VLDB 2026 Research / reviewers in the wild / expert
Claudius Pott
dblp:279/6139
· DBLP profile ↗
4ranked-venue papers
1as first author
4since 2021 · last 2023
0000-0002-1266-378XORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 4 · 1 first-author · 4 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2023 | Overcoming the Pitfalls of HPC-based Cryptojacking Detection in Presence of GPUsabstractWith the rising number of devices connected to the internet, the number of cyber-attacks on these devices increases in parallel. There are several strategies that an attacker can pursue, like stealing intellectual property of a victim or encrypting data to demand ransom for the decryption. In this work, we are focusing on the detection of so called cryptojacking attacks, in which an attacker that gained access to a system, then introduces programs that use the processing power of the victim device to mine cryptocurrencies. The presence of such an attack is not obvious right away and the longer an attacker manages to remain undetected, the longer they can profit having the victim foot the power bill. In this study, we combine previous approaches to demonstrate that cryptojacking attacks can be detected with an accuracy of 96% by leveraging hardware performance counters on the Windows operating system. Further, we present a method to determine which performance events result in the best detection rates, thus allowing the selection of a few performance events that can be monitored simultaneously by modern consumer CPUs. In a next step, we show that the CPU counters-based detection mechanism fails when an attacker switches from using the CPU resources to GPUs for the mining tasks. Based on these findings we then improve the previous detection approaches by extending the CPU performance counters with GPU-specific metrics resulting in 99.86% accuracy for the GPU-based cryptojacking attack class. In addition to a high detection rate the presented approach only causes a negligible performance loss while monitoring the whole system, which allows for continuous monitoring of live systems. Claudius Pott, Berk Gülmezoglu, Thomas Eisenbarth 0001 |
CODASPY | 1 |
| 2023 | Madvex: Instrumentation-Based Adversarial Attacks on Machine Learning Malware Detection
Nils Loose, Felix Mächtle, Claudius Pott, Volodymyr Bezsmertnyi, Thomas Eisenbarth 0001 |
DIMVA | 3 |
| 2022 | ASAP: Algorithm Substitution Attacks on Cryptographic ProtocolsabstractThe security of digital communication relies on few cryptographic protocols that are used to protect internet traffic, from web sessions to instant messaging. These protocols and the cryptographic primitives they rely on have been extensively studied and are considered secure. Yet, sophisticated attackers are often able to bypass rather than break security mechanisms. Kleptography or algorithm substitution attacks (ASA) describe techniques to place backdoors right into cryptographic primitives. While highly relevant as a building block, we show that the real danger of ASAs is their use in cryptographic protocols. In fact, we show that highly desirable security properties of these protocols - forward secrecy and post-compromise security - imply the applicability of ASAs. We then analyze the application of ASAs in three widely used protocols: TLS, WireGuard, and Signal. We show that these protocols can be easily subverted by carefully placing ASAs. Our analysis shows that careful design of ASAs makes detection unlikely while leaking long-term secrets within a few messages in the case of TLS and WireGuard, allowing impersonation attacks. In contrast, Signal's double-ratchet protocol shows higher immunity to ASAs, as the leakage requires much more messages. Sebastian Berndt 0001, Jan Wichelmann, Claudius Pott, Tim-Henrik Traving, Thomas Eisenbarth 0001 |
AsiaCCS | 3 |
| 2021 | Help, My Signal has Bad Device! - Breaking the Signal Messenger's Post-Compromise Security Through a Malicious Device
Jan Wichelmann, Sebastian Berndt 0001, Claudius Pott, Thomas Eisenbarth 0001 |
DIMVA | 3 |