VLDB 2026 Research / reviewers in the wild / expert
Tobias Urban
dblp:224/4499
· DBLP profile ↗
18ranked-venue papers
6as first author
12since 2021 · last 2025
0000-0003-0908-0038ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 14 · 5 first-author · 9 since 2021Databases, data management, data science and information retrieval · 3 · 1 first-author · 2 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 1 first-author · 1 since 2021Systems, architecture and hardware · 1 · 1 since 2021Computer networks · 1 · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Different Seas, Different Phishes - Large-Scale Analysis of Phishing Simulations Across Different Industries
Oskar Braun, Jan Hörnemann, Norbert Pohlmann, Tobias Urban, Matteo Große-Kampmann |
AsiaCCS | 4 |
| 2025 | Padding Matters - Exploring Function Detection in PE Files: Data/Toolset paperabstractFunction detection is a well-known problem in binary analysis. While prior work has focused on Linux/ELF, Windows/PE binaries have only partially been considered. This paper introduces FuncPEval, a dataset for Windows x86 and x64 PE files, featuring Chromium and the Conti ransomware, along with ground truth data for 1,092,820 function starts. Utilizing FuncPEval, we evaluate five heuristics-based (Ghidra, IDA, Nucleus, rev.ng, SMDA) and three machine-learning-based (DeepDi, RNN, XDA) function start detection tools. Among these, IDA achieves the highest F1-score (98.44%) for Chromium x64, while DeepDi closely follows (97%) but stands out as the fastest. Towards explainability, we examine the impact of padding between functions on the detection results, finding all tested tools, except rev.ng, are susceptible to randomized padding. The randomized padding significantly diminishes the effectiveness of the RNN, XDA, and Nucleus. Among the learning-based tools, DeepDi exhibits the least sensitivity, while Nucleus is the most adversely affected among the non-learning-based tools. Raphael Springer, Alexander Schmitz, Artur Leinweber, Tobias Urban, Christian Dietrich 0005 |
CODASPY | 4 |
| 2025 | Privacy from 5 PM to 6 AM: Tracking and Transparency Mechanisms in the HbbTV EcosystemabstractHybrid broadcast broadband television (HbbTV) is an evolving technology that connects linear TV with modern HTML5 applications, delivering extras like games, videos, and online shopping. However, its bidirectional transmission functionality raises privacy concerns, as it introduces new tracking methods for TV channels. While previous studies focused on security issues or user awareness of HbbTV privacy challenges, a detailed examination of the tracking and transparency mechanisms of the HbbTV ecosystem is still missing. This study fills this gap by extensively analyzing these features within the European HbbTV ecosystem, and in particular within German-language TV channels. We monitored more than 350 TV channels for over 400 hours, evaluating 1) prevalent HbbTV tracking methods, 2) consent notice prevalence and user interactions, and 3) privacy policy disclosures. Our findings indicate that the HbbTV tracking system operates independently of the Web, consent notices exploit system constraints to influence users, and privacy policies often do not align with actual data practices. Christian Böttger, Henry Hosseini, Christine Utz, Nurullah Demir, Jan Hörnemann, Christian Wressnegger, Thomas Hupperich, Norbert Pohlmann, Matteo Große-Kampmann, Tobias Urban |
DSN | 10 |
| 2025 | Understanding Regional Filter Lists: Efficacy and ImpactabstractFilter lists are used by various users, tools, and researchers to identify tracking technologies on the Web. These lists are created and maintained by dedicated communities. Aside from popular blocking lists (e.g., EasyList), the communities create region-specific blocklists that account for trackers and ads that are only common in these regions. The lists aim to keep the size of a general blocklist minimal while protecting users against region-specific trackers. In this paper, we perform a large-scale Web measurement study to understand how different region-specific filter lists (e.g., a blocklist specifically designed for French users) protect users when visiting websites. We define three privacy scenarios to understand when and how users benefit from these regional lists and what effect they have in practice. The results show that although the lists differ significantly, the number of rules they contain is unrelated to the number of blocked requests. We find that the lists' overall efficacy varies notably. Filter lists also do not meet the expectation that they increase user protection in the regions for which they were designed. Finally, we show that the majority of the rules on the lists were not used in our experiment and that only a fraction of the rules would provide comparable protection for users. Christian Böttger, Nurullah Demir, Jan Hörnemann, Bhupendra Acharya, Norbert Pohlmann, Thorsten Holz, Matteo Große-Kampmann, Tobias Urban |
Proc. Priv. Enhancing Technol. | 8 |
| 2024 | Comparing Apples to Androids: Discovery, Retrieval, and Matching of iOS and Android Apps for Cross-Platform AnalysesabstractFor years, researchers have been analyzing mobile Android apps to investigate diverse properties such as software engineering practices, business models, security, privacy, or usability, as well as differences between marketplaces. While similar studies on iOS have been limited, recent work has started to analyze and compare Android apps with those for iOS. To obtain the most representative analysis results across platforms, the ideal approach is to compare their characteristics and behavior for the same set of apps, e. g., to study a set of apps for iOS and their respective counterparts for Android. Previous work has only attempted to identify and evaluate such cross-platform apps to a limited degree, mostly comparing sets of apps independently drawn from app stores, manually matching small sets of apps, or relying on brittle matches based on app and developer names. This results in (1) comparing apps whose behavior and properties significantly differ, (2) limited scalability, and (3) the risk of matching only a small fraction of apps. Magdalena Steinböck, Jakob Bleier, Mikka Rainer, Tobias Urban, Christine Utz, Martina Lindorfer |
MSR | 4 |
| 2024 | A Large-Scale Study of Cookie Banner Interaction Tools and their Impact on Users' PrivacyabstractCookie notices (or cookie banners) are a popular mechanism for websites to provide (European) Internet users a tool to choose which cookies the site may set. Banner implementations range from merely providing information that a site uses cookies over offering the choice to accepting or denying all cookies to allowing fine-grained control of cookie usage. Users frequently get annoyed by the banner's pervasiveness as they interrupt ''natural'' browsing on the Web. As a remedy, different browser extensions have been developed to automate the interaction with cookie banners. In this work, we perform a large-scale measurement study comparing the effectiveness of extensions for ''cookie banner interaction.'' We configured the extensions to express different privacy choices (e.g., accepting all cookies, accepting functional cookies, or rejecting all cookies) to understand their capabilities to execute a user's preferences. The results show statistically significant differences in which cookies are set, how many of them are set, and which types are set---even for extensions that aim to implement the same cookie choice. Extensions for ''cookie banner interaction'' can effectively reduce the number of set cookies compared to no interaction with the banners. However, all extensions increase the tracking requests significantly except when rejecting all cookies. Nurullah Demir, Tobias Urban, Norbert Pohlmann, Christian Wressnegger |
Proc. Priv. Enhancing Technol. | 2 |
| 2023 | On the Similarity of Web Measurements Under Different Experimental Setups
Nurullah Demir, Jan Hörnemann, Matteo Große-Kampmann, Tobias Urban, Norbert Pohlmann, Thorsten Holz, Christian Wressnegger |
IMC | 4 |
| 2022 | Reproducibility and Replicability of Web Measurement StudiesabstractWeb measurement studies can shed light on not yet fully understood phenomena and thus are essential for analyzing how the modern Web works. This often requires building new and adjusting existing crawling setups, which has led to a wide variety of analysis tools for different (but related) aspects. If these efforts are not sufficiently documented, the reproducibility and replicability of the measurements may suffer—two properties that are crucial to sustainable research. In this paper, we survey 117 recent research papers to derive best practices for Web-based measurement studies and specify criteria that need to be met in practice. When applying these criteria to the surveyed papers, we find that the experimental setup and other aspects essential to reproducing and replicating results are often missing. We underline the criticality of this finding by performing a large-scale Web measurement study on 4.5 million pages with 24 different measurement setups to demonstrate the influence of the individual criteria. Our experiments show that slight differences in the experimental setup directly affect the overall results and must be documented accurately and carefully. Nurullah Demir, Matteo Große-Kampmann, Tobias Urban, Christian Wressnegger, Thorsten Holz, Norbert Pohlmann |
WWW | 3 |
| 2022 | "We may share the number of diaper changes": A Privacy and Security Analysis of Mobile Child Care ApplicationsabstractMobile child care management applications can help child care facilities, preschools, and kindergartens to save time and money by allowing their employees to speed up everyday child care tasks using mobile devices. Such apps often allow child care workers to communicate with parents or guardians, sharing their children’s most private data (e. g., activities, photos, location, developmental aspects, and sometimes even medical information). To offer these services, child care apps require access to very sensitive data of minors that should never be shared over insecure channels and are subject to restrictive privacy laws. This work analyzes the privacy and security of 42 Android child care applications and their cloud-backends using a combination of static and dynamic analysis frameworks, configuration scanners, and inspecting their privacy policies. The results of our analysis show that while children do not use these apps, they can leak sensitive data about them. Alarming are the findings that many third-party (tracking) services are embedded in the applications and that adversaries can access personal data by abusing vulnerabilities in the applications. We hope our work will raise awareness about the privacy risks introduced by these applications and that regulatory authorities will focus more on these risks in the future. Moritz Gruber, Christian Höfig, Maximilian Golla, Tobias Urban, Matteo Große-Kampmann |
Proc. Priv. Enhancing Technol. | 4 |
| 2022 | Investigating GDPR Fines in the Light of Data FlowsabstractWhile GDPR related fines to big companies like Amazon or Google have seen widespread media attention, data protection authorities have issued several hundred more penalties since 2018. This work analyzes 856 fines and their summaries provided by the CMS Law GDPR Enforcement Tracker. We extend the methodology of previous work that evaluated GDPR fines and, in particular, explore the fines in the light of data flows and we perform a detailed categorization. Our analysis shows that it is a combination of technical and organizational issues that are involved when a fine is imposed. Moreover, data protection authorities more often react to data subjects’ complaints when data breaches become public and when health-related data is involved. We further show that the root causes for fined data processing lie in the early data life cycle phases (e.g., data collection). Here, organizational problems are more prevalent (601 fines) than technical issues (314 fines), while technical issues are mentioned more often in later life cycle phases (e.g., retention, access and usage). Especially mistakes in the early phases of the data collection process (e.g., lacking a legal basis) and unauthorized disclosure in later phases are fined. We cluster the most frequent words and analyze relations to understand where data controllers put personal data at risk. The results confirm that access management is a common problem that results in the unintended disclosure of data. Marlene Saemann, Daniel Theis, Tobias Urban, Martin Degeling |
Proc. Priv. Enhancing Technol. | 3 |
| 2021 | Reining in the Web's Inconsistencies with Site Policy
Stefano Calzavara, Tobias Urban, Dennis Tatang, Marius Steffens, Ben Stock |
NDSS | 2 |
| 2021 | Our (in)Secure Web: Understanding Update Behavior of Websites and Its Impact on Security
Nurullah Demir, Tobias Urban, Kevin Wittek, Norbert Pohlmann |
PAM | 2 |
| 2020 | Measuring the Impact of the GDPR on Data Sharing in Ad NetworksabstractThe European General Data Protection Regulation (GDPR), which went into effect in May 2018, brought new rules for the processing of personal data that affect many business models, including online advertising. The regulation's definition of personal data applies to every company that collects data from European Internet users. This includes tracking services that, until then, argued that they were collecting anonymous information and data protection requirements would not apply to their businesses. Previous studies have analyzed the impact of the GDPR on the prevalence of online tracking, with mixed results. In this paper, we go beyond the analysis of the number of third parties and focus on the underlying information sharing networks between online advertising companies in terms of client-side cookie syncing. Using graph analysis, our measurement shows that the number of ID syncing connections decreased by around 40% around the time the GDPR went into effect, but a long-term analysis shows a slight rebound since then. While we can show a decrease in information sharing between third parties, which is likely related to the legislation, the data also shows that the amount of tracking, as well as the general structure of cooperation, was not affected. Consolidation in the ecosystem led to a more centralized infrastructure that might actually have negative effects on user privacy, as fewer companies perform tracking on more sites. Tobias Urban, Dennis Tatang, Martin Degeling, Thorsten Holz, Norbert Pohlmann |
AsiaCCS | 1 |
| 2020 | Plenty of Phish in the Sea: Analyzing Potential Pre-attack Surfaces
Tobias Urban, Matteo Große-Kampmann, Dennis Tatang, Thorsten Holz, Norbert Pohlmann |
ESORICS (2) | 1 |
| 2020 | Beyond the Front Page: Measuring Third Party Dynamics in the FieldabstractIn the modern Web, service providers often rely heavily on third parties to run their services. For example, they make use of ad networks to finance their services, externally hosted libraries to develop features quickly, and analytics providers to gain insights into visitor behavior. Tobias Urban, Martin Degeling, Thorsten Holz, Norbert Pohlmann |
WWW | 1 |
| 2019 | "Your hashed IP address: Ubuntu.": perspectives on transparency tools for online advertisingabstractAd personalization has been criticized in the past for invading privacy, lack of transparency, and improper controls offered to users. Recently, companies started to provide web portals and other means for users to access data collected about them. In this paper, we study these new transparency tools from multiple perspectives using a mixed-methods approach. Still practices of data sharing barely changed until recently when new legislation required all companies to grant individual access to personal data stored about them. Using a mixed-methods approach we study the benefits of the new rights for users. First, we analyze transparency tools provided by 22 companies and check whether they follow previous recommendations for usability and user expectations. Based on these insights, we conduct a survey with 490 participants to evaluate three common approaches to disclose data. To complement this user-centric view, we shed light on the design decisions and complexities of transparency in online advertising using an online survey (n = 24) and in-person interviews (n = 8) with experts from the industry. We find that newly created transparency tools present a variety of information to users, from detailed technical logs to high-level interest segment information. Our results indicate that users do not (yet) know what to learn from the data and mistrust the accuracy of the information shown to them. At the same time, new transparency requirements pose several challenges to an industry that excessively shares data that even they sometimes cannot relate to an individual. Tobias Urban, Martin Degeling, Thorsten Holz, Norbert Pohlmann |
ACSAC | 1 |
| 2019 | Analyzing leakage of personal information by malwareabstractAdvertisements are the fuel that runs many online services such as websites or mobile apps, but also adversaries started to abuse ads for financial gains. Nowadays, online advertising companies track users all over the web in order to create successful online ads campaigns specifically tailored for a target audience. A popular phenomenon on the Internet, so-called adware, abuses online advertisements by maliciously injecting or replacing ads on websites. As many consider ads to be quite privacy intrusive, much work has gone into studying the effects of online advertisements on users’ privacy. However, only little work has been done so far into analyzing the privacy implications of adware. In this work, we shed light on the capabilities, mainly concerning tracking and personal data exfiltrating, of adware and potentially unwanted programs (PUPs), at scale. To this end, we capture the communication of adware/PUPs in the Firefox browser on the application level to circumvent lower-level encryption (e.g., TLS). Using this framework for capturing the network traffic, we dynamically analyze the communication of over 16,000 adware or potentially unwanted program samples. We find that around 37% of requests issued by the analyzed samples contain some kind of personal information. Furthermore, we identify the services used by adversaries and provide insights on the used tracking techniques. Tobias Urban, Dennis Tatang, Thorsten Holz, Norbert Pohlmann |
J. Comput. Secur. | 1 |
| 2018 | Towards Understanding Privacy Implications of Adware and Potentially Unwanted Programs
Tobias Urban, Dennis Tatang, Thorsten Holz, Norbert Pohlmann |
ESORICS (1) | 1 |