VLDB 2026 Research / reviewers in the wild / expert
David Rupprecht
dblp:77/2192
· DBLP profile ↗
15ranked-venue papers
4as first author
6since 2021 · last 2023
0000-0001-5880-013XORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 12 · 3 first-author · 6 since 2021Theory of computation · 3 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2023 | Instructions Unclear: Undefined Behaviour in Cellular Network Specifications
Daniel Klischies, Moritz Schloegel, Tobias Scharnowski, Mikhail Bogodukhov, David Rupprecht, Veelasha Moonsamy |
USENIX Security Symposium | 5 |
| 2023 | BigMac: Performance Overhead of User Plane Integrity Protection in 5G Networksabstract5G introduces a series of new security features that overcome known issues of the previous mobile generations. One of these features is integrity protection for user plane data. While this addition protects against manipulations like DNS spoofing, it also introduces extra overhead to user plane traffic. As it is optional to enable, this additional overhead can be the decision point for network operators to avoid the additional security feature. In this work, we investigate the overhead induced by different integrity protection algorithms and test the burden they add to the workload of a device. Our results indicate how visible performance differences would be on the end-devices of users, and how the performance of the algorithms differs in isolation. With these results we aim to initiate a discussion regarding the benefits of enabling user plane integrity protection and to overcome misconceptions regarding the performance impairments for end users. Thijs Heijligenberg, Guido Knips, Christian Böhm 0003, David Rupprecht, Katharina Kohls |
WISEC | 4 |
| 2023 | Never Let Me Down Again: Bidding-Down Attacks and Mitigations in 5G and 4GabstractBidding-down attacks reduce the security of a mobile network connection. Weaker encryption algorithms or even downgrades to prior network generations enable an adversary to exploit numerous attack vectors and harm the users of a network. The problem of bidding-down attacks has been known for generations, and various mitigations are integrated into the latest 4G and 5G specifications. However, current research lacks a systematic identification and analysis of the variety of potential attack vectors. In this work, we classify an extensive set of bidding-down attack vectors and mitigations and analyze their specification and implementation in phones and networks. Our results demonstrate vulnerabilities for all attacks and devices, including the latest mobile generation 5G and recent flagship phones. To further prove how the identified attack vectors can be exploited in sophisticated attacks, we conduct two case studies in which we apply a full downgrade attack from 5G SA to 2G and bid down a 5G NSA connection by enforcing null encryption. Again, we find a majority of systems vulnerable. With this paper, we hope to improve the state of bidding-down mitigations in the specification and implementation. Bedran Karakoc, Nils Fürste, David Rupprecht, Katharina Kohls |
WISEC | 3 |
| 2021 | Cryptanalysis of the GPRS Encryption Algorithms GEA-1 and GEA-2
Christof Beierle, Patrick Derbez, Gregor Leander, Gaëtan Leurent, Håvard Raddum, Yann Rotella, David Rupprecht, Lukas Stennes |
EUROCRYPT (2) | 7 |
| 2021 | On the challenges of automata reconstruction in LTE networksabstractMobile networks are a crucial part of our digital lives and require adequate security measures. The 4G and 5G network standards are complex and challenging to implement, which led to several implementation issues being discovered over the last years. Consequently, we aim to strengthen automation in testing and increase test coverage to spot issues and potential security vulnerabilities. Merlin Chlosta, David Rupprecht, Thorsten Holz |
WISEC | 2 |
| 2021 | 5G SUCI-catchers: still catching them all?abstractIn mobile networks, IMSI-Catchers identify and track users simply by requesting all users' permanent identities (IMSI) in range. The 5G standard attempts to fix this issue by encrypting the permanent identifier (now SUPI) and transmitting the SUCI. Since the encrypted SUCI is re-generated with an ephemeral key for each use, an attacker can no longer derive the user's identity. However, this scheme does not prevent all tracking and linking: if the identity of a user is already known, an attacker can probe users for that identity. Merlin Chlosta, David Rupprecht, Christina Pöpper, Thorsten Holz |
WISEC | 2 |
| 2020 | IMP4GT: IMPersonation Attacks in 4G NeTworks
David Rupprecht, Katharina Kohls, Thorsten Holz, Christina Pöpper |
NDSS | 1 |
| 2020 | Call Me Maybe: Eavesdropping Encrypted LTE Calls With ReVoLTE
David Rupprecht, Katharina Kohls, Thorsten Holz, Christina Pöpper |
USENIX Security Symposium | 1 |
| 2019 | On the Challenges of Geographical Avoidance for Tor
Katharina Kohls, Kai Jansen, David Rupprecht, Thorsten Holz, Christina Pöpper |
NDSS | 3 |
| 2019 | Breaking LTE on Layer TwoabstractLong Term Evolution (LTE) is the latest mobile communication standard and has a pivotal role in our information society: LTE combines performance goals with modern security mechanisms and serves casual use cases as well as critical infrastructure and public safety communications. Both scenarios are demanding towards a resilient and secure specification and implementation of LTE, as outages and open attack vectors potentially lead to severe risks. Previous work on LTE protocol security identified crucial attack vectors for both the physical (layer one) and network (layer three) layers. Data link layer (layer two) protocols, however, remain a blind spot in existing LTE security research. In this paper, we present a comprehensive layer two security analysis and identify three attack vectors. These attacks impair the confidentiality and/or privacy of LTE communication. More specifically, we first present a passive identity mapping attack that matches volatile radio identities to longer lasting network identities, enabling us to identify users within a cell and serving as a stepping stone for follow-up attacks. Second, we demonstrate how a passive attacker can abuse the resource allocation as a side channel to perform website fingerprinting that enables the attacker to learn the websites a user accessed. Finally, we present the A LTE R attack that exploits the fact that LTE user data is encrypted in counter mode (AES-CTR) but not integrity protected, which allows us to modify the message payload. As a proof-of-concept demonstration, we show how an active attacker can redirect DNS requests and then perform a DNS spoofing attack. As a result, the user is redirected to a malicious website. Our experimental analysis demonstrates the real-world applicability of all three attacks and emphasizes the threat of open attack vectors on LTE layer two protocols. David Rupprecht, Katharina Kohls, Thorsten Holz, Christina Pöpper |
IEEE Symposium on Security and Privacy | 1 |
| 2019 | LTE security disabled: misconfiguration in commercial networksabstractLong Term Evolution (LTE) is the de-facto standard for mobile communication. It provides effective security features but leaves room for misunderstandings in its configuration and implementation. In particular, providers face difficulties when maintaining network configurations. Merlin Chlosta, David Rupprecht, Thorsten Holz, Christina Pöpper |
WiSec | 2 |
| 2019 | Lost traffic encryption: fingerprinting LTE/4G traffic on layer twoabstractLong Term Evolution (LTE) provides the communication infrastructure for both professional and private use cases and has become an integral part of our everyday life. Even though LTE/4G overcomes many security issues of previous standards, recent work demonstrates several attack vectors on the physical and network layers of the LTE stack. We do, however, have only limited insights into the security and privacy aspects of the second layer. Katharina Kohls, David Rupprecht, Thorsten Holz, Christina Pöpper |
WiSec | 2 |
| 2004 | Semi-numerical absolute factorization of polynomials with integer coefficients
David Rupprecht |
J. Symb. Comput. | 1 |
| 2002 | Irreducible Decomposition of Curves
André Galligo, David Rupprecht |
J. Symb. Comput. | 2 |
| 2001 | Semi-numerical determination of irreducible branches of a reduced space curveabstractIn this paper, we propose a semi-numerical algorithm for computing all irreducible branches of a curve in C3 defined by polynomials with rational coefficients. It is based on some properties appearing after a generic change of coordinate. Using numerical computation, Galois group action and rational approximation, it provides an efficient probabilistic algorithm for medium degrees. Our method generalizes our study on absolute factorization of polynomials ([2, 6]). André Galligo, David Rupprecht |
ISSAC | 2 |