VLDB 2026 Research / reviewers in the wild / expert
Christian Krätzer
dblp:20/5706 · also Christian Kraetzer
· DBLP profile ↗
16ranked-venue papers
4as first author
9since 2021 · last 2024
0000-0002-0138-4638ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 14 · 3 first-author · 9 since 2021Systems, architecture and hardware · 1 · 1 first-authorHuman-computer interaction and ubiquitous computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | Forensic Trace Analysis for MP3 based Stego-Malware: Exemplary Study for Stego-Algorithm and Capacity Attribution to derive YARA Rules for Malware IdentificationabstractStego-malware is a current trend of cyber-criminals to work as unobtrusively as possible in target systems. Common covers are image data but also audio data is plausible. In this paper three exemplary selected MP3 steganography tools (MP3Stego, MP3Stegz and Stegonaut) are forensically investigated to enhance knowledge on how steganographic algorithms can be identified and attributed in a malware scenario. Our study is driven by known steganalysis artefacts and source code analysis. To perform a structured analysis we follow the European Network of Forensic Science Institutes (ENFSI) guidelines for audio authenticity analysis and derive a trace map with meta data and content data from a systematic file structure analysis. From our findings summarised in the trace map, we derive detection patterns to identify the used steganography tool with an embedding algorithm signature. Furthermore, we discuss how known malformed actions from a code book (known malware dictionary) can be attributed with a side-informed capacity analysis and attribution. From the pattern we formulate YARA rules for the configuration of corresponding detectors. Jana Dittmann, Christian Krätzer, Jost Alemann, Bernhard Birnbaum |
IH&MMSec | 2 |
| 2024 | GAN-based Minutiae-driven Fingerprint MorphingabstractFingerprint morphing is the process of combining two or more distinct fingerprints to create a new, morphed fingerprint that includes identity-related characteristics of all constituent fingerprints. Previously, this was done by either applying a model-based minutiae-oriented approach or a data-driven approach based on a Generative Adversarial Network (GAN). The model-based approach provides the ability to manage the number of minutiae coming from the fingerprints, but the resulting fingerprint often appears unrealistic. On the other hand, the data-driven approach produces realistic fingerprints, but it does not guarantee that the resulting fingerprint matches the original fingerprints. In this work, we introduce an algorithm that combines minutiae-oriented and GAN-based approaches to generate morphed fingerprints that look realistic and match their original fingerprints. The algorithm is initially designed to generate double-identity fingerprints and is further extended to generate triple-identity fingerprints. The results of our experiments indicate that the generated fingerprints appear realistic and the majority of them can be seen as double-identity fingerprints. The fingerprints resulting from morphing three fingerprints are unlikely to be triple-identity fingerprints, but rather anonymous ones matching none of the constituent original fingerprints. Meghana Rao Bangalore Narasimha Prasad, Andrey Makrushin, Matteo Ferrara, Christian Krätzer, Jana Dittmann |
IH&MMSec | 4 |
| 2021 | A Semi-Automated HTTP Traffic Analysis for Online Payments for Empowering Security, Forensics and Privacy AnalysisabstractThe paper discusses means to identify potential impacts of data flows on customers’ security, and privacy during online payments. The main objectives of our research are looking into the evolution of cybercrime new trends of online payments and detection, more precisely the usage of mobile phones, and describing methodologies for digital trace identification in data flows for potential online payment fraud. The paper aims to identify potential actions for identity theft while conducting the Reconnaissance step of the kill chain, and documenting a forensic methodology for guidance and further data collection for law enforcement bodies. Moreover, a secondary objective of the paper is to identify, from a user’s perspective, transparency issues of data sharing among involved parties for online payments. We thus declare the transparency analysis as the incident triggering a forensic examination. Hence, we devise a semi-automated traffic analysis approach, based on previous work, to examine data flows, and data exchanged among parties in online payments. For this, the main steps are segmenting traffic generated by the process payment, and other sources, subsequently, identifying data streams in the process. We conduct three tests which include three different payment gateways: PayPal, Klarna-sofort, and Amazon Pay. The experiment setup requires circumventing TLS encryption for the correct identification of forensic data types in TCP/IP traffic, and potential data leaks. However, it requires no extensive expertise in mobile security for its installation. In the results, we identified some important security vulnerabilities from some payment APIs that pose financial and privacy risks to the marketplace’s customers. Salatiel Ezennaya-Gomez, Stefan Kiltz, Christian Krätzer, Jana Dittmann |
ARES | 3 |
| 2021 | A Systematic Analysis of Covert Channels in the Network Time ProtocolabstractCovert channels in network protocols are a technique aiming to hide the very existence of secret communication in computer networks. In this work we present a systematic in-depth analysis of covert channels by modification for the Network Time Protocol (NTP). Our analysis results in the identification of 49 covert channels, by applying a covert channel pattern-based taxonomy. The summary and comparison based on nine selected key attributes show that NTP is a plausible carrier for covert channels. The analysis results are evaluated in regards to common behavior of NTP implementations in six major operating systems. Two channels are selected and implemented to be evaluated in network test-beds. By hiding encrypted high entropy data in a high entropy field of NTP we show in our first assessment that practically undetectable channels can be implemented in NTP, motivating the required further research. In our evaluation, we analyze 40,000 NTP server responses from public NTP server providers. We discuss the general approach of the research community that detection of covert channels is the more promising countermeasure, compared to active suppression of covert channels. Therefore, normalization approaches and a secure network environment are introduced. Jonas Hielscher, Kevin Lamshöft, Christian Krätzer, Jana Dittmann |
ARES | 3 |
| 2021 | Artificial Steganographic Network Data Generation Concept and Evaluation of Detection Approaches to secure Industrial Control Systems against Steganographic AttacksabstractSince industrial control systems (ICS) play an important role in our everyday life, their protection is of great importance. At the same time, security researchers observe an increasing usage of steganographic methods in IT networks used by attackers to embed hidden communication in order to stay undetected as long as possible. This leads to a novel digital threat which includes the embedding of steganographic hidden communication in ICS networks. Thus, novel detection approaches specified for steganographic attacks have to be elaborated. Detectors are often based on machine learning approaches and require training and test data. However, the embedding of sophisticated hidden communication in an ICS is a very time consuming and challenging task which currently leads to a lack of suitable training and test data for the evaluation of detection mechanisms. To address this gap, this work presents an artificial steganographic network data (ASND) generation concept for an easy generation of sophisticated steganographic network data which can be provided for the evaluation of detection mechanisms. In this paper, an exemplary data set is created by ASND generation concept and used to evaluate a state-of-the-art detector and a novel detector, also introduced in this work. The accuracy of the detectors is determined and compared. The novel detector reaches a maximum detection accuracy of 92.5%. Tom Neubert, Claus Vielhauer, Christian Krätzer |
ARES | 3 |
| 2021 | A Revised Taxonomy of Steganography Embedding PatternsabstractSteganography embraces several hiding techniques which spawn across multiple domains. However, the related terminology is not unified among the different domains, such as digital media steganography, text steganography, cyber-physical systems steganography, network steganography (network covert channels), local covert channels, and out-of-band covert channels. To cope with this, a prime attempt has been done in 2015, with the introduction of the so-called hiding patterns, which allow to describe hiding techniques in a more abstract manner. Despite significant enhancements, the main limitation of such a taxonomy is that it only considers the case of network steganography. Steffen Wendzel, Luca Caviglione, Wojciech Mazurczyk, Aleksandra Mileva, Jana Dittmann, Christian Krätzer, Kevin Lamshöft, Claus Vielhauer, Laura Hartmann, Jörg Keller 0001, Tom Neubert |
ARES | 6 |
| 2021 | Information Hiding in Cyber Physical Systems: Challenges for Embedding, Retrieval and Detection using Sensor Data of the SWAT DatasetabstractIn this paper, we present an Information Hiding approach that would be suitable for exfiltrating sensible information of Industrial Control Systems (ICS) by leveraging the long-term storage of process data in historian databases. We show how hidden messages can be embedded in sensor measurements as well as retrieved asynchronously by accessing the historian. We evaluate this approach at the example of water-flow and water-level sensors of the Secure Water Treatment (SWAT) dataset from iTrust. To generalize from specific cover channels (sensors and their transmitted data), we reflect upon general challenges that arise in such Information Hiding scenarios creating network covert channels and discuss aspects of cover channel selection and and sender receiver synchronisation as well as temporal aspects such as the potential persistence of hidden messages in Cyber Physical Systems (CPS). For an empirical evaluation we design and implement a covert channel that makes use of different embedding strategies to perform an adaptive approach in regards to the noise in sensor measurements, resulting in dynamic capacity and bandwidth selection to reduce detection probability. The results of this evaluation show that, using such methods, the exfiltration of sensible information in long-term scaled attacks would indeed be possible. Additionally, we present two detection approaches for the introduced hidden channel and carry out an extensive evaluation of our detectors with multiple test data sets and different parameters. We determine a detection accuracy of up to 87.8% on test data at a false positive rate (FPR) of 0%. Kevin Lamshöft, Tom Neubert, Christian Krätzer, Claus Vielhauer, Jana Dittmann |
IH&MMSec | 3 |
| 2021 | General Requirements on Synthetic Fingerprint Images for Biometric Authentication and Forensic InvestigationsabstractGeneration of synthetic biometric samples such as, for instance, fingerprint images gains more and more importance especially in view of recent cross-border regulations on security of private data. The reason is that biometric data is designated in recent regulations such as the EU GDPR as a special category of private data, making sharing datasets of biometric samples hardly possible even for research purposes. The usage of fingerprint images in forensic research faces the same challenge. The replacement of real datasets by synthetic datasets is the most advantageous straightforward solution which bears, however, the risk of generating "unrealistic" samples or "unrealistic distributions" of samples which may visually appear realistic. Despite numerous efforts to generate high-quality fingerprints, there is still no common agreement on how to define "high-quality'' and how to validate that generated samples are realistic enough. Here, we propose general requirements on synthetic biometric samples (that are also applicable for fingerprint images used in forensic application scenarios) together with formal metrics to validate whether the requirements are fulfilled. Validation of our proposed requirements enables establishing the quality of a generative model (informed evaluation) or even the quality of a dataset of generated samples (blind evaluation). Moreover, we demonstrate in an example how our proposed evaluation concept can be applied to a comparison of real and synthetic datasets aiming at revealing if the synthetic samples exhibit significantly different properties as compared to real ones. Andrey Makrushin, Christof Kauba, Simon Kirchgasser, Stefan Seidlitz, Christian Krätzer, Andreas Uhl, Jana Dittmann |
IH&MMSec | 5 |
| 2021 | Potential advantages and limitations of using information fusion in media forensics - a discussion on the example of detecting face morphing attacksabstractAbstract Information fusion, i.e., the combination of expert systems, has a huge potential to improve the accuracy of pattern recognition systems. During the last decades, various application fields started to use different fusion concepts extensively. The forensic sciences are still hesitant if it comes to blindly applying information fusion. Here, a potentially negative impact on the classification accuracy, if wrongly used or parameterized, as well as the increased complexity (and the inherently higher costs for plausibility validation) of fusion is in conflict with the fundamental requirements for forensics. The goals of this paper are to explain the reasons for this reluctance to accept such a potentially very beneficial technique and to illustrate the practical issues arising when applying fusion. For those practical discussions the exemplary application scenario of morphing attack detection (MAD) is selected with the goal to facilitate the understanding between the media forensics community and forensic practitioners. As general contributions, it is illustrated why the naive assumption that fusion would make the detection more reliable can fail in practice, i.e., why fusion behaves in a field application sometimes differently than in the lab. As a result, the constraints and limitations of the application of fusion are discussed and its impact to (media) forensics is reflected upon. As technical contributions, the current state of the art of MAD is expanded by: The introduction of the likelihood-based fusion and an fusion ensemble composition experiment to extend the set of methods (majority voting, sum-rule, and Dempster-Shafer Theory of evidence) used previously The direct comparison of the two evaluation scenarios “MAD in document issuing” and “MAD in identity verification” using a realistic and some less restrictive evaluation setups A thorough analysis and discussion of the detection performance issues and the reasons why fusion in a majority of the test cases discussed here leads to worse classification accuracy than the best individual classifier Christian Krätzer, Andrey Makrushin, Jana Dittmann, Mario Hildebrandt |
EURASIP J. Inf. Secur. | 1 |
| 2019 | A Face Morphing Detection Concept with a Frequency and a Spatial Domain Feature Space for Images on eMRTDabstractSince the face morphing attack was introduced by Ferrara et al. in 2014, the detection of face morphings has become a wide spread topic in image forensics. By now, the community is very active and has reported diverse detection approaches. So far, the evaluations are mostly performed on images without post-processing. Face images stored within electronic machine readable documents (eMRTD) are ICAO-passport-scaled to a resolution of 413x531 and a JPG or JP2 lesize of 15 kilobytes. This paper introduces a face morphing detection concept with 3 modules (ICAO-aligned pre- processing module, feature extraction module and classi cation module), tailored for such images on eMRTD. In this work we exemplary design and evaluate two feature spaces for the feature extraction module, a frequency domain and a spatial domain feature space. Our evaluation will compare both feature spaces and is carried out with 66,229 passport-scaled images (64,363 morphed face images and 1,866 authentic face images) which are completly independent from training and include all images provided for the IHMMSEC'19 special session: "Media Forensics - Fake or Real?". Furthermore, we investigate the in uence of di erent morph gen- eration pipelines to the detection accuracies of the concept and we analyse the impact of neutral and smiling genuine faces to the morph detector performance. The evaluation determines a detection rate of 86.0% for passport-scaled morphed images with a false alarm rate of 4.4% for genuine images for the spatial domain feature space Tom Neubert, Christian Krätzer, Jana Dittmann |
IH&MMSec | 2 |
| 2018 | Steganography by synthesis: Can commonplace image manipulations like face morphing create plausible steganographic channels?abstractFrom the three basic paradigms to implement steganography, the concept to realise the information hiding by modifying preexisting cover objects (i.e. steganography by modification) is by far dominating the scientific work in this field, while the other two paradigms (steganography by cover selection or -synthesis) are marginalised although they inherently create stego objects that are closer to the statistical properties of unmodified covers and therefore would create better (i.e. harder to detect) stego channels. Here, we revisit the paradigm of steganography by synthesis to discuss its benefits and limitations on the example of face morphing in images as an interesting synthesis method. Christian Krätzer, Jana Dittmann |
ARES | 1 |
| 2018 | Generalized Benford's Law for Blind Detection of Morphed Face ImagesabstractA morphed face image in a photo ID is a serious threat to image-based user verification enabling that multiple persons could be matched with the same document. The application of machine-readable travel documents (MRTD) at automated border control (ABC) gates is an example of a verification scenario that is very sensitive to this kind of fraud. Detection of morphed face images prior to face matching is, therefore, indispensable for effective border security. We introduce the face morphing detection approach based on fitting a logarithmic curve to nine Benford features extracted from quantized DCT coefficients of JPEG compressed original and morphed face images. We separately study the parameters of the logarithmic curve in face and background regions to establish the traces imposed by the morphing process. The evaluation results show that a single parameter of the logarithmic curve may be sufficient to clearly separate morphed and original images. Andrey Makrushin, Christian Krätzer, Tom Neubert, Jana Dittmann |
IH&MMSec | 2 |
| 2017 | Modeling Attacks on Photo-ID Documents and Applying Media Forensics for the Detection of Facial MorphingabstractSince 2014, a novel approach to attack face image based person verification designated as face morphing attack has been actively discussed in the biometric and media forensics communities. Up until that point, modern travel documents were considered to be extremely hard to forge or to successfully manipulate. In the case of template-targeting attacks like facial morphing, the face verification process becomes vulnerable, making it a necessity to design protection mechanisms. In this paper, a new modeling approach for face morphing attacks is introduced. We start with a life-cycle model for photo-ID documents. We extend this model by an image editing history model, allowing for a precise description of attack realizations as a foundation for performing media forensics as well as training and testing scenarios for the attack detectors. On the basis of these modeling approaches, two different realizations of the face morphing attack as well as a forensic morphing detector are implemented and evaluated. The design of the feature space for the detector is based on the idea that the blending operation in the morphing pipeline causes the reduction of face details. To quantify this reduction, we adopt features implemented in the OpenCV image processing library, namely the number of SIFT, SURF, ORB, FAST and AGAST keypoints in the face region as well as the loss of edge-information with Canny and Sobel edge operators. Our morphing detector is trained with 2000 self-acquired authentic and 2000 morphed images captured with three camera types (Canon EOS 1200D, Nikon D 3300, Nikon Coolpix A100) and tested with authentic and morphed face images from a public database. Morphing detection accuracies of a decision tree classifier vary from 81.3% to 98% for different training and test scenarios. Christian Krätzer, Andrey Makrushin, Tom Neubert, Mario Hildebrandt, Jana Dittmann |
IH&MMSec | 1 |
| 2011 | Statistical effects of selected noise characteristics on speaker recognition in automotive environments: a first ANOVA-based investigationabstractA statistical analysis using the univariate, multifactorial analysis of variance (ANOVA) is used in this paper to investigate the impact of selected noise characteristics (here a 4-factorial design: amplitude, complexity, harmony and fundamental frequency) to speech signals and consecutively to the detection performance in speaker recognition systems (exemplarily used here: the BioSecure reference system ALIZE) in automotive application scenarios. An application scenario specific set of noise signals is recorded and generated and used to evaluate the influence of the noise characteristics. The results show that especially the amplitude and the fundamental frequency show a significant impact (p-values < 0.01), which is completely independent of the features used in the speaker recognition system. The two other characteristics (complexity and harmony) show much less significant impacts (p-values >0.5). Sven Tuchscheerer, Christian Krätzer, Jana Dittmann, Tobias Hoppe |
AutomotiveUI | 2 |
| 2011 | Fingerprint Forensics Application Protocol: Semi-automated Modeling and Verification of Watermark-Based Communication Using CASPER and FDR
Ronny Merkel, Christian Krätzer, Robert Altschaffel, Eric Clausing, Maik Schott, Jana Dittmann |
IWDW | 2 |
| 2006 | Design and evaluation of steganography for voice-over-IPabstractAccording to former results from (Dittmann et al., 2005) in this paper we summarize the design principles from the general approach and introduce extended experimental test results of a voice-over-IP (VoIP) framework including a steganographic channel based on (Dittmann et al., 2005), (Dittmann and Hesse, 2004), (Kraetzer et al., 2006) and (Vogel et al., 2006). We show that using this framework it is largely secure to transmit hidden messages during a VoIP session and demonstrate results with respect to perceptibility for music and speech data Christian Krätzer, Jana Dittmann, Thomas Vogel 0002, Reyk Hillert |
ISCAS | 1 |