VLDB 2026 Research / reviewers in the wild / expert
Konrad Wolsing
dblp:215/5849
· DBLP profile ↗
16ranked-venue papers
7as first author
12since 2021 · last 2026
0000-0002-7571-0555ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 9 · 5 first-author · 7 since 2021Computer networks · 6 · 2 first-author · 4 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | A Deep Dive into Wormhole Attacks in Underwater Acoustic Communication: From Theory to Practiceabstract256 Luisa Lux, Eric Wagner 0003, Konrad Wolsing, Ulrike Meyer |
WISEC | 4 |
| 2025 | Sherlock: A Dataset for Process-aware Intrusion Detection Research on Power Grid Networks: Dataset Paperabstract419 Eric Wagner 0003, Lennart Bader, Konrad Wolsing, Martin Serror |
CODASPY | 3 |
| 2025 | Detecting Ransomware Despite I/O Overhead: A Practical Multi-Staged Approach
Christian van Sloun, Vincent Woeste, Konrad Wolsing, Jan Pennekamp, Klaus Wehrle |
NDSS | 3 |
| 2025 | GeCos Replacing Experts: Generalizable and Comprehensible Industrial Intrusion Detection
Konrad Wolsing, Eric Wagner 0003, Luisa Lux, Klaus Wehrle, Martin Henze |
USENIX Security Symposium | 1 |
| 2024 | Demo: Maritime Radar Systems under Attack. Help is on the Way!abstractFor a long time, attacks on radar systems were limited to military targets. With increasing interconnection, cyber attacks have nowadays become a serious complementary threat also affecting civil radar systems for aviation traffic control or maritime navigation. Hence, operators need to be enabled to detect and respond to cyber attacks and must be supported by defense capabilities. However, security research in this domain is only just beginning and is hampered by a lack of adequate test and development environments. In this demo, we thus present a maritime Radar Cyber Security Lab (RCSL) as a holistic framework to identify vulnerabilities of navigation radars and to support the development of defensive solutions. RCSL offers an offensive tool for attacking navigation radars and a defensive module leveraging network-based anomaly detection. In our demonstration, we will showcase the radars’ vulnerabilities in a simulative environment and demonstrate the benefit of an application-specific Intrusion Detection System. Frederik Basels, Konrad Wolsing, Elmar Gerhards-Padilla |
LCN | 2 |
| 2023 | One IDS Is Not Enough! Exploring Ensemble Learning for Industrial Intrusion Detection
Konrad Wolsing, Dominik Kus, Eric Wagner 0003, Jan Pennekamp, Klaus Wehrle, Martin Henze |
ESORICS (2) | 1 |
| 2023 | Retrofitting Integrity Protection into Unused Header Fields of Legacy Industrial ProtocolsabstractIndustrial networks become increasingly interconnected, which opens the floodgates for cyberattacks on legacy networks designed without security in mind. Consequently, the vast landscape of legacy industrial communication protocols urgently demands a universal solution to integrate security features retroactively. However, current proposals are hardly adaptable to new scenarios and protocols, even though most industrial protocols share a common theme: Due to their progressive development, previously important legacy features became irrelevant and resulting unused protocol fields now offer a unique opportunity for retrofitting security. Our analysis of three prominent protocols shows that headers offer between 36 and 63 bits of unused space. To take advantage of this space, we designed the REtrofittable ProtEction Library (RePeL), which supports embedding authentication tags into arbitrary combinations of unused header fields. We show that RePeL incurs negligible overhead beyond the cryptographic processing, which can be adapted to hit performance targets or fulfill legal requirements. Eric Wagner 0003, Nils Rothaug, Konrad Wolsing, Lennart Bader, Klaus Wehrle, Martin Henze |
LCN | 3 |
| 2023 | XLab-UUV - A Virtual Testbed for Extra-Large Uncrewed Underwater VehiclesabstractRoughly two-thirds of our planet is covered with water, and so far, the oceans have predominantly been used at their surface for the global transport of our goods and commodities. Today, there is a rising trend toward subsea infrastructures such as pipelines, telecommunication cables, or wind farms which demands potent vehicles for underwater work. To this end, a new generation of vehicles, large and Extra-Large Unmanned Underwater Vehicles (XLUUVs), is currently being engineered that allow for long-range, remotely controlled, and semi-autonomous missions in the deep sea. However, although these vehicles are already heavily developed and demand state-of-the-art communication technologies to realize their autonomy, no dedicated test and development environments exist for research, e.g., to assess the implications on cybersecurity. Therefore, in this paper, we present XLab-UUV, a virtual testbed for XLUUVs that allows researchers to identify novel challenges, possible bottlenecks, or vulnerabilities, as well as to develop effective technologies, protocols, and procedures. Konrad Wolsing, Antoine Saillard, Elmar Gerhards-Padilla |
LCN | 1 |
| 2022 | Can Industrial Intrusion Detection Be SIMPLE?
Konrad Wolsing, Lea Thiemt, Christian van Sloun, Eric Wagner 0003, Klaus Wehrle, Martin Henze |
ESORICS (3) | 1 |
| 2022 | Network Attacks Against Marine Radar Systems: A Taxonomy, Simulation Environment, and DatasetabstractShipboard marine radar systems are essential for safe navigation, helping seafarers perceive their surroundings as they provide bearing and range estimations, object detection, and tracking. Since onboard systems have become increasingly digitized, interconnecting distributed electronics, radars have been integrated into modern bridge systems. But digitization increases the risk of cyberattacks, especially as vessels cannot be considered air-gapped. Consequently, in-depth security is crucial. However, particularly radar systems are not sufficiently protected against harmful network-level adversaries. Therefore, we ask: Can seafarers believe their eyes? In this paper, we identify possible attacks on radar communication and discuss how these threaten safe vessel operation in an attack taxonomy. Furthermore, we develop a holistic simulation environment with radar, complementary nautical sensors, and prototypically implemented cyberattacks from our taxonomy. Finally, leveraging this environment, we create a comprehensive dataset (RadarPWN) with radar network attacks that provides a foundation for future security research to secure marine radar communication. Konrad Wolsing, Antoine Saillard, Eric Wagner 0003, Christian van Sloun, Ina Berenice Fink, Mari Schmidt, Klaus Wehrle, Martin Henze |
LCN | 1 |
| 2022 | IPAL: Breaking up Silos of Protocol-dependent and Domain-specific Industrial Intrusion Detection SystemsabstractThe increasing interconnection of industrial networks exposes them to an ever-growing risk of cyber attacks. To reveal such attacks early and prevent any damage, industrial intrusion detection searches for anomalies in otherwise predictable communication or process behavior. However, current efforts mostly focus on specific domains and protocols, leading to a research landscape broken up into isolated silos. Thus, existing approaches cannot be applied to other industries that would equally benefit from powerful detection. To better understand this issue, we survey 53 detection systems and find no fundamental reason for their narrow focus. Although they are often coupled to specific industrial protocols in practice, many approaches could generalize to new industrial scenarios in theory. To unlock this potential, we propose IPAL, our industrial protocol abstraction layer, to decouple intrusion detection from domain-specific industrial protocols. After proving IPAL’s correctness in a reproducibility study of related work, we showcase its unique benefits by studying the generalizability of existing approaches to new datasets and conclude that they are indeed not restricted to specific domains or protocols and can perform outside their restricted silos. Konrad Wolsing, Eric Wagner 0003, Antoine Saillard, Martin Henze |
RAID | 1 |
| 2021 | SIGMAR: Ensuring Integrity and Authenticity of Maritime Systems using Digital SignaturesabstractDistributed maritime bridge systems are customary standard equipment on today’s commercial shipping and cruising vessels. The exchange of nautical data, e.g., geographical positions, is usually implemented using multicast network communication without security measures, which poses serious risks to the authenticity and integrity of transmitted data. In this paper, we introduce digital SIGnatures for MARitime systems (SIGMAR), a low-cost solution to seamlessly retrofit authentication of nautical data based on asymmetric cryptography. Extending the existing IEC 61162-450 protocol makes it is possible to build a backward-compatible authentication mechanism that prevents common cyber attacks. The development was successfully accompanied by permanent investigations in a bridge simulation environment, including a maritime cyber attack generator. We demonstrate SIGMAR’s feasibility by introducing a proof-of-concept implementation on low-cost and low-resource hardware and present a performance analysis of our approach. Christian Hemminghaus, Konrad Wolsing |
ISNCC | 3 |
| 2020 | Facilitating Protocol-independent Industrial Intrusion Detection SystemsabstractCyber-physical systems are increasingly threatened by sophisticated attackers, also attacking the physical aspect of systems. Supplementing protective measures, industrial intrusion detection systems promise to detect such attacks. However, due to industrial protocol diversity and lack of standard interfaces, great efforts are required to adapt these technologies to a large number of different protocols. To address this issue, we identify existing universally applicable intrusion detection approaches and propose a transcription for industrial protocols to realize protocol-independent semantic intrusion detection on top of different industrial protocols. Konrad Wolsing, Eric Wagner 0003, Martin Henze |
CCS | 1 |
| 2019 | Perceiving QUIC: do users notice or even care?abstractQUIC, as the foundation for HTTP/3, is becoming an Internet reality. A plethora of studies already show that QUIC excels beyond TCP+ TLS+HTTP/2. Yet, these studies compare a highly optimized QUIC Web stack against an unoptimized TCP-based stack. In this paper, we bring TCP up to speed to perform an eye-level comparison. Instead of relying on technical metrics, we perform two extensive user studies to investigate QUIC's impact on the quality of experience. First, we investigate if users can distinguish two protocol versions in a direct comparison, and we find that QUIC is indeed rated faster than TCP and even a tuned TCP. Yet, our second study shows that this perceived performance increase does mostly not matter to the users, and they rate QUIC and TCP indistinguishable. Jan Rüth, Konrad Wolsing, Klaus Wehrle, Oliver Hohlfeld |
CoNEXT | 2 |
| 2018 | Digging into Browser-based Crypto Mining
Jan Rüth, Torsten Zimmermann, Konrad Wolsing, Oliver Hohlfeld |
Internet Measurement Conference | 3 |
| 2018 | Characterizing a Meta-CDN
Oliver Hohlfeld, Jan Rüth, Konrad Wolsing, Torsten Zimmermann |
PAM | 3 |