VLDB 2026 Research / reviewers in the wild / expert
Stefan Tatschner
dblp:205/2160
· DBLP profile ↗
3ranked-venue papers
2as first author
2since 2021 · last 2024
0000-0002-2288-9010ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 2 · 2 first-author · 2 since 2021Systems, architecture and hardware · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | ParsEval: Evaluation of Parsing Behavior using Real-world Out-in-the-wild X.509 CertificatesabstractX.509 certificates play a crucial role in establishing secure communication over the internet by enabling authentication and data integrity. Equipped with a rich feature set, the X.509 standard is defined by multiple, comprehensive ISO/IEC documents. Due to its internet-wide usage, there are different implementations in multiple programming languages leading to a large and fragmented ecosystem. This work addresses the research question “Are there user-visible and security-related differences between X.509 certificate parsers?”. Relevant libraries offering APIs for parsing X.509 certificates were investigated and an appropriate test suite was developed. From 34 libraries 6 were chosen for further analysis. The X.509 parsing modules of the chosen libraries were called with 186,576,846 different certificates from a real-world dataset and the observed error codes were investigated. This study reveals an anomaly in wolfSSL’s X.509 parsing module and that there are fundamental differences in the ecosystem. While related studies nowadays mostly focus on fuzzing techniques resulting in artificial certificates, this study confirms that available X.509 parsing modules differ largely and yield different results, even for real-world out-in-the-wild certificates. Stefan Tatschner, Sebastian N. Peters, Michael P. Heinl, Tobias Specht, Thomas Newe |
ARES | 1 |
| 2023 | A Quic(k) Security Overview: A Literature Research on Implemented Security RecommendationsabstractBuilt on top of UDP, the relatively new QUIC protocol serves as the baseline for modern web protocol stacks. Equipped with a rich feature set, the protocol is defined by a 151 pages strong IETF standard complemented by several additional documents. Enabling fast updates and feature iteration, most QUIC implementations are implemented as user space libraries leading to a large and fragmented ecosystem. This work addresses the research question, “if a complex standard with a large number of different implementations leads to an insecure ecosystem?”. The relevant RFC documents were studied and “Security Consideration” items describing conceptional problems were extracted. During the research, 13 popular production ready QUIC implementations were compared by evaluating 10 security considerations from RFC9000. While related studies mostly focused on the functional part of QUIC, this study confirms that available QUIC implementations are not yet mature enough from a security point of view. Stefan Tatschner, Sebastian N. Peters, David Emeis, John Morris, Thomas Newe |
ARES | 1 |
| 2019 | Securing future decentralised industrial IoT infrastructures: Challenges and free open source solutions
Sven Plaga, Norbert Wiedermann, Simon Duque Antón, Stefan Tatschner, Hans D. Schotten, Thomas Newe |
Future Gener. Comput. Syst. | 4 |