VLDB 2026 Research / reviewers in the wild / expert
Andriy Panchenko 0001
dblp:82/5164-1
· DBLP profile ↗
30ranked-venue papers
9as first author
8since 2021 · last 2025
0009-0004-2563-4234ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 18 · 6 first-author · 5 since 2021Computer networks · 7 · 3 first-author · 1 since 2021Databases, data management, data science and information retrieval · 2 · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Poster: Characterization of Dominant and Specific Network Patterns in Industrial Control SystemsabstractThe increasing digitization and interconnection of Industrial Control Systems (ICS) to the Internet render them susceptible to cyber attacks. Thus, a major line of research focuses on the design of reactive security solutions in the form of industrial intrusion detection systems, which aim to detect anomalies in a normal system operation. However, a crucial prerequisite for the accurate detection and localization of anomalies is the identification of typical traffic patterns that are exclusive to characterize the normal ICS behavior. Unlike previous work focusing on complex and protocol-dependent models, for characterizing ICS network traffic, in this work we propose simple, easy deployable, and effective rules for determining whether ICS network traffic, unlike traditional IT networks, remains stable over time. The main advantage of our rules is that they can be used to estimate the time required to identify the most dominant ICS traffic patterns in a given ICS. We show the efficacy of our rules by analyzing multiple ICS datasets with different industrial network protocols. Asya Mitseva, Marco Lewandowsky, Andriy Panchenko 0001 |
NCA | 3 |
| 2024 | Reviewing War: Unconventional User Reviews as a Side Channel to Circumvent Information ControlsabstractDuring the first days of the 2022 Russian invasion of Ukraine, Russia's media regulator blocked access to many global social media platforms and news sites, including Twitter, Facebook, and the BBC. To bypass the information controls set by Russian authorities, pro-Ukrainian groups explored unconventional ways to reach out to the Russian population, such as posting war-related content in the user reviews of Russian businesses available on Google Maps or Tripadvisor. This paper provides a first analysis of this new phenomenon by analyzing the unconventional strategies used to avoid state censorship in the Russian Federation during the conflict. Specifically, we analyze reviews posted on these platforms from the beginning of the war to September 2022. We measure the channeling of war-related messages through user reviews on Tripadvisor and Google Maps. Our analysis of the content posted on these services reveals that users leveraged these platforms to seek and exchange humanitarian and travel advice, but also to disseminate disinformation and polarized messages. Finally, we analyze the response of platforms in terms of content moderation and their impact. José Miguel Moreno, Sergio Pastrana, Jens Helge Reelfs, Pelayo Vallina, Savvas Zannettou, Andriy Panchenko 0001, Georgios Smaragdakis, Oliver Hohlfeld, Narseo Vallina-Rodriguez, Juan Tapiador |
ICWSM | 6 |
| 2024 | Stop, Don't Click Here Anymore: Boosting Website Fingerprinting By Considering Sets of Subpages
Asya Mitseva, Andriy Panchenko 0001 |
USENIX Security Symposium | 2 |
| 2023 | Design Rationale for Symbiotically Secure Key Management Systems in IoT and BeyondabstractThe overwhelmingly widespread use of Internet of Things (IoT) in different application domains brought not only benefits, but, alas, security concerns as a result of the increased attack surface and vectors. One of the most critical mechanisms in IoT infrastructure is key management. This paper reflects on the problems and challenges of existing key management systems, starting with the discussion of a recent real-world attack. We identify and elaborate on the drawbacks of security primitives based purely on physical variations and - after highlighting the problems of such systems - continue on to deduce an effective and cost-efficient key management solution for IoT systems extending the symbiotic security approach in a previous work. The symbiotic architecture combines software, firmware, and hardware resources for secure IoT while avoiding the traditional scheme of static key storage and generating entropy for key material on-the-fly via a combination of a Physical Unclonable Function (PUF) and pseudo-random bits pre-populated in firmware. Witali Bartsch, Prosanta Gope, Elif Bilge Kavun, Owen Millwood, Andriy Panchenko 0001, Aryan Mohammadi Pasikhani, Ilia Polian |
ICISSP | 5 |
| 2023 | Security and performance implications of BGP rerouting-resistant guard selection algorithms for Tor
Asya Mitseva, Marharyta Aleksandrova, Andriy Panchenko 0001 |
Comput. Secur. | 3 |
| 2021 | POSTER: How Dangerous is My Click? Boosting Website Fingerprinting By Considering Sequences of WebpagesabstractWebsite fingerprinting (WFP) is a special case of traffic analysis, where a passive attacker infers information about the content of encrypted and anonymized connections by observing patterns of data flows. Although modern WFP attacks pose a serious threat to online privacy of users, including Tor users, they usually aim to detect single pages only. By ignoring the browsing behavior of users, the attacker excludes valuable information: users visit multiple pages of a single website consecutively, e.g., by following links. In this paper, we propose two novel methods that can take advantage of the consecutive visits of multiple pages to detect websites. We show that two up to three clicks within a site allow attackers to boost the accuracy by more than 20% and to dramatically increase the threat to users' privacy. We argue that WFP defenses have to consider this new dimension of the attack surface. Asya Mitseva, Jan Pennekamp, Johannes Lohmöller, Torsten Ziemann, Carl Hoerchner, Klaus Wehrle, Andriy Panchenko 0001 |
CCS | 7 |
| 2021 | WhisperChord: Scalable and Secure Node Discovery for Overlay NetworksabstractNode discovery is a fundamental service for any overlay network, including anonymization networks. Although anonymization and node discovery are two disjoint services, the node discovery has a direct impact on the anonymization. Centralized methods require a trusted third party, limit the network scalability, and are vulnerable to intersection (statistical disclosure) attacks. Therefore, several distributed node discovery methods were proposed to meet the security requirements of anonymization networks through additional structures within Distributed Hash Tables (DHTs). However, they require a high management overhead, a strict cooperation between nodes, and are susceptible to active and passive attacks.We propose WhisperChord—an alternative distributed node discovery approach, which incorporates gossiping into structured overlays. WhisperChord is based on a Chord DHT and neither creates any additional structures within the DHT nor requires any trusted third party. Via simulations, we show that our method provides superior protection against active attacks than prior methods and can effectively thwart information leakages. Andriy Panchenko 0001, Asya Mitseva, Sara Knabe |
LCN | 1 |
| 2021 | GuardedGossip: Secure and Anonymous Node Discovery in Untrustworthy Networks
Andriy Panchenko 0001, Asya Mitseva, Torsten Ziemann, Till Hering |
SecureComm (1) | 1 |
| 2020 | TrafficSliver: Fighting Website Fingerprinting Attacks with Traffic SplittingabstractWebsite fingerprinting (WFP) aims to infer information about the content of encrypted and anonymized connections by observing patterns of data flows based on the size and direction of packets. By collecting traffic traces at a malicious Tor entry node --- one of the weakest adversaries in the attacker model of Tor --- a passive eavesdropper can leverage the captured meta-data to reveal the websites visited by a Tor user. As recently shown, WFP is significantly more effective and realistic than assumed. Concurrently, former WFP defenses are either infeasible for deployment in real-world settings or defend against specific WFP attacks only. Wladimir De la Cadena, Asya Mitseva, Jens Hiller, Jan Pennekamp, Sebastian Reuter, Julian Filter, Thomas Engel 0001, Klaus Wehrle, Andriy Panchenko 0001 |
CCS | 9 |
| 2020 | Out-of-the-box Multipath TCP as a Tor Transport Protocol: Performance and Privacy ImplicationsabstractThe transport design of Tor - the most popular anonymization network - has been identified as a key factor responsible for its performance unfairness. In Tor, traffic from multiple users is multiplexed in a single TCP connection between two relays. While this has positive effects on privacy, it negatively influences performance and is characterized by unfairness as TCP congestion control gives all the multiplexed Tor traffic as little of the available bandwidth as it gives to every single TCP connection that competes for the same resource. To counter this, we propose to use multipath TCP (MPTCP). It allows for better resource utilization and increases throughput of the Tor traffic to a fairer extent. Our evaluation in realworld settings shows that using out-of-the-box MPTCP leads to 15% performance gain. We analyze the privacy implications of MPTCP in Tor settings and discuss potential threats and mitigation strategies. Wladimir De la Cadena, Daniel Kaiser 0001, Andriy Panchenko 0001, Thomas Engel 0001 |
NCA | 3 |
| 2020 | Security and Performance Implications of BGP Rerouting-Resistant Guard Selection Algorithms for Tor
Asya Mitseva, Marharyta Aleksandrova, Thomas Engel 0001, Andriy Panchenko 0001 |
SEC | 4 |
| 2019 | POSTER: Traffic Splitting to Counter Website FingerprintingabstractWebsite fingerprinting (WFP) is a special type of traffic analysis, which aims to infer the websites visited by a user. Recent studies have shown that WFP targeting Tor users is notably more effective than previously expected. Concurrently, state-of-the-art defenses have been proven to be less effective. In response, we present a novel WFP defense that splits traffic over multiple entry nodes to limit the data a single malicious entry can use. Here, we explore several traffic-splitting strategies to distribute user traffic. We establish that our weighted random strategy dramatically reduces the accuracy from nearly 95% to less than 35% for four state-of-the-art WFP attacks without adding any artificial delays or dummy traffic. Wladimir De la Cadena, Asya Mitseva, Jan Pennekamp, Jens Hiller, Fabian Lanze, Thomas Engel 0001, Klaus Wehrle, Andriy Panchenko 0001 |
CCS | 8 |
| 2019 | Analysis of Multi-path Onion Routing-Based Anonymization Networks
Wladimir De la Cadena, Daniel Kaiser 0001, Asya Mitseva, Andriy Panchenko 0001, Thomas Engel 0001 |
DBSec | 4 |
| 2019 | Tailoring Onion Routing to the Internet of Things: Security and Privacy in Untrusted EnvironmentsabstractAn increasing number of IoT scenarios involve mobile, resource-constrained IoT devices that rely on untrusted networks for Internet connectivity. In such environments, attackers can derive sensitive private information of IoT device owners, e.g., daily routines or secret supply chain procedures, when sniffing on IoT communication and linking IoT devices and owner. Furthermore, untrusted networks do not provide IoT devices with any protection against attacks from the Internet. Anonymous communication using onion routing provides a well-proven mechanism to keep the relationship between communication partners secret and (optionally) protect against network attacks. However, the application of onion routing is challenged by protocol incompatibilities and demanding cryptographic processing on constrained IoT devices, rendering its use infeasible. To close this gap, we tailor onion routing to the IoT by bridging protocol incompatibilities and offloading expensive cryptographic processing to a router or web server of the IoT device owner. Thus, we realize resource-conserving access control and end-to-end security for IoT devices. To prove applicability, we deploy onion routing for the IoT within the well-established Tor network enabling IoT devices to leverage its resources to achieve the same grade of anonymity as readily available to traditional devices. Jens Hiller, Jan Pennekamp, Markus Dahlmanns, Martin Henze, Andriy Panchenko 0001, Klaus Wehrle |
ICNP | 5 |
| 2019 | Multipathing Traffic to Reduce Entry Node Exposure in Onion RoutingabstractUsers of an onion routing network, such as Tor, depend on its anonymity properties. However, especially malicious entry nodes, which know the client's identity, can also observe the whole communication on their link to the client and, thus, conduct several de-anonymization attacks. To limit this exposure and to impede corresponding attacks, we propose to multipath traffic between the client and the middle node to reduce the information an attacker can obtain at a single vantage point. To facilitate the deployment, only clients and selected middle nodes need to implement our approach, which works transparently for the remaining legacy nodes. Furthermore, we let clients control the splitting strategy to prevent any external manipulation. Jan Pennekamp, Jens Hiller, Sebastian Reuter, Wladimir De la Cadena, Asya Mitseva, Martin Henze, Thomas Engel 0001, Klaus Wehrle, Andriy Panchenko 0001 |
ICNP | 9 |
| 2018 | The state of affairs in BGP security: A survey of attacks and defensesabstractThe Border Gateway Protocol (BGP) is the de facto standard interdomain routing protocol. Despite its critical role on the Internet, it does not provide any security guarantees. In response to this, a large amount of research has proposed a wide variety BGP security extensions and detection-recovery systems in recent decades. Nevertheless, BGP remains vulnerable to many types of attack. In this work, we conduct an up-to-date review of fundamental BGP threats and present a methodology for evaluation of existing BGP security proposals. Based on this, we introduce a comprehensive and up-to-date survey of proposals intended to make BGP secure and methods for detection and mitigation of routing instabilities. Last but not least, we identify gaps in research, and pinpoint open issues and unsolved challenges. Asya Mitseva, Andriy Panchenko 0001, Thomas Engel 0001 |
Comput. Commun. | 2 |
| 2016 | POSTER: Fingerprinting Tor Hidden ServicesabstractThe website fingerprinting attack aims to infer the content of encrypted and anonymized connections by analyzing patterns from the communication such as packet sizes, their order, and direction. Although recent study has shown that no existing fingerprinting method scales in Tor when applied in realistic settings, this does not consider the case of Tor hidden services. In this work, we propose a two-phase fingerprinting approach applied in the scope of Tor hidden services and explore its scalability. We show that the success of the only previously proposed fingerprinting attack against hidden services strongly depends on the Tor version used; i.e., it may be applicable to less than 1.5% of connections to hidden services due to its requirement for control of the first anonymization node. In contrast, in our method, the attacker needs merely to be somewhere on the link between the client and the first anonymization node and the attack can be mounted for any connection to a hidden service. Asya Mitseva, Andriy Panchenko 0001, Fabian Lanze, Martin Henze, Klaus Wehrle, Thomas Engel 0001 |
CCS | 2 |
| 2016 | Website Fingerprinting at Internet Scale
Andriy Panchenko 0001, Fabian Lanze, Jan Pennekamp, Thomas Engel 0001, Andreas Zinnen, Martin Henze, Klaus Wehrle |
NDSS | 1 |
| 2015 | Hacker's toolbox: Detecting software-based 802.11 evil twin access pointsabstractThe usage of public Wi-Fi hotspots has become a common routine in our everyday life. They are ubiquitous and offer fast and budget-friendly connectivity for various client devices. However, they are exposed to a severe security threat: since 802.11 identifiers (SSID, BSSID) can be easily faked, an attacker can setup an evil twin, i.e., an access point (AP) that users are unable to distinguish from a legitimate one. Once a user connects to the evil twin, he inadvertently creates a playground for various attacks such as collection of sensitive data (e.g., credit card information, passwords) or man-in-the-middle attacks even on encrypted traffic. It is particularly alarming that this security flaw has led to the development of several tools that are freely available, easy to use and allow mounting the attack from commodity client devices such as laptops, smartphones or tablets without attracting attention. In this paper we provide a detailed overview of tools that have been developed (or can be misused) to set up evil twin APs. We inspect them thoroughly in order to identify characteristics that allow them to be distinguished from legitimate hardware-based access points. Our analysis has discovered three methods for detecting software-based APs. These exploit accuracy flaws due to emulation of hardware behavior or peculiarities of the client Wi-Fi hardware they operate on. Our evaluation with 60 hardware APs and a variety of tools on different platforms reveals enormous potential for reliable detection. Furthermore, our methods can be performed on typical client hardware within a short period of time without even connecting to a potentially untrustworthy access point. Fabian Lanze, Andriy Panchenko 0001, Ignacio Ponce-Alcaide, Thomas Engel 0001 |
CCNC | 2 |
| 2014 | Letting the puss in boots sweat: detecting fake access points using dependency of clock skews on temperatureabstractThe only available IEEE 802.11 network identifiers (i.e., the network name and the MAC address) can be easily spoofed. Consequently, an attacker is able to fake a real hotspot and attract its traffic. By this means, the attacker can intercept, collect, or change users' traffic (often even if it is encrypted). In this paper, we describe an efficient method for detecting the replacement of access points (APs) by passive remote physical device fingerprinting. The main feature of our fingerprinting approach is the clock skew - an unavoidable phenomenon that causes clocks to run at minuscule yet remotely observable different speeds - which is extracted from information contained in beacon frames. We are the first to achieve a high discriminability of devices by completely eliminating the fingerprinters' influence and considering the clock skew's dependency on temperature. Finally, we develop a method for reliable detection of the presence of AP impostors that works without explicit temperature information. Compared to the best state-of-the-art approach, our method improves detection accuracy from about 30% to 90% without generating any traffic and requires less than one minute to collect a sufficient number of observations. Our approach yields a strong feature for passive remote physical device fingerprinting in wireless networks. Fabian Lanze, Andriy Panchenko 0001, Benjamin Braatz, Thomas Engel 0001 |
AsiaCCS | 2 |
| 2012 | Clock skew based remote device fingerprinting demystifiedabstractCommonly used identifiers for IEEE 802.11 access points (APs), such as network name (SSID), MAC, or IP address can be easily spoofed. This allows an attacker to fake a real AP and intercept, collect, or alter (potentially even encrypted) data. In this paper, we address the aforementioned problem by studying limits of unique remote physical device identification based on their clock skew - an unavoidable phenomenon that causes clocks to run at marginal but measurably different speed. To this end, we propose an algorithm for passive fingerprinting using timestamps regularly sent by APs in beacon frames. The major advantages of our method are that it is online and that we are able to eliminate the influence of clock skew of the measurement device. Hence, fingerprints performed by different devices become comparable. We calculate the precision of our clock skew measurement algorithm and provide a termination criterion for estimation of the clock skew with arbitrary precision. Moreover, conducting a large scale evaluation, we study the stability and uniqueness of clock skew as a means for remote wireless device identification. Fabian Lanze, Andriy Panchenko 0001, Benjamin Braatz, Andreas Zinnen |
GLOBECOM | 2 |
| 2012 | Improving performance and anonymity in the Tor networkabstractAnonymous communication aims to hide the relationship between communicating parties on the Internet. It is the technical basis for achieving privacy and overcoming censorship. Presently there are only a few systems that are of practical relevance for providing anonymity. One of the most widespread and well researched is Tor which is based on onion routing. Usage of Tor, however, often leads to long delays which are not tolerated by end-users. This, in return, discourages many of them from using the system and lowers the protection for the remaining ones. In this paper we analyze the bottlenecks in the Tor network and propose new methods of path selection that better utilize available capacities in the heterogeneous network and allow performance-improved onion routing. Our methods are based on the combination of remotely measured current load of the nodes and an estimation of their maximum capacity. We evaluate the proposed methods in a Tor network running in PlanetLab where we tried as far as possible to recreate real-world conditions. Finally, we present a practical approach to empirically analyze the strength of anonymity that different methods of path selection provide in comparison to each other. We show the risk of the currently used method for path selection in Tor and provide a countermeasure to protect against this risk by effectively detecting nodes that lie about their capacity. Andriy Panchenko 0001, Fabian Lanze, Thomas Engel 0001 |
IPCCC | 1 |
| 2011 | Lightweight Hidden ServicesabstractHidden services (HS) are mechanisms designed to provide network services while preserving anonymity for the identity of the server. Besides protecting the identity of the server, hidden services help to resist censorship, are resistant against distributed DoS attacks, and allow server functionality even if the service provider does not own a public IP address. Currently, only the Tor network offers this feature in full functionality. However, the HS concept in Tor is complex and provides poor performance. According to recent studies, average contact time for a hidden service is 24s which is far beyond what an average user is willing to wait. In this paper we introduce a novel approach for hidden services that achieves similar functionality as HS in Tor but does so in a simple and lightweight way with the goal to improve performance and usability. Additionally, contrary to Tor, in our approach clients are not required to install any specific software for accessing hidden services. This increases usability of our approach. Simplicity makes our approach easier to understand for normal users, eases protocol reviews, and increases chances of having several implementations of the protocol available. Moreover, simpler solutions are easier to analyze and they are naturally less prone to implementation failures rather than complex protocols. In this paper, we describe our approach and provide performance as well as anonymity analysis of resulting properties of the protocol. Andriy Panchenko 0001, Otto Spaniol, André Egners, Thomas Engel 0001 |
TrustCom | 1 |
| 2009 | NISAN: network information service for anonymization networksabstractNetwork information distribution is a fundamental service for any anonymization network. Even though anonymization and information distribution about the network are two orthogonal issues, the design of the distribution service has a direct impact on the anonymization. Requiring each node to know about all other nodes in the network (as in Tor and AN.ON -- the most popular anonymization networks) limits scalability and offers a playground for intersection attacks. The distributed designs existing so far fail to meet security requirements and have therefore not been accepted in real networks. Andriy Panchenko 0001, Stefan Richter 0001, Arne Rache |
CCS | 1 |
| 2009 | Interconnected Tool-assistance for Development of Agent-oriented Software Systems
Karl-Heinz Krempels, Andriy Panchenko 0001, Janno von Stülpnagel, Christoph Terwelp |
KEOD | 2 |
| 2009 | SHALON: Lightweight Anonymization Based on Open StandardsabstractIn this paper, we introduce a novel lightweight anonymization technique called Shalon. It is based on onion routing, aims to reduce complexity, and delivers high bandwidth. We have, compared to the widely known approach Tor, slightly reduced the level of security in favor for greatly increased performance. The most significant advantage compared to other approaches is that Shalon is fully based on standardized protocols, which makes our approach highly efficient and easy to deploy. It also makes Shalon easier to understand for normal users, eases protocol reviews, and increases the chance of having several implementations of Shalon available. In this work, we provide a description of the design and implementation of Shalon, a performance and anonymity analysis, and a discussion on the scalability properties. Andriy Panchenko 0001, Benedikt Westermann, Lexi Pimenidis, Christer Andersson |
ICCCN | 1 |
| 2008 | Performance Analysis of Anonymous Communication Channels Provided by TorabstractProviding anonymity for end-users on the Internet is a very challenging and difficult task. There are currently only a few systems that are of practical relevance for the provision of low-latency anonymity. One of the most important to mention is the Tor network that is based on onion routing. Practical usage of the system often leads to delays which are not tolerated by the average end-user. This, in return, discourages many of them from the use of such systems and hence indirectly lowers the protection of remaining users due to a smaller user base. In this paper we show to which extend overloaded nodes and links, as well as geographical diversity of nodes have an influence on the general performance of Tor communication channels. After that, we propose new methods of path selection for performance-improved onion routing which are based on actively measured latencies and estimated available capacities using passive observations of link- wise throughput. Andriy Panchenko 0001, Lexi Pimenidis, Johannes Renner |
ARES | 1 |
| 2008 | Self-certified Sybil-free pseudonymsabstractAccurate and trusted identifiers are a centerpiece for any security architecture. Protecting against Sybil attacks in a privacy-friendly manner is a non-trivial problem in wireless infrastructureless networks, such as mobile ad hoc networks. In this paper, we introduce self-certified Sybil-free pseudonyms as a means to provide privacy-friendly Sybil-freeness without requiring continuous online availability of a trusted third party. These pseudonyms are self-certified and computed by the users themselves from their cryptographic long term identities. Contrary to identity certificates, we preserve location privacy and improve protection against some notorious attacks on anonymous communication systems. Leonardo A. Martucci, Markulf Kohlweiss, Christer Andersson, Andriy Panchenko 0001 |
WISEC | 4 |
| 2008 | A Self-certified and Sybil-Free Framework for Secure Digital Identity Domain Buildup
Christer Andersson, Markulf Kohlweiss, Leonardo A. Martucci, Andriy Panchenko 0001 |
WISTP | 4 |
| 2007 | Using Trust to Resist Censorship in the Presence of Collusion
Andriy Panchenko 0001, Lexi Pimenidis |
SEC | 1 |