Jana Dittmann

dblp:d/JDittmann · DBLP profile ↗
← Back
55ranked-venue papers
9as first author
17since 2021 · last 2025
0009-0003-7985-8041ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 38 · 4 first-author · 15 since 2021Graphics, computer vision, multimedia, augmented reality and games · 14 · 5 first-author · 3 since 2021Artificial intelligence and machine learning · 2 · 1 since 2021Human-computer interaction and ubiquitous computing · 2 · 1 since 2021Systems, architecture and hardware · 1Applied, interdisciplinary, general and emerging computing · 1
YearPublicationVenuePosition
2025 Traces Left by the Originator: Forensic Fingerprinting Hidden Malware in Images to Enable Attribution on the Example of SteganoAmor
abstract
Information Hiding used in malware is a recent trend.Its detection as well as origin attribution is of interest to hold actors responsible and provide well tuned prevention and reaction.We propose a Forensic Fingerprint for images to individualize traces left from malicious actors.The idea is to define feature spaces to structure artefacts in the stego objects caused by embedding code into a cover image as StegoFingerprint to describe Parameter-based-Artefacts and artefacts included in embedded malicious payloads as PayloadFingerprint to collect Payload-based-Artefacts.The approach is exemplary applied on 11 live samples (AV-Test cases) from the SteganoAmor campaign (appending code into JPEG meta data) and compared with a simulation using the known steganographic algorithm StegHide with an embedding into media data.We investigate how a first feature space of 10 StegoFingerprint and 32 PayloadFingerprint features can answer the questions: (1) Enable-Detection (EDE): How many incidents can be detected?, (2) Enable-Attribution (EAT): How many different attackers are active in detected cases? and (3) Enable-Discrimination of Identity (EDI): Can traces be used to attribute digital or real identities by using found trace knowledge in context searches.In summary results for the live samples and our simulations show that the Fingerprint can differentiate between attacks and derive for one live sample an attacker identity, pseudonymized in this paper.
Jana Dittmann, Stefan Kiltz, Robert Altschaffel, Judith Antal
IH&MMSec1
2024 Forensic Trace Analysis for MP3 based Stego-Malware: Exemplary Study for Stego-Algorithm and Capacity Attribution to derive YARA Rules for Malware Identification
abstract
Stego-malware is a current trend of cyber-criminals to work as unobtrusively as possible in target systems. Common covers are image data but also audio data is plausible. In this paper three exemplary selected MP3 steganography tools (MP3Stego, MP3Stegz and Stegonaut) are forensically investigated to enhance knowledge on how steganographic algorithms can be identified and attributed in a malware scenario. Our study is driven by known steganalysis artefacts and source code analysis. To perform a structured analysis we follow the European Network of Forensic Science Institutes (ENFSI) guidelines for audio authenticity analysis and derive a trace map with meta data and content data from a systematic file structure analysis. From our findings summarised in the trace map, we derive detection patterns to identify the used steganography tool with an embedding algorithm signature. Furthermore, we discuss how known malformed actions from a code book (known malware dictionary) can be attributed with a side-informed capacity analysis and attribution. From the pattern we formulate YARA rules for the configuration of corresponding detectors.
Jana Dittmann, Christian Krätzer, Jost Alemann, Bernhard Birnbaum
IH&MMSec1
2024 Forensic Image Trace Map for Image-Stego-Malware Analysis: Validation of the Effectiveness with Structured Image Sets
abstract
Cybersecurity incident become more and more hardened with obfuscation techniques such as steganography. Especially image data is often used for malicious action such as infiltration, exfiltration and Command&Control. To allow an easy forensic assessment of steganographic images traces in Stego-Malware, we propose a Forensic Image Trace Map motivated from Trace Map in [4] from general IT forensic incident handling. The trace map for images include properties of meta data and media data traces such as used in image forensics from European Network of Forensic Science Institutes (ENFSI) [5]. The approach is validated based on four validation metrics from [4] within an informed analysis of four simple known image techniques and a test set of 10 challenging heterogeneous JPEG image samples. In the validation we structure the traces in the Forensic Image Trace Map and from the map we can conclude that out of the 9 primary traces, some are more distinctive between stego tools and their parametrization, such as file size alteration, and their combination enhances the discriminatory power. Also, some image type characteristics influence the support of individualization, the synthetic bicolour image from our test set resulted in very distinctive cover images.
Stefan Kiltz, Jana Dittmann, Fabian Loewe, Christian Heidecke, Max John, Jonas Mädel, Fabian Preißler
IH&MMSec2
2024 GAN-based Minutiae-driven Fingerprint Morphing
abstract
Fingerprint morphing is the process of combining two or more distinct fingerprints to create a new, morphed fingerprint that includes identity-related characteristics of all constituent fingerprints. Previously, this was done by either applying a model-based minutiae-oriented approach or a data-driven approach based on a Generative Adversarial Network (GAN). The model-based approach provides the ability to manage the number of minutiae coming from the fingerprints, but the resulting fingerprint often appears unrealistic. On the other hand, the data-driven approach produces realistic fingerprints, but it does not guarantee that the resulting fingerprint matches the original fingerprints. In this work, we introduce an algorithm that combines minutiae-oriented and GAN-based approaches to generate morphed fingerprints that look realistic and match their original fingerprints. The algorithm is initially designed to generate double-identity fingerprints and is further extended to generate triple-identity fingerprints. The results of our experiments indicate that the generated fingerprints appear realistic and the majority of them can be seen as double-identity fingerprints. The fingerprints resulting from morphing three fingerprints are unlikely to be triple-identity fingerprints, but rather anonymous ones matching none of the constituent original fingerprints.
Meghana Rao Bangalore Narasimha Prasad, Andrey Makrushin, Matteo Ferrara, Christian Krätzer, Jana Dittmann
IH&MMSec5
2023 Protocol Based Similarity Evaluation of Publicly Available Synthetic and Real Fingerprint Datasets
abstract
Several attempts have been made recently to generate synthetic fingerprint data. This has become necessary after legal changes in Europe and some US states in order to allow and continue long-term developments in the field of fingerprint biometrics. Apart from utilizing traditional methods (often based on Gabor filters), deep convolutional neural networks are widely used to generate synthetic fingerprint samples. The current study aims at comparing several publicly available synthetic fingerprint datasets with several datasets that consist of imprints taken from real people. To enable a comparison, first a detailed description of these datasets is carried out. Secondly, an available 4-level protocol is used, which is supposed to show similarities and/or differences between real and synthetic fingerprint samples in terms of quality assessment and non-mated as well as mated comparison scores’ behavior. Furthermore, a new synthetic FP dataset composed of 50k samples is created and made publicly available in the course of this study.
Dominik Söllinger, Simon Kirchgasser, Andreas Uhl, Andrey Makushin, Jana Dittmann
IJCB5
2022 Revisiting Online Privacy and Security Mechanisms Applied in the In-App Payment Realm from the Consumers' Perspective
abstract
This paper presents an in-depth network data stream analysis on data gathering to evaluate the current data protection situation of online payment in smartphone applications. To this end, we applied a digital forensic methodology from previous work in the field, analyzing network traffic generated by applications during a purchase process. We revisit previous work’s results on browser-based payments and compare them to the current security and privacy situation of in-app payments in 2022. We study an exemplary selection of ten mobile apps and four payment systems often used by young consumers (i.e., between 20 and 25 years old): Paypal, Google Pay, Klarna, and Visa/Mastercard credit cards. Furthermore, we examine the apps concerning their trackers and applications’ privacy policies. For this purpose, we use OSINT sources to perform a static tracker analysis and their purposes based on privacy policy descriptions. Subsequently, we perform a dynamic analysis applying a man-in-the middle attack vector, which allows us to bypass the TLS encryption of the smartphone’s HTTPS traffic, and analyze the data stream payload. We repeatedly identify significant security vulnerabilities and how applications handling sensitive data do not follow standard recommendations in security and data protection regulations during the result analysis. Moreover, some data sharing is noticed, with sensitive data passed on to third parties. The data obtained can also be used in application fields, such as by a forensic expert in a financial crime case in steps of a forensic investigation.
Salatiel Ezennaya-Gomez, Edgar Blumenthal, Marten Eckardt, Justus Krebs, Christopher Kuo, Julius Porbeck, Emirkan Toplu, Stefan Kiltz, Jana Dittmann
ARES9
2022 Hidden in Plain Sight - Persistent Alternative Mass Storage Data Streams as a Means for Data Hiding With the Help of UEFI NVRAM and Implications for IT Forensics
abstract
This article presents a first study on the possibility of hiding data using the UEFI NVRAM of today's computer systems as a storage channel. Embedding and extraction of executable data as well as media data are discussed and demonstrated as a proof of concept. This is successfully evaluated using 10 different systems. This paper further explores the implications of data hiding within UEFI NVRAM for computer forensic investigations and provides forensics measures to address this new challenge.
Stefan Kiltz, Robert Altschaffel, Jana Dittmann
IH&MMSec3
2022 Covert Channels in Network Time Security
abstract
Network Time Security (NTS) specified in RFC8915 is a mechanism to provide cryptographic security for clock synchronization using the Network Time Protocol (NTP) as foundation. By using Transport Layer Security (TLS) and Authenticated Encryption with Associated Data (AEAD) NTS is able to ensure integrity and authenticity between server and clients synchronizing time. However, in the past it was shown that time synchronisation protocols such as the Network Time Protocol (NTP) and the Precision Time Protocol (PTP) might be leveraged as carrier for covert channels, potentially infiltrating or exfiltrating information or to be used as Command-and-Control channels in case of malware infections. By systematically analyzing the NTS specification, we identified 12 potential covert channels, which we describe and discuss in this paper. From the 12 channels, we exemplary selected an client-side approach for a proof-of-concept implementation using NTS random UIDs. Further, we analyze and investigate potential countermeasures and propose a design for an active warden capable of mitigating the covert channels described in this paper.
Kevin Lamshöft, Jana Dittmann
IH&MMSec2
2022 Data-driven Reconstruction of Fingerprints from Minutiae Maps
abstract
In this paper we explore the power of conditional generative adversarial networks and in particular of the pix2pix network to reconstruct realistic fingerprint patterns from minutiae maps. In our considerations a minutiae map is a grayscale image that encodes minutiae locations and orientations as these are presented in a minutiae template. We propose a novel approach for minutiae encoding in a minutiae map and study to which degree the reconstruction may be successful if trained with a low number of samples. Moreover, we explore the generalization ability of the trained models in cross-dataset and cross-sensor experiments. Reconstruction from pseudo-random minutiae enables synthesis of anonymous fingerprints as well as controlling the diversity of generated samples including synthesis of mated fingerprints which is vital for compilation of large-scale public evaluation datasets.
Andrey Makrushin, Venkata Srinath Mannam, B. N. Meghana Rao, Jana Dittmann
MMSP4
2021 A Semi-Automated HTTP Traffic Analysis for Online Payments for Empowering Security, Forensics and Privacy Analysis
abstract
The paper discusses means to identify potential impacts of data flows on customers’ security, and privacy during online payments. The main objectives of our research are looking into the evolution of cybercrime new trends of online payments and detection, more precisely the usage of mobile phones, and describing methodologies for digital trace identification in data flows for potential online payment fraud. The paper aims to identify potential actions for identity theft while conducting the Reconnaissance step of the kill chain, and documenting a forensic methodology for guidance and further data collection for law enforcement bodies. Moreover, a secondary objective of the paper is to identify, from a user’s perspective, transparency issues of data sharing among involved parties for online payments. We thus declare the transparency analysis as the incident triggering a forensic examination. Hence, we devise a semi-automated traffic analysis approach, based on previous work, to examine data flows, and data exchanged among parties in online payments. For this, the main steps are segmenting traffic generated by the process payment, and other sources, subsequently, identifying data streams in the process. We conduct three tests which include three different payment gateways: PayPal, Klarna-sofort, and Amazon Pay. The experiment setup requires circumventing TLS encryption for the correct identification of forensic data types in TCP/IP traffic, and potential data leaks. However, it requires no extensive expertise in mobile security for its installation. In the results, we identified some important security vulnerabilities from some payment APIs that pose financial and privacy risks to the marketplace’s customers.
Salatiel Ezennaya-Gomez, Stefan Kiltz, Christian Krätzer, Jana Dittmann
ARES4
2021 A Systematic Analysis of Covert Channels in the Network Time Protocol
abstract
Covert channels in network protocols are a technique aiming to hide the very existence of secret communication in computer networks. In this work we present a systematic in-depth analysis of covert channels by modification for the Network Time Protocol (NTP). Our analysis results in the identification of 49 covert channels, by applying a covert channel pattern-based taxonomy. The summary and comparison based on nine selected key attributes show that NTP is a plausible carrier for covert channels. The analysis results are evaluated in regards to common behavior of NTP implementations in six major operating systems. Two channels are selected and implemented to be evaluated in network test-beds. By hiding encrypted high entropy data in a high entropy field of NTP we show in our first assessment that practically undetectable channels can be implemented in NTP, motivating the required further research. In our evaluation, we analyze 40,000 NTP server responses from public NTP server providers. We discuss the general approach of the research community that detection of covert channels is the more promising countermeasure, compared to active suppression of covert channels. Therefore, normalization approaches and a secure network environment are introduced.
Jonas Hielscher, Kevin Lamshöft, Christian Krätzer, Jana Dittmann
ARES4
2021 A Revised Taxonomy of Steganography Embedding Patterns
abstract
Steganography embraces several hiding techniques which spawn across multiple domains. However, the related terminology is not unified among the different domains, such as digital media steganography, text steganography, cyber-physical systems steganography, network steganography (network covert channels), local covert channels, and out-of-band covert channels. To cope with this, a prime attempt has been done in 2015, with the introduction of the so-called hiding patterns, which allow to describe hiding techniques in a more abstract manner. Despite significant enhancements, the main limitation of such a taxonomy is that it only considers the case of network steganography.
Steffen Wendzel, Luca Caviglione, Wojciech Mazurczyk, Aleksandra Mileva, Jana Dittmann, Christian Krätzer, Kevin Lamshöft, Claus Vielhauer, Laura Hartmann, Jörg Keller 0001, Tom Neubert
ARES5
2021 Meta and Media Data Stream Forensics in the Encrypted Domain of Video Conferences
abstract
Our paper presents a systematic approach to investigate whether and how events can be identified and extracted during the use of video conferencing software. Our approach is based on the encrypted meta and multimedia data exchanged during video conference sessions. It relies on the network data stream which contains data interpretable without decryption (plain data) and encrypted data (encrypted content) some of which is decrypted using our approach (decrypted content). This systematic approach uses a forensic process model and the fission of network data streams before applying methods on the specific individual data types. Our approach is applied exemplary to the Zoom Videoconferencing Service with Client Version 5.4.57862.0110 [4], the mobile Android App Client Version 5.5.2 (1328) [4], the webbased client and the servers (accessed between Jan 21st and Feb 4th). The investigation includes over 50 different configurations. For the heuristic speaker identification, two series of nine sets for eight different speakers are collected. The results show that various user data can be derived from characteristics of encrypted media streams, even if end-to-end encryption is used. The findings suggest user privacy risks. Our approach offers the identification of various events, which enable activity tracking (e.g. camera on/off, increased activity in front of camera) by evaluating heuristic features of the network streams. Further research into user identification within the encrypted audio stream based on pattern recognition using heuristic features of the corresponding network data stream is conducted and suggests the possibility to identify users within a specific set.
Robert Altschaffel, Jonas Hielscher, Stefan Kiltz, Jana Dittmann
IH&MMSec4
2021 Information Hiding in Cyber Physical Systems: Challenges for Embedding, Retrieval and Detection using Sensor Data of the SWAT Dataset
abstract
In this paper, we present an Information Hiding approach that would be suitable for exfiltrating sensible information of Industrial Control Systems (ICS) by leveraging the long-term storage of process data in historian databases. We show how hidden messages can be embedded in sensor measurements as well as retrieved asynchronously by accessing the historian. We evaluate this approach at the example of water-flow and water-level sensors of the Secure Water Treatment (SWAT) dataset from iTrust. To generalize from specific cover channels (sensors and their transmitted data), we reflect upon general challenges that arise in such Information Hiding scenarios creating network covert channels and discuss aspects of cover channel selection and and sender receiver synchronisation as well as temporal aspects such as the potential persistence of hidden messages in Cyber Physical Systems (CPS). For an empirical evaluation we design and implement a covert channel that makes use of different embedding strategies to perform an adaptive approach in regards to the noise in sensor measurements, resulting in dynamic capacity and bandwidth selection to reduce detection probability. The results of this evaluation show that, using such methods, the exfiltration of sensible information in long-term scaled attacks would indeed be possible. Additionally, we present two detection approaches for the introduced hidden channel and carry out an extensive evaluation of our detectors with multiple test data sets and different parameters. We determine a detection accuracy of up to 87.8% on test data at a false positive rate (FPR) of 0%.
Kevin Lamshöft, Tom Neubert, Christian Krätzer, Claus Vielhauer, Jana Dittmann
IH&MMSec5
2021 General Requirements on Synthetic Fingerprint Images for Biometric Authentication and Forensic Investigations
abstract
Generation of synthetic biometric samples such as, for instance, fingerprint images gains more and more importance especially in view of recent cross-border regulations on security of private data. The reason is that biometric data is designated in recent regulations such as the EU GDPR as a special category of private data, making sharing datasets of biometric samples hardly possible even for research purposes. The usage of fingerprint images in forensic research faces the same challenge. The replacement of real datasets by synthetic datasets is the most advantageous straightforward solution which bears, however, the risk of generating "unrealistic" samples or "unrealistic distributions" of samples which may visually appear realistic. Despite numerous efforts to generate high-quality fingerprints, there is still no common agreement on how to define "high-quality'' and how to validate that generated samples are realistic enough. Here, we propose general requirements on synthetic biometric samples (that are also applicable for fingerprint images used in forensic application scenarios) together with formal metrics to validate whether the requirements are fulfilled. Validation of our proposed requirements enables establishing the quality of a generative model (informed evaluation) or even the quality of a dataset of generated samples (blind evaluation). Moreover, we demonstrate in an example how our proposed evaluation concept can be applied to a comparison of real and synthetic datasets aiming at revealing if the synthetic samples exhibit significantly different properties as compared to real ones.
Andrey Makrushin, Christof Kauba, Simon Kirchgasser, Stefan Seidlitz, Christian Krätzer, Andreas Uhl, Jana Dittmann
IH&MMSec7
2021 On feasibility of GAN-based fingerprint morphing
abstract
Morphing of two fingerprints is shown to be feasible when using a model-based minutia-oriented approach, in which original fingerprint images are cut to two almost equal parts. The morphed fingerprint is a result of assembling two parts of different fingerprints along a cut line. It is important that each part of an original fingerprint in the morphed fingerprint contains enough minutiae to enable the successful matching between the morphed and both original fingerprints. The major drawback of this approach is that the resulting fingerprint often does not appear realistic. Another way to morph fingerprints is exploiting neural generative models. The projections of fingerprints onto the latent space of the generator network are blended and the resulting latent vector is fed to the generator network. In contrast to the model-based approach, a morphed fingerprint almost always appears realistic, but there is no guarantee that it matches successfully both original fingerprints, unless the identity prior is included into the generation process. This paper discusses the advantages and pitfalls of fingerprint morphing using generative adversarial networks (GAN). We experimentally show that GAN-based fingerprint morphing is feasible for creating double-identity fingerprints but fails to anonymize fingerprints i.e. create new virtual identities.
Andrey Makrushin, Mark Trebeljahr, Stefan Seidlitz, Jana Dittmann
MMSP4
2021 Potential advantages and limitations of using information fusion in media forensics - a discussion on the example of detecting face morphing attacks
abstract
Abstract Information fusion, i.e., the combination of expert systems, has a huge potential to improve the accuracy of pattern recognition systems. During the last decades, various application fields started to use different fusion concepts extensively. The forensic sciences are still hesitant if it comes to blindly applying information fusion. Here, a potentially negative impact on the classification accuracy, if wrongly used or parameterized, as well as the increased complexity (and the inherently higher costs for plausibility validation) of fusion is in conflict with the fundamental requirements for forensics. The goals of this paper are to explain the reasons for this reluctance to accept such a potentially very beneficial technique and to illustrate the practical issues arising when applying fusion. For those practical discussions the exemplary application scenario of morphing attack detection (MAD) is selected with the goal to facilitate the understanding between the media forensics community and forensic practitioners. As general contributions, it is illustrated why the naive assumption that fusion would make the detection more reliable can fail in practice, i.e., why fusion behaves in a field application sometimes differently than in the lab. As a result, the constraints and limitations of the application of fusion are discussed and its impact to (media) forensics is reflected upon. As technical contributions, the current state of the art of MAD is expanded by: The introduction of the likelihood-based fusion and an fusion ensemble composition experiment to extend the set of methods (majority voting, sum-rule, and Dempster-Shafer Theory of evidence) used previously The direct comparison of the two evaluation scenarios “MAD in document issuing” and “MAD in identity verification” using a realistic and some less restrictive evaluation setups A thorough analysis and discussion of the detection performance issues and the reasons why fusion in a majority of the test cases discussed here leads to worse classification accuracy than the best individual classifier
Christian Krätzer, Andrey Makrushin, Jana Dittmann, Mario Hildebrandt
EURASIP J. Inf. Secur.3
2020 Information Hiding in Industrial Control Systems: An OPC UA based Supply Chain Attack and its Detection
abstract
Industrial Control Systems (ICS) help to automate various cyber-physical systems in our world. The controlled processes range from rather simple traffic lights and elevators to complex networks of ICS in car manufacturing or controlling nuclear power plants. With the advent of industrial Ethernet ICS are increasingly connected to networks of Information Technology (IT). Thus, novel attack vectors on ICS are possible. In IT networks information hiding and steganography is increasingly used in advanced persistent threats to conceal the infection of the systems allowing the attacker to retain control over the compromised networks. In parallel ICS are more and more a target for attacks as well. Here, simple automated attacks as well as targeted attacks of nation state actors with the intention of damaging components or infrastructures as a part of cyber crime have already been observed. Information hiding could bring such attacks to a new level by integrating backdoors and hidden/covert communication channels that allow for attacking specific processes whenever it is deemed necessary. This paper sheds light on potential attack vectors on Programmable Logic Controllers (PLCs) using OPC Unified Architecture (OPC UA) network protocol based communication. We implement an exemplary supply chain attack consisting of an OPC UA server (Bob, B) and a Siemens S7-1500 PLC as OPC UA client (Alice, A). The hidden storage channel is using source timestamps to embed encrypted control sequences allowing for setting digital outputs to arbitrary values. The attack is solely relying on the programming of the PLC and does not require firmware level access. Due to the potential harm to life caused by attacks on cyber-physical systems any presentation of novel attack vectors need to present suitable mitigation strategies. Thus, we investigate potential approaches for the detection of the hidden storage channel for a warden W as well as potential countermeasures in order to increase the warden-compliance. Our machine learning based detection approach using a One-Class-Classifier yields a detection performance of 89.5% with zero false positives within an experiment with 46,159 OPC UA read responses without a steganographic message and 7,588 OPC UA read responses with an embedded steganographic message.
Mario Hildebrandt, Kevin Lamshöft, Jana Dittmann, Tom Neubert, Claus Vielhauer
IH&MMSec3
2020 Simulation of Border Control in an Ongoing Web-based Experiment for Estimating Morphing Detection Performance of Humans
abstract
A morphed face image injected into an identity document destroys the unique link between a person and a document meaning that such a multi-identity document may be successfully used by several persons for face-recognition-based identity verification. A morphed face in an electronic machine readable travel document may allow a wanted criminal to illicitly cross a border. This paper describes an improvement of our ongoing web-based experiment for a border control simulation in which human examiners should first detect high-resolution morphed face images and second match potentially morphed document images against "live" faces of travelers. The error rates of humans in both parts of the experiment are compared with those of automated morphing detectors and face recognition systems. This experiment improves understanding the capabilities and limits of humans in withstanding the face morphing attack as well as the factors influencing their performance.
Andrey Makrushin, Dennis Siegel, Jana Dittmann
IH&MMSec3
2020 Keystroke biometrics in the encrypted domain: a first study on search suggestion functions of web search engines
abstract
Abstract A feature of search engines is prediction and suggestion to complete or extend input query phrases, i.e. search suggestion functions (SSF). Given the immediate temporal nature of this functionality, alongside the character submitted to trigger each suggestion, adequate data is provided to derive keystroke features. The potential of such biometric features to be used in identification and tracking poses risks to user privacy.For our initial experiment, we evaluate SSF traffic with different browsers and search engines on a Linux PC and an Android mobile phone. The keystroke network traffic is captured and decrypted using mitmproxy to verify if expected keystroke information is contained, which we call quality assurance (QA). In our second experiment, we present first results for identification of five subjects searching for up to three different phrases on both PC and phone using naive Bayesian and nearest neighbour classifiers. The third experiment investigates potential for identification and verification by an external observer based purely on the encrypted traffic, thus without QA, using the Euclidean distance. Here, ten subjects search for two phrases across several sessions on a Linux virtual machine, and statistical features are derived for classification. All three test cases show positive tendencies towards the feasibility of distinguishing users within a small group. The results yield lowest equal error rates of 5.11% for the single PC and 11.37% for the mobile device with QA and 23.61% for various PCs without QA. These first tendencies motivate further research in feature analysis of encrypted network traffic and prevention approaches to ensure protection and privacy.
Nicholas Whiskerd, Nicklas Körtge, Kris Jürgens, Kevin Lamshöft, Salatiel Ezennaya-Gomez, Claus Vielhauer, Jana Dittmann, Mario Hildebrandt
EURASIP J. Inf. Secur.7
2019 A Face Morphing Detection Concept with a Frequency and a Spatial Domain Feature Space for Images on eMRTD
abstract
Since the face morphing attack was introduced by Ferrara et al. in 2014, the detection of face morphings has become a wide spread topic in image forensics. By now, the community is very active and has reported diverse detection approaches. So far, the evaluations are mostly performed on images without post-processing. Face images stored within electronic machine readable documents (eMRTD) are ICAO-passport-scaled to a resolution of 413x531 and a JPG or JP2 lesize of 15 kilobytes. This paper introduces a face morphing detection concept with 3 modules (ICAO-aligned pre- processing module, feature extraction module and classi cation module), tailored for such images on eMRTD. In this work we exemplary design and evaluate two feature spaces for the feature extraction module, a frequency domain and a spatial domain feature space. Our evaluation will compare both feature spaces and is carried out with 66,229 passport-scaled images (64,363 morphed face images and 1,866 authentic face images) which are completly independent from training and include all images provided for the IHMMSEC'19 special session: "Media Forensics - Fake or Real?". Furthermore, we investigate the in uence of di erent morph gen- eration pipelines to the detection accuracies of the concept and we analyse the impact of neutral and smiling genuine faces to the morph detector performance. The evaluation determines a detection rate of 86.0% for passport-scaled morphed images with a false alarm rate of 4.4% for genuine images for the spatial domain feature space
Tom Neubert, Christian Krätzer, Jana Dittmann
IH&MMSec3
2019 Digital Forensics in Industrial Control Systems
Robert Altschaffel, Mario Hildebrandt, Stefan Kiltz, Jana Dittmann
SAFECOMP4
2018 Steganography by synthesis: Can commonplace image manipulations like face morphing create plausible steganographic channels?
abstract
From the three basic paradigms to implement steganography, the concept to realise the information hiding by modifying preexisting cover objects (i.e. steganography by modification) is by far dominating the scientific work in this field, while the other two paradigms (steganography by cover selection or -synthesis) are marginalised although they inherently create stego objects that are closer to the statistical properties of unmodified covers and therefore would create better (i.e. harder to detect) stego channels. Here, we revisit the paradigm of steganography by synthesis to discuss its benefits and limitations on the example of face morphing in images as an interesting synthesis method.
Christian Krätzer, Jana Dittmann
ARES2
2018 Generalized Benford's Law for Blind Detection of Morphed Face Images
abstract
A morphed face image in a photo ID is a serious threat to image-based user verification enabling that multiple persons could be matched with the same document. The application of machine-readable travel documents (MRTD) at automated border control (ABC) gates is an example of a verification scenario that is very sensitive to this kind of fraud. Detection of morphed face images prior to face matching is, therefore, indispensable for effective border security. We introduce the face morphing detection approach based on fitting a logarithmic curve to nine Benford features extracted from quantized DCT coefficients of JPEG compressed original and morphed face images. We separately study the parameters of the logarithmic curve in face and background regions to establish the traces imposed by the morphing process. The evaluation results show that a single parameter of the logarithmic curve may be sufficient to clearly separate morphed and original images.
Andrey Makrushin, Christian Krätzer, Tom Neubert, Jana Dittmann
IH&MMSec4
2017 Modeling Attacks on Photo-ID Documents and Applying Media Forensics for the Detection of Facial Morphing
abstract
Since 2014, a novel approach to attack face image based person verification designated as face morphing attack has been actively discussed in the biometric and media forensics communities. Up until that point, modern travel documents were considered to be extremely hard to forge or to successfully manipulate. In the case of template-targeting attacks like facial morphing, the face verification process becomes vulnerable, making it a necessity to design protection mechanisms. In this paper, a new modeling approach for face morphing attacks is introduced. We start with a life-cycle model for photo-ID documents. We extend this model by an image editing history model, allowing for a precise description of attack realizations as a foundation for performing media forensics as well as training and testing scenarios for the attack detectors. On the basis of these modeling approaches, two different realizations of the face morphing attack as well as a forensic morphing detector are implemented and evaluated. The design of the feature space for the detector is based on the idea that the blending operation in the morphing pipeline causes the reduction of face details. To quantify this reduction, we adopt features implemented in the OpenCV image processing library, namely the number of SIFT, SURF, ORB, FAST and AGAST keypoints in the face region as well as the loss of edge-information with Canny and Sobel edge operators. Our morphing detector is trained with 2000 self-acquired authentic and 2000 morphed images captured with three camera types (Canon EOS 1200D, Nikon D 3300, Nikon Coolpix A100) and tested with authentic and morphed face images from a public database. Morphing detection accuracies of a decision tree classifier vary from 81.3% to 98% for different training and test scenarios.
Christian Krätzer, Andrey Makrushin, Tom Neubert, Mario Hildebrandt, Jana Dittmann
IH&MMSec5
2017 A First Public Research Collection of High-Resolution Latent Fingerprint Time Series for Short- and Long-Term Print Age Estimation
abstract
The creation of publicly available image databases for the signal processing community is a very time-consuming, yet immensely valuable task, enabling scientific progress by providing the opportunity of an objective comparison and reproduction of results. This paper presents for the first time a public research collection of high-resolution latent fingerprint time series for age estimation, captured from a pool of 116 different test subjects. It comprises ten different sets with a total of 2,618 time series (117,384 scans), varying between capturing devices (CWL and CLSM), data types (intensity versus topography), aging periods (short-term aging: 24 h, long-term aging: 0.5 - 3 years) and resolutions (1,270 - 180,142 ppi). Most series are annotated with donor information (age and gender) and capturing conditions (scan parameters, ambient temperature, and humidity). The data are anonymized (using partial prints only) and an organizational revocation mechanism is included to assure non-identifiability of donors in the future. Baseline results for age estimation on all ten sets are provided in the form of correlation coefficients and machine-learning based age estimation (kappa), using 19 features from prior feature spaces as well as new ones (Tamura contrast, Benford's law, and improved dust feature). Classification results exhibit kappa values between 0.51 and 0.85, highlighting the progress made in this very challenging area in recent years and also emphasizing the need of future studies on the issue.
Ronny Merkel, Jana Dittmann, Claus Vielhauer
IEEE Trans. Inf. Forensics Secur.2
2016 Your Industrial Facility and Its IP Address: A First Approach for Cyber-Physical Attack Modeling
Robert Clausing, Robert Fischer 0001, Jana Dittmann, Yongjian Ding
SAFECOMP3
2015 From classical forensics to digitized crime scene analysis
abstract
The aim of this paper is to discuss selected aspects of the emerging trend of digitization in the field of crime scene forensics, known as 'digitized crime scene forensics'. This work summarizes recent findings in the field and discusses the current state of transfer from the analogue to the digital domain. The trace types of latent fingerprints, fibers as well as firearm and lock picking related toolmarks are addressed in respect to the major steps of acquisition, preprocessing, feature extraction and decision making, as support for the subjective expert assessment. Based on the findings, challenges are identified to provide future directions on the issue and to stimulate an increased research in this area. Overall, it can be concluded that a complete digital and automated processing pipeline is missing for most of the considered trace types. The introduction of first digital processing schemes has enabled certain novel, so far not-addressed opportunities, such as separation of overlapped prints, age estimation as well as the application of topographic data and has been able to provide first promising results. But even if parts of this pipeline have been recently automated in first studies, significant challenges remain, such as selecting suitable capturing devices and processing methods, identifying characteristic features and classification strategies as well as employing comprehensive test sets. Most of all, the final classification performance is often not yet good enough to achieve the quality of results obtained in manual investigations, and a significant research effort is required to address the specific needs of numerous trace types and investigation objectives.
Ronny Merkel, Claus Vielhauer, Jana Dittmann, Robert Fischer 0001, Mario Hildebrandt, Christian Arndt
ICME3
2015 ForeMan, a Versatile and Extensible Database System for Digitized Forensics Based on Benchmarking Properties
abstract
To benefit from new opportunities offered by the digitalization of forensic disciplines, the challenges especially w.r.t. comprehensibility and searchability have to be met. Important tools in this forensic process are databases containing digitized representations of physical crime scene traces. We present ForeMan, an extensible database system for digitized forensics handling separate databases and enabling intra and inter trace type searches. It now contains 762 fiber data sets and 27 fingerprint data sets (anonymized time series). Requirements of the digitized forensic process model are mapped to design aspects and conceptually modeled around benchmarking properties. A fiber categorization scheme is used to structure fiber data according to forensic use case identification. Our research extends the benchmarking properties by fiber fold shape derived from the application field of fibers (part of micro traces) and sequence number derived from the application field of time series analysis for fingerprint aging research. We identify matching data subsets from both digitized trace types and introduce the terms of entity-centered and spatial-centered information. We show how combining two types of digitized crime scene traces (fiber and fingerprint data) can give new insights for research and casework and discuss requirements for other trace types such as firearm and toolmarks.
Christian Arndt, Stefan Kiltz, Jana Dittmann, Robert Fischer 0001
IH&MMSec3
2015 Simulation of Automotive Security Threat Warnings to Analyze Driver Interpretations and Emotional Transitions
Robert Altschaffel, Tobias Hoppe, Sven Kuhlmann, Jana Dittmann
SAFECOMP4
2015 StirTraceV2.0: Enhanced Benchmarking and Tuning of Printed Fingerprint Detection
abstract
In this paper, we address the problem of assessing the overall quality of forgery detection approaches for artificial sweat printed latent fingerprints placed at crime scenes. It is very important to have reliable detection mechanisms tested on manifold characteristics caused for example by different surfaces, printers and during acquisition, avoiding misleading crime scene investigations. Today only a limited number of detection methods exist in the literature and test sets are still limited in size and quality covering all different conditions (influence factors). Based on the recently introduced publicly available StirTrace tool, we enhance the functionality to simulate complex and realistic test sets and discuss how detection approaches can be tuned by further preprocessing and feature selection. Our contributions here are twofold. First, we suggest a benchmarking design in 16-bit domain working in full bit-depth of today's nanometer sensory and propose enhancements for further simulations of sensor and substrate characteristics as well as single and combined scan artifacts (simulated, novel experimental data set of in sum 1.254.000 samples). Second, we benchmark exemplarily two known feature sets on nonsimulated and simulated data and compare findings with additional preprocessing and feature selection. Finally, we summarize lessons learned how good today's detection works and which challenges exist for achieving a high reliability. For the community we provide a tool, which can be used as fundamental basis to simulate influence factors allowing a systematic comparison and benchmarking of results. We also want to motivate further research in the design and tuning of forgery detection approaches.
Mario Hildebrandt, Jana Dittmann
IEEE Trans. Inf. Forensics Secur.2
2014 Latent fingerprint persistence: A new temporal feature space for forensic trace evidence analysis
abstract
In forensic applications, traces are often hard to detect and segment from challenging substrates at crime scenes. In this paper, we propose to use the temporal domain of forensic signals as a novel feature space to provide additional information about a trace. In particular we introduce a degree of persistence measure and a protocol for its computation, allowing for a flexible extraction of time domain information based on different features and approximation techniques. At the example of latent fingerprints on semi-/porous surfaces and a CWL sensor, we show the potential of such approach to achieve an increased performance for the challenge of separating prints from background. Based on 36 earlier introduced spectral texture features, we achieve an increased separation performance (0.01 ≤ Δκ ≤ 0.13, respective 0.6% to 6.7%) when using the time domain signal instead of spatial segmentation. The test set consists of 60 different prints on photographic-, catalogue- and copy paper, acquired in a sequence of ten times. We observe a dependency on the used surface as well as the number of consecutive images and identify the accuracy and reproducibility of the capturing device as the main limitation, proposing additional steps for even higher performances in future work.
Ronny Merkel, Jana Dittmann, Mario Hildebrandt
ICIP2
2014 From StirNark to StirTrace: benchmarking pattern recognition based printed fingerprint detection
abstract
Artificial sweat printed fingerprints need to be detected during crime scene investigations of latent fingerprints. Several detection approaches have been suggested on a rather small test set. In this paper we use the findings from StirMark applied to exemplar fingerprints to build a new StirTrace tool for simulating different printer effects and enhancing test sets for benchmarking detection approaches. We show how different influence factors during the printing process and acquisition of the scan sample can be simulated. Furthermore, two new feature classes are suggested to improve detection performance of banding and rotation effects during printing. The results are compared with original existing detection feature space. Our evaluation based on 6000 samples indicates that StirTrace is suitable to simulate influence factors resulting into overall 195000 simulated samples. Furthermore, the original and our extended feature set show resistance towards image manipulations with the exception of scaling (to 50 and 200%) and cropping to 25%. The new feature space enhancement is capable for handling banding, rotation as well as removal of lines and columns and shearing artifacts, while the original feature space performs better for additive noise, median cut and stretching in X-direction.
Mario Hildebrandt, Jana Dittmann
IH&MMSec2
2013 First investigation of latent fingerprints long-term aging using chromatic white light sensors
abstract
Non-invasive high-resolution Chromatic White Light (CWL) measurement devices offer great potential for solving the challenge of latent fingerprints age determination. In this paper, we place 40 prints from different subjects on hard disk platters and capture them from three different indoor locations every week over 1.5 years, acquiring high-resolution time series (10 μm and 20 μm). In contrast to prior findings from Popa et al. (using glass substrates) we show that the ridge thickness of our very precise images does not significantly decrease over time (test goal 1). We furthermore show that pores exhibit a significant loss in contrast and contour, which might lead to the impression of becoming bigger and fewer (test goal 2). Computing the contrast based Binary Pixel aging feature (test goal 3), we observe very characteristic results, leading to the conclusion that the dominant aging property seems to be an overall loss of image contrast rather than a specific change of ridge thickness or pore size. Comparing our findings between three different indoor locations (test goal 4) and discussing them from a police point of view, we conclude that sweat composition, environmental influences and scan parameters have a significant impact on fingerprints long-term aging.
Ronny Merkel, Karen Otte, Robert Clausing, Jana Dittmann, Claus Vielhauer, Anja Bräutigam
IH&MMSec4
2012 IT-Forensic Automotive Investigations on the Example of Route Reconstruction on Automotive System and Communication Data
Tobias Hoppe, Sven Kuhlmann, Stefan Kiltz, Jana Dittmann
SAFECOMP4
2011 Statistical effects of selected noise characteristics on speaker recognition in automotive environments: a first ANOVA-based investigation
abstract
A statistical analysis using the univariate, multifactorial analysis of variance (ANOVA) is used in this paper to investigate the impact of selected noise characteristics (here a 4-factorial design: amplitude, complexity, harmony and fundamental frequency) to speech signals and consecutively to the detection performance in speaker recognition systems (exemplarily used here: the BioSecure reference system ALIZE) in automotive application scenarios. An application scenario specific set of noise signals is recorded and generated and used to evaluate the influence of the noise characteristics. The results show that especially the amplitude and the fundamental frequency show a significant impact (p-values < 0.01), which is completely independent of the features used in the speaker recognition system. The two other characteristics (complexity and harmony) show much less significant impacts (p-values >0.5).
Sven Tuchscheerer, Christian Krätzer, Jana Dittmann, Tobias Hoppe
AutomotiveUI3
2011 Fingerprint Forensics Application Protocol: Semi-automated Modeling and Verification of Watermark-Based Communication Using CASPER and FDR
Ronny Merkel, Christian Krätzer, Robert Altschaffel, Eric Clausing, Maik Schott, Jana Dittmann
IWDW6
2009 Automotive IT-Security as a Challenge: Basic Attacks from the Black Box Perspective on the Example of Privacy Threats
Tobias Hoppe, Stefan Kiltz, Jana Dittmann
SAFECOMP3
2009 Handwriting verification - Comparison of a multi-algorithmic and a multi-semantic approach
Tobias Scheidat, Claus Vielhauer, Jana Dittmann
Image Vis. Comput.3
2008 Adaptive Dynamic Reaction to Automotive IT Security Incidents Using Multimedia Car Environment
abstract
Modern cars offer an increasingly powerful multimedia environment. While also the potential for an application as human computer interface (HCI) is growing, in this paper we concentrate on already existing possibilities for their use as computer-human-interface (CHI) to communicate system security related information to the driver. After identifying the intrusion detection approach from desktop IT as a promising supplemental measure for the IT security of future automotive systems and successfully testing it in practice, in this paper we investigate about how such an automotive intrusion detection system (IDS) could communicate security-related information to the driver. We propose an adaptive dynamic concept to address the frequently changing environmental conditions in the automotive domain and discuss it using three exemplarily selected scenarios.
Tobias Hoppe, Stefan Kiltz, Jana Dittmann
IAS3
2008 Security Threats to Automotive CAN Networks - Practical Examples and Selected Short-Term Countermeasures
Tobias Hoppe, Stefan Kiltz, Jana Dittmann
SAFECOMP3
2007 Single-Semantic Multi-Instance Fusion of Handwriting Based Biometric Authentication Systems
abstract
The fusion of biometric systems, algorithms and/or traits is a well known solution to improve authentication performance of biometric systems. In this article the fusion of two instances of the same semantic is suggested, where semantics are alternative handwritten contents such as numbers or sentences, in addition to commonly used signature. In order to fuse two instances of one semantic, a biometric authentication is carried out on both by Biometric Hash algorithm up to matching score computation. The fusion is done by combination of matching scores to a joint score as basis for authentication decision. Three individual fusion strategies are used to study to which degree the authentication performance can be improved or degraded. Therefore one pragmatic and two optimistically weighting approaches for biometric fusion are used. The best fusion result is even better than the corresponding best individual result by approximately 17%.
Tobias Scheidat, Claus Vielhauer, Jana Dittmann
ICIP (2)3
2007 Future Perspectives: The Car and Its IP-Address - A Potential Safety and Security Risk Assessment
Andreas Lang 0001, Jana Dittmann, Stefan Kiltz, Tobias Hoppe
SAFECOMP2
2006 Design and evaluation of steganography for voice-over-IP
abstract
According to former results from (Dittmann et al., 2005) in this paper we summarize the design principles from the general approach and introduce extended experimental test results of a voice-over-IP (VoIP) framework including a steganographic channel based on (Dittmann et al., 2005), (Dittmann and Hesse, 2004), (Kraetzer et al., 2006) and (Vogel et al., 2006). We show that using this framework it is largely secure to transmit hidden messages during a VoIP session and demonstrate results with respect to perceptibility for music and speech data
Christian Krätzer, Jana Dittmann, Thomas Vogel 0002, Reyk Hillert
ISCAS2
2005 Distance-Level Fusion Strategies for Online Signature Verification
abstract
In this paper an approach for combining online signature authentication experts will be proposed. The different experts are based on one feature extraction method presented in our earlier work, the Biometric Hash algorithm [C. Viehauer, et al., (2002)], to which different distance measurement functions are applied. We will show that by the fusion of several algorithms with an appropriately parameterized strategy an improvement of the recognition accuracy can be achieved. The best fusion strategy results in a decrease of the EER of 12.1% in comparison to the best individual algorithm. The database we used contains 1761 genuine enrollments (with 4 signatures per enrollment), 1101 genuine verification signatures and 431 well skilled forgeries (so-called "brute force attack") by 22 persons. Based on our experimental results, we further discuss usability of alternative handwriting semantics such as pass phrases or PIN
Tobias Scheidat, Claus Vielhauer, Jana Dittmann
ICME3
2005 Ensuring Media Integrity on Third-Party Infrastructures
Jana Dittmann, Stefan Katzenbeisser 0001, Christian Schallhart, Helmut Veith
SEC1
2005 Editorial to the special issue about multimedia and security
Jana Dittmann
Multim. Syst.1
2004 Network based intrusion detection to detect steganographic communication channels: on the example of audio data
abstract
Due to the nature of multimedia data exchange over the Internet between authorized users, one of the most difficult tasks is to control unauthorized information flow. With respect to confidentiality requirements and breaches in security, steganography offers an instrument for attackers to hide a communication by embedding the secret message into an innocuous communication channel, the so-called cover data. Due to the improvements of audio steganography, disclosure of information becomes possible for a lot of applications. In our paper we investigate voice-over-IP applications and intrusion detection systems (IDS) to detect hidden communication channels. Besides an general application scenario and performance of audio capturing, we introduce two steganalysis classifier for speech: one for MP3Stego and one for Steghide. Our first tests are based on an offline analysis of captured speech data.
Jana Dittmann, Danny Hesse
MMSP1
2004 Benchmarking of Image Watermarking Algorithms for Digital Rights Management
abstract
We discuss the issues related to image watermarking benchmarking and scenarios based on digital rights management requirements. We show that improvements are needed in image quality evaluation, especially related to image geometrical deformation assessments, in risk evaluation related to specific delivery scenarios and in multidimensional criteria evaluation. Efficient benchmarking is still an open issue and we suggest the use of open-source Web-based evaluation systems for collective progress in this domain.
Benoît Macq, Jana Dittmann, Edward J. Delp
Proc. IEEE2
2003 Illustration Watermarks for Vector Graphics
abstract
Digital watermarking is a technique for embedding information into data, such as images, 3D models, or audio files, such that some properties (i.e., security, imperceptibility, robustness) are maintained. While most of the existing watermarking techniques focus on encoding copyright information where security is one of the most important properties, we have developed algorithms for embedding Illustration Watermarking, i.e., content-related annotations for the image. Robustness against common media transformations, high capacity, and blind detection are our aspired properties while security and the usage of secure keys are less important. The medium that we are using for embedding data are 2D vector graphics. We introduce algorithms that change line attributes, introduce new vertices in certain patterns, and replace existing stroke segments by new lines in a stylistic way. Based on the modification they introduced, we categorize our techniques into whether they change the appearance of the image or not and whether the changes are perceivable by the naked eye or not. We demonstrate our techniques with silhouette lines obtained from 3D models. Such line drawings are a very common style utilized in many illustrations, in particular in the medical and technical domain.
Henry Sonnet, Tobias Isenberg 0001, Jana Dittmann, Thomas Strothotte
PG3
2003 Editorial
Jana Dittmann, Stefan Katzenbeisser 0001, Nasir Memon
Multim. Syst.1
2001 Joint watermarking of audio-visual data
abstract
Both audio and video watermarking enable copyright protection with owner or customer authentication and the detection of media manipulations. The available watermarking technology concentrates on single media like audio or video. But the typical multimedia stream consists of both video and audio data. Our goal is to provide a solution with robust and fragile aspects to guarantee authentication and integrity by using watermarks in combination with content information. To achieve this, video stream parsing capabilities have to be added to existing watermarking algorithms. We propose to extract the audio and video content, called feature, and embed the content features with a robust watermarking scheme into the audio and video data. These features of audio and video data have to be identified. Watermarking payload and feature data requirements have to be compared. Our goal is to describe our current state of work in audio and video processing. We introduce a new approach for a/v content security. We embed watermarks both in video and audio channels of a MPEG system stream to increase security against attacks on content integrity.
Jana Dittmann, Martin Steinebach
MMSP1
1998 Robust MPEG Video Watermarking Technologies
abstract
ABSTIUCTThe development of new multimedia services and environments requires new concepts both to support the new working process on distributed computers and to protect the multimedia data during the production and the distribution in digital marketplaces.This article addresses copyright protection as a major security demand in digital marketplaces We propose and compare two watermarking techniques for MPEG video with the intention to show the advantages and the possible weakness in the schemes working in the frequency domain and in the spatial domain.To improve the view to the distortion of the watermarked frames we generate a 3D-difference view measuring the changes which were made during watermarking process and/or caused by several damaging attacks. 1.1
Jana Dittmann, Mark Stabenau, Ralf Steinmetz
ACM Multimedia1
1998 Protecting VoD the Easier Way
abstract
S.21-28
Carsten Griwodz, Oliver Merkel, Jana Dittmann, Ralf Steinmetz
ACM Multimedia3
1997 Enabling Technology for the Trading of MPEG-encoded Video
Jana Dittmann, Arnd Steinmetz
ACISP1