Alexander Giehl

dblp:223/3060 · DBLP profile ↗
← Back
3ranked-venue papers
1as first author
2since 2021 · last 2024
0000-0001-7648-3895ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 3 · 1 first-author · 2 since 2021
YearPublicationVenuePosition
2024 EmuFlex: A Flexible OT Testbed for Security Experiments with OPC UA
abstract
Modern communication standards for the Industrial Internet of Things (IIoT) like the Open Platform Communications Unified Architecture (OPC UA) were developed with security in mind. However, their correct implementation in operational technology (OT) environments is often neglected due to a lack of appropriate monetary and human resources, especially among small and medium-sized enterprises. We present a flexible, inexpensive, and easy to use testbed enabling OT operators to experiment with different security scenarios. Our testbed is purely virtual so that procurement and construction of physical or hybrid test environments is not required. It can be operated as a web-hosted service and leverages Docker as well as OPC UA. The testbed therefore combines usability and support for modern technologies enabling future-oriented security studies as well as flexible usage across verticals and company boundaries.
Alexander Giehl, Michael P. Heinl, Victor Embacher
ARES1
2023 From Standard to Practice: Towards ISA/IEC 62443-Conform Public Key Infrastructures
Michael P. Heinl, Maximilian Pursche, Nikolai Puch, Sebastian N. Peters, Alexander Giehl
SAFECOMP5
2020 AntiPatterns regarding the application of cryptographic primitives by the example of ransomware
abstract
Cryptographic primitives are the basic building blocks for many cryptographic schemes and protocols. Implementing them incorrectly can lead to flaws, making a system or a product vulnerable to various attacks. As shown in the present paper, this statement also applies to ransomware. The paper surveys common errors occurring during the implementation of cryptographic primitives. Based on already existing research, it establishes a categorization framework to match selected ransomware samples by their respective vulnerabilities and assign them to the corresponding error categories. Subsequently, AntiPatterns are derived from the extracted error categories. These AntiPatterns are meant to support the field of software development by helping to detect and correct errors early during the implementation phase of cryptography.
Michael P. Heinl, Alexander Giehl, Lukas Graif
ARES2