VLDB 2026 Research / reviewers in the wild / expert
Sebastian Schinzel
dblp:43/11495
· DBLP profile ↗
25ranked-venue papers
0as first author
12since 2021 · last 2026
0000-0002-7944-5488ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 24 · 11 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | SoK: A Taxonomy for Cybersecurity Incident Response Influence FactorsabstractCybersecurity incident response has emerged as a critical area of interest for both researchers and practitioners. The corpus of literature on cybersecurity incident response is expanding, yet a unified framework for systematically organizing the accumulated knowledge remains absent. The aspects of incident response span multiple domains, including technology, human-computer interaction, organizational theory, and human factors. A comprehensive, integrative perspective on these factors can enable researchers to identify underexplored areas and more effectively target their empirical and theoretical investigations. Our study systematizes the factors that influence organizational preparedness for and response to cybersecurity incidents. Through a systematic review of academic literature (n = 417) and non-scientific publications (n = 40), we derived the "Cybersecurity Incident Response Influencing Factor Taxonomy" (\textit{CIR-IF Taxonomy}). Existing empirical findings were classified within this taxonomy, providing a comprehensive and up-to-date overview of knowledge from the period 1999 to mid-2024. The taxonomy categories were systematically compared with seven established scientific frameworks and with the \textit{NIST Cyber Security Framework} elements referenced in the \textit{NIST Special Publication 800-61r3} incident response profile. The results of this comparison show that the \textit{CIR-IF Taxonomy} delivers a richer, more rigorous, and more systematically organized view of the factors that drive and shape incident response. Thomas Biege, Marius Brockhoff, Jonas Kaspereit, Fabian Ising, Lea Gröber, Sebastian Schinzel |
EuroS&P | 6 |
| 2026 | Measuring Healthcare Data Leaks and Security Flaws at Internet ScaleabstractSystems that process medical data should be meticulously secured. Yet, network services in healthcare environments often fail to implement basic security measures. For example, previous studies showed that network segmentation flaws led to DICOM systems leaking millions of patient records. In addition to DICOM, healthcare facilities rely heavily on the HL7 and FHIR protocols to transmit data. For nine months, we operated a low-interaction honeypot for medical protocols. We found it was regularly scanned for DICOM but never for HL7 or FHIR, indicating that despite their widespread use and importance for patient data security, the security of these services remains underexplored. In this paper, we present the first large-scale study on HL7 and FHIR services and expand previous work on DICOM. Our large-scale Internet scans, covering the three major healthcare protocols across IPv4 and IPv6 address spaces, identify healthcare systems and uncover data leaks due to authentication flaws. Additionally, we scanned for deficiencies in TLS configurations of these services and known insecure healthcare software. In total, we found 2,841 healthcare services with authentication flaws. 94.4% of all exposed systems do not support transport encryption, and 1,373 systems have known software vulnerabilities, including those with potential for system takeover and CVSS scores up to 9.8. Overall, our study reveals an alarming state of cybersecurity in healthcare deployments, for which we discuss potential reasons and countermeasures. Finally, we report on the coordinated disclosure campaign we initiated to improve the security of patient data. Nico Brüggemann, Lukas Schmidt, Marvin Dölzer, Marius Brockhoff, Fabian Ising, Christoph Saatjohann, Sebastian Schinzel |
EuroS&P | 7 |
| 2025 | Characterizing Hosting and Security Practices for Public-Facing LDAP ServersabstractThe Lightweight Directory Access Protocol (LDAP) is widely used to make structured data available for standardized lookup, which may sometimes include personal information or authentication credentials. Previous work, including ours, found security issues such as public LDAP servers leaking sensitive information without prior authentication and server configurations with poor communication security. However, prior work did not investigate whether, or to what extent, the identified problems are linked to hosting and management setups. In this paper, we address this gap and explore the organizations hosting publicfacing LDAP servers. We identify the network segments more likely to host LDAP instances, the products and operating systems used, and examine the management practices related to Public Key Infrastructure (PKI) setups for LDAP. In contrast to studies on Web and email, which have revealed strong centralization tendencies in deployment, we show that the LDAP ecosystem is diverse, with a wide range of different hosting networks. In this study, we identify 69.1 k LDAP instances- $6.5 \times$ more than prior work-and map these to the respective LDAP products. We find that 5.8% of the servers use a product that is end-of-life or runs on a deprecated OS. We identify servers using problematic X. 509 certificates, e.g., those associated with publicly known private keys. From our observations, we give recommendations for network operators to improve their security posture. Gustavo Luvizotto Cesar, Gurur Öndarö, Jonas Kaspereit, Fabian Ising, Sebastian Schinzel, Mattijs Jonker, Ralph Holz |
CNSM | 5 |
| 2025 | BreachHydra: Measuring the Resilience of an Underground Data Breach ForumabstractUnderground forums are thriving markets for illicit goods and services, such as data leaks. While these forums regularly come under the focus of criminal prosecution, often leading to platform shutdowns and the conviction of operators, successors emerge quickly. In this paper, we present a study of the underground forum BreachForums. BreachForums served as the successor to the popular RaidForums, survived several forum takedowns, and remained operational until June 2025. We perform the first public analysis of the leaked BreachForums database from 2022, and enrich our results with scraped data from the latest successor. This enables us to conduct a longitudinal study on the factors contributing to the forum’s resilience.We find that the operational security of forum users, particularly Key Users selling products and services, is generally strong, making their identification challenging. However, some users involved in data leak exchanges exhibit weak operational security, which may potentially allow law enforcement to track them. Moreover, our analysis reveals that takedown efforts have a limited impact on the availability of illegal data, as externally hosted leaks remain accessible and get reposted on successor platforms. We argue that law enforcement’s current focus on arresting forum operators seems insufficient, as new platforms continue to emerge. Marius Brockhoff, Lukas Schmidt, Fabian Ising, Sebastian Schinzel |
TrustCom | 4 |
| 2025 | Towards Automated and Robust Forensic Event ReconstructionabstractReconstructing past events in IT systems is a critical bottleneck in forensic investigations, consuming valuable time from investigators. It requires meticulous analysis of complex digital traces in an environment where attackers may try to erase traces. For example, deletion of digital artifacts is an anti-forensic technique used to jeopardize the success of forensic investigations.To address these challenges, we introduce Investigator Copilot, a novel framework that automates post-mortem event reconstruction using explainable machine learning. To overcome the general scarcity of datasets, Investigator Copilot replays realistic events on virtual machines, and creates datasets by extracting, normalizing and labeling traces from corresponding hard disks. Using these datasets, Investigator Copilot trains human-interpretable decision tree stumps that evaluate digital evidence and combines these binary classifiers in Forensic Forests. Forensic Forests utilize an adjusted voting scheme to provide robust event reconstruction even when faced with deleted evidence.We evaluate our approach by executing 2100 events on 50 virtual machines, training Forensic Forests and measuring their event reconstruction performance on previously unseen data. Our results demonstrate that tree-based classifiers perform exceedingly well in event reconstruction. When measuring reconstruction performance on manipulated evidence, we observe that Forensic Forests significantly outperform the state-of-the-art, which positions them as a valuable tool for investigators. Our findings indicate that automated frameworks such as Investigator Copilot can contribute to the efficiency and robustness of forensic analyses, and may save scarce resources of human investigators. Lukas Schmidt, Sebastian Schinzel |
TrustCom | 2 |
| 2025 | S/MINE: Collecting and Analyzing S/MIME Certificates at Scale
Gurur Öndarö, Jonas Kaspereit, Samson Umezulike, Christoph Saatjohann, Fabian Ising, Sebastian Schinzel |
USENIX Security Symposium | 6 |
| 2024 | LanDscAPe: Exploring LDAP weaknesses and data leaks at Internet scale
Jonas Kaspereit, Gurur Öndarö, Gustavo Luvizotto Cesar, Simon Ebbers, Fabian Ising, Christoph Saatjohann, Mattijs Jonker, Ralph Holz, Sebastian Schinzel |
USENIX Security Symposium | 9 |
| 2023 | Content-Type: multipart/oracle - Tapping into Format Oracles in Email End-to-End Encryption
Fabian Ising, Damian Poddebniak, Tobias Kappert, Christoph Saatjohann, Sebastian Schinzel |
USENIX Security Symposium | 5 |
| 2021 | Grand Theft App: Digital Forensics of Vehicle Assistant AppsabstractDue to the increasing connectivity of modern vehicles, collected data is no longer only stored in the vehicle itself but also transmitted to car manufacturers and vehicle assistant apps. This development opens up new possibilities for digital forensics in criminal investigations involving modern vehicles. This paper deals with the digital forensic analysis of vehicle assistant apps of eight car manufacturers. We reconstruct the driver’s activities based on the data stored on the smartphones and in the manufacturer’s backend. Simon Ebbers, Fabian Ising, Christoph Saatjohann, Sebastian Schinzel |
ARES | 4 |
| 2021 | Listen to Your Heart: Evaluation of the Cardiologic EcosystemabstractModern implantable cardiologic devices communicate via radio frequency techniques and nearby gateways to a backend server on the internet. Those implanted devices, gateways, and servers form an ecosystem of proprietary hardware and protocols that process sensitive medical data and is often vital for patients’ health. Endres Puschner, Christoph Saatjohann, Markus Willing, Christian Dresen, Julia Köbe, Benjamin Rath, Christof Paar, Lars Eckardt, Uwe Haverkamp, Sebastian Schinzel |
ARES | 10 |
| 2021 | ALPACA: Application Layer Protocol Confusion - Analyzing and Mitigating Cracks in TLS Authentication
Marcus Brinkmann, Christian Dresen, Robert Merget, Damian Poddebniak, Jens Müller 0007, Juraj Somorovsky, Jörg Schwenk, Sebastian Schinzel |
USENIX Security Symposium | 8 |
| 2021 | Why TLS is better without STARTTLS: A Security Analysis of STARTTLS in the Email Context
Damian Poddebniak, Fabian Ising, Hanno Böck, Sebastian Schinzel |
USENIX Security Symposium | 4 |
| 2020 | STALK: security analysis of smartwatches for kidsabstractSmart wearable devices become more and more prevalent in the age of the Internet of Things. While people wear them as fitness trackers or full-fledged smartphones, they also come in unique versions as smartwatches for children. These watches allow parents to track the location of their children in real-time and offer a communication channel between parent and child. Christoph Saatjohann, Fabian Ising, Luise Krings, Sebastian Schinzel |
ARES | 4 |
| 2020 | CORSICA: Cross-Origin Web Service IdentificationabstractVulnerabilities in private networks are difficult to detect for attackers outside of the network. While there are known methods for port scanning internal hosts that work by luring unwitting internal users to an external web page that hosts malicious JavaScript code, no such method for detailed and precise service identification is known. The reason is that the Same Origin Policy (SOP) prevents access to HTTP responses of other origins by default. Christian Dresen, Fabian Ising, Damian Poddebniak, Tobias Kappert, Thorsten Holz, Sebastian Schinzel |
AsiaCCS | 6 |
| 2020 | Mitigation of Attacks on Email End-to-End EncryptionabstractOpenPGP and S/MIME are two major standards for securing email communication introduced in the early 1990s. Three recent classes of attacks exploit weak cipher modes (EFAIL Malleability Gadgets, or EFAIL-MG), the flexibility of the MIME email structure (EFAIL Direct Exfiltration, or EFAIL-DE), and the Reply action of the email client (REPLY attacks). Although all three break message confidentiality by using standardized email features, only EFAIL-MG has been mitigated in IETF standards with the introduction of AEAD algorithms. So far, no uniform and reliable countermeasures have been adopted by email clients to prevent EFAIL-DE and REPLY attacks. Instead, email clients implement a variety of different ad-hoc countermeasures which are only partially effective, cause interoperability problems, and fragment the secure email ecosystem. Jörg Schwenk, Marcus Brinkmann, Damian Poddebniak, Jens Müller 0007, Juraj Somorovsky, Sebastian Schinzel |
CCS | 6 |
| 2019 | Re: What's Up Johnny? - Covert Content Attacks on Email End-to-End Encryption
Jens Müller 0007, Marcus Brinkmann, Damian Poddebniak, Sebastian Schinzel, Jörg Schwenk |
ACNS | 4 |
| 2019 | Practical Decryption exFiltration: Breaking PDF EncryptionabstractThe Portable Document Format, better known as PDF, is one of the most widely used document formats worldwide, and in order to ensure information confidentiality, this file format supports document encryption. In this paper, we analyze PDF encryption and show two novel techniques for breaking the confidentiality of encrypted documents. First, we abuse the PDF feature of partially encrypted documents to wrap the encrypted part of the document within attacker-controlled content and therefore, exfiltrate the plaintext once the document is opened by a legitimate user. Second, we abuse a flaw in the PDF encryption specification to arbitrarily manipulate encrypted content. The only requirement is that a single block of known plaintext is needed, and we show that this is fulfilled by design. Our attacks allow the recovery of the entire plaintext of encrypted documents by using exfiltration channels which are based on standard compliant PDF properties. We evaluated our attacks on 27 widely used PDF viewers and found all of them to be vulnerable. We responsibly disclosed the vulnerabilities and supported the vendors in fixing the issues. Jens Müller 0007, Fabian Ising, Vladislav Mladenov, Christian Mainka, Sebastian Schinzel, Jörg Schwenk |
CCS | 5 |
| 2019 | "Johnny, you are fired!" - Spoofing OpenPGP and S/MIME Signatures in Emails
Jens Müller 0007, Marcus Brinkmann, Damian Poddebniak, Hanno Böck, Sebastian Schinzel, Juraj Somorovsky, Jörg Schwenk |
USENIX Security Symposium | 5 |
| 2018 | Attacking Deterministic Signature Schemes Using Fault AttacksabstractMany digital signature schemes rely on random numbers that are unique and non-predictable per signature. Failures of random number generators may have catastrophic effects such as compromising private signature keys. In recent years, many widely-used cryptographic technologies adopted deterministic signature schemes because they are presumed to be safer to implement. In this paper, we analyze the security of deterministic ECDSA and EdDSA signature schemes and show that the elimination of random number generators in these schemes enables new kinds of fault attacks. We formalize these attacks and introduce practical attack scenarios against EdDSA using the Rowhammer fault attack. EdDSA is used in many widely used protocols such as TLS, SSH, and IPSec, and we show that these protocols are not vulnerable to our attack. We formalize the necessary requirements of protocols using these deterministic signature schemes to be vulnerable, and discuss mitigation strategies and their effect on fault attacks against deterministic signature schemes. Damian Poddebniak, Juraj Somorovsky, Sebastian Schinzel, Manfred Lochter, Paul Rösler |
EuroS&P | 3 |
| 2018 | Efail: Breaking S/MIME and OpenPGP Email Encryption using Exfiltration Channels
Damian Poddebniak, Christian Dresen, Jens Müller 0007, Fabian Ising, Sebastian Schinzel, Simon Friedberger, Juraj Somorovsky, Jörg Schwenk |
USENIX Security Symposium | 5 |
| 2017 | kAFL: Hardware-Assisted Feedback Fuzzing for OS Kernels
Sergej Schumilo, Cornelius Aschermann, Robert Gawlik, Sebastian Schinzel, Thorsten Holz |
USENIX Security Symposium | 4 |
| 2016 | DROWN: Breaking TLS Using SSLv2
Nimrod Aviram, Sebastian Schinzel, Juraj Somorovsky, Nadia Heninger, Maik Dankel, Jens Steube, Luke Valenta, David Adrian, J. Alex Halderman, Viktor Dukhovni, Emilia Käsper, Shaanan Cohney, Susanne Engels, Christof Paar, Yuval Shavitt |
USENIX Security Symposium | 2 |
| 2014 | Revisiting SSL/TLS Implementations: New Bleichenbacher Side Channels and Attacks
Christopher Meyer, Juraj Somorovsky, Eugen Weiss, Jörg Schwenk, Sebastian Schinzel, Erik Tews |
USENIX Security Symposium | 5 |
| 2012 | Bleichenbacher's Attack Strikes again: Breaking PKCS#1 v1.5 in XML Encryption
Tibor Jager, Sebastian Schinzel, Juraj Somorovsky |
ESORICS | 2 |
| 2011 | Detecting Hidden Storage Side Channel Vulnerabilities in Networked Applications
Felix C. Freiling, Sebastian Schinzel |
SEC | 2 |