VLDB 2026 Research / reviewers in the wild / expert
Tom Neubert
dblp:185/0473
· DBLP profile ↗
9ranked-venue papers
4as first author
4since 2021 · last 2022
0000-0001-8474-6560ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 9 · 4 first-author · 4 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2022 | Improving Performance of Machine Learning based Detection of Network Steganography in Industrial Control SystemsabstractIn view of the strong increase of targeted attacks on industrial control systems (ICS) of manufacturies and critical infrastructures, it can be noticed that for the concealment of communication, steganographic information hiding techniques become increasingly popular for attackers. Particularly in Advanced Persistent Threats, attackers focus on hiding network information flows between infected components from any possible detection mechanism in order to remain on the invaded system for as long as possible. In order to be able to detect these kinds of threats by hidden communication in future, defense concepts such as intrusion detection systems need to be supplemented by steganalytic detectors for ICS network traffic. First state-of-the-art detection mechanisms have been proposed and deliver decent but improvable results. This paper proposes a novel, convolutional neural network (CNN) based detection approach relying on a handcrafted feature space as CNN input layer. The detection approach is evaluated extensively in experiments. The evaluation results are compared to three state-of-the-art approaches in a laboratory ICS setup. We show that our novel approach is able to outperform all state-of-the-art approaches significantly. It delivers a performance of up to 94.3% correct classified test data samples. Tom Neubert, Antonio José Caballero Morcillo, Claus Vielhauer |
ARES | 1 |
| 2021 | Artificial Steganographic Network Data Generation Concept and Evaluation of Detection Approaches to secure Industrial Control Systems against Steganographic AttacksabstractSince industrial control systems (ICS) play an important role in our everyday life, their protection is of great importance. At the same time, security researchers observe an increasing usage of steganographic methods in IT networks used by attackers to embed hidden communication in order to stay undetected as long as possible. This leads to a novel digital threat which includes the embedding of steganographic hidden communication in ICS networks. Thus, novel detection approaches specified for steganographic attacks have to be elaborated. Detectors are often based on machine learning approaches and require training and test data. However, the embedding of sophisticated hidden communication in an ICS is a very time consuming and challenging task which currently leads to a lack of suitable training and test data for the evaluation of detection mechanisms. To address this gap, this work presents an artificial steganographic network data (ASND) generation concept for an easy generation of sophisticated steganographic network data which can be provided for the evaluation of detection mechanisms. In this paper, an exemplary data set is created by ASND generation concept and used to evaluate a state-of-the-art detector and a novel detector, also introduced in this work. The accuracy of the detectors is determined and compared. The novel detector reaches a maximum detection accuracy of 92.5%. Tom Neubert, Claus Vielhauer, Christian Krätzer |
ARES | 1 |
| 2021 | A Revised Taxonomy of Steganography Embedding PatternsabstractSteganography embraces several hiding techniques which spawn across multiple domains. However, the related terminology is not unified among the different domains, such as digital media steganography, text steganography, cyber-physical systems steganography, network steganography (network covert channels), local covert channels, and out-of-band covert channels. To cope with this, a prime attempt has been done in 2015, with the introduction of the so-called hiding patterns, which allow to describe hiding techniques in a more abstract manner. Despite significant enhancements, the main limitation of such a taxonomy is that it only considers the case of network steganography. Steffen Wendzel, Luca Caviglione, Wojciech Mazurczyk, Aleksandra Mileva, Jana Dittmann, Christian Krätzer, Kevin Lamshöft, Claus Vielhauer, Laura Hartmann, Jörg Keller 0001, Tom Neubert |
ARES | 11 |
| 2021 | Information Hiding in Cyber Physical Systems: Challenges for Embedding, Retrieval and Detection using Sensor Data of the SWAT DatasetabstractIn this paper, we present an Information Hiding approach that would be suitable for exfiltrating sensible information of Industrial Control Systems (ICS) by leveraging the long-term storage of process data in historian databases. We show how hidden messages can be embedded in sensor measurements as well as retrieved asynchronously by accessing the historian. We evaluate this approach at the example of water-flow and water-level sensors of the Secure Water Treatment (SWAT) dataset from iTrust. To generalize from specific cover channels (sensors and their transmitted data), we reflect upon general challenges that arise in such Information Hiding scenarios creating network covert channels and discuss aspects of cover channel selection and and sender receiver synchronisation as well as temporal aspects such as the potential persistence of hidden messages in Cyber Physical Systems (CPS). For an empirical evaluation we design and implement a covert channel that makes use of different embedding strategies to perform an adaptive approach in regards to the noise in sensor measurements, resulting in dynamic capacity and bandwidth selection to reduce detection probability. The results of this evaluation show that, using such methods, the exfiltration of sensible information in long-term scaled attacks would indeed be possible. Additionally, we present two detection approaches for the introduced hidden channel and carry out an extensive evaluation of our detectors with multiple test data sets and different parameters. We determine a detection accuracy of up to 87.8% on test data at a false positive rate (FPR) of 0%. Kevin Lamshöft, Tom Neubert, Christian Krätzer, Claus Vielhauer, Jana Dittmann |
IH&MMSec | 2 |
| 2020 | Information Hiding in Industrial Control Systems: An OPC UA based Supply Chain Attack and its DetectionabstractIndustrial Control Systems (ICS) help to automate various cyber-physical systems in our world. The controlled processes range from rather simple traffic lights and elevators to complex networks of ICS in car manufacturing or controlling nuclear power plants. With the advent of industrial Ethernet ICS are increasingly connected to networks of Information Technology (IT). Thus, novel attack vectors on ICS are possible. In IT networks information hiding and steganography is increasingly used in advanced persistent threats to conceal the infection of the systems allowing the attacker to retain control over the compromised networks. In parallel ICS are more and more a target for attacks as well. Here, simple automated attacks as well as targeted attacks of nation state actors with the intention of damaging components or infrastructures as a part of cyber crime have already been observed. Information hiding could bring such attacks to a new level by integrating backdoors and hidden/covert communication channels that allow for attacking specific processes whenever it is deemed necessary. This paper sheds light on potential attack vectors on Programmable Logic Controllers (PLCs) using OPC Unified Architecture (OPC UA) network protocol based communication. We implement an exemplary supply chain attack consisting of an OPC UA server (Bob, B) and a Siemens S7-1500 PLC as OPC UA client (Alice, A). The hidden storage channel is using source timestamps to embed encrypted control sequences allowing for setting digital outputs to arbitrary values. The attack is solely relying on the programming of the PLC and does not require firmware level access. Due to the potential harm to life caused by attacks on cyber-physical systems any presentation of novel attack vectors need to present suitable mitigation strategies. Thus, we investigate potential approaches for the detection of the hidden storage channel for a warden W as well as potential countermeasures in order to increase the warden-compliance. Our machine learning based detection approach using a One-Class-Classifier yields a detection performance of 89.5% with zero false positives within an experiment with 46,159 OPC UA read responses without a steganographic message and 7,588 OPC UA read responses with an embedded steganographic message. Mario Hildebrandt, Kevin Lamshöft, Jana Dittmann, Tom Neubert, Claus Vielhauer |
IH&MMSec | 4 |
| 2019 | A Face Morphing Detection Concept with a Frequency and a Spatial Domain Feature Space for Images on eMRTDabstractSince the face morphing attack was introduced by Ferrara et al. in 2014, the detection of face morphings has become a wide spread topic in image forensics. By now, the community is very active and has reported diverse detection approaches. So far, the evaluations are mostly performed on images without post-processing. Face images stored within electronic machine readable documents (eMRTD) are ICAO-passport-scaled to a resolution of 413x531 and a JPG or JP2 lesize of 15 kilobytes. This paper introduces a face morphing detection concept with 3 modules (ICAO-aligned pre- processing module, feature extraction module and classi cation module), tailored for such images on eMRTD. In this work we exemplary design and evaluate two feature spaces for the feature extraction module, a frequency domain and a spatial domain feature space. Our evaluation will compare both feature spaces and is carried out with 66,229 passport-scaled images (64,363 morphed face images and 1,866 authentic face images) which are completly independent from training and include all images provided for the IHMMSEC'19 special session: "Media Forensics - Fake or Real?". Furthermore, we investigate the in uence of di erent morph gen- eration pipelines to the detection accuracies of the concept and we analyse the impact of neutral and smiling genuine faces to the morph detector performance. The evaluation determines a detection rate of 86.0% for passport-scaled morphed images with a false alarm rate of 4.4% for genuine images for the spatial domain feature space Tom Neubert, Christian Krätzer, Jana Dittmann |
IH&MMSec | 1 |
| 2018 | Generalized Benford's Law for Blind Detection of Morphed Face ImagesabstractA morphed face image in a photo ID is a serious threat to image-based user verification enabling that multiple persons could be matched with the same document. The application of machine-readable travel documents (MRTD) at automated border control (ABC) gates is an example of a verification scenario that is very sensitive to this kind of fraud. Detection of morphed face images prior to face matching is, therefore, indispensable for effective border security. We introduce the face morphing detection approach based on fitting a logarithmic curve to nine Benford features extracted from quantized DCT coefficients of JPEG compressed original and morphed face images. We separately study the parameters of the logarithmic curve in face and background regions to establish the traces imposed by the morphing process. The evaluation results show that a single parameter of the logarithmic curve may be sufficient to clearly separate morphed and original images. Andrey Makrushin, Christian Krätzer, Tom Neubert, Jana Dittmann |
IH&MMSec | 3 |
| 2017 | Modeling Attacks on Photo-ID Documents and Applying Media Forensics for the Detection of Facial MorphingabstractSince 2014, a novel approach to attack face image based person verification designated as face morphing attack has been actively discussed in the biometric and media forensics communities. Up until that point, modern travel documents were considered to be extremely hard to forge or to successfully manipulate. In the case of template-targeting attacks like facial morphing, the face verification process becomes vulnerable, making it a necessity to design protection mechanisms. In this paper, a new modeling approach for face morphing attacks is introduced. We start with a life-cycle model for photo-ID documents. We extend this model by an image editing history model, allowing for a precise description of attack realizations as a foundation for performing media forensics as well as training and testing scenarios for the attack detectors. On the basis of these modeling approaches, two different realizations of the face morphing attack as well as a forensic morphing detector are implemented and evaluated. The design of the feature space for the detector is based on the idea that the blending operation in the morphing pipeline causes the reduction of face details. To quantify this reduction, we adopt features implemented in the OpenCV image processing library, namely the number of SIFT, SURF, ORB, FAST and AGAST keypoints in the face region as well as the loss of edge-information with Canny and Sobel edge operators. Our morphing detector is trained with 2000 self-acquired authentic and 2000 morphed images captured with three camera types (Canon EOS 1200D, Nikon D 3300, Nikon Coolpix A100) and tested with authentic and morphed face images from a public database. Morphing detection accuracies of a decision tree classifier vary from 81.3% to 98% for different training and test scenarios. Christian Krätzer, Andrey Makrushin, Tom Neubert, Mario Hildebrandt, Jana Dittmann |
IH&MMSec | 3 |
| 2017 | Face Morphing Detection: An Approach Based on Image Degradation Analysis
Tom Neubert |
IWDW | 1 |