Sebastian Zillien

dblp:224/0409 · DBLP profile ↗
← Back
7ranked-venue papers
4as first author
7since 2021 · last 2026
0000-0003-3360-1251ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 7 · 4 first-author · 7 since 2021
YearPublicationVenuePosition
2026 A survey of internet censorship and its measurement: Methodology, trends, and challenges
abstract
Internet censorship limits the access of nodes residing within a specific network environment to the public Internet, and vice versa. During the last decade, techniques for conducting Internet censorship have been developed further. Consequently, methodology for measuring Internet censorship had been improved as well. In this paper, we firstly provide a survey of network-level Internet censorship techniques. Secondly, we survey censorship measurement methodology. We further cover the censorship of circumvention tools and its measurement, as well as available datasets. In cases where it is beneficial, we bridge the terminology and taxonomy of Internet censorship with related domains, namely traffic obfuscation and information hiding. We further extend the technical perspective with recent trends and challenges, including human aspects of Internet censorship.
Steffen Wendzel, Simon Volpert, Sebastian Zillien, Julia Lenz, Philip Rünz, Luca Caviglione
Comput. Secur.3
2025 Domainator: Detecting and Identifying DNS-Tunneling Malware Using Metadata Sequences
abstract
Abstract For a few years, malware with tunneling (or: covert channel) capabilities has been on the rise. While malware research led to several methods and innovations, the detection and differentiation of malware solely based on its DNS tunneling features is still in its infancy. Moreover, no work so far has used the DNS tunneling traffic to gain knowledge over the current actions taken by the malware. In this paper, we present , an approach to detect and differentiate state-of-the-art malware and DNS tunneling tools without relying on trivial (but quickly altered) features such as “magic bytes” that are embedded into subdomains. Instead, we apply an analysis of sequential patterns to identify specific types of malware. We evaluate our approach with 7 real-world malware samples and tunneling tools and can identify the particular malware based on its DNS traffic. We further infer the rough behavior of the particular malware through its DNS tunneling artifacts. Finally, we compare our with related methods.
Denis Petrov 0001, Pascal Ruffing, Sebastian Zillien, Steffen Wendzel
ARES (1)3
2025 DYST (Did You See That?): An Amplified Covert Channel That Points To Previously Seen Data
abstract
Covert channels are stealthy communication channels that enable manifold adversary and legitimate scenarios, ranging from stealthy malware communications to the exchange of confidential information by journalists. We present DYST, which represents a new class of covert channels we callhistory covert channelsjointly with the new paradigm of covert channelamplification. All covert channels described until now need to craft seemingly legitimate flows or need to modify third-party flows, mimicking unsuspicious behavior. In contrast, history covert channels can communicate bypointingtounaltered legitimatetraffic created by regular network nodes. Only a negligible fraction of the covert communication process requires the transfer of actual covert channel information by the covert channel's sender. This information can be sent through different protocols/channels. Our methodology allows anamplificationof the covert channel's message size, i.e., minimizing the fraction ofactually transferredsecret data by a covert channel's sender in relation to theoverallsecret data being exchanged. Further, we extend the current taxonomy for covert channels to show how history channels can be categorized. We describe multiple scenarios in which history covert channels can be realized, analyze the characteristics of these channels, and show how their configuration can be optimized.
Steffen Wendzel, Tobias Schmidbauer, Sebastian Zillien, Jörg Keller 0001
IEEE Trans. Dependable Secur. Comput.3
2024 Look What's There! Utilizing the Internet's Existing Data for Censorship Circumvention with OPPRESSION
abstract
An ongoing challenge in censorship circumvention is optimizing the stealthiness of communications, enabled by covert channels. Recently, a new variant called history covert channels has been proposed. Instead of modifying or mimicking legitimate data, such channels solely point to observed data matching secret information. This approach reduces the amount of secret data a sender explicitly must transfer and thus limits detectability. However, the only published history channel is only suitable for special scenarios due to severe limitations in terms of bandwidth. We propose a significant performance enhancement of history covert channels that allows their use in real-world scenarios through utilizing the content of online social media and online archives. Our approach, which we call OPPRESSION (Open-knowledge Compression), takes advantage of the massive amounts of textual data on the Internet that can be referenced by short pointer messages. Broadly, OPPRESSION can be considered a novel encoding strategy for censorship circumvention.
Sebastian Zillien, Tobias Schmidbauer, Mario Kubek, Jörg Keller 0001, Steffen Wendzel
AsiaCCS1
2024 A Development Framework for TCP/IP Network Steganography Malware Detection
abstract
Stegomalware poses a rising threat in the security landscape as more and more malware samples use steganography to disguise their network traffic, rendering traditional detection approaches less and less useful. To detect such advanced threats, it is important to identify and focus on unique characteristics of stegomalware. We present a new malware detection framework tailored for stegomalware nested in TCP/IP protocols. With the framework, we are able to observe real malware in a secure environment, use the gained insights to create realistic simulations, extract relevant characteristics and perform detection based on the gained data. The goal of the framework is to enable and streamline the process of developing new detection methods.
Sebastian Zillien, Denis Petrov 0001, Pascal Ruffing, Friedrich Gross
IH&MMSec1
2023 Weaknesses of Popular and Recent Covert Channel Detection Methods and a Remedy
abstract
Network covert channels are applied for the secret exfiltration of confidential data, the stealthy operation of malware, and legitimate purposes, such as censorship circumvention. In recent decades, some major detection methods for network covert channels have been developed. In this paper, we investigate two highly cited detection methods for covert timing channels, namely$\epsilon$-similarity and compressibility score from Cabuk et al. (jointly cited by 930 papers and applied by thousands of researchers). We additionally analyze two recent ML-based detection methods:GAS(2022) andSnapCatch(2021). While all these detection methods must be considered valuable for the analysis of typical covert timing channels, we show that these methods are not reliable when a covert channel's behavior is slightly modified. In particular, we demonstrate that when confronted with a simple covert channel that we call$\epsilon$-$\kappa$libur, all detection methods can be circumvented or their performance can be significantly reduced although the covert channel still provides a high bitrate. In comparison to previous timing channels that circumvent these methods,$\epsilon$-$\kappa$libur is much simpler and eliminates the need of altering previously recorded traffic. Moreover, we propose an enhanced$\epsilon$-similarity that can detect the classical covert timing channel as well as$\epsilon$-$\kappa$libur.
Sebastian Zillien, Steffen Wendzel
IEEE Trans. Dependable Secur. Comput.1
2021 Reconnection-Based Covert Channels in Wireless Networks
Sebastian Zillien, Steffen Wendzel
SEC1