VLDB 2026 Research / reviewers in the wild / expert
Daniel Spiekermann
dblp:167/5566
· DBLP profile ↗
9ranked-venue papers
6as first author
5since 2021 · last 2025
0000-0003-4762-6062ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 5 · 3 first-author · 2 since 2021Computer networks · 2 · 1 first-author · 2 since 2021Software engineering, systems software and programming languages · 2 · 2 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Protocol Design Rules from Hiding Patterns to Avoid Steganographic Channels in Wireless CommunicationabstractCovert channels for the transmission of stegano-graphic messages are not only possible in classic internet protocols but also in wireless communications such as 4G and 5G air interface. Hiding patterns collect the central ideas behind these channels. We therefore derive rules for protocol design, conformance to which disables at least the most frequently used covert channel approaches. Starting from 5G, we investigate where 6G standardization might take such rules into account to better protect 6G protocols against covert channels from the beginning, Jörg Keller 0001, Daniel Spiekermann, Markus Walter |
WCNC | 2 |
| 2024 | Manipulating the Swap Memory for Forensic InvestigationabstractSwap memory plays a critical role in modern operating systems’ memory management. This paper explores the potential for manipulating swap memory to alter memory content at runtime and thereby control the behaviour of the target system. While conventional memory security techniques typically focus on preventing runtime manipulation of memory pages, they often overlook the moment when pages are swapped and later reloaded into memory. Therefore, we investigate the feasibility of manipulating swap memory and describe the necessary steps of extracting involved memory areas as well as techniques to force swapping of relevant processes. We verify this theoretical concept with a prototype implementing a manipulation of memory of a given program. Maximilian Olbort, Daniel Spiekermann, Jörg Keller 0001 |
ARES | 2 |
| 2023 | Network Covert Channels in Routing ProtocolsabstractComputer networks play a key role in everyday lives. To guarantee fail-safe operation, routing protocols are used that enable dynamic routing via redundant paths. Because of this, routing protocols like RIP or OSPF play an important role in modern network infrastructures. The widespread use together with the mostly missing traffic monitoring of these protocols provide a possible base to exploit these protocols for network steganographic channels. In this paper, we present a novel storage covert channel based on the OSPF routing protocol. We analyzed the protocol in detail with the help of hiding patterns to identify protocol fields that might be suitable for covert communication. We provide a proof-of-concept implementation of our covert channel inside a simulated network, which demonstrates the possibility of covert communication in a routing protocol. Our evaluation covers detectability and countermeasures, steganographic bandwidth and robustness. Furthermore, we sketch an application scenario where such a covert channel can be deployed. Michael Schneider 0013, Daniel Spiekermann, Jörg Keller 0001 |
ARES | 2 |
| 2021 | Encapcap: Transforming Network Traces to Virtual NetworksabstractValid and complete network captures are a valuable source when detecting network based attacks and adversarial data exfiltration techniques like covert channels or performing network forensic investigation Also in training, testing, benchmarking and algorithm development, the availability of prerecorded, entire packet captures is eminent. Such a packet capture contains the entire packet stream with all incoming and outgoing network packets recorded over a defined period of time. Whereas a large number of recorded packet captures with well-known protocols from physical networks exists, the number of available files focused on virtual networks is low. Yet, virtual networks are taking on an ever greater role in modern environments. The creation of such network traces is a time-consuming and error-prone task, and the inherent behaviour of virtual networks eradicates a straight-forward automation of trace generation in comparison to common networks. In this paper we analyze relevant conditions of modern networks which hamper the generation of valid test captures and propose Encapcap, a tool that transforms given network packets stored in a capture file to virtual network packets. This improves the process of generating real-life packet captures for testing or training in virtual networks. We evaluate Encapcap with several experiments to demonstrate its correctness, usefulness and applicability. Daniel Spiekermann, Jörg Keller 0001 |
NetSoft | 1 |
| 2021 | Unsupervised packet-based anomaly detection in virtual networksabstractThe enormous number of network packets transferred in modern networks together with the high speed of transmissions hamper the implementation of successful IT security mechanisms. In addition, virtual networks create highly dynamic and flexible environments which differ widely from well-known infrastructures of the past decade. Network forensic investigation that aims at the detection of covert channels, malware usage or anomaly detection is faced with new problems and is thus a time-consuming, error-prone and complex process. Machine learning provides advanced techniques to perform this work faster, more precise and, simultaneously, with fewer errors. Depending on the learning technique, algorithms work nearly without any interaction to detect relevant events in the transferred network packets. Current algorithms work well in static environments, but the highly dynamic environments of virtual networks create additional events which might confuse anomaly detection algorithms. This paper analyzes highly flexible networks and their inherent on-demand changes like the migration of virtual machines, SDN-programmability or user customization and the resulting effect on the detection rate of anomalies in the environment. Our research shows the need for adapted pre-processing of the network data and improved cooperation between IT security and IT administration departments. Daniel Spiekermann, Jörg Keller 0001 |
Comput. Networks | 1 |
| 2020 | Impact of Virtual Networks on Anomaly Detection with Machine LearningabstractThe enormous number of network packets transferred in modern networks together with the high-speed transmissions hamper the implementation of successful IT security mechanisms. In addition to this, virtual networks create highly dynamic and flexible environments, which differ widely from well-known infrastructures of the past decade. Network forensic investigation aiming at the detection of covert channels, malware usage or anomaly detection is faced with new problems and gets a time-consuming, error-prone and complex process. Machine learning provides advanced techniques to perform this work faster with a lower error rate. Depending on the learning technique, algorithms work nearly without any necessary interaction to detect relevant events in the transferred network packets. Occurring changes are noticed and additional processes might be started. Current algorithms work well in static environments, but the highly-dynamic environments of virtual networks create additional events, which might irritate the anomaly detection algorithms. This paper analyses virtual network protocols like VXLAN, GRE and GENVE and their impact of the detection rate of anomalies in the environment. Our research shows the need for adapted pre-processing of the network data, in the worst case on demand if changes are detected. Daniel Spiekermann, Jörg Keller 0001 |
NetSoft | 1 |
| 2019 | A Study of Network Forensic Investigation in Docker EnvironmentsabstractCyber-criminals harness more and more techniques like virtual machines or container-based infrastructures for their malicious activities. The inherent dynamic of these virtual environments simplifies the fast creation of vicious services and hide the involved systems like no other technology before. The primary use of virtualisation and especially containers facilitates software developers and administrators to create new applications, perform tests, debug their code and install pre-defined services based on provided container images. Docker as the most notable container technique provides a great variety of existing container templates, which pave the way for implementing highly dynamic environments. As virtual machines, container-based environments are mostly a short-living on-demand infrastructure, which might be used by cyber-criminals to perform their malicious activities. Especially the virtual layer and the ephemeral nature of the container impede any kind of digital investigation or forensic analysis. In this paper we analyze different methods for network forensic investigation in Docker environments. The virtualisation demands for adapted techniques of packet capture like iptables-manipulation, accessing the internal network bridges or vNICs and the use of software-based techniques. We propose the use of further monitoring processes in Docker swarms to implement a valid packet capture and to collect all relevant network packets. As a result, we define appropriate techniques of packet captures based on parameters of the related container. Daniel Spiekermann, Tobias Eggendorfer, Jörg Keller 0001 |
ARES | 1 |
| 2017 | Towards Covert Channels in Cloud Environments: A Study of Implementations in Virtual Networks
Daniel Spiekermann, Jörg Keller 0001, Tobias Eggendorfer |
IWDW | 1 |
| 2016 | Towards Digital Investigation in Virtual Networks: A Study of Challenges and Open ProblemsabstractThe evolution of virtualization techniques is still changing operating principles in today's datacenters (DC). The virtualization of ordinary servers was just the first step, which increased the dynamic and flexibility of the DC. Providers are now able to offer different virtual machines (VM) faster and with less overhead to their customers. But this provision raises new problems for the providers. Aspects like isolation, security or multi-tenancy are increasingly relevant and demand new setups in the DC. Current network infrastructures are not able to handle these aspects with an acceptable effort, but the development of virtual networks offers new possibilities, with benefits for the provider and the user. Based on a physical underlay network, different virtual networks can be defined, either by a provider or the customer. Protocols like VXLAN or GENEVE appear to eliminate restrictions of current networks. New paradigms like Software-defined-Networks (SDN) or Network Function Virtualization (NFV) offer new capabilities to redesign the whole network infrastructure in the DC. But the need for digital investigation is still necessary regardless of all new paradigms and evolution. As a branch of digital investigation, network forensic investigation (NFI) is used to examine network traffic by capturing the data of a suspicious target system and analyzing this data. The modern virtual data centers and the implemented virtual networks impede the NFI, proved techniques and methods fail because of the increased complexity of the new logical networks. Not only the analysis of the new network protocols impede the NFI, even the the capture process of relevant data needs to be refined. In this paper, we analyze in detail new arising problems of digital investigation in virtual networks and explore the new challenges for NFI. Based on the discussion of network forensics and current utilized methodologies and the new techniques of network virtualization the arising problems are defined and classified in three categories. This classification helps to develop new methods and possible solutions, which might simplify further necessary investigations in cloud-computing environments. Daniel Spiekermann, Tobias Eggendorfer |
ARES | 1 |