VLDB 2026 Research / reviewers in the wild / expert
Marko Schuba
dblp:34/1779
· DBLP profile ↗
17ranked-venue papers
3as first author
6since 2021 · last 2025
0000-0002-3302-3060ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 12 · 5 since 2021Computer networks · 3 · 2 first-authorSystems, architecture and hardware · 1 · 1 first-authorApplied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | CampusQuest: Motivating Computer Science Students for Cybersecurity from Day One
Luca Pöhler, Marko Schuba, Tim Hoener, Sacha Hack, Georg Neugebauer |
ICISSP (1) | 2 |
| 2024 | A Framework for E2E Audit Trails in System Architectures of Different Enterprise Classes
Luca Patzelt, Georg Neugebauer, Meik Döll, Sacha Hack, Tim Hoener, Marko Schuba |
ICISSP | 6 |
| 2024 | An Open-Source Approach to OT Asset Management in Industrial Environments
Luca Pöhler, Marko Schuba, Tim Hoener, Sacha Hack, Georg Neugebauer |
ICISSP | 2 |
| 2023 | Security Analysis of the KNX Smart Building ProtocolabstractKNX is a protocol for smart building automation, e.g., for automated heating, air conditioning, or lighting. This paper analyses and evaluates state-of-the-art KNX devices from manufacturers Merten, Gira and Siemens with respect to security. On the one hand, it is investigated if publicly known vulnerabilities like insecure storage of passwords in software, unencrypted communication, or denial-of-service attacks, can be reproduced in new devices. On the other hand, the security is analyzed in general, leading to the discovery of a previously unknown and high risk vulnerability related to so-called BCU (authentication) keys. Malte Küppers, Marko Schuba, Georg Neugebauer, Tim Hoener, Sacha Hack |
ARES | 2 |
| 2023 | Digital Forensics Triage App for AndroidabstractDigital forensics of smartphones is of utmost importance in many criminal cases. As modern smartphones store chats, photos, videos etc. that can be relevant for investigations and as they can have storage capacities of hundreds of gigabytes, they are a primary target for forensic investigators. However, it is exactly this large amount of data that is causing problems: extracting and examining the data from multiple phones seized in the context of a case is taking more and more time. This bears the risk of wasting a lot of time with irrelevant phones while there is not enough time left to analyze a phone which is worth examination. Forensic triage can help in this case: Such a triage is a preselection step based on a subset of data and is performed before fully extracting all the data from the smartphone. Triage can accelerate subsequent investigations and is especially useful in cases where time is essential. The aim of this paper is to determine which and how much data from an Android smartphone can be made directly accessible to the forensic investigator – without tedious investigations. For this purpose, an app has been developed that can be used with extremely limited storage of data in the handset and which outputs the extracted data immediately to the forensic workstation in a human- and machine-readable format. Jannik Neth, Marko Schuba, Karsten Brodkorb, Georg Neugebauer, Tim Hoener, Sacha Hack |
ARES | 2 |
| 2021 | Challenges and Opportunities in Securing the Industrial Internet of ThingsabstractGiven the tremendous success of the Internet of Things in interconnecting consumer devices, we observe a natural trend to likewise interconnect devices in industrial settings, referred to as industrial Internet of Things or Industry 4.0. While this coupling of industrial components provides many benefits, it also introduces serious security challenges. Although sharing many similarities with the consumer Internet of Things, securing the industrial Internet of Things introduces its own challenges but also opportunities, mainly resulting from a longer lifetime of components and a larger scale of networks. In this article, we identify the unique security goals and challenges of the industrial Internet of Things, which, unlike consumer deployments, mainly follow from safety and productivity requirements. To address these security goals and challenges, we provide a comprehensive survey of research efforts to secure the industrial Internet of Things, discuss their applicability, and analyze their security benefits. Martin Serror, Sacha Hack, Martin Henze, Marko Schuba, Klaus Wehrle |
IEEE Trans. Ind. Informatics | 4 |
| 2018 | Towards In-Network Security for Smart HomesabstractThe proliferation of the Internet of Things (IoT) in the context of smart homes entails new security risks threatening the privacy and safety of end users. In this paper, we explore the design space of in-network security for smart home networks, which automatically complements existing security mechanisms with a rule-based approach, i. e., every IoT device provides a specification of the required communication to fulfill the desired services. In our approach, the home router as the central network component then enforces these communication rules with traffic filtering and anomaly detection to dynamically react to threats. We show that in-network security can be easily integrated into smart home networks based on existing approaches and thus provides additional protection for heterogeneous IoT devices and protocols. Furthermore, in-network security relieves users of difficult home network configurations, since it automatically adapts to the connected devices and services. Martin Serror, Martin Henze, Sacha Hack, Marko Schuba, Klaus Wehrle |
ARES | 4 |
| 2016 | Streamlining Extraction and Analysis of Android RAM Images
Simon Broenner, Hans Höfken, Marko Schuba |
ICISSP | 3 |
| 2015 | Cold Boot Attacks on DDR2 and DDR3 SDRAMabstractCold boot attacks provide a means to obtain a dump of a computer's volatile memory even if the machine is locked. Such a dump can be used to reconstruct hard disk encryption keys and get access to the content of Bit locker or True crypt encrypted drives. This is even possible, if the obtained dump contains errors. Cold boot attacks have been demonstrated successfully on DDR1 and DDR2 SDRAM. They have also been tried on DDR3 SDRAM using various types of equipment but all attempts have failed so far. In this paper we describe a different hardware setup which turns out to work for DDR3 SDRAM as well. Using this setup it will be possible for digital forensic investigators to recover keys from newer machines that use DDR3 SDRAM. Simon Lindenlauf, Hans Höfken, Marko Schuba |
ARES | 3 |
| 2015 | ICS/SCADA Security - Analysis of a Beckhoff CX5020 PLCabstractA secure and reliable critical infrastructure is a concern of industry and governments. SCADA systems (Supervisory Control and Data Acquisition) are a subgroup of ICS (Industrial Control Systems) and known to be well interconnected with other networks. It is not uncommon to use public networks as transport route but a rising number of incidents of industrial control systems shows the danger of excessive crosslinking. Beckhoff Automation GmbH is a German automation manufacturer that did not have bad press so far. The Beckhoff CX5020 is a typical PLC (Programmable Logic Controller) that is used in today’s SCADA systems. It is cross-linked through Ethernet and running a customized Windows CE 6.0, therefore the CX5020 is a good representative for modern PLCs which have emerged within the last years that use de facto standard operation systems and open standard communication protocols. This paper presents vulnerabilities of Beckhoff’s CX5020 PLC and shows ways to achieve rights to control the PLC program and the operation system itself. These vulnerabilities do not need in-depth knowledge of penetration testing, they demonstrate that switching to standard platforms brings hidden features and encapsulating SCADA protocols into TCP/IP might not always be a good idea – underlining that securing ICS systems is still a challenging topic. Gregor Bonney, Hans Höfken, Benedikt Paffen, Marko Schuba |
ICISSP | 4 |
| 2013 | Artificial Aging of Mobile Devices Using a Simulated GSM/GPRS NetworkabstractThe analysis of mobile devices is a fast moving area in digital forensics. Investigators frequently are challenged by devices which are not supported by existing mobile forensic tools. Low level techniques like de-soldering the flash memory chip and extracting its data provide an investigator with the exhibits internal memory, however, the interpretation of the data can be difficult as mobile device and flash chip manufacturers use their own proprietary techniques to encode and store data. The approach presented in this paper helps investigators to analyze this proprietary encoding by feeding a reference device identical to the exhibit with real data in a controlled way. This "artificial ageing" of the reference device is achieved using an isolated GSM/GPRS network plus additional software in a lab environment. After the ageing process is completed, the internal memory of the reference device can be acquired and used to reverse engineer the high level file system and the encoding of the data previously fed to the phone, like received SMS messages or calls. When sufficient knowledge about the interpretation of the memory image has been built up, it can be applied to the original evidence in order to analyze data and files relevant for the case. The successful operation of the solution is demonstrated in a proof of concept for SMS messages. Rolf Stobe, Hans Höfken, Marko Schuba, Michael Breuer |
ARES | 3 |
| 2012 | Simplifying RAM Forensics: A GUI and Extensions for the Volatility FrameworkabstractThe Volatility Framework is a collection of tools for the analysis of computer RAM. The framework offers a multitude of analysis options and is used by many investigators worldwide. Volatility currently comes with a command line interface only, which might be a hinderer for some investigators to use the tool. In this paper we present a GUI and extensions for the Volatility Framework, which on the one hand simplify the usage of the tool and on the other hand offer additional functionality like storage of results in a database, shortcuts for long Volatility Framework command sequences, and entirely new commands based on correlation of data stored in the database. Steffen Logen, Hans Höfken, Marko Schuba |
ARES | 3 |
| 2011 | Windows Phone 7 from a Digital Forensics' Perspective
Thomas Schaefer, Hans Höfken, Marko Schuba |
ICDF2C | 3 |
| 2000 | Performance evaluation of multicast communication in packet-switched networks
Marko Schuba, Boudewijn R. Haverkort, Gaby Schneider |
Perform. Evaluation | 1 |
| 1998 | SRMT-a scalable and reliable multicast transport protocolabstractMany applications require reliable multicast for data transmission. A number of protocols have been proposed previously for large-scale reliable multicast. Unfortunately these protocols may suffer from the length of the retransmission paths between the source and receivers which yields a very high cost for retransmissions. Therefore we propose the SRMT protocol (scalable and reliable multicast transport protocol) as an alternative to existing approaches. In SRMT an overlay network consisting of SRMT nodes is built on top of existing multicast routing protocols. Retransmissions take place between neighbouring SRMT nodes in the multicast tree. A simple analysis shows the advantages of our method compared to two existing protocols. In the case of networks with high loss probabilities our approach is the only one applicable. For small loss probabilities our protocol (in an example) yields a reduction of more than 65% of the retransmission load caused by the other methods. Marko Schuba |
ICC | 1 |
| 1997 | A Performance Evaluation of Connectionless Overlay Networks for ATMabstractIntroducing the asynchronous transfer mode (ATM) causes a backwards compatibility problem, because ATM is connection-oriented whereas most of today's LANs are connectionless. Interconnection can be achieved by the use of connectionless servers (CLS). These servers together with a number of preestablished virtual circuits form a connectionless overlay network on top of ATM. In this paper we evaluate overlay networks that differ in number location and interconnection of CLSs by computation of mean cell delay and link load. Marko Schuba |
INFOCOM | 1 |
| 1996 | Performance Investigations of the IP Multicast Architecture
Oliver Hermanns, Marko Schuba |
Comput. Networks ISDN Syst. | 2 |