VLDB 2026 Research / reviewers in the wild / expert
Milan Stute
dblp:183/6724 · also Milan Schmittner
· DBLP profile ↗
15ranked-venue papers
8as first author
6since 2021 · last 2022
0000-0003-4921-8476ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 8 · 5 first-authorSecurity and privacy · 7 · 3 first-author · 6 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2022 | RESCUE: A Resilient and Secure Device-to-Device Communication Framework for EmergenciesabstractDuring disasters, existing telecommunication infrastructures are often congested or even destroyed. In these situations, mobile devices can form a backup communication network for civilians and emergency services using disruption-tolerant networking (DTN) principles. Unfortunately, such distributed and resource-constrained networks are particularly susceptible to a wide range of attacks such as terrorists trying to cause more harm. In this article, we presentRESCUE, a resilient and secure device-to-device communication framework for emergency scenarios that provides comprehensive protection against common attacks.RESCUEfeatures a minimalistic DTN protocol that, by design, is secure against notable attacks such as routing manipulations, dropping, message manipulations, blackholing, or impersonation. To further protect against message flooding and Sybil attacks, we present a twofold mitigation technique. First, a mobile and distributed certificate infrastructure particularly tailored to the emergency use case hinders the adversarial use of multiple identities. Second, a message buffer management scheme significantly increases resilience against flooding attacks, even if they originate from multiple identities, without introducing additional overhead. Finally, we demonstrate the effectiveness ofRESCUEvia large-scale simulations in a synthetic as well as a realistic natural disaster scenario. Our simulation results show thatRESCUEachieves very good message delivery rates, even under flooding and Sybil attacks. Milan Stute, Florian Kohnhäuser, Lars Baumgärtner, Lars Almon, Matthias Hollick, Stefan Katzenbeisser 0001, Bernd Freisleben |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2021 | PrivateDrop: Practical Privacy-Preserving Authentication for Apple AirDrop
Alexander Heinrich, Matthias Hollick, Thomas Schneider 0003, Milan Stute, Christian Weinert |
USENIX Security Symposium | 4 |
| 2021 | Disrupting Continuity of Apple's Wireless Ecosystem Security: New Tracking, DoS, and MitM Attacks on iOS and macOS Through Bluetooth Low Energy, AWDL, and Wi-Fi
Milan Stute, Alexander Heinrich, Jannik Lorenz, Matthias Hollick |
USENIX Security Symposium | 1 |
| 2021 | AirCollect: efficiently recovering hashed phone numbers leaked via Apple AirDropabstractApple's file-sharing service AirDrop leaks phone numbers and email addresses by exchanging vulnerable hash values of the user's own contact identifiers during the authentication handshake with nearby devices. In a paper presented at USENIX Security'21, we theoretically describe two attacks to exploit these vulnerabilities and propose "PrivateDrop" as a privacy-preserving drop-in replacement for Apple's AirDrop protocol based on private set intersection. Alexander Heinrich, Matthias Hollick, Thomas Schneider 0003, Milan Stute, Christian Weinert |
WISEC | 4 |
| 2021 | OpenHaystack: a framework for tracking personal bluetooth devices via Apple's massive find my networkabstractOpenHaystack is an open-source framework for locating personal Bluetooth devices using Apple's Find My Network. A user can integrate it into Bluetooth-capable devices, such as notebooks, or create custom tracking accessories that can be attached to personal items (key rings, backpacks, etc.). We provide firmware images for the Nordic nRF5 chips and the ESP32. We show that they consume little energy and run from a single coin cell for a year. Our macOS application can locate personal accessories. Finally, we make both application and firmware available on GitHub. Alexander Heinrich, Milan Stute, Matthias Hollick |
WISEC | 2 |
| 2021 | Who Can Find My Devices? Security and Privacy of Apple's Crowd-Sourced Bluetooth Location Tracking SystemabstractAbstract Overnight, Apple has turned its hundreds-of-million-device ecosystem into the world’s largest crowd-sourced location tracking network called o~ine finding (OF). OF leverages online finder devices to detect the presence of missing o~ine devices using Bluetooth and report an approximate location back to the owner via the Internet. While OF is not the first system of its kind, it is the first to commit to strong privacy goals. In particular, OF aims to ensure finder anonymity, prevent tracking of owner devices, and confidentiality of location reports. This paper presents the first comprehensive security and privacy analysis of OF. To this end, we recover the specifications of the closed-source OF protocols by means of reverse engineering. We experimentally show that unauthorized access to the location reports allows for accurate device tracking and retrieving a user’s top locations with an error in the order of 10 meters in urban areas. While we find that OF’s design achieves its privacy goals, we discover two distinct design and implementation flaws that can lead to a location correlation attack and unauthorized access to the location history of the past seven days, which could deanonymize users. Apple has partially addressed the issues following our responsible disclosure. Finally, we make our research artifacts publicly available. Alexander Heinrich, Milan Stute, Tim Kornhuber, Matthias Hollick |
Proc. Priv. Enhancing Technol. | 2 |
| 2020 | LIDOR: A Lightweight DoS-Resilient Communication Protocol for Safety-Critical IoT SystemsabstractIoT devices penetrate different aspects of our life including critical services, such as health monitoring, public safety, and autonomous driving. Such safety-critical IoT systems often consist of a large number of devices and need to withstand a vast range of known Denial-of-Service (DoS) network attacks to ensure a reliable operation while offering low-latency information dissemination. As the first solution to jointly achieve these goals, we propose LIDOR, a secure and lightweight multihop communication protocol designed to withstand all known variants of packet dropping attacks. Specifically, LIDOR relies on an end-to-end feedback mechanism to detect and react on unreliable links and draws solely on efficient symmetric-key cryptographic mechanisms to protect packets in transit. We show the overhead of LIDOR analytically and provide the proof of convergence for LIDOR which makes LIDOR resilient even to strong and hard-to-detect wormhole-supported grayhole attacks. In addition, we evaluate the performance via testbed experiments. The results indicate that LIDOR improves the reliability under DoS attacks by up to 91% and reduces network overhead by 32% compared to a state-of-the-art benchmark scheme. Milan Stute, Pranay Agarwal, Abhinav Kumar 0001, Arash Asadi, Matthias Hollick |
IEEE Internet Things J. | 1 |
| 2019 | A Billion Open Interfaces for Eve and Mallory: MitM, DoS, and Tracking Attacks on iOS and macOS Through Apple Wireless Direct Link
Milan Stute, Sashank Narain, Alex Mariotto, Alexander Heinrich, David Kreitschmann, Guevara Noubir, Matthias Hollick |
USENIX Security Symposium | 1 |
| 2018 | One Billion Apples' Secret Sauce: Recipe for the Apple Wireless Direct Link Ad hoc ProtocolabstractApple Wireless Direct Link (AWDL) is a proprietary and undocumented IEEE 802.11-based ad hoc protocol. Apple first introduced AWDL around 2014 and has since integrated it into its entire product line, including iPhone and Mac. While we have found that AWDL drives popular applications such as AirPlay and AirDrop on more than one billion end-user devices, neither the protocol itself nor potential security and Wi-Fi coexistence issues have been studied. In this paper, we present the operation of the protocol as the result of binary and runtime analysis. In short, each AWDL node announces a sequence of Availability Windows (AWs) indicating its readiness to communicate with other AWDL nodes. An elected master node synchronizes these sequences. Outside the AWs, nodes can tune their Wi-Fi radio to a different channel to communicate with an access point, or could turn it off to save energy. Based on our analysis, we conduct experiments to study the master election process, synchronization accuracy, channel hopping dynamics, and achievable throughput. We conduct a preliminary security assessment and publish an open source Wireshark dissector for AWDL to nourish future work. Milan Stute, David Kreitschmann, Matthias Hollick |
MobiCom | 1 |
| 2018 | Linux Goes Apple Picking: Cross-Platform Ad hoc Communication with Apple Wireless Direct LinkabstractApple Wireless Direct Link (AWDL) is a proprietary and undocumented wireless ad hoc protocol that Apple introduced around 2014 and which is the base for applications such as AirDrop and AirPlay. We have reverse engineered the protocol and explain its frame format and operation in our MobiCom '18 paper "One Billion Apples' Secret Sauce: Recipe of the Apple Wireless Direct Link Ad hoc Protocol." AWDL builds on the IEEE 802.11 standard and implements election, synchronization, and channel hopping mechanisms on top of it. Furthermore, AWDL features an IPv6-based data path which enables direct communication. To validate our own work, we implement a working prototype of AWDL on Linux-based systems. Our implementation is written in C, runs in userspace, and makes use of Linux's Netlink API for interactions with the system's networking stack and the pcap library for frame injection and reception. In our demonstrator, we show how our Linux system synchronizes to an existing AWDL cluster or takes over the master role itself. Furthermore, it can receive data frames from and send them to a MacBook or iPhone via AWDL. We demonstrate the data exchange via ICMPv6 echo request and replies as well as sending and receiving data over a TCP connection. Milan Stute, David Kreitschmann, Matthias Hollick |
MobiCom | 1 |
| 2017 | Temporal Coverage Analysis of Router-Based Cloudlets Using Human Mobility PatternsabstractResponsive applications such as augmented reality require nearby computational offloading units with low latency. The concept of cloudlets is one promising approach that satisfies these requirements. However, due to their wireless range restrictions cloudlets have always been faced with deployment issues of achieving high spatial coverage. In this paper, we look at the coverage issue from an end-user's perspective instead of an established provider perspective: we first argue that temporal coverage of cloudlet accessibility is preferable to spatial coverage for an end- user's experience considering his daily mobility behavior. Next, we investigate what is necessary to achieve a high temporal coverage for an individual user and to what extent is temporal coverage realizable with concepts like router- based cloudlets. To show our hypothesis and understanding the temporal coverage aspect, we collected two comprehensive datasets, an access points dataset with estimated location information and a human mobility dataset consisting of mobility traces from 30 participants within a major city over 4 weeks. Our analysis results show that high temporal coverage can be achieved by a relatively small set of router-based cloudlets since students mainly stay at two places, their homes and university, which represent a large part of the temporal coverage. The remaining rate at which coverage increases heavily depends on the user's mobility patterns. Our findings can be used to place router-based cloudlets at the right locations and estimate the number needed to achieve a certain temporal coverage in urban environments. Christian Meurisch, Julien Gedeon, Artur Gogel, The An Binh Nguyen, Fabian Kaup, Florian Kohnhäuser, Lars Baumgärtner, Milan Stute, Max Mühlhäuser |
GLOBECOM | 8 |
| 2017 | Upgrading Wireless Home Routers as Emergency Cloudlet and Secure DTN Communication BridgeabstractReliable communications are crucial for the success of emergency response and management. However, today's technologies used by rescuers and civilians mainly rely on either centralized or specialized emergency approaches, which reveal individual issues especially in infrastructure- less emergency situations (e.g., blackout). In this paper, we present a customary home router upgraded as self- sustaining emergency device which can ad hoc network with nearby devices (e.g., other upgraded routers, smartphones) using wireless communication technologies. On top of the ad-hoc networking, an upgraded router provides (1) personal computing capacities for low-latency offloading from mobile devices (aka cloudlet) using isolated lightweight containers; and (2) store-and-forward delay-tolerant data exchanges to serve as secure communication bridge for cooperation between involved or affected people (e.g., rescuers, civilians). We believe that upgrading ubiquitous routers is a very promising concept for a scalable ad-hoc networking and energy-efficient computing infrastructure in urban emergency situations. Christian Meurisch, The An Binh Nguyen, Julien Gedeon, Florian Kohnhäuser, Milan Stute, Stefan Niemczyk, Stefan Wullkotte, Max Mühlhäuser |
ICCCN | 5 |
| 2017 | SEDCOS: A Secure Device-to-Device Communication System for Disaster ScenariosabstractDuring disasters, existing telecommunication infrastructures are often congested or even destroyed. In these situations, mobile devices can be interconnected using wireless ad hoc and disruption-tolerant networking to establish a backup emergency communication system for civilians and emergency services. However, such communication systems entail serious security risks, since adversaries may attempt to steal confidential data, fake notifications of emergency services, or perform denial-of-service (DoS) attacks. In this paper, we present SEDCOS, a secure device-to-device communication system for disaster scenarios. SEDCOS allows new users to join the network during disasters, mitigates flooding DoS attacks, and offers role revocation for detected adversaries to withdraw their permissions and exclude them from group communication. SEDCOS mitigates flooding DoS attacks and offers role revocation for detected adversaries to withdraw their permissions and exclude them from group communication. SEDCOS mitigates flooding DoS attacks and offers role revocation for detected adversaries to withdraw their permissions. We demonstrate the effectiveness of SEDCOS by large-scale network simulations. Florian Kohnhäuser, Milan Stute, Lars Baumgärtner, Lars Almon, Stefan Katzenbeisser 0001, Matthias Hollick, Bernd Freisleben |
LCN | 2 |
| 2017 | Reverse Engineering Human Mobility in Large-scale Natural DisastersabstractDelay/Disruption-Tolerant Networks (DTNs) have been around for more than a decade and have especially been proposed to be used in scenarios where communication infrastructure is unavailable. In such scenarios, DTNs can offer a best-effort communication service by exploiting user mobility. Natural disasters are an important application scenario for DTNs when the cellular network is destroyed by natural forces. To assess the performance of such networks before deployment, we require appropriate knowledge of human mobility. In this paper, we address this problem by designing, implementing, and evaluating a novel mobility model for large-scale natural disasters. Due to the lack of GPS traces, we reverse-engineer human mobility of past natural disasters (focusing on 2010 Haiti earthquake and 2013 Typhoon Haiyan) by leveraging knowledge of 126 experts from 71 Disaster Response Organizations (DROs). By means of simulation-based experiments, we compare and contrast our mobility model to other well-known models, and evaluate their impact on DTN performance. Finally, we make our source code available to the public. Milan Stute, Max Maaß, Tom Schons, Matthias Hollick |
MSWiM | 1 |
| 2016 | Xcastor: Secure and scalable group communication in ad hoc networksabstractMobile ad hoc networks (MANETs) are emerging as a practical technology for emergency response communication in the case a centralized infrastructure malfunctions or is not available. Using smartphones as communication devices, MANETs may be readily established among the civilian population of affected areas. Beneficiaries would be civilian first responders, which may form small collaborating groups. Communication in such groups must be reliable for disaster response to be effective. In this paper, we address the issue of reliable group communication on the network layer. We design and implement the first secure explicit multicast routing protocol called Xcastor, in which we extend the secure and scalable routing concept of the Castor unicast routing protocol towards supporting reliable communication for large numbers of small groups. By simulation, we show significant performance improvements over Castor. Milan Stute, Matthias Hollick |
WoWMoM | 1 |