Elmar Gerhards-Padilla

dblp:61/2236 · also Elmar Padilla · DBLP profile ↗
← Back
25ranked-venue papers
2as first author
11since 2021 · last 2026
0009-0001-6642-0660ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 15 · 1 first-author · 5 since 2021Computer networks · 6 · 1 first-author · 3 since 2021Software engineering, systems software and programming languages · 2 · 2 since 2021Systems, architecture and hardware · 1
YearPublicationVenuePosition
2026 To GOTO or Not to GOTO: Measuring Structural Complexity of (Decompiled) Code
abstract
Gotos are prevalent in many programs and contexts. Although it is widely assumed that gotos reduce readability, empirical evidence is limited, and most code metrics either ignore them or fail to model their impact on program comprehension. The problem is especially noticeable in highly optimized code, automatically transformed or AI generated code, and decompiler output, where gotos are very common. Without a metric that measures the structural complexity of such code with gotos, it remains challenging to evaluate and improve approaches involving program comprehension.
Steffen Enders, Eva-Maria C. Behner, Elmar Gerhards-Padilla
ICPC3
2025 SoK: No Goto, No Cry? The Fairy Tale of Flawless Control-Flow Structuring
abstract
Decompilers play a crucial role in the detailed analysis of malware or firmware, particularly because control-flow structuring allows the recovery of high-level code that is more readable to human analysts. Despite the ongoing debate over their usage of gotos to work around constraints during control-flow structuring, pattern-matching approaches remain prevalent among both commercial and open-source decompilers. With the emergence of pattern-independent restructuring techniques, various attempts have been made to overcome readability limitations, especially concerning the use of gotos. However, despite these advances, recent approaches often fail to thoroughly address several inherent challenges of control-flow structuring, thereby affecting output quality or practicality.In this paper, we systematize the intrinsic challenges of control-flow structuring that every approach must address. In addition, we review existing methods, comparing them, while highlighting both their advantages and limitations with respect to these challenges. Specifically, we emphasize the practicability issues of current pattern-independent restructuring techniques and discuss whether and how future methods might overcome them. Finally, we explore the theoretical potential to mitigate some of these challenges by suggesting methodology ideas for various aspects of control-flow structuring. Overall, this paper enables other researchers to make informed decisions when developing or enhancing control-flow structuring methods, thereby preventing negative side-effects arising from the interdependence of challenges.
Eva-Maria C. Behner, Steffen Enders, Elmar Gerhards-Padilla
EuroS&P3
2025 A Jump-Table-Agnostic Switch Recovery on ASTs
abstract
Recovering high-level control-flow structures is a crucial part of modern reverse engineering, especially in fields like binary analysis. Here, analysts often use decompilers to convert functions of binary programs into a more humanreadable C -like representation. Among these control-flow structures, switch statements have unique significance because of their ability to represent complex decision-making and branching behavior in a concise and readable manner. Consequently, the successful recovery of switch statements during decompilation can greatly enhance the readability of the resulting output, making it a highly desired goal in the field of reverse engineering. In this paper, we present a new technique for identifying abstract syntax tree components that can be transformed into semantically equivalent switches, thus improving code readability. In contrast to other approaches, we do not rely on jump tables that have or have not been emitted during compilation. Instead, we identify clusters of comparisons involving the same expression but with varying constant values within the abstract syntax tree to be transformed into switch constructs. Because this approach is inherently linked to the semantic definition of a switch statements, it only generates meaningful switches by design. We evaluated our approach on the coreutils-9.3 dataset and compared it to the leading decompilers Ghidra and Hex-Rays, both of which attempt to recover switch statements as well. Our evaluation results indicate that our approach outperforms both Ghidra and Hex-Rays by successfully recovering more than twice as many switch constructs in the given dataset.
Steffen Enders, Eva-Maria C. Behner, Elmar Gerhards-Padilla
ICSME3
2025 Seeing is Believing - a Practical Study of Cyber Attacks on a Ship Navigation Bridge
abstract
The maritime transportation system is the backbone of global trade and the economy. At the same time, the legacy IT and communication systems onboard modern cargo ships with their integrated bridge systems are increasingly vulnerable to cyber attacks, as researchers have repeatedly demonstrated. Despite the growing threat, progress on securing maritime systems remains slow. One major obstacle is the protracted standardization process, which delays the deployment of effective countermeasures. Another, however, is the limited awareness – and resulting inaction – among maritime stakeholders regarding the potentially fatal impact of cyber attacks on bridge systems and navigation decisions. In this paper, we therefore compile known academic cyber attacks targeting ship IT and apply them to a representative, real-world ship navigation bridge to highlight its vulnerabilities and raise stakeholder awareness. We also share insights and lessons learned from our implementation.
Frederik Basels, Philipp Sedlmeier, Elmar Gerhards-Padilla
LCN3
2025 Mens Sana In Corpore Sano: Sound Firmware Corpora for Vulnerability Research
René Helmke, Elmar Gerhards-Padilla, Nils Aschenbruck
NDSS2
2024 Demo: Maritime Radar Systems under Attack. Help is on the Way!
abstract
For a long time, attacks on radar systems were limited to military targets. With increasing interconnection, cyber attacks have nowadays become a serious complementary threat also affecting civil radar systems for aviation traffic control or maritime navigation. Hence, operators need to be enabled to detect and respond to cyber attacks and must be supported by defense capabilities. However, security research in this domain is only just beginning and is hampered by a lack of adequate test and development environments. In this demo, we thus present a maritime Radar Cyber Security Lab (RCSL) as a holistic framework to identify vulnerabilities of navigation radars and to support the development of defensive solutions. RCSL offers an offensive tool for attacking navigation radars and a defensive module leveraging network-based anomaly detection. In our demonstration, we will showcase the radars’ vulnerabilities in a simulative environment and demonstrate the benefit of an application-specific Intrusion Detection System.
Frederik Basels, Konrad Wolsing, Elmar Gerhards-Padilla
LCN3
2023 Comprehensively Analyzing the Impact of Cyberattacks on Power Grids
abstract
The increasing digitalization of power grids and especially the shift towards IP-based communication drastically increase the susceptibility to cyberattacks, potentially leading to blackouts and physical damage. Understanding the involved risks, the interplay of communication and physical assets, and the effects of cyberattacks are paramount for the uninterrupted operation of this critical infrastructure. However, as the impact of cyberattacks cannot be researched in real-world power grids, current efforts tend to focus on analyzing isolated aspects at small scales, often covering only either physical or communication assets. To fill this gap, we present Wattson, a comprehensive research environment that facilitates reproducing, implementing, and analyzing cyberattacks against power grids and, in particular, their impact on both communication and physical processes. We validate Wattson’s accuracy against a physical testbed and show its scalability to realistic power grid sizes. We then perform authentic cyberattacks, such as Industroyer, within the environment and study their impact on the power grid’s energy and communication side. Besides known vulnerabilities, our results reveal the ripple effects of susceptible communication on complex cyber-physical processes and thus lay the foundation for effective countermeasures.
Lennart Bader, Martin Serror, Olav Lamberts, Ömer Sen, Dennis van der Velde, Immanuel Hacker, Julian Filter, Elmar Gerhards-Padilla, Martin Henze
EuroS&P8
2023 A Measurement Study on Interprocess Code Propagation of Malicious Software
Thorsten Jenke, Simon Liessem, Elmar Gerhards-Padilla, Lilli Bruckschen
ICDF2C (2)3
2023 XLab-UUV - A Virtual Testbed for Extra-Large Uncrewed Underwater Vehicles
abstract
Roughly two-thirds of our planet is covered with water, and so far, the oceans have predominantly been used at their surface for the global transport of our goods and commodities. Today, there is a rising trend toward subsea infrastructures such as pipelines, telecommunication cables, or wind farms which demands potent vehicles for underwater work. To this end, a new generation of vehicles, large and Extra-Large Unmanned Underwater Vehicles (XLUUVs), is currently being engineered that allow for long-range, remotely controlled, and semi-autonomous missions in the deep sea. However, although these vehicles are already heavily developed and demand state-of-the-art communication technologies to realize their autonomy, no dedicated test and development environments exist for research, e.g., to assess the implications on cybersecurity. Therefore, in this paper, we present XLab-UUV, a virtual testbed for XLUUVs that allows researchers to identify novel challenges, possible bottlenecks, or vulnerabilities, as well as to develop effective technologies, protocols, and procedures.
Konrad Wolsing, Antoine Saillard, Elmar Gerhards-Padilla
LCN3
2022 Keeping the Baddies Out and the Bridge Calm: Embedded Authentication for Maritime Networks
abstract
Integrated bridges of today’s vessels are complex and distributed maritime systems that interconnect versatile electronic equipment. However, digitized vessels have long ceased to be isolated systems and are thus increasingly vulnerable to cyber attacks. In this context, integrity and authentication of the communication onboard is crucial. Therefore, we introduce MARMAC, a low-cost solution to retrofit authentication of nautical communication. MARMAC is based on symmetric cryptography and extends the prevalent IEC61162-450 protocol enabling a backward-compatible solution which mitigates common attacks. Using a specific gatekeeper approach, MARMAC can prevent unauthenticated messages from being processed that could otherwise affect the nautical situational awareness on the bridge. Our approach is evaluated using real network traffic in a laboratory testbed with low-cost hardware, highlighting its feasibility and potential to secure existing maritime systems.
Lucca Ruhland, Mari Schmidt, Elmar Gerhards-Padilla
ISNCC4
2021 PIdARCI: Using Assembly Instruction Patterns to Identify, Annotate, and Revert Compiler Idioms
abstract
Analysis of binary code is a building block of computer security. Especially in malware or firmware analysis where source code oftentimes is not available, techniques like decompilation are utilized to Figure out the functionality of binaries. During the optimization phase in modern compilers, human-readable expressions are often transformed into instruction sequences (compiler idioms or idioms) that may be more efficient in terms of speed or size than the direct translation. However, these transformations are often considerably worse in terms of readability for the analyst. Such compiler specific sequences are not only significantly longer than the apparent translation of the original high-level language operation but also have no trivial correlation to the original expression’s semantics. Modern decompilers address this issue by reverting idioms using static, manually crafted rules. In this paper, we introduce a novel approach to find and annotate arithmetic idioms with their corresponding high-level language expressions to significantly simplify manual analysis. In contrast to previous approaches, our method does not require manual work to create the patterns for matching idioms and significantly less manual labour to derive the transformation rules to calculate the original constants. In our evaluation, we compared the results of PIdARCI against the current academic and commercial state-of-the-art Ghidra, RetDec, and Hex Rays / IDA Pro. We show that PIdARCI matches more than 99% of all considered idioms, exceeding the matching rate of the other approaches.
Steffen Enders, Mariia Rybalka, Elmar Gerhards-Padilla
PST3
2017 Quincy: Detecting Host-Based Code Injection Attacks in Memory Dumps
Thomas Barabosch, Niklas Bergmann, Adrian Dombeck, Elmar Gerhards-Padilla
DIMVA4
2016 discovRE: Efficient Cross-Architecture Identification of Bugs in Binary Code
Sebastian Eschweiler, Khaled Yakdan, Elmar Gerhards-Padilla
NDSS3
2016 Helping Johnny to Analyze Malware: A Usability-Optimized Decompiler and Malware Analysis User Study
abstract
Analysis of malicious software is an essential task in computer security, it provides the necessary understanding to devise effective countermeasures and mitigation strategies. The level of sophistication and complexity of current malware continues to evolve significantly, as the recently discovered "Regin" malware family strikingly illustrates. This complexity makes the already tedious and time-consuming task of manual malware reverse engineering even more difficult and challenging. Decompilation can accelerate this process by enabling analysts to reason about a high-level, more abstract from of binary code. While significant advances have been made, state-of-the-art decompilers still produce very complex and unreadable code and malware analysts still frequently go back to analyzing the assembly code. In this paper, we present several semantics-preserving code transformations to make the decompiled code more readable, thus helping malware analysts understand and combat malware. We have implemented our optimizations as extensions to the academic decompiler DREAM. To evaluate our approach, we conducted the first user study to measure the quality of decompilers for malware analysis. Our study includes 6 analysis tasks based on real malware samples we obtained from independent malware experts. We evaluate three decompilers: the leading industry decompiler Hex-Rays, the state-of-the-art academic decompiler DREAM, and our usability-optimized decompiler DREAM++. The results show that our readability improvements had a significant effect on how well our participants could analyze the malware samples. DREAM++ outperforms both Hex-Rays and DREAM significantly. Using DREAM++ participants solved 3x more tasks than when using Hex-Rays and 2x more tasks than when using DREAM.
Khaled Yakdan, Sergej Dechand, Elmar Gerhards-Padilla, Matthew Smith 0001
IEEE Symposium on Security and Privacy3
2016 A Comprehensive Measurement Study of Domain Generating Malware
Daniel Plohmann, Khaled Yakdan, Michael Klatt, Elmar Gerhards-Padilla
USENIX Security Symposium5
2015 No More Gotos: Decompilation Using Pattern-Independent Control-Flow Structuring and Semantic-Preserving Transformations
Khaled Yakdan, Sebastian Eschweiler, Elmar Gerhards-Padilla, Matthew Smith 0001
NDSS3
2015 BotWatcher - Transparent and Generic Botnet Tracking
Thomas Barabosch, Adrian Dombeck, Khaled Yakdan, Elmar Gerhards-Padilla
RAID4
2014 Bee Master: Detecting Host-Based Code Injection Attacks
Thomas Barabosch, Sebastian Eschweiler, Elmar Gerhards-Padilla
DIMVA3
2013 Resurrection: A Carver for Fragmented Files
Martin Lambertz, Rafael Uetz, Elmar Gerhards-Padilla
ICDF2C3
2012 Applicability of crypto-based security approaches in tactical wireless multi-hop networks
abstract
Security is one of the core challenges especially for wireless multi-hop networks in public safety scenarios. Sensitive data is transmitted via insecure links. Furthermore, there may be competing interests. Thus, there is a high probability of disturbance or eavesdropping of communication. Confidentiality, integrity, and authenticity of transmitted packets can be provided by cryptographic means. However, as the devices used in multi-hop networks are usually resource constrained, the goal of this paper is to scrutinize the feasibility of securing such networks using strong but computationally expensive cryptography. In this paper, we show generic benchmarking results for tactical multi-hop network devices as well as a case study comparing two routing security approaches.
Nils Aschenbruck, Elmar Gerhards-Padilla, Martin Lambertz
LCN2
2012 PDF Scrutinizer: Detecting JavaScript-based attacks in PDF documents
abstract
For a long time PDF documents have arrived in the everyday life of the average computer user, corporate businesses and critical structures, as authorities and military. Due to its wide spread in general, and because out-of-date versions of PDF readers are quite common, using PDF documents has become a popular malware distribution strategy. In this context, malicious documents have useful features: they are trustworthy, attacks can be camouflaged by inconspicuous document content, but still, they can often download and install malware undetected by firewall and anti-virus software. In this paper we present PDF Scrutinizer, a malicious PDF detection and analysis tool. We use static, as well as, dynamic techniques to detect malicious behavior in an emulated environment. We evaluate the quality and the performance of the tool with PDF documents from the wild, and show that PDF Scrutinizer reliably detects current malicious documents, while keeping a low false-positive rate and reasonable runtime performance.
Florian Schmitt, Jan Gassen, Elmar Gerhards-Padilla
PST3
2011 TOGBAD - an approach to detect routing attacks in tactical environments
abstract
Abstract Topology graph based anomaly detection (TOGBAD) is a centralized approach to detect routing attacks in tactical multi‐hop networks. It uses anomaly detection based on topology graphs to identify attackers trying to launch routing attacks. Such attacks are a serious threat to multi‐hop networks since they may be used to disrupt, eavesdrop or manipulate the network. In this work, we present studies on the impact of an attacker launching a routing attack. Furthermore, we show a reasonable choice of attack parameters for the attacker. In our main contribution, we introduce TOGBAD and an evaluation of TOGBAD concerning its detection rate with and without packet loss. Finally, we illustrate TOGBAD's detection rate with an attacker trying to inure TOGBAD's anomaly detection to his attack. Copyright © 2010 John Wiley & Sons, Ltd.
Elmar Gerhards-Padilla, Nils Aschenbruck, Peter Martini
Secur. Commun. Networks1
2009 Modeling mobility in disaster area scenarios
Nils Aschenbruck, Elmar Gerhards-Padilla, Peter Martini
Perform. Evaluation2
2007 Detecting Black Hole Attacks in Tactical MANETs using Topology Graphs
abstract
Black hole attacks are a serious threat to communication in tactical MANETs. In this work we present TOGBAD a new centralised approach, using topology graphs to identify nodes attempting to create a black hole. We use well-established techniques to gain knowledge about the network topology and use this knowledge to perform plausibility checks of the routing information propagated by the nodes in the network. We consider a node generating fake routing information as malicious. Therefore, we trigger an alarm if the plausibility check fails. Furthermore, we present promising first simulation results. With our new approach, it is possible to already detect the attempt to create a black hole before the actual impact occurs.
Elmar Gerhards-Padilla, Nils Aschenbruck, Peter Martini, Marko Jahnke, Jens Tölle
LCN1
2007 Modelling mobility in disaster area scenarios
abstract
This paper provides a model that realistically represents the movements in a disaster area scenario. The model is based on an analysis of tactical issues of civil protection. This analysis provides characteristics influencing network performance in public safety communication networks like heterogeneous area-based movement, obstacles, and joining/leaving of nodes. As these characteristics cannot be modelled with existing mobility models, we introduce a new disaster area mobility model. To examine the impact of our more realistic modelling, we compare it to existing ones (modelling the same scenario) using different pure movement and link based metrics. The new model shows specific characteristics like heterogeneous node density. Finally, the impact of the new model is evaluated in an exemplary simulative network performance analysis. The simulations show that the new model discloses new information and has a significant impact on performance analysis.
Nils Aschenbruck, Elmar Gerhards-Padilla, Michael Gerharz, Matthias Frank 0001, Peter Martini
MSWiM2