VLDB 2026 Research / reviewers in the wild / expert
Christian Banse
dblp:50/11236
· DBLP profile ↗
19ranked-venue papers
5as first author
7since 2021 · last 2025
0000-0002-4874-0273ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 8 · 1 first-author · 3 since 2021Computer networks · 3 · 1 first-authorSystems, architecture and hardware · 2 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 1 first-author · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 first-author · 1 since 2021Human-computer interaction and ubiquitous computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | EMERALD: Evidence Management for Continuous Certification as a Service in the Cloudabstract190 Christian Banse, Björn Fanta, Juncal Alonso, Cristina Martínez |
CLOSER | 1 |
| 2024 | owl2proto: Enabling Semantic Processing in Modern Cloud Micro-Servicesabstract199 Christian Banse, Angelika Schneider, Immanuel Kunz |
KEOD | 1 |
| 2023 | Privacy Property Graph: Towards Automated Privacy Threat Modeling via Static Graph-based AnalysisabstractPrivacy threat modeling should be done frequently throughout development and production to be able to quickly mitigate threats. Yet, it can also be a very time-consuming activity. In this paper, we use an enhanced code property graph to partly automate the privacy threat modeling process: It automatically generates a data flow diagram from source code which exhibits privacy properties of data flows, and which can be analyzed semi-automatically via queries. We provide a list of such reusable queries that can be used to detect various privacy threats. To enable this analysis, we integrate a taint-tracking mechanism into the graph using privacy-specific labels. Since no benchmark for such an approach exists, we also present a test suite for privacy threat implementations which comprises implementations for 22 privacy threats in multiple programming languages. We expect that our approach significantly reduces time consumption of threat modeling and show that it also has potential beyond the threat categories defined by LINDDUN, e.g. to detect privacy anti-patterns and verify compliance to privacy policies. Immanuel Kunz, Konrad Weiss, Angelika Schneider, Christian Banse |
Proc. Priv. Enhancing Technol. | 4 |
| 2022 | A Continuous Risk Assessment Methodology for Cloud InfrastructuresabstractCloud systems are dynamic environments which make it difficult to keep track of security risks that resources are exposed to. Traditionally, risk assessment is conducted for individual assets to evaluate existing threats-their results, however, are quickly outdated in such a dynamic environment. In this paper, we propose an adaptation of the traditional risk assessment methodology for cloud infrastructures which loosely couples manual, in-depth analyses with continuous, automatic application of their results. These two parts are linked by a novel threat profile definition that allows to reusably describe configuration weaknesses based on properties that are common across assets and cloud providers. This way, threats can be identified automatically for all resources that exhibit the same properties, including new and modified ones. We also present a prototype implementation which automatically evaluates an infrastructure as code template of a cloud system against a set of threat profiles, and we evaluate its performance. Our methodology not only enables organizations to reuse their threat analysis results, but also to collaborate on their development, e.g. with the public community. To that end, we propose an initial open-source repository of threat profiles. Immanuel Kunz, Angelika Schneider, Christian Banse |
CCGRID | 3 |
| 2022 | Poster: Patient Community - A Test Bed for Privacy Threat AnalysisabstractResearch and development of privacy analysis tools currently suffers from a lack of test beds for evaluation and comparison of such tools. In this work, we propose a benchmark application that implements an extensive list of privacy weaknesses based on the LINDDUN methodology. It represents a social network for patients whose architecture has first been described in an example analysis conducted by one of the LINDDUN authors. We have implemented this architecture and extended it with more privacy threats to build a test bed that enables comprehensive and independent testing of analysis tools. Immanuel Kunz, Angelika Schneider, Christian Banse, Konrad Weiss, Andreas Binder |
CCS | 3 |
| 2022 | Representing LLVM-IR in a Code Property Graph
Alexander Küchler, Christian Banse |
ISC | 2 |
| 2021 | Cloud Property Graph: Connecting Cloud Security Assessments with Static Code AnalysisabstractIn this paper, we present the Cloud Property Graph (CloudPG), which bridges the gap between static code analysis and runtime security assessment of cloud services. The CloudPG is able to resolve data flows between cloud applications deployed on different resources, and contextualizes the graph with runtime information, such as encryption settings. To provide a vendorand technology-independent representation of a cloud service's security posture, the graph is based on an ontology of cloud resources, their functionalities and security features. We show, using an example, that our CloudPG framework can be used by security experts to identify weaknesses in their cloud deployments, spanning multiple vendors or technologies, such as AWS, Azure and Kubernetes. This includes misconfigurations, such as publicly accessible storages or undesired data flows within a cloud service, as restricted by regulations such as GDPR. Christian Banse, Immanuel Kunz, Angelika Schneider, Konrad Weiss |
CLOUD | 1 |
| 2020 | Towards Tracking Data Flows in Cloud ArchitecturesabstractAs cloud services become central in an increasing number of applications, they process and store more personal and business-critical data. At the same time, privacy and compliance regulations such as the General Data Protection Regulation (GDPR), the EU ePrivacy regulation, and the upcoming EU Cybersecurity Act raise the bar for secure processing and traceability of critical data. Especially the demand to provide information about existing data records of an individual and the ability to delete them on demand is central in privacy regulations. Common to these requirements is that cloud providers must be able to track data as it flows across the different services to ensure that it never moves outside of the legitimate realm, and it is known at all times where a specific copy of a record that belongs to a specific individual or business process is located. However, current cloud architectures do neither provide the means to holistically track data flows across different services nor to enforce policies on data flows. In this paper, we point out the deficits in the data flow tracking functionalities of major cloud providers by means of a set of practical experiments. We then generalize from these experiments introducing a generic architecture that aims at solving the problem of cloud-wide data flow tracking and show how it can be built in a Kubernetes-based prototype implementation. Immanuel Kunz, Valentina Casola, Angelika Schneider, Christian Banse, Julian Schütte |
CLOUD | 4 |
| 2020 | An Edge Framework for the Application of Privacy Enhancing Technologies in IoT CommunicationsabstractIoT devices generate large amounts of data that is often processed in cloud backends. This data, however, is often personal and sensitive. At the same time, IoT devices often communicate via edge devices that allow to pre-process the devices' data before it is sent to the cloud. To facilitate the privacy-preserving communication between IoT devices and cloud backends, we propose a framework that can be deployed on edge devices and which allows the application of Privacy Enhancing Technologies (PETs) and other computational tasks. It is designed as a practical tool for service providers supporting the privacy-friendly design and operation of edge-based services. It supports various stakeholder requirements, e.g. extendibility and auditability, as well as legal requirements which result from the General Data Protection Regulation (GDPR), e.g. data minimization. We also present an example application using the AWS IoT service and its Greengrass software to show how the framework can be used in a car-sharing service. Immanuel Kunz, Philipp Stephanow, Christian Banse |
ICC | 3 |
| 2020 | Selecting Privacy Enhancing Technologies for IoT-Based Services
Immanuel Kunz, Christian Banse, Philipp Stephanow |
SecureComm (2) | 2 |
| 2020 | Privacy Smells: Detecting Privacy Problems in Cloud ArchitecturesabstractMany organizations are still reluctant to move sensitive data to the cloud. Moreover, data protection regulations have established considerable punishments for violations of privacy and security requirements. Privacy, however, is a concept that is difficult to measure and to demonstrate. While many privacy design strategies, tactics and patterns have been proposed for privacy-preserving system design, it is difficult to evaluate an existing system with regards to whether these strategies have or have not appropriately been implemented. In this paper we propose indicators for a system's non-compliance with privacy design strategies, called privacy smells. To that end we first identify concrete metrics that measure certain aspects of existing privacy design strategies. We then define smells based on these metrics and discuss their limitations and usefulness. We identify these indicators on two levels of a cloud system: the data flow level and the access control level. Using a cloud system built in Microsoft Azure we show how the metrics can be measured technically and discuss the differences to other cloud providers, namely Amazon Web Services and Google Cloud Platform. We argue that while it is difficult to evaluate the privacy-awareness in a cloud system overall, certain privacy aspects in cloud systems can be mapped to useful metrics that can indicate underlying privacy problems. With this approach we aim at enabling cloud users and auditors to detect deep-rooted privacy problems in cloud systems. Immanuel Kunz, Angelika Schneider, Christian Banse |
TrustCom | 3 |
| 2019 | Reducing Implementation Efforts in Continuous Auditing Certification Via an Audit APIabstractContinuous auditing reduces the frequency in which compliance is verified. This results in more trustworthiness for the cloud service and therefore lowers the barrier of adopting cloud for customers in high-risk sectors such as banking. However, implementing continuous auditing as of today is a tedious task and not standardized, which leaves the service providers implementing the whole audit process and the technical infrastructure. We are proposing a solution for this problem by defining a standardized way of establishing the continuous auditing process for an IT infrastructure as well as providing the necessary tools as a reference implementation. In this paper we present how complexity in setting up the technical requirements for continuous auditing can be highly reduced by providing an easy to implement Audit API and continuous auditing methodology. Dorian Knoblauch, Christian Banse |
WETICE | 2 |
| 2018 | Enhancing NFV Orchestration with Security PoliciesabstractWith cloud computing and the evolution towards 5G, dynamic, self-provisioned and flexible service architectures will become even more prominent. Instead of deploying a service and its component on a single platform, components may be spread out to run at the mobile edge. At the same time, mobile edge computing requires that services move around with their consumers. In this highly dynamic service deployment scenario, it is important to maintain technology-agnostic service descriptions. In addition, these service descriptions must carry their associated security policies with them to be able to decide whether resources are usable when upscaling or moving a service. To this end, we illustrate the definition of security policies in the technology-agnostic TOSCA service specification language. Our goal is to initiate the development of a security policy catalog for NFV services and the implementation of the necessary software tools for their enforcement. Florian Wendland, Christian Banse |
ARES | 2 |
| 2017 | Evaluating the performance of continuous test-based cloud service certificationabstractContinuous test-based cloud certification uses tests to automatically and repeatedly evaluate whether a cloud service satisfies customer requirements over time. However, inaccurate tests can decrease customers' trust in test results and can lead to providers disputing results of test-based certification techniques. In this paper, we propose an approach how to evaluate the performance of test-based cloud certification techniques. Our method allows to infer conclusions about the general performance of test-based techniques, compare alternative techniques, and compare alternative configurations of test-based techniques. We present experimental results on how we used our approach to evaluate and compare exemplary test-based techniques which support the certification of requirements related to security, reliability and availability. Philipp Stephanow, Christian Banse |
CCGrid | 2 |
| 2017 | Continuous Location Validation of Cloud Service ComponentsabstractContinuously, i.e. automatically and repeatedly checking at what geographical locations cloud service components are hosted aims at validating that the cloud service satisfies regulatory and other compliance requirements. Yet continuous validation is challenging since it requires location techniques to adapt to network changes over time. In this paper, we present adaptive location classification, an approach to continuously validate the location of cloud service components. Our approach combines supervised and unsupervised learning techniques and is capable of adapting to network changes over time. We demonstrate the feasibility of our approach by presenting experimental results where we continuously validate the locations of cloud service components hosted at 14 different locations of the AWS Global Infrastructure. Philipp Stephanow, Mohammad Moein, Christian Banse |
CloudCom | 3 |
| 2017 | A taxonomy-based approach for security in software-defined networkingabstractSoftware Defined Networking (SDN) promises to abstract hardware and hard-wired network topologies in favor of programmable dynamic infrastructures. However, especially features like multi-tenancy require for new ways to ensure that access to critical network resources are restricted to trusted applications and users. The challenge here is that these entities are not necessarily known at the time of planning and setup, but are rather added dynamically to the network at runtime. Controlling access to northbound interfaces of SDN controllers thus requires for new ways to express access control policies which are able to cope with this degree of complexity and abstraction. We thus introduce a taxonomy-based policy engine, which allows the definition of fine-grained security policies based on a first-order logic description of the network environment. We describe the taxonomy structure and show how it can be used in a Prolog-based policy engine to protect a secure SDN northbound interface developed in previous work. By evaluating the implementation in a virtual SDN environment, we found the performance overhead of our approach to be tolerable. Christian Banse, Julian Schütte |
ICC | 1 |
| 2014 | Demonstrating the optimal placement of virtualized cellular network functions in case of large crowd eventsabstractNo abstract available. Steffen Gebert, David Hock, Thomas Zinner, Phuoc Tran-Gia, Marco Hoffmann, Michael Jarschel, Ernst-Dieter Schmidt, Ralf-Peter Braun, Christian Banse, Andreas Köpsel |
SIGCOMM | 9 |
| 2013 | Behavior-based tracking: Exploiting characteristic patterns in DNS traffic
Dominik Herrmann, Christian Banse, Hannes Federrath |
Comput. Secur. | 2 |
| 2012 | Tracking Users on the Internet with Behavioral Patterns: Evaluation of Its Practical Feasibility
Christian Banse, Dominik Herrmann, Hannes Federrath |
SEC | 1 |