Zinaida Benenson

dblp:b/ZBenenson · DBLP profile ↗
← Back
24ranked-venue papers
4as first author
6since 2021 · last 2026
0009-0006-7158-0219ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 15 · 2 first-author · 3 since 2021Human-computer interaction and ubiquitous computing · 5 · 3 since 2021Artificial intelligence and machine learning · 1 · 1 first-authorComputer networks · 1Software engineering, systems software and programming languages · 1 · 1 first-authorDatabases, data management, data science and information retrieval · 1 · 1 first-authorApplied, interdisciplinary, general and emerging computing · 1 · 1 first-author
YearPublicationVenuePosition
2026 Lending a Hand: The Effectiveness of Support Systems in Assisting Users to Detect Phishing Attacks
abstract
We investigate the effectiveness of anti-phishing support systems through a quantitative study involving 453 participants. To this end, we developed a tool that allows participants to immerse themselves in a realistic setting, tasked with classifying emails as either phishing or legitimate, while being assisted by support systems. Despite the prevalence of support systems in webmailers and email clients, our results indicate no significant difference in correctly assessing emails of varying difficulty between these systems and the control group. We found a minor negative effect of the support system that uses tooltips compared to other support systems. In the subsequent survey, we found that the support systems are appreciated and considered helpful by users, as supported by the results of the UEQ-S, even if they have no observable effect. Email context, such as the contact list, as well as hovering over the links, had stronger effects on the classification than the tested support systems.
Katharina Schiller, Jörg Scheidt, Florian Adamsky, Zinaida Benenson
CHI4
2026 "Technically speaking I'm at the top of the hierarchy": How System Administrators Think About Power
Lydia Weinberger, Carolin Lämmle, Andreas Hammer 0003, Christian Eichenmüller, Freya Gassmann, Zinaida Benenson
CHI6
2025 Achieving Resilience: Data Loss and Recovery on Devices for Personal Use in Three Countries
Julia Wunder, Rick Wash, Karen Renaud, Daniela A Oliveira, Zinaida Benenson
CHI5
2024 Employees' Attitudes towards Phishing Simulations: "It's like when a child reaches onto the hot hob"
abstract
E-mail phishing attacks remain one of the most significant challenges in IT security and are often used for initial access. Many organizations rely on phishing simulations to educate their staff to recognize suspicious e-mails. Previous studies have analyzed the effectiveness of these phishing simulations with mixed findings. However, the perception of and attitudes towards phishing simulations among staff have received little to no attention. This paper presents findings from a study that we carried out in cooperation with a multinational company that conducted phishing simulations over more than 12 months. We first conducted a quantitative survey involving 757 employees and then qualitative interviews with 22 participants to gain deeper insights into the perception of phishing simulations and the corresponding e-learning. We could not find evidence that employees feel attacked by their organization, as previous studies suspected. On the contrary, we found that a majority 86.9 % have a positive or very positive attitude towards phishing simulations. The interviews revealed that some employees developed new routines for e-mail processing, but most describe themselves as having become more vigilant without concrete changes. Furthermore, we found evidence that phishing simulations create a false sense of security, as the employees feel protected by them. Additionally, a lack of communication and feedback can negatively impact employees' attitudes and lead to adverse consequences. Finally, we show that only a small portion of the employees who clicked on the phishing website interacted with the interactive e-learning elements, which raises questions about its objective usefulness, although they are perceived as useful.
Katharina Schiller, Florian Adamsky, Christian Eichenmüller, Matthias Reimert, Zinaida Benenson
CCS5
2024 Shedding Light on CVSS Scoring Inconsistencies: A User-Centric Study on Evaluating Widespread Security Vulnerabilities
abstract
The Common Vulnerability Scoring System (CVSS) is a popular method for evaluating the severity of vulnerabilities in vulnerability management. In the evaluation process, a numeric score between 0 and 10 is calculated, 10 being the most severe (critical) value. The goal of CVSS is to provide comparable scores across different evaluators. However, previous works indicate that CVSS might not reach this goal: If a vulnerability is evaluated by several analysts, their scores often differ. This raises the following questions: Are CVSS evaluations consistent? Which factors influence CVSS assessments? We systematically investigate these questions in an online survey with 196 CVSS users. We show that specific CVSS metrics are inconsistently evaluated for widespread vulnerability types, including Top 3 vulnerabilities from the "2022 CWE Top 25 Most Dangerous Software Weaknesses" list. In a follow-up survey with 59 participants, we found that for the same vulnerabilities from the main study, 68% of these users gave different severity ratings. Our study reveals that most evaluators are aware of the problematic aspects of CVSS, but they still see CVSS as a useful tool for vulnerability assessment. Finally, we discuss possible reasons for inconsistent evaluations and provide recommendations on improving the consistency of scoring.
Julia Wunder, Andreas Kurtz 0004, Christian Eichenmüller, Freya Gassmann, Zinaida Benenson
SP5
2022 Usability of Antivirus Tools in a Threat Detection Scenario
Michael Körber, Anatoli Kalysch, Werner Massonne, Zinaida Benenson
SEC4
2020 Security Update Labels: Establishing Economic Incentives for Security Patching of IoT Consumer Products
abstract
With the expansion of the Internet of Things (IoT), the number of security incidents due to insecure and misconfigured IoT devices is increasing. Especially on the consumer market, manufacturers focus on new features and early releases at the expense of a comprehensive security strategy. Hence, experts have started calling for regulation of the IoT consumer market, while policymakers are seeking for suitable regulatory approaches. We investigate how manufacturers can be incentivized to increase sustainable security efforts for IoT products. We propose mandatory security update labels that inform consumers during buying decisions about the willingness of the manufacturer to provide security updates in the future. Mandatory means that the labels explicitly state when security updates are not guaranteed. We conducted a user study with more than 1,400 participants to assess the importance of security update labels for the consumer choice by means of a conjoint analysis. The results show that the availability of security updates (until which date the updates are guaranteed) accounts for 8% to 35% impact on overall consumers' choice, depending on the perceived security risk of the product category. For products with a high perceived security risk, this availability is twice as important as other high-ranked product attributes. Moreover, provisioning time for security updates (how quickly the product will be patched after a vulnerability is discovered) additionally accounts for 7% to 25% impact on consumers' choices. The proposed labels are intuitively understood by consumers, do not require product assessments by third parties before release, and have a potential to incentivize manufacturers to provide sustainable security support.
Philipp Morgner, Christoph Mai, Nicole Koschate-Fischer, Felix C. Freiling, Zinaida Benenson
SP5
2020 Long-Term Observation on Browser Fingerprinting: Users' Trackability and Perspective
abstract
Abstract Browser fingerprinting as a tracking technique to recognize users based on their browsers’ unique features or behavior has been known for more than a decade. We present the results of a 3-year online study on browser fingerprinting with more than 1,300 users. This is the first study with ground truth on user level, which allows the assessment of trackability based on fingerprints of multiple browsers and devices per user. Based on our longitudinal observations of 88,000 measurements with over 300 considered browser features, we optimized feature sets for mobile and desktop devices. Further, we conducted two user surveys to determine the representativeness of our user sample based on users’ demographics and technical background, and to learn how users perceive browser fingerprinting and how they protect themselves.
Gaston Pugliese, Christian Riess, Freya Gassmann, Zinaida Benenson
Proc. Priv. Enhancing Technol.4
2019 Security Managers Are Not The Enemy Either
abstract
Security managers are leading employees whose decisions shape security measures and thus influence the everyday work of all users in their organizations. To understand how security managers handle user requirements and behavior, we conducted semi-structured interviews with seven security managers from large-scale German companies. Our results indicate that due to the absence of organizational structures that include users into security development processes, security managers unintentionally obtain a negative view on users. Their distrust towards users leads to the creation of technical security measures that cannot be influenced by users in any way. However, as previous research has repeatedly shown, rigid security measures lead to frustration and discouragement of users, and also to creative (but usually insecure) methods of security circumvention. We conclude that in order to break through this vicious cycle, security managers need organizational structures, methods and tools that facilitate systematic feedback from users.
Lena Reinfelder, Robert Landwirth, Zinaida Benenson
CHI3
2019 Privacy implications of room climate data
abstract
Smart heating applications promise to increase energy efficiency and comfort by collecting and processing room climate data. While it has been suspected that the sensed data may leak crucial personal information about the occupants, this belief has up until now not been supported by evidence. In this work, we investigate privacy risks arising from the collection of room climate measurements. We assume that an attacker has access to the most basic measurements only: temperature and relative humidity. We train machine learning classifiers to predict the presence and number of room occupants and to discriminate between different types of activities. On data that was collected at three different locations, we show that occupancy can be detected from data measured by a single sensor with up to [Formula: see text] accuracy. One can even distinguish between the cases that no, one, or two persons are present with up to [Formula: see text] accuracy. Moreover, the four actions reading, working on a PC, standing, and walking, can be discriminated with up to [Formula: see text] accuracy, which is likewise clearly better than guessing ([Formula: see text]). Constraining the set of actions allows to achieve even higher prediction rates. For example, we discriminate standing and walking occupants with [Formula: see text] accuracy. In addition, we show that the accuracy can be increased in most cases if an attacker has access to measurements from two different sensors located in the same room. Our results provide evidence that even the leakage of such ‘inconspicuous’ data as temperature and relative humidity can seriously violate privacy.
Frederik Armknecht, Zinaida Benenson, Philipp Morgner, Christian Müller 0015, Christian Riess
J. Comput. Secur.2
2018 Malicious IoT Implants: Tampering with Serial Communication over the Internet
Philipp Morgner, Stefan Pfennig, Dennis Salzner, Zinaida Benenson
RAID4
2018 An Inquiry into Perception and Usage of Smartphone Permission Models
Lena Reinfelder, Andrea Schankin, Sophie Russ, Zinaida Benenson
TrustBus4
2018 Opinion: Security Lifetime Labels - Overcoming Information Asymmetry in Security of IoT Consumer Products
abstract
The installed base of Internet of Things (IoT) consumer products is steadily increasing, in conjunction with the number of disclosed security vulnerabilities in these devices. In this paper, we share the opinion that strong security measures are necessary but IoT security cannot solely be improved by means of sophisticated technical solutions. From our point of view, economic incentives for the manufacturers have to be established through enabling consumers to reward security. This is currently not the case, as an asymmetric information barrier prevents consumers from assessing the level of security that is provided by IoT products. As a result, consumers are not willing to pay for a comprehensive security design as they cannot distinguish it from insufficient security measures. Learning from regulatory approaches that overcame information asymmetries about other non-functional properties in consumer products, e.g., energy labels to compare the power consumption, we propose security lifetime labels, a mechanism that transforms security into an accessible feature and enables consumers to make informed buying decisions. Focusing on the delivering of security updates as an important aspect of enforcing IoT security, we aim to transform the asymmetric information about the manufacturers' willingness to provide security updates into a label that can be assessed by the consumers.
Philipp Morgner, Felix C. Freiling, Zinaida Benenson
WISEC3
2017 Privacy Implications of Room Climate Data
Philipp Morgner, Christian Müller 0015, Matthias Ring, Björn M. Eskofier, Christian Riess, Frederik Armknecht, Zinaida Benenson
ESORICS (2)7
2017 Insecure to the touch: attacking ZigBee 3.0 via touchlink commissioning
abstract
Hundred millions of Internet of Things devices implement ZigBee, a low-power mesh network standard, and the number is expected to be growing. To facilitate an easy integration of new devices into a ZigBee network, touchlink commissioning was developed. It was adopted in the latest specifications, ZigBee 3.0, which were released to the public in December 2016, as one of two commissioning options for ZigBee devices. ZigBee 3.0 products can be used in various applications, also including security-critical products such as door locks and intruder alarm systems. The aim of this work is to warn about a further adoption of this commissioning mode. We analyze the security of touchlink commissioning procedure and present novel attacks that make direct use of standard's features, showing that this commissioning procedure is insecure by design. We release an open-source penetration testing framework to evaluate the practical implications of these vulnerabilities. Evaluating our tools on popular ZigBee-certified products, we demonstrate that a passive eavesdropper can extract key material from a distance of 130 meters. Furthermore, an active attacker is able to take-over devices from distances of 190 meters. Our analysis concludes that even a single touchlink-enabled device is sufficient to compromise the security of a ZigBee 3.0 network, and therefore, touchlink commissioning should not be supported in any future ZigBee products.
Philipp Morgner, Stephan Mattejat, Zinaida Benenson, Christian Müller 0015, Frederik Armknecht
WISEC3
2016 Look Before You Leap: Improving the Users' Ability to Detect Fraud in Electronic Marketplaces
abstract
Reputation systems in current electronic marketplaces can easily be manipulated by malicious sellers in order to appear more reputable than appropriate. We conducted a controlled experiment with 40 UK and 41 German participants on their ability to detect malicious behavior by means of an eBay-like feedback profile versus a novel interface involving an interactive visualization of reputation data. The results show that participants using the new interface could better detect and understand malicious behavior in three out of four attacks (the overall detection accuracy 77% in the new vs. 56% in the old interface). Moreover, with the new interface, only 7% of the users decided to buy from the malicious seller (the options being to buy from one of the available sellers or to abstain from buying), as opposed to 30% in the old interface condition.
Johannes Sänger, Norman Hänsch, Brian Glass, Zinaida Benenson, Robert Landwirth, M. Angela Sasse
CHI4
2015 Maybe Poor Johnny Really Cannot Encrypt: The Case for a Complexity Theory for Usable Security
abstract
Psychology and neuroscience literature shows the existance of upper bounds on the human capacity for executing cognitive tasks and for information processing. These bounds are where, demonstrably, people start experiencing cognitive strain and consequently committing errors in the tasks execution. We argue that the usable security discipline should scientifically understand such bounds in order to have realistic expectations about what people can or cannot attain when coping with security tasks. This may shed light on whether Johnny will be ever be able to encrypt. We propose a conceptual framework for evaluation of human capacities in security that also assigns systems to complexity categories according to their security and usability. From what we have initiated in this paper, we ultimately aim at providing designers of security mechanisms and policies with the ability to say: "This feature of the security mechanism X or this security policy element Y is inappropriate, because this evidence shows that it is beyond the capacity of its target community".
Zinaida Benenson, Gabriele Lenzini, Daniela Oliveira 0001, Simon Edward Parkin, Sven Übelacker
NSPW1
2014 Differences between Android and iPhone Users in Their Security and Privacy Awareness
Lena Reinfelder, Zinaida Benenson, Freya Gassmann
TrustBus2
2012 Security feeling of mobile phone users
Zinaida Benenson, Olaf Kroll-Peters, Matthias Krupp
FedCSIS1
2009 Cooperative Intrusion Detection in Wireless Sensor Networks
Ioannis Krontiris, Zinaida Benenson, Thanassis Giannetsos, Felix C. Freiling, Tassos Dimitriou
EWSN2
2007 Advanced Evasive Data Storage in Sensor Networks
abstract
In case the data which is stored and processed in a sensor network has some value, it needs to be protected from unauthorized access through a security mechanism. The idea of evasive data storage is that data moves around the sensor network instead of remaining at a fixed location. In this way, an adversary, who has once (through node capture) had access to the data stored at some particular node, must compromise more sensors in order to maintain his illegitimate access to the sensor data. We refine the previously published simple evasive data storage techniques in two ways: (1) we improve the efficiency of data retrieval by bounding the area in which data may move, (2) we introduce data splitting as a technique to protect against sleeper attacks in which the adversary simply takes over a subset of nodes and waits for valuable data to pass by. We demonstrate the effectiveness of our approach using extensive simulations.
Zinaida Benenson, Felix C. Freiling, Peter M. Cholewinski
MDM1
2006 TrustedPals: Secure Multiparty Computation Implemented with Smart Cards
Milan Fort, Felix C. Freiling, Lucia Draque Penso, Zinaida Benenson, Dogan Kesdogan
ESORICS4
2006 Implementing Agreement Protocols in Sensor Networks
abstract
We investigate application of agreement protocols tolerating malicious failures in sensor networks. We identify several scenarios where agreement can be used, and report on our experience with implementing an agreement protocol. The ultimate goal is to implement a secure and energy-efficient agreement protocol for sensor networks
Andreas Achtzehn, Zinaida Benenson, Christian Rohner
MASS2
2006 Authenticated Query Flooding in Sensor Networks
abstract
We propose a novel mechanism for authentication of queries in a sensor network in case these queries are flooded. In our protocol, the base station appends an authenticator to every query, such that each sensor can verify with certain probability that the query is sent by the base station. Implicit cooperation between sensor nodes during the flooding process ensures that legitimate queries propagate quickly in the network, whereas the propagation of illegitimate queries is limited to only a small part of the network.
Zinaida Benenson, Felix C. Freiling, Ernest Hammerschmidt, Stefan Lucks, Lexi Pimenidis
SEC1