Bernhard Garn

dblp:149/4315 · DBLP profile ↗
← Back
12ranked-venue papers
5as first author
5since 2021 · last 2023
0000-0001-6084-211XORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 8 · 3 first-author · 4 since 2021Artificial intelligence and machine learning · 2 · 1 first-authorSecurity and privacy · 1 · 1 first-author · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 first-authorHuman-computer interaction and ubiquitous computing · 1Theory of computation · 1
YearPublicationVenuePosition
2023 Applying Pairwise Combinatorial Testing to Large Language Model Testing
Bernhard Garn, Ludwig Kampel, Manuel Leithner, Berina Celic, Ceren Çulha, Irene Hiess, Klaus Kieseberg, Marlene Koelbing, Dominik-Philip Schreiber, Michael Wagner 0026, Christoph Wech, Jovan Zivanovic, Dimitris E. Simos
ICTSS1
2022 A Two-Step TLS-Based Browser fingerprinting approach using combinatorial sequences
Bernhard Garn, Stefan Zauner, Dimitris E. Simos, Manuel Leithner, D. Richard Kuhn, Raghu Kacker
Comput. Secur.1
2022 Combinatorial methods for testing Internet of Things smart home systems
abstract
Summary In this paper, we report on applying combinatorial testing to Internet of Things (IoT) home automation hub systems. We detail how to create a dedicated input parameter model of an IoT home automation hub system for use with combinatorial test case generation strategies. Further, we developed an automated test execution framework and two test oracles for evaluation purposes. We applied and evaluated our proposed methodological approach to a real‐world IoT system and analysed the obtained results of various combinatorial test sets with different properties generated based on the derived input model. Additionally, we compare these results to a random testing approach. Our empirical testing evaluations revealed multiple errors in the tested devices and also showed that all considered approaches performed nearly equally well.
Bernhard Garn, Dominik-Philip Schreiber, Dimitris E. Simos, D. Richard Kuhn, Jeffrey M. Voas, Raghu Kacker
Softw. Test. Verification Reliab.1
2022 Combinatorial methods for dynamic gray-box SQL injection testing
abstract
Summary This work presents an extended and enhanced gray‐box combinatorial security testing methodology for SQL injection vulnerabilities in web applications. We propose multiple new attack grammars modelling SQLi attacks against MySQL‐compatible databases, each one targeting a different injection context. Additionally, these grammars are also dynamically refined at the beginning of each attack against an endpoint of a web application, as a further optimization of the used attack model by taking into account the specifics of the generated query of that endpoint. Our goal is to enhance existing combinatorial approaches for detecting SQL injection vulnerabilities. The newly developed methodology is implemented in a prototype security testing tool called SQLInjector+, which is an extension of an earlier prototype developed by us in prior work. This improved tool can attack (i.e. test) any web application that uses a MySQL‐compatible database management system. We evaluate our revised approach and improved prototype tool in a case study comprising of different kinds of web applications to which SQLi is a potential security threat. The case study contains the well‐known verification framework WAVSEP among other five real‐world web applications and one web application firewall. Our generated attack vectors, constructed via combinatorial methods applied to our improved and dynamically optimized attack grammars, are capable of injecting every known vulnerable endpoint in WAVSEP and also of finding new vulnerable parameters in some of the real‐world applications investigated in this paper. Our approach performs equally well or better when compared with existing state‐of‐art of SQL injection security testing tools (sqlmap, w3af, wapiti and fuzzdb) across all tested web applications in the case study.
Bernhard Garn, Jovan Zivanovic, Manuel Leithner, Dimitris E. Simos
Softw. Test. Verification Reliab.1
2021 HYDRA: Feedback-driven black-box exploitation of injection vulnerabilities
Manuel Leithner, Bernhard Garn, Dimitris E. Simos
Inf. Softw. Technol.2
2019 Knowledge Extraction for Cryptographic Algorithm Validation Test Vectors by Means of Combinatorial Coverage Measurement
Dimitris E. Simos, Bernhard Garn, Ludwig Kampel, D. Richard Kuhn, Raghu Kacker
CD-MAKE2
2019 A Fault-Driven Combinatorial Process for Model Evolution in XSS Vulnerability Detection
Bernhard Garn, Marco Radavelli, Angelo Gargantini, Manuel Leithner, Dimitris E. Simos
IEA/AIE1
2019 Testing TLS using planning-based combinatorial methods and execution framework
Dimitris E. Simos, Josip Bozic, Bernhard Garn, Manuel Leithner, Feng Duan 0002, Kristoffer Kleine, Yu Lei 0001, Franz Wotawa
Softw. Qual. J.3
2019 Problems and algorithms for covering arrays via set covers
Ludwig Kampel, Manuel Leithner, Bernhard Garn, Dimitris E. Simos
Theor. Comput. Sci.3
2017 Testing TLS Using Combinatorial Methods and Execution Framework
Dimitris E. Simos, Josip Bozic, Feng Duan 0002, Bernhard Garn, Kristoffer Kleine, Yu Lei 0001, Franz Wotawa
ICTSS4
2016 A Combinatorial Approach to Analyzing Cross-Site Scripting (XSS) Vulnerabilities in Web Application Security Testing
Dimitris E. Simos, Kristoffer Kleine, Laleh Shikh Gholamhossein Ghandehari, Bernhard Garn, Yu Lei 0001
ICTSS4
2015 Attack Pattern-Based Combinatorial Testing with Constraints for Web Security Testing
abstract
Security testing of web applications remains a major problem of software engineering. In order to reveal vulnerabilities, manual and automatic testing approaches use different strategies for detection of certain kinds of inputs that might lead to a security breach. In this paper we compared a state-of-the-art manual testing tool with an automated one that is based on model-based testing. The first tool requires user input from the tester whereas the second one reduces the necessary amount of manual manipulation. Both approaches depend on the corresponding test case generation technique and its produced inputs are executed against the system under test (SUT). For this case we enhance a novel technique, which combines a combinatorial testing technique for input generation and a model-based technique for test execution. In this work the input parameter modelling is improved by adding constraints to generate more comprehensive and sophisticated testing inputs. The evaluated results indicate that both techniques succeed in detecting security leaks in web applications with different results, depending on the background logic of the testing approach. Last but not least, we claim that attack pattern-based combinatorial testing with constraints can be an alternative method for web application security testing, especially when we compare our method to other test generation techniques like fuzz testing.
Josip Bozic, Bernhard Garn, Ioannis Kapsalis, Dimitris E. Simos, Severin Winkler, Franz Wotawa
QRS2