Fabian Schwarz

dblp:272/7031 · DBLP profile ↗
← Back
4ranked-venue papers
4as first author
3since 2021 · last 2024
0000-0002-8549-3881ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 4 · 4 first-author · 3 since 2021
YearPublicationVenuePosition
2024 00SEVen - Re-enabling Virtual Machine Forensics: Introspecting Confidential VMs Using Privileged in-VM Agents
Fabian Schwarz, Christian Rossow
USENIX Security Symposium1
2022 FeIDo: Recoverable FIDO2 Tokens Using Electronic IDs
abstract
Two-factor authentication (2FA) mitigates the security risks of passwords as sole authentication factor. FIDO2---the de facto standard for interoperable web authentication---leverages strong, hardware-backed second factors. However, practical challenges hinder wider FIDO2 user adoption for 2FA tokens, such as the extra costs (20-30 per token) or the risk of inaccessible accounts upon token loss/theft.
Fabian Schwarz, Khue Do, Gunnar Heide, Lucjan Hanzlik, Christian Rossow
CCS1
2022 TrustedGateway: TEE-Assisted Routing and Firewall Enforcement Using ARM TrustZone
abstract
Gateway routers are at the heart of every network infrastructure, interconnecting subnetworks and enforcing access control policies using firewalls. However, their central position makes them high-value targets for network compromises. Typically, gateways are erroneously assumed to be hardened against software vulnerabilities (“bastion host”). In fact, though, they inherit the attack surface of their underlying commodity OSes which together with the wealth of auxiliary services available on both consumer and enterprise gateways—web and VoIP, file sharing, remote logins, monitoring, etc.—undermines this belief. This is underlined by a plethora of recent CVEs for commodity OSes and services of popular routers which resulted in authentication bypass or remote code execution thus enabling attackers full control over their security policies.
Fabian Schwarz
RAID1
2020 SENG, the SGX-Enforcing Network Gateway: Authorizing Communication from Shielded Clients
Fabian Schwarz, Christian Rossow
USENIX Security Symposium1