VLDB 2026 Research / reviewers in the wild / expert
Tobias Heer
dblp:94/1260
· DBLP profile ↗
23ranked-venue papers
4as first author
10since 2021 · last 2025
0000-0003-3119-252XORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 10 · 9 since 2021Computer networks · 9 · 4 first-author · 1 since 2021Human-computer interaction and ubiquitous computing · 3Applied, interdisciplinary, general and emerging computing · 3 · 3 since 2021Security and privacy · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Detecting QoS Degradation in Time-Critical Networks due to Misconfiguration or AttacksabstractCommunication in Industrial Control Systems (ICSs) depends on predictable timing to ensure reliable operation. In converged networks, this timing can be disrupted not only by cyber attacks but also by misconfiguration or benign misbehavior of devices. Such issues degrade Quality of Service (QoS) through delays or jitter, without altering packet content, making it hard to detect them with traditional monitoring systems.This paper presents a configuration-agnostic monitoring system that detects QoS degradation using statistical anomaly detection. We evaluate three detection methods, single-value thresholds, exponential moving averages, and distribution-based analysis, and show that distribution-based detection offers the most robust results. The system supports both passive and active timing measurement to balance accuracy and overhead. By operating independently of network configuration, the proposed approach enables early detection of timing anomalies caused by misbehavior, misconfiguration, or attacks, demonstrating applicability in real-world industrial networks. Lukas Bechtel, Lukas Popperl, Michael Menth, Tobias Heer |
ETFA | 4 |
| 2025 | Time-Limited Software Firewall Based on DPDK Supporting TSN and DetNet TrafficabstractThe convergence of IT and OT networks introduces strict latency and security requirements, especially in virtualized industrial environments. While TSN and DetNet provide bounded-latency traffic delivery, traditional software firewalls break determinism due to variable rule evaluation times. Hence, we propose a time-limited firewall design that limits per-packet rule evaluation time to a fixed budget, ensuring deterministic processing even under high load. To preserve security despite partial rule checks, we propose that a deferred filtering stage verifies and, if necessary, retroactively corrects earlier forwarding decisions. We implement this design in a software firewall prototype and evaluate it under maximum packet rate. The system guarantees limited latency for all packets, maintains high throughput, and ensures eventual security consistency, all without requiring specialized hardware. Lukas Bechtel, Markus Schramm, Michael Menth, Tobias Heer |
ETFA | 4 |
| 2025 | Security Gateway for Automated Micro-Segmentation and VPN Encryption in Industrial Legacy SystemsabstractIn today’s industrial networks, secure communication among participants is crucial. Security measures commonly employed in IT networks, e.g., network segmentation and Virtual Private Networks (VPN), prevent unauthorized access by restricting communication flows within logical segments and ensure data confidentiality by encryption, respectively. In industrial networks, however, security measures are often not used due to legacy devices lacking the required capabilities to implement them. Thus, maintaining network security is particularly difficult. In this work, we take up the concept of retrofitting security measures using a security gateway. The gateway is placed in front of a legacy device and takes over tasks such as micro-segmentation and VPN encryption. A resulting challenge is the derivation of appropriate micro-segments and VPN tunnels. We address this challenge using heuristics based on observed network traffic. We demonstrate the feasibility of the approach through a Proof-of-Concept (PoC). The proposed semi-automated approach allows for retrofitting of security measures, thereby ensuring a seamless migration from the existing to a more secure infrastructure and contributing to the secure integration of legacy devices. Sabrina Kaniewski, Lukas Bechtel, Pascal Kneisel, Michael Menth, Tobias Heer |
ETFA | 5 |
| 2025 | Transforming the Network into a Filter: Distributed Firewall Rules for Time-Critical TrafficabstractIndustrial networks require strict security policies while supporting time-sensitive communication for automation and control processes. Traditional centralized firewalls enforce security by filtering traffic between network segments but introduce unacceptable delays for real-time applications. This paper presents a novel approach that distributes firewall rules across industrial switches, leveraging their Access Control Lists (ACLs) to transform the entire network into a unified, low-latency filtering system. The proposed algorithm accounts for challenges such as rule semantics adaptation, dynamic end-device locations, network redundancy, and ACL resource constraints. It systematically analyzes network topology, calculates rule placement strategies, and ensures correct filtering behavior across distributed enforcement points. Evaluation results demonstrate that our approach significantly reduces filtering delays while maintaining security, enabling real-time communication in industrial environments. Lukas Bechtel, Samuel Müller 0007, Michael Menth, Tobias Heer |
WFCS | 4 |
| 2025 | IoTWall: An Efficient Host-Based Firewall for Resource-Constrained IoT DevicesabstractIn areas such as the industrial sector, IoT devices have become an important component. For example, they serve as temperature sensors or switches. Often, IoT devices share the wireless network with other devices, increasing the potential for attacks through compromised hosts in the network. IoT devices typically lack a packet filtering mechanism that network administrators can configure to limit access to the IoT device by trusted hosts. To enhance IoT device security, we present IoTWall, a lightweight host firewall designed to run on resourceconstrained IoT devices. IoTWall is easy to integrate into existing IoT software projects with only a few code changes to encourage developers to adopt stronger security measures. A REST API enables easy configuration by network administrators without requiring code changes. We also show that IoTWall operates efficiently within the constraints of resource-constrained devices with acceptable latency and energy consumption. Markus Schramm, Lukas Bechtel, Florian Hoss, Michael Menth, Tobias Heer |
WFCS | 5 |
| 2024 | GeNESIS: Generator for Network Evaluation Scenarios of Industrial SystemsabstractThe lack of standardized, realistic industrial net-work scenarios hinders the comparative evaluation of scientific research for industrial networks. Current evaluations often use non-public or synthetic scenarios, making it difficult to compare results across different studies. This paper introduces GeNESIS, a tool designed to generate and exchange realistic, reproducible industrial network evaluation scenarios. GeNESIS produces comprehensive topologies formatted according to IETF standards, including network devices and connections. Additionally, it gen-erates configurations for network devices, supporting evaluations such as algorithm comparisons or network simulations. GeNESIS was created to evaluate firewall configurations but is designed to further support other use cases, such as QoS or reliability. By providing a standardized exchange format, GeNESIS ensures the simple availability of evaluation scenarios, promoting compara-bility and reproducibility in industrial network research. Lukas Bechtel, Samuel Müller 0007, Michael Menth, Tobias Heer |
ETFA | 4 |
| 2024 | Monitoring IP- ID Behavior for Spoofed IPv4 Traffic DetectionabstractMonitoring network traffic and devices is crucial for ensuring secure network operation, particularly in industrial networks, which operate for a long time and contain a mix of devices, i.e., devices with state-of-the-art security and legacy devices whose security features are often insufficient. Such legacy devices require additional compensating security measures for secure operation, especially due to increasing connectivity, exposing legacy devices to new security threats, such as spoofing. For this purpose, we propose an anomaly detection mechanism based on the IPv4 Identifier (IP-ID) field that provides hints for spoofed IPv4 devices. The IP-ID field is a 16-bit value in the IPv4 header. Receiving hosts use it to identify and reassemble parts of a fragmented IP packet. Multiple variants for assigning IP-IDs exist. For example, many legacy devices use a global counter with a fixed increment between subsequent packets. The proposed mechanism is based on the observation that IP-IDs in spoofed traffic may not comply with the previously observed IP-ID assignment behavior of the device. Such deviations can be detected as an anomaly and taken as a hint for spoofing. We provide an overview of existing assignment behaviors and present a classification algorithm using captured traffic. Likewise, we present a simple monitoring algorithm for detecting deviations in a host's classified IP-ID assignment behavior. We address various challenges, such as incomplete captures and unsuited deployment positions, and how to deal with them. We evaluate the feasibility of the algorithms on real-world traces. Further, we present a proof-of-concept implementation that detects various spoofing attacks in a testbed. The proposed mechanism improves security in industrial and related brownfield networks by passively detecting spoofed devices. Sabrina Kaniewski, Lukas Bechtel, Michael Menth, Tobias Heer |
ETFA | 4 |
| 2024 | Secure Resource Allocation Protocol (SecRAP) for Time-Sensitive NetworkingabstractThe convergence of operational technology (OT) and information technology (IT) networks through Time-Sensitive Networking (TSN) promises enhanced efficiency and new use cases in industrial settings. However, ensuring security in this shared infrastructure is crucial to prevent potential attacks that could compromise Quality of Service (QoS) of real-time streams and pose risks to operations and safety. This paper focuses on auditing the security of the Resource Allocation Protocol (RAP), a distributed QoS signaling protocol for TSN. We analyze the vulnerability of RAP to attacks during admission control, where end stations request network resources for data transmission. We leverage the Dolev-Yao attacker model to assess the security properties of RAP in both distributed hop-by-hop admission control and hybrid admission control with a central controller. We introduce novel security extensions to RAP, called Secure Resource Allocation Protocol (SecRAP), to mitigate the identified attack vectors. Finally, we present a prototype and discuss the security properties of SecRAP. Lukas Osswald, Steffen Lindner, Lukas Bechtel, Tobias Heer, Michael Menth |
ETFA | 4 |
| 2022 | Analyzing and modeling the latency and jitter behavior of mixed industrial TSN and DetNet networksabstractToday, industrial real-time communication is commonly designed based on two key principles to satisfy the challenging Quality of Service (QoS) requirements of industrial applications: a) local communication and b) purpose-built networks. IEEE Time-Sensitive Networking (TSN) and IETF Deterministic Networking (DetNet) promise to lift these two limitations. This facilitates the transformation of previously loosely integrated automation network parts from isolated, purpose-built real-time networks to more tightly integrated, open, multi-purpose networks of networks. With TSN and DetNet, each of these interconnected networks, e.g., machine or backbone networks, can and will be fined-tuned for optimal performance regarding the different real-time applications located inside them. The resulting patchwork of DetNet-connected TSN networks, however, creates a challenge for cross-network real-time communication: predicting QoS properties, such as the end-to-end latency. To address this challenge, we propose a model that allows calculating best-case and worst-case latencies for time-critical communication across different DetNet-connected TSN networks. This enables validating end-to-end communication requirements in open, multi-purpose industrial networks. Our evaluation with real industrial hardware shows the applicability of our proposed model. Lukas Wüsteney, David Hellmanns, Markus Schramm, Lukas Osswald, René Hummen, Michael Menth, Tobias Heer |
CoNEXT | 7 |
| 2021 | Impact of Packet Filtering on Time-Sensitive Networking TrafficabstractThe Industrial Internet of Things, Industry 4.0 and cloud computing are fundamentally transforming today's industrial networks towards high connectivity. At the same time, the number of cyber-attacks against industrial infrastructure increased drastically over the last years, requiring to tightly limit the connectivity between the networked devices of a plant. For both of these trends, there are mechanisms evolving and partially already in place. Network segmentation with packet filters is a key mechanism for achieving improved network security while Time-Sensitive Networking (TSN) is a promising option to realize advanced real-time applications in future industrial networks. However, although being built based on widely accepted standards and despite their practical relevance, these two concepts don't play together well. In this paper, we analyze the problems that arise when TSN networks are segmented using today's firewalls and packet filters. In particular, we discuss and quantify the impact of delay and jitter caused by packet filters on TSN traffic. We also show that the delays and jitter introduced by CPU-based filtering can be prohibitively high in real-time scenarios. Based on our analysis, we present and compare three approaches to overcome the challenges created by the combination of these two major trends in industrial networks. Lukas Wüsteney, Michael Menth, René Hummen, Tobias Heer |
WFCS | 4 |
| 2012 | Mesh-DHT: A locality-based distributed look-up structure for Wireless Mesh NetworksabstractDistributed Hash Tables (DHTs) offer an elegant and fully distributed solution for reliably storing and retrieving data. Wireless Mesh Networks (WMNs) envision a fully decentralized fashion, and as such require efficient decentralized mechanisms for service discovery, mobility support and data storage and retrieval. Hence, DHTs and WMNs seem to complement each other nicely and even share common traits and challenges, such as multi-path routing and dynamic membership of unreliable nodes. Existing Internet-based DHT approaches are designed to emphasize performance and stability in Internet scenarios and do not consider the special conditions in WMNs. In particular, they do not focus on the impact of the physical neighbor relations of DHT nodes and assume efficient global connectivity. In contrast, in a WMN, locality of communication is essential to avoid unnecessary multi-hop data transmissions and congestion on the wireless link. We present Mesh-DHT, an approach for building a scalable DHT in WMNs that puts special emphasis on the locality of nodes and links. We construct a stable, location-aware overlay network that enables fully distributed organization of information. By design, our DHT geometry is closely aligned to the network topology of the WMN to emphasize local communication. We show that our approach preserves locality in the overlay construction, is robust against node failure, and makes efficient use of local information. These properties make our approach scalable even in the presence of hundreds of mesh nodes. Hanno Wirtz, Tobias Heer, René Hummen, Klaus Wehrle |
ICC | 2 |
| 2012 | DHT-based localized service discovery in wireless mesh networksabstractWireless mesh networks (WMNs) provide high-bandwidth wireless network access to mobile clients in extensible, robust multi-hop networks. WMNs support distributed service provision and data storage, catering to the advanced capabilities of current mobile devices. Services and data discovery using undirected broadcast or multicast messages, as in traditional discovery protocols, significantly harms network performance due to interference and collisions. In contrast, distributed hash tables (DHTs) offer consistent mapping of service and data identifiers to the providing devices and therefore allow a directed unicast discovery and access. However, traditional DHTs place identifiers at arbitrary distant devices in the network, resulting in frequent use of long multi-hop routing paths. Such multi-hop transmissions suffer from performance loss at each hop and also degrade the overall network performance. We propose DLSD, a DHT-based localized index structure that establishes a hierarchy of locally bounded address spaces ranging from a few nearby devices to the whole network. Iterating through this hierarchy bottom-up allows devices to find the most local provider of the requested item, thereby minimizing multi-hop transmissions while ensuring global reachability. Through this reduction of routing hops, we maintain high transmission performance and minimize interference in the network. We evaluate the feasibility of our approach and show that it significantly reduces routing overhead and outperforms traditional service discovery and DHT approaches. Hanno Wirtz, Tobias Heer, Martin Serror, Klaus Wehrle |
MASS | 2 |
| 2012 | SEAMS: A Signaling Layer for End-Host-Assisted Middlebox ServicesabstractOn-path network elements, such as NATs and firewalls, are an accepted commonality in today's networks. They are essential when extending network functionality and providing additional security. However, these so called middleboxes are not explicitly considered in the original TCP/IP-based network architecture. As a result, the protocols of the TCP/IP suite provide middleboxes with the same information about data flows as packet-forwarding routers. Yet, middleboxes typically perform complex functions within the network that require additional knowledge. Inferring this knowledge from observing the sparse information available in network packets requires these devices to base their decisions on ambiguous or forgeable data. In this paper, we first discuss problems arising from insufficient information and identify the resulting informational requirements of middleboxes. We then propose SEAMS, a signaling layer that provides middleboxes with descriptive and verifiable data flow contexts in addition to the IP address and port information that many middleboxes use today. Specifically, SEAMS enables middleboxes to request and use detailed information about the host, application, and user that is accessible at the communicating end hosts. This information can then be used to provide more secure and richer middlebox functions in home and enterprise network scenarios. Our evaluation shows that SEAMS is a feasible addition to TCP/IP-based networks and that it scales well in the presence of multiple on-path middleboxes. René Hummen, Jan Henrik Ziegeldorf, Tobias Heer, Hanno Wirtz, Klaus Wehrle |
TrustCom | 3 |
| 2011 | Secure Resolution of End-Host Identifiers for Mobile ClientsabstractMany efforts of the network research community focus on the introduction of a new identifier to relieve the IP address from its dual role of end-host identifier and routable locator. This identifier-locator split introduces a new identifier between human readable domain names and routable IP addresses. Mapping between identifiers and locators requires additional name mapping mechanisms because their relation is not trivial. Despite its popularity and efficiency, the DNS system is not a perfect choice for performing this mapping because identifiers are not hierarchically structured and mappings are frequently updated by users. In this paper we discuss the features needed to resolve flat identifiers to locators in a secure manner. In particular, we focus on the features and the performance that identifier-locator split protocols require from a mapping system. To this end, we consider a mapping system for an identifier-locator split based mobility solution and evaluate its performance. Samu Varjonen, Tobias Heer, Ken Rimey, Andrei V. Gurtov |
GLOBECOM | 2 |
| 2011 | SliceTime: A Platform for Scalable and Accurate Network Emulation
Elias Weingärtner, Florian Schmidt 0002, Hendrik vom Lehn, Tobias Heer, Klaus Wehrle |
NSDI | 4 |
| 2010 | PiSA-SA: Municipal Wi-Fi Based on Wi-Fi SharingabstractNA Tobias Heer, Thomas Jansen 0003, René Hummen, Stefan Götz 0001, Hanno Wirtz, Elias Weingärtner, Klaus Wehrle |
ICCCN | 1 |
| 2009 | End-Host Authentication and Authorization for Middleboxes Based on a Cryptographic NamespaceabstractToday, middleboxes such as firewalls and network address translators have advanced beyond simple packet forwarding and address mapping. They also inspect and filter traffic, detect network intrusion, control access to network resources, and enforce different levels of quality of service. The cornerstones for these security-related network services are end- host authentication and authorization. Using a cryptographic namespace for end-hosts simplifies these tasks since it gives them an explicit and verifiable identity. The host identity protocol (HIP) is a key-exchange protocol that introduces such a cryptographic namespace for secure end-to-end communication. Although HIP was designed with middleboxes in mind, these cannot securely use its namespace because the on-path identity verification is susceptible to replay attacks. Moreover, the binding between HIP as an authentication protocol and IPsec as payload transport is insufficient because on-path middleboxes cannot securely map payload packets to a HIP association. In this paper, we propose to prevent replay attacks by allowing packet- forwarding middleboxes to directly interact with end-hosts. Also we propose a method for strengthening the binding between the HIP authentication process and its payload channel with hash-chain-based authorization tokens for IPsec. Our solution allows on-path middleboxes to efficiently leverage cryptographic end- host identities and integrates cleanly into existing standards. Tobias Heer, René Hummen, Miika Komu, Stefan Götz 0001, Klaus Wehrle |
ICC | 1 |
| 2009 | Security for pervasive medical sensor networksabstractWireless sensor networks are going to allow for ubiquitous health monitoring, improving users’ well-being, the healthcare system, and helping to quickly react on emergency situations. Meeting the strict security needs of these ubiquitous medical applications is a big challenge, since safety and priv Óscar García-Morchón, Thomas Falck, Tobias Heer, Klaus Wehrle |
MobiQuitous | 3 |
| 2009 | Security for pervasive healthcareabstractWireless sensor networks are going to allow for ubiquitous health monitoring, improving users' well-being, making the healthcare system more efficient, and helping to quickly react on emergency situations. Meeting the strict security needs of ubiquitous medical applications is a big challenge: safet Óscar García-Morchón, Thomas Falck, Tobias Heer, Klaus Wehrle |
MobiQuitous | 3 |
| 2009 | Brief announcement: lightweight key agreement and digital certificates for wireless sensor networksabstractKey agreement and digital certificates allow bootstrapping secure communication links and verifying identities or information. Thus, they are the cornerstone of many basic security functionalities. However, the resource-constrained nature of wireless sensor nodes limits the use of traditional solutions in wireless sensor networks. We propose a novel scheme allowing for fast, resource-friendly, and distributed key agreement and verification of information, featuring the efficiency of symmetric-key cryptography and the functionality of public-key certificates. The core idea of our system relies on the cryptographic association of identification information with polynomial shares. This concept allows the base station of a sensor network to sign node identification and configuration information such as routing addresses or access control roles. The information is signed by means of the polynomial shares distributed to nodes creating a lightweight digital certificate for each node. The proposed system operates in a fully stand-alone and distributed way, being able to perform a combined key agreement and lightweight digital certificate verification handshake within a few milliseconds with very low memory requirements. Óscar García-Morchón, Tobias Heer, Klaus Wehrle |
PODC | 2 |
| 2008 | ALPHA: an adaptive and lightweight protocol for hop-by-hop authenticationabstractWireless multi-hop networks are particularly susceptible to attacks based on flooding and the interception, tampering with, and forging of packets. Thus, reliable communication in such networks quintessentially depends on mechanisms to verify the authenticity of network traffic and the identity of communicating peers. A major challenge to achieve this functionality are the tight resource constraints of such devices as smartphones, mesh- and sensor nodes with regard to CPU, memory, and energy. Since existing approaches suffer from significant drawbacks related to functionality and efficiency, we present in this paper ALPHA, an Adaptive and Lightweight Protocol for Hop-by-hop Authentication. ALPHA establishes a verifiable notion of identity for network traffic, based on computationally cheap hash functions, enabling end-to-end as well as hop-by-hop integrity protection for unicast traffic. Our evaluation shows that ALPHA is a generic security mechanism that makes full traffic authentication and secure middlebox signaling viable in resource-constrainted multi-hop networks. Tobias Heer, Stefan Götz 0001, Óscar García-Morchón, Klaus Wehrle |
CoNEXT | 1 |
| 2007 | Cooperative security in distributed sensor networksabstractDistributed sensor network protocols, such as routing, time synchronization or data aggregation protocols make use of collaborative techniques to minimize the consumption of scarce resources in sensors. However, compromised and misbehaving nodes are a serious threat, as an attacker can employ them to eavesdrop on communication, inject forged data, or manipulate protocol operation. In this context, distributed revocation protocols play a decisive role since they allow removing compromised nodes in an efficient way. The design of distributed revocation protocols is challenging due to technical restrictions of sensor nodes, the distributed operation of sensor networks, and the presence of compromised nodes that can collude to subvert protocol operation. We propose the Cooperative Security Protocol (CSP) to enhance network security and enable efficient distributed revocation. The CSP is based on the distribution of revocation information — so called partial revocation votes — to the neighbors of a node as prerequisite to join the network. If an intruder refuses to disclose its revocation votes, the network does not allow it to join. Thus, the node is prevented from attacking the network. If the intruder cooperates by disclosing its revocation information, it can endanger the network neither, since its neighbors, which cooperate to monitor its correct operation, can use the revocation information to ban it from the network. Óscar García-Morchón, Heribert Baldus, Tobias Heer, Klaus Wehrle |
CollaborateCom | 3 |
| 2007 | PISA: P2P Wi-Fi Internet Sharing ArchitectureabstractWe develop a model of the interaction of rational peers in an incentive-free peer-to-peer (P2P) network and use game theoretic analysis to derive results about peer and network behavior. We calculate and discuss Nash equilibria and predict peer behavior in terms of individual contribution. At the heart of our model is altruism, an intrinsic parameter reflecting peers inherent willingness to contribute. Two different approaches for modelling altruistic behavior and its attendant benefit are introduced and discussed. We consider the cases of P2P networks of peers that (i) have homogeneous altruism levels or (ii) have heterogeneous altruism levels, but with known probability distributions. We find that, under the effects of altruism, a substantial fraction of peers will contribute when altruism levels are within certain intervals, even though no incentive mechanism is used. Our results corroborate empirical evidence of large P2P networks surviving or even flourishing without or with barely functioning incentive mechanisms. Tobias Heer, Klaus Wehrle |
Peer-to-Peer Computing | 1 |