VLDB 2026 Research / reviewers in the wild / expert
Leonard Bradatsch
dblp:170/1086
· DBLP profile ↗
6ranked-venue papers
4as first author
3since 2021 · last 2024
0000-0001-7120-6557ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 4 · 2 first-author · 1 since 2021Security and privacy · 2 · 2 first-author · 2 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | Attribute Threat Analysis and Risk Assessment for ABAC and TBAC Systems
Leonard Bradatsch, Artur Hermann, Frank Kargl |
SECRYPT | 1 |
| 2023 | Zero Trust Score-based Network-level Access Control in Enterprise NetworksabstractZero Trust security has recently gained attention in enterprise network security. One of its key ideas is making network-level access decisions based on trust scores. However, score-based access control in the enterprise domain still lacks essential elements in our understanding, and in this paper, we contribute with respect to three crucial aspects. First, we provide a comprehensive list of 29 trust attributes that can be used to calculate a trust score. By introducing a novel mathematical approach, we demonstrate how to quantify these attributes. Second, we describe a dynamic risk-based method to calculate the trust threshold the trust score must meet for permitted access. Third, we introduce a novel trust algorithm based on Subjective Logic that incorporates the first two contributions and offers fine-grained decision possibilities. We discuss how this algorithm shows a higher expressiveness compared to a lightweight additive trust algorithm. Performance-wise, a prototype of the Subjective Logic-based approach showed similar calculation times for making an access decision as the additive approach. In addition, the dynamic threshold calculation showed only 7% increased decision-making times compared to a static threshold. Leonard Bradatsch, Oleksandr Miroshkin, Natasa Trkulja, Frank Kargl |
TrustCom | 1 |
| 2022 | Secure Service Function Chaining in the Context of Zero Trust SecurityabstractService Function Chaining (SFC) enables dynamic steering of traffic through a set of service functions based on classification of packets, allowing network operators fine-grained and flexible control of packet flows. New paradigms like Zero Trust (ZT) pose additional requirements to the security of network architectures. This includes client authentication, confidentiality, and integrity throughout the whole network, while also being able to perform operations on the unencrypted payload of packets. However, these requirements are only partially addressed in existing SFC literature. Therefore, we first present a comprehensive analysis of the security requirements for SFC architectures. Based on this analysis, we propose a concept towards the fulfillment of the requirements while maintaining the flexibility of SFC. In addition, we provide and evaluate a proof of concept implementation, and discuss the implications of the design choices. Leonard Bradatsch, Marco Häberle, Benjamin Steinert, Frank Kargl, Michael Menth |
LCN | 1 |
| 2017 | A Testing Framework for High-Speed Network and Security DevicesabstractThere is an increasing availability of high throughput networks which leads to the need of security appliances in these networks. Testing these appliances with regards to performance and effectiveness relies on testing tools that can achieve or even surpass the capabilities of the devices and networks under test. However, current tools are not capable of achieving both the flexibility and performance demands of modern high-speed security equipment. We propose a concept and an architecture that can fulfil these demands and introduce the General Purpose Network Testing Framework (GPNTF) as a prototype implementation. This framework can achieve high throughput while being highly adaptable with regard to network testing scenarios. Leonard Bradatsch, Thomas Lukaseder, Frank Kargl |
LCN | 1 |
| 2016 | A Comparison of TCP Congestion Control Algorithms in 10G NetworksabstractThe increasing availability of 10G Ethernet network capabilities challenges existing transport layer protocols. As 10G connections gain momentum outside of backbone networks, the choice of appropriate TCP congestion control algorithms becomes even more relevant for networked applications running in environments such as data centers. Therefore, we provide an extensive overview of relevant TCP congestion control algorithms for high-speed environments leveraging 10G. We analyzed and evaluated six TCP variants using a physical network testbed, with a focus on the effects of propagation delay and significant drop rates. The results indicate that of the algorithms compared, BIC is most suitable when no legacy variant is present, CUBIC is suggested otherwise. Thomas Lukaseder, Leonard Bradatsch, Benjamin Erb, Rens W. van der Heijden, Frank Kargl |
LCN | 2 |
| 2016 | Setting Up a High-Speed TCP Benchmarking Environment - Lessons LearnedabstractThere are many high-speed TCP variants with different congestion control algorithms, which are designed for specific settings or use cases. Distinct features of these algorithms are meant to optimize different aspects of network performance, and the choice of TCP variant strongly influences application performance. However, setting up tests to help with the decision of which variant to use can be problematic, as many systems are not designed to deal with high bandwidths, such as 10 Gbps or more. This paper provides an overview of pitfalls and challenges of realistic network analysis to help in the decision making process. Thomas Lukaseder, Leonard Bradatsch, Benjamin Erb, Frank Kargl |
LCN | 2 |