VLDB 2026 Research / reviewers in the wild / expert
Marcel Kneib
dblp:208/7179
· DBLP profile ↗
5ranked-venue papers
2as first author
2since 2021 · last 2023
0000-0002-2327-7059ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 5 · 2 first-author · 2 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2023 | SPARTA: Signal Propagation-based Attack Recognition and Threat Avoidance for Automotive NetworksabstractWith wider availability of wireless interfaces and a rising integration of software, it becomes easier for attackers to access vehicular communication networks and exploit vulnerabilities in Electronic Control Units (ECUs). Once having compromised an ECU, the intruder can control safety-relevant functions without requiring physical access to the vehicle. An essential aspect for the feasibility of such attacks is the lack of security measures in the Controller Area Network (CAN). And although physical-based Intrusion Detection Systems (IDSs) gain relevance for CAN security, current voltage and time-based systems have reached a point where crucial improvements can only be achieved at intolerable expense. To assess the potential of novel approaches, we present SPARTA, an advanced Intrusion Detection and Prevention System (IDPS) which identifies the sending ECU by measuring signal arrival differences on the CAN bus. With a highly reliable detection procedure, SPARTA improves current IDSs and implements an active prevention mechanism to decimate the impact of attacks. In this context, it not only detects violations of the transmission authenticity, but also recognizes the attempt of a denial-of-service (DoS) attack. Further, SPARTA was designed to require few resources and to meet real-time constraints of automotive systems. For this reason, the entire approach was realized on a resource-constrained embedded system and evaluated on different CAN and CAN with Flexible Data-Rate (CAN-FD) setups to demonstrate the efficiency, performance and adaptability to external influences of a dynamic environment. Oleg Schell, Marcel Kneib |
AsiaCCS | 2 |
| 2022 | Asymmetric Symbol and Skew Sender Identification for Automotive NetworksabstractOver recent years, many vulnerabilities have been exposed in vehicles, whose probability of occurrence will rise in the future due to connectivity and increasing system complexity. Even more serious that the Controller Area Network (CAN), widely used by Electronic Control Units (ECUs) to exchange safety-critical messages within a vehicle, does not provide any security measures. In this context, Intrusion Detection Systems (IDSs) have recently been proposed that use time characteristics in the analog transmission signal to identify the sending ECU and detect unauthorized messages. However, realistic application of proposed approaches is not yet tangible, with the full potential of time-based systems yet to be determined. In this elaboration, we therefore establish a foundation by working out robust time characteristics first and analyze root causes for their variation between ECUs. Combining the results with insights from related research, we deduce properties which help to design reliable and feasible IDSs for CAN. Finally, we emphasize these properties by presenting ASSASSIN, an IDS that uses time characteristics to identify the sender of a CAN message and assess authenticity. Achieving an average detection rate of 99.02 %, real-time capable classification and an adaptability to temperature fluctuations, we demonstrate the potential of time-based IDSs on a prototype setup and a real vehicle using resource-limited hardware, also contrasting them with well-elaborated voltage-based IDSs. Oleg Schell, Claudio Oechsler, Marcel Kneib |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2020 | EASI: Edge-Based Sender Identification on Resource-Constrained Platforms for Automotive Networks
Marcel Kneib, Oleg Schell, Christopher Huth |
NDSS | 1 |
| 2020 | VALID: Voltage-Based Lightweight Intrusion Detection for the Controller Area NetworkabstractThe Controller Area Network (CAN), a broadcasting bus for intra-vehicle communication, does not provide any security mechanisms, although it is implemented in almost every vehicle. Attackers can exploit this issue, transmit malicious messages unnoticeably and cause severe harm. As the utilization of Message Authentication Codes (MACs) is only possible to a limited extent in resource-constrained systems, the focus is put on the development of Intrusion Detection Systems (IDSs). Due to their simple idea of operation, current developments are increasingly utilizing physical signal properties like voltages to realize these systems. Although the feasibility for CAN-based networks could be demonstrated, the least approaches consider the constrained resource-availability of vehicular hardware. To close this gap, we present Voltage-Based Lightweight Intrusion Detection (VALID), which provides physics-based intrusion detection with low resource requirements. By utilizing solely the individual voltage levels on the network during communication, the system detects unauthorized message transmissions without any sophisticated sampling approaches and feature calculations. Having performed evaluations on data from two real vehicles, we show that VALID is not only able to detect intrusions with an accuracy of 99.54 %, but additionally is capable of identifying the attack source reliably. These properties make VALID one of the most lightweight intrusion detection approaches that is ready-to-use, as it can be easily implemented on hardware already installed in vehicles and does not require any further components. Additionally, this allows existing platforms to be retrofitted and vehicular security systems to be improved and extended. Oleg Schell, Marcel Kneib |
TrustCom | 2 |
| 2018 | Scission: Signal Characteristic-Based Sender Identification and Intrusion Detection in Automotive NetworksabstractIncreased connectivity increases the attack vector. This also applies to connected vehicles in which vulnerabilities not only threaten digital values but also humans and the environment. Typically, attackers try to exploit the Controller Area Network (CAN) bus, which is the most widely used standard for internal vehicle communication. Once an Electronic Control Unit (ECU) connected to the CAN bus is compromised, attackers can manipulate messages at will. The missing sender authentication by design of the CAN bus enables adversarial access to vehicle functions with severe consequences. In order to address this problem, we propose Scission, an Intrusion Detection System (IDS) which uses fingerprints extracted from CAN frames, enabling the identification of sending ECUs. Scission utilizes physical characteristics from analog values of CAN frames to assess whether it was sent by the legitimate ECU. In addition, to detect comprised ECUs, the proposed system is able to recognize attacks from unmonitored and additional devices. We show that Scission is able to identify the sender with an average probability of 99.85%, during the evaluation on two series production cars and a prototype setup. Due to the robust design of the system, the evaluation shows that all false positives were prevented. Compared to previous approaches, we have significantly reduced hardware costs and increased identification rates, which enables a broad application of this technology. Marcel Kneib, Christopher Huth |
CCS | 1 |