VLDB 2026 Research / reviewers in the wild / expert
Katharina Kohls
dblp:155/5132 · also Katharina Siobhan Kohls
· DBLP profile ↗
19ranked-venue papers
6as first author
6since 2021 · last 2023
0000-0002-5656-7116ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 17 · 6 first-author · 6 since 2021Computer networks · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2023 | Hope of Delivery: Extracting User Locations From Mobile Instant Messengers
Theodor Schnitzler, Katharina Kohls, Evangelos Bitsikas, Christina Pöpper |
NDSS | 2 |
| 2023 | BigMac: Performance Overhead of User Plane Integrity Protection in 5G Networksabstract5G introduces a series of new security features that overcome known issues of the previous mobile generations. One of these features is integrity protection for user plane data. While this addition protects against manipulations like DNS spoofing, it also introduces extra overhead to user plane traffic. As it is optional to enable, this additional overhead can be the decision point for network operators to avoid the additional security feature. In this work, we investigate the overhead induced by different integrity protection algorithms and test the burden they add to the workload of a device. Our results indicate how visible performance differences would be on the end-devices of users, and how the performance of the algorithms differs in isolation. With these results we aim to initiate a discussion regarding the benefits of enabling user plane integrity protection and to overcome misconceptions regarding the performance impairments for end users. Thijs Heijligenberg, Guido Knips, Christian Böhm 0003, David Rupprecht, Katharina Kohls |
WISEC | 5 |
| 2023 | Never Let Me Down Again: Bidding-Down Attacks and Mitigations in 5G and 4GabstractBidding-down attacks reduce the security of a mobile network connection. Weaker encryption algorithms or even downgrades to prior network generations enable an adversary to exploit numerous attack vectors and harm the users of a network. The problem of bidding-down attacks has been known for generations, and various mitigations are integrated into the latest 4G and 5G specifications. However, current research lacks a systematic identification and analysis of the variety of potential attack vectors. In this work, we classify an extensive set of bidding-down attack vectors and mitigations and analyze their specification and implementation in phones and networks. Our results demonstrate vulnerabilities for all attacks and devices, including the latest mobile generation 5G and recent flagship phones. To further prove how the identified attack vectors can be exploited in sophisticated attacks, we conduct two case studies in which we apply a full downgrade attack from 5G SA to 2G and bid down a 5G NSA connection by enforcing null encryption. Again, we find a majority of systems vulnerable. With this paper, we hope to improve the state of bidding-down mitigations in the specification and implementation. Bedran Karakoc, Nils Fürste, David Rupprecht, Katharina Kohls |
WISEC | 4 |
| 2022 | VerLoc: Verifiable Localization in Decentralized Systems
Katharina Kohls, Claudia Díaz |
USENIX Security Symposium | 1 |
| 2022 | Trace Oddity: Methodologies for Data-Driven Traffic Analysis on TorabstractTraffic analysis attacks against encrypted web traffic are a persisting problem. However, there is a large gap between the scientific estimate of attack threats and the real-world situation. As traffic analysis attacks depend on very specific metadata information, they are sensitive to artificial changes in the transmission characteristics. While the advent of deep learning greatly improves the performance rates of traffic analysis attacks on Tor in research settings, deep neural networks are known for being implicitly vulnerable to artifacts in data. Removing artifacts from our experimental setups is essential to minimizing the risk of evaluation bias. In this work, we study a state-of-the-art end-to-end traffic correlation attack on Tor and propose a novel data collection setup. Our design addresses the key constraint of prior work: instead of using a single proxy node for collecting exit traffic, we deploy multiple proxies. Our extensive analysis shows that in the multi-proxy design (i) end-to-end round-trip times are more realistic than in the original design, and that (ii) traffic correlation attack performance degrades significantly on realistic timings. For a reliable and informative evaluation, we develop a general scientific methodology for replication and comparison of machine and deep-learning attacks on Tor. Our evaluation indicates high relevance of the multi-proxy data collection setup and the novel dataset. Vera Rimmer, Theodor Schnitzler, Tom van Goethem, Abel Rodríguez Romero, Wouter Joosen, Katharina Kohls |
Proc. Priv. Enhancing Technol. | 6 |
| 2021 | We Built This Circuit: Exploring Threat Vectors in Circuit Establishment in TorabstractTraffic analysis attacks against the Tor network are a persisting threat to the anonymity of its users. The technical capabilities of attacks against encrypted Internet traffic have come a long way. Although the current state-of-the-art predicts high precision and accuracy for website fingerprinting and end-to-end confirmation, the concepts of these attacks often solely focus on their technical capabilities and ignore the operational requirements that are mandatory to get access to transmissions. In this work, we introduce three novel stepping-stone attacks that enable an adversary to (i) gain additional information about monitored connections, (ii) manipulate the Tor connection build-up, and (iii) conduct a targeted Denial-of-Service attack within the Tor infrastructure. All attacks exploit core defensive features of Tor and, consequently, are hard to patch. At the same time, our attacks are in line with standard attacker models for traffic analysis attacks. We demonstrate the feasibility of all three attacks in simulations and empirical case studies and emphasize their pivotal role in preparing a realistic setting for end-to-end confirmation attacks. Theodor Schnitzler, Christina Pöpper, Markus Dürmuth, Katharina Kohls |
EuroS&P | 4 |
| 2020 | Censored Planet: An Internet-wide, Longitudinal Censorship ObservatoryabstractRemote censorship measurement techniques offer capabilities for monitoring Internet reachability around the world. However, operating these techniques continuously is labor-intensive and requires specialized knowledge and synchronization, leading to limited adoption. In this paper, we introduce Censored Planet, an online censorship measurement platform that collects and analyzes measurements from ongoing deployments of four remote measurement techniques (Augur, Satellite/Iris, Quack, and Hyperquack). Censored Planet adopts a modular design that supports synchronized baseline measurements on six Internet protocols as well as customized measurements that target specific countries and websites. Censored Planet has already collected and published more than 21.8 billion data points of longitudinal network observations over 20 months of operation. Censored Planet complements existing censorship measurement platforms such as OONI and ICLab by offering increased scale, coverage, and continuity. We introduce a new representative censorship metric and show how time series analysis can be applied to Censored Planet's longitudinal measurements to detect 15 prominent censorship events, two-thirds of which have not been reported previously. Using trend analysis, we find increasing censorship activity in more than 100 countries, and we identify 11 categories of websites facing increasing censorship, including provocative attire, human rights issues, and news media. We hope that the continued publication of Censored Planet data helps counter the proliferation of growing restrictions to online freedom. Ram Sundara Raman, Prerana Shenoy, Katharina Kohls, Roya Ensafi |
CCS | 3 |
| 2020 | IMP4GT: IMPersonation Attacks in 4G NeTworks
David Rupprecht, Katharina Kohls, Thorsten Holz, Christina Pöpper |
NDSS | 2 |
| 2020 | Call Me Maybe: Eavesdropping Encrypted LTE Calls With ReVoLTE
David Rupprecht, Katharina Kohls, Thorsten Holz, Christina Pöpper |
USENIX Security Symposium | 2 |
| 2019 | On the Challenges of Geographical Avoidance for Tor
Katharina Kohls, Kai Jansen, David Rupprecht, Thorsten Holz, Christina Pöpper |
NDSS | 1 |
| 2019 | Adversarial Attacks Against Automatic Speech Recognition Systems via Psychoacoustic Hiding
Lea Schönherr, Katharina Kohls, Steffen Zeiler, Thorsten Holz, Dorothea Kolossa |
NDSS | 2 |
| 2019 | Breaking LTE on Layer TwoabstractLong Term Evolution (LTE) is the latest mobile communication standard and has a pivotal role in our information society: LTE combines performance goals with modern security mechanisms and serves casual use cases as well as critical infrastructure and public safety communications. Both scenarios are demanding towards a resilient and secure specification and implementation of LTE, as outages and open attack vectors potentially lead to severe risks. Previous work on LTE protocol security identified crucial attack vectors for both the physical (layer one) and network (layer three) layers. Data link layer (layer two) protocols, however, remain a blind spot in existing LTE security research. In this paper, we present a comprehensive layer two security analysis and identify three attack vectors. These attacks impair the confidentiality and/or privacy of LTE communication. More specifically, we first present a passive identity mapping attack that matches volatile radio identities to longer lasting network identities, enabling us to identify users within a cell and serving as a stepping stone for follow-up attacks. Second, we demonstrate how a passive attacker can abuse the resource allocation as a side channel to perform website fingerprinting that enables the attacker to learn the websites a user accessed. Finally, we present the A LTE R attack that exploits the fact that LTE user data is encrypted in counter mode (AES-CTR) but not integrity protected, which allows us to modify the message payload. As a proof-of-concept demonstration, we show how an active attacker can redirect DNS requests and then perform a DNS spoofing attack. As a result, the user is redirected to a malicious website. Our experimental analysis demonstrates the real-world applicability of all three attacks and emphasizes the threat of open attack vectors on LTE layer two protocols. David Rupprecht, Katharina Kohls, Thorsten Holz, Christina Pöpper |
IEEE Symposium on Security and Privacy | 2 |
| 2019 | Lost traffic encryption: fingerprinting LTE/4G traffic on layer twoabstractLong Term Evolution (LTE) provides the communication infrastructure for both professional and private use cases and has become an integral part of our everyday life. Even though LTE/4G overcomes many security issues of previous standards, recent work demonstrates several attack vectors on the physical and network layers of the LTE stack. We do, however, have only limited insights into the security and privacy aspects of the second layer. Katharina Kohls, David Rupprecht, Thorsten Holz, Christina Pöpper |
WiSec | 1 |
| 2018 | DigesTor: Comparing Passive Traffic Analysis Attacks on Tor
Katharina Kohls, Christina Pöpper |
ESORICS (1) | 1 |
| 2017 | Traffic Analysis Attacks in Anonymity NetworksabstractWith more than 1.7 million daily users, Tor is a large-scale anonymity network that helps people to protect their identities in the Internet. Tor provides low-latency transmissions that can serve a wide range of applications including web browsing, which renders it an easily accessible tool for a large user base. Unfortunately, its wide adoption makes Tor a valuable target for de-anonymization attacks. Recent work proved that powerful traffic analysis attacks exist which enable an adversary to relate traffic streams in the network and identify users and accessed contents. One open research question in the field of anonymity networks therefore addresses efficient countermeasures to the class of traffic analysis attacks. Defensive techniques must improve the security features of existing networks while still providing an acceptable performance that can maintain the wide acceptance of a system. The proposed work presents an analysis of mixing strategies as a countermeasure to traffic analysis attacks in Tor. First simulation results indicate the security gains and performance impairments of three main mixing strategies. Katharina Kohls, Christina Pöpper |
AsiaCCS | 1 |
| 2016 | SkypeLine: Robust Hidden Data Transmission for VoIPabstractInternet censorship is used in many parts of the world to prohibit free access to online information. Different techniques such as IP address or URL blocking, DNS hijacking, or deep packet inspection are used to block access to specific content on the Internet. In response, several censorship circumvention systems were proposed that attempt to bypass existing filters. Especially systems that hide the communication in different types of cover protocols attracted a lot of attention. However, recent research results suggest that this kind of covert traffic can be easily detected by censors. In this paper, we present SkypeLine, a censorship circumvention system that leverages Direct-Sequence Spread Spectrum (DSSS) based steganography to hide information in Voice-over-IP (VoIP) communication. SkypeLine introduces two novel modulation techniques that hide data by modulating information bits on the voice carrier signal using pseudo-random, orthogonal noise sequences and repeating the spreading operation several times. Our design goals focus on undetectability in presence of a strong adversary and improved data rates. As a result, the hiding is inconspicuous, does not alter the statistical characteristics of the carrier signal, and is robust against alterations of the transmitted packets. We demonstrate the performance of SkypeLine based on two simulation studies that cover the theoretical performance and robustness. Our measurements demonstrate that the data rates achieved with our techniques substantially exceed existing DSSS approaches. Furthermore, we prove the real-world applicability of the presented system with an exemplary prototype for Skype. Katharina Kohls, Thorsten Holz, Dorothea Kolossa, Christina Pöpper |
AsiaCCS | 1 |
| 2016 | Neuralyzer: Flexible Expiration Times for the Revocation of Online DataabstractOnce data is released to the Internet, there is little hope to successfully delete it, as it may have been duplicated, reposted, and archived in multiple places. This poses a significant threat to users' privacy and their right to permanently erase their very own data. One approach to control the implications on privacy is to assign a lifetime value to the published data and ensure that the data is no longer accessible after this point in time. However, such an approach suffers from the inability to successfully predict the right time when the data should vanish. Consequently, the author of the data can only estimate the correct time, which unfortunately can cause the premature or belated deletion of data. Apostolis Zarras, Katharina Kohls, Markus Dürmuth, Christina Pöpper |
CODASPY | 2 |
| 2014 | Distributed Flow Permission Inspection for Mission-Critical Communication of Untrusted Autonomous VehiclesabstractSwarms of Unmanned Aerial Vehicles (UAVs) and Unmanned Ground Vehicles (UGVs) are used for cooperative sensing, clarification and communication relaying in disaster situations and, thereby, allow to reduce jeopardizing the health of rescue personnel. Having meshed interconnection, a swarm maintains a communication network dedicated for applications with context-dependent performance requirements that require reliable traffic classification and conditioning. Nevertheless, these systems are vulnerable because UAVs/UGVs may act incorrectly resulting in an erroneous network behavior which may affect the performance of mission-critical flows. This is a major problem if a couple of untrusted UAVs and UGVs from different rescue organizations are connected. In this paper, the reliability of traffic conditioning within untrusted swarms is enhanced by the Distributed Flow Permission Inspection (DiFPIN) scheme. DiFPIN is used to verify the flow classification to circumvent the usage of erroneous entities on the transmission path. Thereby, the negative impairment of mission-critical flows can be reduced. Patrick-Benjamin Bök, Katharina Kohls, Daniel Behnke, Christian Wietfeld |
VTC Fall | 2 |
| 2012 | Improving the Distributed Fair Congestion Avoidance Protocol for Home Area Networks with Internet Access LinksabstractIf network congestion occurs, packets cannot be delivered timely, the data rate decreases significantly and the required level of QoS cannot be achieved for all nodes. Especially in Home Area Networks (HANs) with limited uplink bandwidth for internet access, congestion is a major problem. Different approaches for congestion aware link sharing and QoS provisioning exist. Also the Distributed Fair Congestion Avoidance Protocol has been proposed for this purpose, but has to be modified to work efficient in HANs. In this paper, we present an enhanced version of the former proposed DiFCAP protocol which works proactive and independent of the congestion handling capabilities of Transport Layer protocols. Patrick-Benjamin Bök, Katharina Kohls, Stephanie Dünhaupt, York Tüchelmann |
ICCCN | 2 |