. However, traditional DHTs place identifiers at arbitrary distant devices in the network, resulting in frequent use of long multi-hop routing paths. Such multi-hop transmissions suffer from performance loss at each hop and also degrade the overall network performance. We propose DLSD, a DHT-based localized index structure that establishes a hierarchy of locally bounded address spaces ranging from a few nearby devices to the whole network. Iterating through this hierarchy bottom-up allows devices to find the most local provider of the requested item, thereby minimizing multi-hop transmissions while ensuring global reachability. Through this reduction of routing hops, we maintain high transmission performance and minimize interference in the network. We evaluate the feasibility of our approach and show that it significantly reduces routing overhead and outperforms traditional service discovery and DHT approaches.
Hanno Wirtz, Tobias Heer, Martin Serror, Klaus Wehrle
MASS3