Sebastian Karius

dblp:300/2236 · DBLP profile ↗
← Back
4ranked-venue papers
1as first author
4since 2021 · last 2026
0009-0009-7698-7554ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 2 · 2 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Network Anomaly Detection Through ILP-Based Symbolic Distillation of Autoencoder Models Into Datalog Programs
Philipp Rösner, Stefan Brass, Sebastian Karius, Sandro Wefel
DEXA (2)3
2025 Support of Forensic Attribution by Visualizing Textual Embeddings of Stegomalware
abstract
The goal of this work is to support forensic procedures and models in attribution by demonstrating how the categorization and characterization of attackers or attacker groups, who use steganographic text channels to embed stegomalware, can be effectively supported through the visualization of embeddings.The rapid advancements in artificial intelligence are expected to significantly simplify and enhance the use of covert channels in text, making the visualization of embeddings an essential and indispensable component.Only by effectively detecting and clearly presenting steganographic embeddings can the characterization and categorization of such activities be performed meaningfully and accurately.To achieve this, embeddings from various steganographic algorithms were analyzed, and requirements for their visualization were developed.These requirements emphasize clarity, interpretability, and measurable outcomes.Based on these criteria, the visualization methods for different steganographic techniques were optimized to ensure that embeddings are not only easily recognizable but also straightforward to interpret.This process also highlights the importance of making such visualizations accessible and applicable in practical forensic scenarios.As a result, this research presents a specialized tool capable of detecting embeddings across multiple algorithms and displaying them in an interpretable and understandable way.This tool simplifies the analysis of texts containing steganographic embeddings.In some cases, the tool even makes it possible to visualize the embeddings in the first place.It further facilitates the characterization and categorization of attackers and their strategies, thereby contributing to more effective attribution in the context of cyber forensics.
Felix Feist, Sebastian Karius, Mandy Knöchel, Sandro Wefel
IH&MMSec2
2024 Text Steganography Methods and their Influence in Malware: A Comprehensive Overview and Evaluation
abstract
Steganography describes techniques and algorithms for hiding secret information in a cover medium such as images, audio or text files. Malware that makes use of steganographic techniques, known as stegomalware, is becoming increasingly common. This paper provides a comprehensive analysis of various text steganography methods and their application in the context of stegomalware. We give an extensive overview of occurrences of text stegomalware in the real world and the steganographic methods used in these attacks. The cover text includes any files or data containing natural language text or machine-readable digital texts and source code such as HTML, CSS, JavaScript, etc. A categorical overview of known text steganography methods is presented, whereas text steganography techniques are classified into the categories insertion, substitution, permutation and generation. For each category, selected representatives have been practically implemented and tested with different cover text files and messages of varying lengths. The authors also look at real-world applications and instances of stegomalware that utilize these methods. The paper reveals that while there is a vast array of text steganography methods, only a few are used in practice. To assess the strengths and weaknesses of each method, the evaluation is based on the metrics capacity, imperceptibility and robustness, which are commonly used to evaluate steganographic methods, and additionally complexity. The evaluation results show the performance of each method based on the defined metrics. We further discuss possible countermeasures and their effect on each steganography method. The analysis also shows that with the rise of machine learning and large language models, text steganography methods might become more common in the future.
Mandy Knöchel, Sebastian Karius
IH&MMSec2
2022 Training and Validating of Advanced Flow-Based Network Traffic Classifiers under Real-World Conditions
abstract
Robust network traffic classification (NTC) is an essential component of intrusion detection and intrusion prevention systems as well as quality of service applications. Modern NTCs use flow-based methods to either support or replace single-packet-based methods, since network traffic is usually encrypted. The flow-based methods are often implemented using neural networks. These neural networks are usually trained and tested using the same dataset. We propose a new testing method in which the data used to test the neural network occurs at a later time than the data used to train the neural network. For this, we used a dataset recorded by a honeypod that captured attacks, particularly on the SSH service, as well as authorized logins. The data was recorded over a period of over two years. Past data was used for training and recent data was used for testing, with a large time gap between the last datapoint of the training data and the first datapoint of the testing data. We show that existing neural network models developed for NTC are able to classify the attacks in our test scenario equally well, for authorized accesses the quality is worse. This shows that the proposed learning method for our chosen models is sufficient to robustly classify future network traffic in the scenarios tested here.
Sebastian Karius, Mandy Knöchel, Sandro Wefel
APCC1