VLDB 2026 Research / reviewers in the wild / expert
Fabian Ising
dblp:224/9447
· DBLP profile ↗
13ranked-venue papers
1as first author
9since 2021 · last 2026
0000-0001-9852-1231ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 12 · 1 first-author · 8 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | SoK: A Taxonomy for Cybersecurity Incident Response Influence FactorsabstractCybersecurity incident response has emerged as a critical area of interest for both researchers and practitioners. The corpus of literature on cybersecurity incident response is expanding, yet a unified framework for systematically organizing the accumulated knowledge remains absent. The aspects of incident response span multiple domains, including technology, human-computer interaction, organizational theory, and human factors. A comprehensive, integrative perspective on these factors can enable researchers to identify underexplored areas and more effectively target their empirical and theoretical investigations. Our study systematizes the factors that influence organizational preparedness for and response to cybersecurity incidents. Through a systematic review of academic literature (n = 417) and non-scientific publications (n = 40), we derived the "Cybersecurity Incident Response Influencing Factor Taxonomy" (\textit{CIR-IF Taxonomy}). Existing empirical findings were classified within this taxonomy, providing a comprehensive and up-to-date overview of knowledge from the period 1999 to mid-2024. The taxonomy categories were systematically compared with seven established scientific frameworks and with the \textit{NIST Cyber Security Framework} elements referenced in the \textit{NIST Special Publication 800-61r3} incident response profile. The results of this comparison show that the \textit{CIR-IF Taxonomy} delivers a richer, more rigorous, and more systematically organized view of the factors that drive and shape incident response. Thomas Biege, Marius Brockhoff, Jonas Kaspereit, Fabian Ising, Lea Gröber, Sebastian Schinzel |
EuroS&P | 4 |
| 2026 | Measuring Healthcare Data Leaks and Security Flaws at Internet ScaleabstractSystems that process medical data should be meticulously secured. Yet, network services in healthcare environments often fail to implement basic security measures. For example, previous studies showed that network segmentation flaws led to DICOM systems leaking millions of patient records. In addition to DICOM, healthcare facilities rely heavily on the HL7 and FHIR protocols to transmit data. For nine months, we operated a low-interaction honeypot for medical protocols. We found it was regularly scanned for DICOM but never for HL7 or FHIR, indicating that despite their widespread use and importance for patient data security, the security of these services remains underexplored. In this paper, we present the first large-scale study on HL7 and FHIR services and expand previous work on DICOM. Our large-scale Internet scans, covering the three major healthcare protocols across IPv4 and IPv6 address spaces, identify healthcare systems and uncover data leaks due to authentication flaws. Additionally, we scanned for deficiencies in TLS configurations of these services and known insecure healthcare software. In total, we found 2,841 healthcare services with authentication flaws. 94.4% of all exposed systems do not support transport encryption, and 1,373 systems have known software vulnerabilities, including those with potential for system takeover and CVSS scores up to 9.8. Overall, our study reveals an alarming state of cybersecurity in healthcare deployments, for which we discuss potential reasons and countermeasures. Finally, we report on the coordinated disclosure campaign we initiated to improve the security of patient data. Nico Brüggemann, Lukas Schmidt, Marvin Dölzer, Marius Brockhoff, Fabian Ising, Christoph Saatjohann, Sebastian Schinzel |
EuroS&P | 5 |
| 2025 | Characterizing Hosting and Security Practices for Public-Facing LDAP ServersabstractThe Lightweight Directory Access Protocol (LDAP) is widely used to make structured data available for standardized lookup, which may sometimes include personal information or authentication credentials. Previous work, including ours, found security issues such as public LDAP servers leaking sensitive information without prior authentication and server configurations with poor communication security. However, prior work did not investigate whether, or to what extent, the identified problems are linked to hosting and management setups. In this paper, we address this gap and explore the organizations hosting publicfacing LDAP servers. We identify the network segments more likely to host LDAP instances, the products and operating systems used, and examine the management practices related to Public Key Infrastructure (PKI) setups for LDAP. In contrast to studies on Web and email, which have revealed strong centralization tendencies in deployment, we show that the LDAP ecosystem is diverse, with a wide range of different hosting networks. In this study, we identify 69.1 k LDAP instances- $6.5 \times$ more than prior work-and map these to the respective LDAP products. We find that 5.8% of the servers use a product that is end-of-life or runs on a deprecated OS. We identify servers using problematic X. 509 certificates, e.g., those associated with publicly known private keys. From our observations, we give recommendations for network operators to improve their security posture. Gustavo Luvizotto Cesar, Gurur Öndarö, Jonas Kaspereit, Fabian Ising, Sebastian Schinzel, Mattijs Jonker, Ralph Holz |
CNSM | 4 |
| 2025 | BreachHydra: Measuring the Resilience of an Underground Data Breach ForumabstractUnderground forums are thriving markets for illicit goods and services, such as data leaks. While these forums regularly come under the focus of criminal prosecution, often leading to platform shutdowns and the conviction of operators, successors emerge quickly. In this paper, we present a study of the underground forum BreachForums. BreachForums served as the successor to the popular RaidForums, survived several forum takedowns, and remained operational until June 2025. We perform the first public analysis of the leaked BreachForums database from 2022, and enrich our results with scraped data from the latest successor. This enables us to conduct a longitudinal study on the factors contributing to the forum’s resilience.We find that the operational security of forum users, particularly Key Users selling products and services, is generally strong, making their identification challenging. However, some users involved in data leak exchanges exhibit weak operational security, which may potentially allow law enforcement to track them. Moreover, our analysis reveals that takedown efforts have a limited impact on the availability of illegal data, as externally hosted leaks remain accessible and get reposted on successor platforms. We argue that law enforcement’s current focus on arresting forum operators seems insufficient, as new platforms continue to emerge. Marius Brockhoff, Lukas Schmidt, Fabian Ising, Sebastian Schinzel |
TrustCom | 3 |
| 2025 | S/MINE: Collecting and Analyzing S/MIME Certificates at Scale
Gurur Öndarö, Jonas Kaspereit, Samson Umezulike, Christoph Saatjohann, Fabian Ising, Sebastian Schinzel |
USENIX Security Symposium | 5 |
| 2024 | LanDscAPe: Exploring LDAP weaknesses and data leaks at Internet scale
Jonas Kaspereit, Gurur Öndarö, Gustavo Luvizotto Cesar, Simon Ebbers, Fabian Ising, Christoph Saatjohann, Mattijs Jonker, Ralph Holz, Sebastian Schinzel |
USENIX Security Symposium | 5 |
| 2023 | Content-Type: multipart/oracle - Tapping into Format Oracles in Email End-to-End Encryption
Fabian Ising, Damian Poddebniak, Tobias Kappert, Christoph Saatjohann, Sebastian Schinzel |
USENIX Security Symposium | 1 |
| 2021 | Grand Theft App: Digital Forensics of Vehicle Assistant AppsabstractDue to the increasing connectivity of modern vehicles, collected data is no longer only stored in the vehicle itself but also transmitted to car manufacturers and vehicle assistant apps. This development opens up new possibilities for digital forensics in criminal investigations involving modern vehicles. This paper deals with the digital forensic analysis of vehicle assistant apps of eight car manufacturers. We reconstruct the driver’s activities based on the data stored on the smartphones and in the manufacturer’s backend. Simon Ebbers, Fabian Ising, Christoph Saatjohann, Sebastian Schinzel |
ARES | 2 |
| 2021 | Why TLS is better without STARTTLS: A Security Analysis of STARTTLS in the Email Context
Damian Poddebniak, Fabian Ising, Hanno Böck, Sebastian Schinzel |
USENIX Security Symposium | 2 |
| 2020 | STALK: security analysis of smartwatches for kidsabstractSmart wearable devices become more and more prevalent in the age of the Internet of Things. While people wear them as fitness trackers or full-fledged smartphones, they also come in unique versions as smartwatches for children. These watches allow parents to track the location of their children in real-time and offer a communication channel between parent and child. Christoph Saatjohann, Fabian Ising, Luise Krings, Sebastian Schinzel |
ARES | 2 |
| 2020 | CORSICA: Cross-Origin Web Service IdentificationabstractVulnerabilities in private networks are difficult to detect for attackers outside of the network. While there are known methods for port scanning internal hosts that work by luring unwitting internal users to an external web page that hosts malicious JavaScript code, no such method for detailed and precise service identification is known. The reason is that the Same Origin Policy (SOP) prevents access to HTTP responses of other origins by default. Christian Dresen, Fabian Ising, Damian Poddebniak, Tobias Kappert, Thorsten Holz, Sebastian Schinzel |
AsiaCCS | 2 |
| 2019 | Practical Decryption exFiltration: Breaking PDF EncryptionabstractThe Portable Document Format, better known as PDF, is one of the most widely used document formats worldwide, and in order to ensure information confidentiality, this file format supports document encryption. In this paper, we analyze PDF encryption and show two novel techniques for breaking the confidentiality of encrypted documents. First, we abuse the PDF feature of partially encrypted documents to wrap the encrypted part of the document within attacker-controlled content and therefore, exfiltrate the plaintext once the document is opened by a legitimate user. Second, we abuse a flaw in the PDF encryption specification to arbitrarily manipulate encrypted content. The only requirement is that a single block of known plaintext is needed, and we show that this is fulfilled by design. Our attacks allow the recovery of the entire plaintext of encrypted documents by using exfiltration channels which are based on standard compliant PDF properties. We evaluated our attacks on 27 widely used PDF viewers and found all of them to be vulnerable. We responsibly disclosed the vulnerabilities and supported the vendors in fixing the issues. Jens Müller 0007, Fabian Ising, Vladislav Mladenov, Christian Mainka, Sebastian Schinzel, Jörg Schwenk |
CCS | 2 |
| 2018 | Efail: Breaking S/MIME and OpenPGP Email Encryption using Exfiltration Channels
Damian Poddebniak, Christian Dresen, Jens Müller 0007, Fabian Ising, Sebastian Schinzel, Simon Friedberger, Juraj Somorovsky, Jörg Schwenk |
USENIX Security Symposium | 4 |