VLDB 2026 Research / reviewers in the wild / expert
Claudia Eckert 0001
dblp:e/ClaudiaEckert
· DBLP profile ↗
72ranked-venue papers
6as first author
5since 2021 · last 2021
0000-0002-2201-3828ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 48 · 5 first-author · 2 since 2021Artificial intelligence and machine learning · 14 · 2 since 2021Databases, data management, data science and information retrieval · 6Applied, interdisciplinary, general and emerging computing · 3Graphics, computer vision, multimedia, augmented reality and games · 2Systems, architecture and hardware · 1 · 1 first-authorSoftware engineering, systems software and programming languages · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1Theory of computation · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2021 | Falcon: Malware Detection and Categorization with Network Traffic Images
Peng Xu 0057, Claudia Eckert 0001, Apostolis Zarras |
ICANN (1) | 2 |
| 2021 | HawkEye: Cross-Platform Malware Detection with Representation Learning on Graphs
Peng Xu 0057, Youyi Zhang, Claudia Eckert 0001, Apostolis Zarras |
ICANN (3) | 3 |
| 2021 | Hybroid: Toward Android Malware Detection and Categorization with Program Code and Network Traffic
Mohammad Reza Norouzian, Peng Xu 0057, Claudia Eckert 0001, Apostolis Zarras |
ISC | 3 |
| 2021 | iTOP: Automating Counterfeit Object-Oriented Programming AttacksabstractExploiting a program requires a security analyst to manipulate data in program memory with the goal to obtain control over the program counter and to escalate privileges. However, this is a tedious and lengthy process as: (1) the analyst has to massage program data such that a logical reliable data passing chain can be established, and (2) depending on the attacker goal certain in-place fine-grained protection mechanisms need to be bypassed. Previous work has proposed various techniques to facilitate exploit development. Unfortunately, none of them can be easily used to address the given challenges. This is due to the fact that data in memory is difficult to be massaged by an analyst who does not know the peculiarities of the program as the attack specification is most of the time only textually available, and not automated at all. Paul Muntean 0001, Richard Viehoever, Zhiqiang Lin 0001, Gang Tan, Jens Grossklags, Claudia Eckert 0001 |
RAID | 6 |
| 2021 | IntRepair: Informed Repairing of Integer OverflowsabstractInteger overflows have threatened software applications for decades. Thus, in this paper, we propose a novel technique to provide automatic repairs of integer overflows inCsource code. Our technique, based on static symbolic execution, fusesdetection,repair generationandvalidation. This technique is implemented in a prototype namedIntRepair. We appliedIntRepairto 2,052Cprograms (approx. 1 million lines of code) contained in SAMATE's Juliet test suite and 50 synthesized programs that range up to 20 KLOC. Our experimental results show thatIntRepairis able to effectively detect integer overflows and successfully repair them, while only increasing the source code (LOC) and binary (Kb) size by around 1 percent, respectively. Further, we present the results of a user study with 30 participants which shows thatIntRepairrepairs are more than 10x efficient as compared to manually generated code repairs. Paul Muntean 0001, Martin Monperrus, Jens Grossklags, Claudia Eckert 0001 |
IEEE Trans. Software Eng. | 5 |
| 2020 | ρFEM: Efficient Backward-edge Protection Using Reversed Forward-edge MappingsabstractIn this paper, we propose reversed forward-edge mapper (ρFEM), a Clang/LLVM compiler-based tool, to protect the backward edges of a program’s control flow graph (CFG) against runtime control-flow hijacking (e.g., code reuse attacks). It protects backward-edge transfers in C/C++ originating from virtual and non-virtual functions by first statically constructing a precise virtual table hierarchy, with which to form a precise forward-edge mapping between callees and non-virtual calltargets based on precise function signatures, and then checks each instrumented callee return against the previously computed set at runtime. We have evaluated ρFEM using the Chrome browser, NodeJS, Nginx, Memcached, and the SPEC CPU2017 benchmark. Our results show that ρFEM enforces less than 2.77 return targets per callee in geomean, even for applications heavily relying on backward edges. ρFEM’s runtime overhead is less than 1% in geomean for the SPEC CPU2017 benchmark and 3.44% in geomean for the Chrome browser. Paul Muntean 0001, Matthias Neumayer, Zhiqiang Lin 0001, Gang Tan, Jens Grossklags, Claudia Eckert 0001 |
ACSAC | 6 |
| 2019 | Analyzing control flow integrity with LLVM-CFIabstractControl-flow hijacking attacks are used to perform malicious computations. Current solutions for assessing the attack surface after a control flow integrity (CFI) policy was applied can measure only indirect transfer averages in the best case without providing any insights w.r.t. the absolute calltarget reduction per callsite, and gadget availability. Further, tool comparison is underdeveloped or not possible at all. CFI has proven to be one of the most promising protections against control flow hijacking attacks, thus many efforts have been made to improve CFI in various ways. However, there is a lack of systematic assessment of existing CFI protections. Paul Muntean 0001, Matthias Neumayer, Zhiqiang Lin 0001, Gang Tan, Jens Grossklags, Claudia Eckert 0001 |
ACSAC | 6 |
| 2018 | Attack Graph-Based Assessment of Exploitability Risks in Automotive On-Board NetworksabstractHigh-end vehicles incorporate about one hundred computers; physical and virtualized ones; self-driving vehicles even more. This allows a plethora of attack combinations. This paper demonstrates how to assess exploitability risks of vehicular on-board networks via automatically generated and analyzed attack graphs. Our stochastic model and algorithm combine all possible attack vectors and consider attacker resources more efficiently than Bayesian networks. We designed and implemented an algorithm that assesses a compilation of real vehicle development documents within only two CPU minutes, using an average of about 100 MB RAM. Our proof of concept "Security Analyzer for Exploitability Risks" (SAlfER) is 200 to 5 000 times faster and 40 to 200 times more memory-efficient than an implementation with UnBBayes1. Our approach aids vehicle development by automatically re-checking the architecture for attack combinations that may have been enabled by mistake and which are not trivial to spot by the human developer. Our approach is intended for and relevant for industrial application. Our research is part of a collaboration with a globally operating automotive manufacturer and is aimed at supporting the security of autonomous, connected, electrified, and shared vehicles. Martin Salfer, Claudia Eckert 0001 |
ARES | 2 |
| 2018 | Hiding in the Shadows: Empowering ARM for Stealthy Virtual Machine IntrospectionabstractARM has become the leading processor architecture for mobile and IoT devices, while it has recently started claiming a bigger slice of the server market pie as well. As such, it will not be long before malware more regularly target the ARM architecture. Therefore, the stealthy operation of Virtual Machine Introspection (VMI) is an obligation to successfully analyze and proactively mitigate this growing threat. Stealthy VMI has proven itself perfectly suitable for malware analysis on Intel's architecture, yet, it often lacks the foundation required to be equally effective on ARM. Sergej Proskurin, Tamas K. Lengyel, Marius Momeu, Claudia Eckert 0001, Apostolis Zarras |
ACSAC | 4 |
| 2018 | CastSan: Efficient Detection of Polymorphic C++ Object Type Confusions with LLVM
Paul Muntean 0001, Sebastian Würl, Jens Grossklags, Claudia Eckert 0001 |
ESORICS (1) | 4 |
| 2018 | Learning on a Budget for User Authentication on Mobile DevicesabstractSince the amount of sensitive information stored on smart-phones expands with the growth of their popularity, the need for reliable and usable authentication on these devices increases. Constant reauthentication requests of standard methods, such as PINs, passwords, and swipe patterns, annoy many users who prefer to sacrifice the security of their mobile devices for the quest for maximum usability. An alternative to this approach is sensor-based authentication, where we fingerprint the user interaction by processing signals from sensors such as touchscreen or accelerometer. In this paper, we construct a budgeted online version of One-Class Support Vector Machine (OC-SVM) to maintain authentication performance while limiting the model size and evaluate the performance compared to an unconstrained model. The results of our experiments reveal that it is possible to correctly detect invalid smartphone users in a constrained environment using our budgeted learning methodology. Bojan Kolosnjaji, Antonia Hufner, Claudia Eckert 0001, Apostolis Zarras |
ICASSP | 3 |
| 2018 | τCFI: Type-Assisted Control Flow Integrity for x86-64 Binaries
Paul Muntean 0001, Gang Tan, Zhiqiang Lin 0001, Jens Grossklags, Claudia Eckert 0001 |
RAID | 6 |
| 2017 | Finding the Needle: A Study of the PE32 Rich Header and Respective Malware Triage
George D. Webster, Bojan Kolosnjaji, Christian von Pentz, Julian Kirsch, Zachary D. Hanif, Apostolis Zarras, Claudia Eckert 0001 |
DIMVA | 7 |
| 2017 | Empowering convolutional networks for malware classification and analysisabstractPerforming large-scale malware classification is increasingly becoming a critical step in malware analytics as the number and variety of malware samples is rapidly growing. Statistical machine learning constitutes an appealing method to cope with this increase as it can use mathematical tools to extract information out of large-scale datasets and produce interpretable models. This has motivated a surge of scientific work in developing machine learning methods for detection and classification of malicious executables. However, an optimal method for extracting the most informative features for different malware families, with the final goal of malware classification, is yet to be found. Fortunately, neural networks have evolved to the state that they can surpass the limitations of other methods in terms of hierarchical feature extraction. Consequently, neural networks can now offer superior classification accuracy in many domains such as computer vision and natural language processing. In this paper, we transfer the performance improvements achieved in the area of neural networks to model the execution sequences of disassembled malicious binaries. We implement a neural network that consists of convolutional and feedforward neural constructs. This architecture embodies a hierarchical feature extraction approach that combines convolution of n-grams of instructions with plain vectorization of features derived from the headers of the Portable Executable (PE) files. Our evaluation results demonstrate that our approach outperforms baseline methods, such as simple Feedforward Neural Networks and Support Vector Machines, as we achieve 93% on precision and recall, even in case of obfuscations in the data. Bojan Kolosnjaji, Ghadir Eraisha, George D. Webster, Apostolis Zarras, Claudia Eckert 0001 |
IJCNN | 5 |
| 2017 | Combating Control Flow Linearization
Julian Kirsch, Clemens Jonischkeit, Thomas Kittel 0001, Apostolis Zarras, Claudia Eckert 0001 |
SEC | 5 |
| 2016 | CoKey: fast token-based cooperative cryptography
Julian Horsch, Sascha Wessel, Claudia Eckert 0001 |
ACSAC | 3 |
| 2016 | DeepFuzz: Triggering Vulnerabilities Deeply Hidden in Binaries - (Extended Abstract)
Konstantin Böttinger, Claudia Eckert 0001 |
DIMVA | 2 |
| 2016 | Adaptive Semantics-Aware Malware Classification
Bojan Kolosnjaji, Apostolis Zarras, Tamas K. Lengyel, George D. Webster, Claudia Eckert 0001 |
DIMVA | 5 |
| 2016 | Policy-Based Implicit Attestation for Microkernel-Based Virtualized Systems
Steffen Wagner, Claudia Eckert 0001 |
ISC | 2 |
| 2016 | SKALD: A Scalable Architecture for Feature Extraction, Multi-user Analysis, and Real-Time Information Sharing
George D. Webster, Zachary D. Hanif, Andre L. P. Ludwig, Tamas K. Lengyel, Apostolis Zarras, Claudia Eckert 0001 |
ISC | 6 |
| 2015 | iDeFEND: Intrusion Detection Framework for Encrypted Network Data
Fatih Kiliç 0001, Claudia Eckert 0001 |
CANS | 2 |
| 2015 | Detecting Fingerprinted Data in TLS TrafficabstractWe present a new method for detecting known data in certain TLS encrypted communication channels. Our approach enables us to detect single files in eavesdropped TLS secured network traffic. We generate fingerprints by a fine-grained measurement of the entropy of fragments of known data and introduce the application of methods from the field of machine learning to the problem of file detection. We implement all proposed methods on a real data base and show the practical efficiency of our approach. Konstantin Böttinger, Dieter Schuster, Claudia Eckert 0001 |
AsiaCCS | 3 |
| 2015 | Interactive Function Identification Decreasing the Effort of Reverse Engineering
Fatih Kiliç 0001, Hannes Laner, Claudia Eckert 0001 |
Inscrypt | 3 |
| 2015 | Learning better while sending less: Communication-efficient online semi-supervised learning in client-server settingsabstractWe consider a novel distributed learning problem: A server receives potentially unlimited data from clients in a sequential manner, but only a small initial fraction of these data are labeled. Because communication bandwidth is expensive, each client is limited to sending the server only a small (high-priority) fraction of the unlabeled data it generates, and the server is limited in the amount of prioritization hints it sends back to the client. The goal is for the server to learn a good model of all the client data from the labeled and unlabeled data it receives. This setting is frequently encountered in real-world applications and has the characteristics of online, semi-supervised, and active learning. However, previous approaches are not designed for the client-server setting and do not hold the promise of reducing communication costs. We present a novel framework for solving this learning problem in an effective and communication-efficient manner. On the server side, our solution combines two diverse learners working collaboratively, yet in distinct roles, on the partially labeled data stream. A compact, online graph-based semi-supervised learner is used to predict labels for the unlabeled data arriving from the clients. Samples from this model are used as ongoing training for a linear classifier. On the client side, our solution prioritizes data based on an active-learning metric that favors instances that are close to the classifier's decision hyperplane and yet far from each other. To reduce communication, the server sends the classifier's weight-vector to the client only periodically. Experimental results on real-world data sets show that this particular combination of techniques outperforms other approaches, and in particular, often outperforms (communication expensive) approaches that send all the data to the server. Han Xiao 0002, Shou-De Lin, Mi-Yen Yeh, Phillip B. Gibbons, Claudia Eckert 0001 |
DSAA | 5 |
| 2015 | Is Feature Selection Secure against Training Data Poisoning?abstractLearning in adversarial settings is becoming an important task for application domains where attackers may inject malicious data into the training set to subvert normal operation of data-driven technologies. Feature selection has been widely used in machine learning for security applications to improve generalization and computational efficiency, although it is not clear whether its use may be beneficial or even counterproductive when training data are poisoned by intelligent attackers. In this work, we shed light on this issue by providing a framework to investigate the robustness of popular feature selection methods, including LASSO, ridge regression and the elastic net. Our results on malware detection show that feature selection methods can be significantly compromised under attack (we can reduce LASSO to almost random choices of feature sets by careful insertion of less than 5% poisoned training samples), highlighting the need for specific countermeasures. Huang Xiao, Battista Biggio, Gavin Brown 0001, Giorgio Fumera, Claudia Eckert 0001, Fabio Roli |
ICML | 5 |
| 2015 | Neural Network-Based User-Independent Physical Activity Recognition for Mobile Devices
Bojan Kolosnjaji, Claudia Eckert 0001 |
IDEAL | 2 |
| 2015 | User Identity Verification Based on Touchscreen Interaction Analysis in Web Contexts
Michael Velten, Peter Schneider 0002, Sascha Wessel, Claudia Eckert 0001 |
ISPEC | 4 |
| 2015 | Counteracting Data-Only Malware with Code Pointer Examination
Thomas Kittel 0001, Sebastian Vogl, Julian Kirsch, Claudia Eckert 0001 |
RAID | 4 |
| 2015 | Automated Generation of Buffer Overflow Quick Fixes Using Symbolic Execution and SMT
Paul Muntean 0001, Vasantha Kommanapalli, Andreas Ibing, Claudia Eckert 0001 |
SAFECOMP | 4 |
| 2015 | Attack Surface and Vulnerability Assessment of Automotive Electronic Control UnitsabstractModern vehicles are controlled by an on-board network of ECUs (Electronic Control Units), which are specially designed computers that contain tightly tailored and customized software. Especially the trends for ECU connectivity and for semi-autonomous driver assistance functions may have an impact on passenger safety and require thorough security assessments, yet the ECU divergence strains those assessments. We therefore propose an easily automated, quantitative, probabilistic method and metric based on ECU development data and software flash images for the attack surface and vulnerability assessment automation. Our method and metric is designed for the integration into an (iterative) engineering process and the facilitation of code reviews and other security assessments, such as penetration tests. The automotive attack surface comprises especially internal communication interfaces, including diagnosis protocols, external and user-accessible interfaces, such as USB sockets, as well as low-level hardware interfaces. Some exemplary indicators for the vulnerability are access restrictions, casing tamper-resistance, code size, previously found vulnerabilities; strictness of compilers, frameworks and application binary interfaces; conducted security audits and deployed exploit mitigation techniques. This paper's main contributions are I) a method and a metric for collecting attack surface and predicting the engineering effort for a code injection exploit from ECU development data and II) an application of our metric and method into our graph-based security assessment. Martin Salfer, Claudia Eckert 0001 |
SECRYPT | 2 |
| 2015 | Improving mobile device security with operating system-level virtualization
Sascha Wessel, Manuel Huber 0001, Frederic Stumpf, Claudia Eckert 0001 |
Comput. Secur. | 4 |
| 2015 | Support vector machines under adversarial label contamination
Huang Xiao, Battista Biggio, Blaine Nelson, Han Xiao 0002, Claudia Eckert 0001, Fabio Roli |
Neurocomputing | 5 |
| 2014 | SobrTrA: a software-based trust anchor for ARM cortex application processorsabstractIn this paper, we present SobTrA, a Software-based Trust Anchor for ARM Cortex-A processors to protect systems against software-based attacks. SobTrA enables the implementation of a software-based secure boot controlled by a third party independent from the manufacturer. Compared to hardware-based trust anchors, our concept provides some other advantages like being updateable and also usable on legacy hardware. The presented software-based trust anchor involves a trusted third party device, the verifier, locally connected to the untrusted device, e.g., via the microSD card slot of a smartphone. The verifier is verifying the integrity of the untrusted device by making sure that a piece of code is executed untampered on it using a timing-based approach. This code can then act as an anchor for a chain of trust similar to a hardware-based secure boot. Tests on our prototype showed that tampered and untampered execution of SobTrA can be clearly and reliably distinguished. Julian Horsch, Sascha Wessel, Frederic Stumpf, Claudia Eckert 0001 |
CODASPY | 4 |
| 2014 | Efficient Attack Forest Construction for Automotive On-board Networks
Martin Salfer, Hendrik Schweppe, Claudia Eckert 0001 |
ISC | 3 |
| 2014 | Persistent Data-only Malware: Function Hooks without Code
Sebastian Vogl, Jonas Pfoh, Thomas Kittel 0001, Claudia Eckert 0001 |
NDSS | 4 |
| 2014 | Blind Format String Attacks
Fatih Kiliç 0001, Thomas Kittel 0001, Claudia Eckert 0001 |
SecureComm (2) | 3 |
| 2014 | Dynamic Hooks: Hiding Control Flow Changes within Non-Control Data
Sebastian Vogl, Robert Gawlik, Behrad Garmany, Thomas Kittel 0001, Jonas Pfoh, Claudia Eckert 0001, Thorsten Holz |
USENIX Security Symposium | 6 |
| 2014 | A flexible approach to distributed data anonymization
Florian Kohlmayer, Fabian Prasser, Claudia Eckert 0001, Klaus A. Kuhn |
J. Biomed. Informatics | 3 |
| 2013 | Lazy Gaussian Process Committee for Real-Time Online RegressionabstractA significant problem of Gaussian process (GP) is its unfavorable scaling with a large amount of data. To overcome this issue, we present a novel GP approximation scheme for online regression. Our model is based on a combination of multiple GPs with random hyperparameters. The model is trained by incrementally allocating new examples to a selected subset of GPs. The selection is carried out efficiently by optimizing a submodular function. Experiments on real-world data sets showed that our method outperforms existing online GP regression methods in both accuracy and efficiency. The applicability of the proposed method is demonstrated by the mouse-trajectory prediction in an Internet banking scenario. Han Xiao 0002, Claudia Eckert 0001 |
AAAI | 2 |
| 2013 | OPARS: Objective Photo Aesthetics Ranking System
Huang Xiao, Han Xiao 0002, Claudia Eckert 0001 |
ECIR | 3 |
| 2013 | Efficient Online Sequence Prediction with Side InformationabstractSequence prediction is a key task in machine learning and data mining. It involves predicting the next symbol in a sequence given its previous symbols. Our motivating application is predicting the execution path of a process on an operating system in real-time. In this case, each symbol in the sequence represents a system call accompanied with arguments and a return value. We propose a novel online algorithm for predicting the next system call by leveraging both context and side information. The online update of our algorithm is efficient in terms of time cost and memory consumption. Experiments on real-world data sets showed that our method outperforms state-of-the-art online sequence prediction methods in both accuracy and efficiency, and incorporation of side information does significantly improve the predictive accuracy. Han Xiao 0002, Claudia Eckert 0001 |
ICDM | 2 |
| 2013 | Indicative Support Vector Clustering with Its Application on Anomaly DetectionabstractIn many learning scenarios, supervised learning is hardly applicable due to the unavailability of a complete set of data labels, while unsupervised model overlooks valuable user feedback in an interactive system setting. In this paper, a novel semi-supervised support vector clustering algorithm is presented, where a small number of user indicated labels are available as supervised information. We apply the clustering algorithm in the anomaly detection area, and show that the given labels significantly improve the recognition of anomalies. Moreover, the partially labeled data proliferates the information without extra computation but strengthening the robustness to anomalies. Huang Xiao, Claudia Eckert 0001 |
ICMLA (1) | 2 |
| 2013 | Lightweight Attestation and Secure Code Update for Multiple Separated Microkernel Tasks
Steffen Wagner, Christoph Krauß, Claudia Eckert 0001 |
ISC | 3 |
| 2013 | Leveraging String Kernels for Malware Detection
Jonas Pfoh, Christian A. Schneider, Claudia Eckert 0001 |
NSS | 3 |
| 2013 | X-TIER: Kernel Module Injection
Sebastian Vogl, Fatih Kiliç 0001, Christian A. Schneider, Claudia Eckert 0001 |
NSS | 4 |
| 2013 | Learning from Multiple Observers with Unknown Expertise
Han Xiao 0002, Huang Xiao, Claudia Eckert 0001 |
PAKDD (1) | 3 |
| 2013 | Improving Mobile Device Security with Operating System-Level Virtualization
Sascha Wessel, Frederic Stumpf, Ilja Herdt, Claudia Eckert 0001 |
SEC | 4 |
| 2012 | Highly efficient optimal k-anonymity for biomedical datasetsabstractK-anonymization is a wide-spread technique for the de-identification of biomedical datasets. To not render the data useless for further analysis it is often important to find an optimal solution to the k-anonymity problem, i.e., a transformation with minimum information loss. As performance is often a key requirement this paper describes an efficient implementation of a k-anonymization algorithm which is especially suitable for biomedical datasets. Although our basic implementation already offers excellent performance we present several further optimizations and show that these yield an additional speedup of up to a factor offive even for large datasets. Florian Kohlmayer, Fabian Prasser, Claudia Eckert 0001, Alfons Kemper, Klaus A. Kuhn |
CBMS | 3 |
| 2012 | Evasion Attack of Multi-class Linear Classifiers
Han Xiao 0002, Thomas Stibor, Claudia Eckert 0001 |
PAKDD (1) | 3 |
| 2012 | Towards Secure Fieldbus Communication
Felix Wieczorek, Christoph Krauß, Frank Schiller, Claudia Eckert 0001 |
SAFECOMP | 4 |
| 2011 | T-CUP: A TPM-Based Code Update Protocol Enabling Attestations for Sensor Networks
Steffen Wagner, Christoph Krauß, Claudia Eckert 0001 |
SecureComm | 3 |
| 2009 | Enhancing Control of Service Compositions in Service-Oriented ArchitecturesabstractIn a service-oriented architecture, service compositions are assembled from other component services. Such compositions may include services from unknown and potentially untrusted providers. As there is no direct control of those services, it is not ensured that pre-negotiated policies are actually enforced as specified.In this work, we propose a pluggable component for controlling interactions of service compositions which we call orchestration service. It executes arbitrary service compositions on behalf of others and intercepts messages exchanged between the involved services. Thus, the orchestration service can ensure a correct enforcement of the stipulated policies. Moreover, it also monitors obligation statements and logs all interactions in an audit compliant way. Using this approach, the control over existing service compositions can be enhanced with little effort. We present the concept of the orchestration service, describe its usage and discuss which applications can be supported by our approach. Christian A. Schneider, Frederic Stumpf, Claudia Eckert 0001 |
ARES | 3 |
| 2008 | Towards Secure E-Commerce Based on Virtualization and Attestation TechniquesabstractWe present a secure e-commerce architecture that is resistant to client compromise and man-in-the-middle attacks on SSL. To this end, we propose several security protocols that use attestation techniques offered by the Trusted Computing Group (TCG). Using these protocols, we can ensure that the client configuration remains untampered and trusted for the duration of the transaction. In addition, confidential data, such as authentication passwords, are only accessible by the electronic commerce server to which the users intend to transfer their data. Since we employ a trusted third party that is responsible for verifying a client's platform configuration, our approach does not depend on trusted computing at the server but instead only requires minor modification to server logic. Frederic Stumpf, Claudia Eckert 0001, Shane Balfe |
ARES | 2 |
| 2008 | 506 Ways to Track Your LoverabstractIn the near future vehicular communication will be used to increase traffic safety, efficiency and convenience. This work focuses on the privacy of vehicle owners. The privacy situation in vehicular communication is modeled using graphs. Adversary classes are described and the vehicular communication scenario is analyzed with respect to linkability of positional messages. Further, new and known privacy enhancing methods are discussed in the light of this model. Lars Fischer 0002, Claudia Eckert 0001 |
VTC Fall | 2 |
| 2008 | An Enhanced Scheme to Defend against False-Endorsement-Based DoS Attacks in WSNsabstractNode compromise is a serious threat in wireless sensor networks, as it enables an adversary to perform various attacks. Many security schemes exploit the redundancy of many wireless sensor networks to mitigate the impact of node compromise. A report for the base station, generated by one node, must be endorsed by multiple neighboring sensor nodes. However, already proposed schemes are susceptible to False-Endorsement-Based Denial of Service attacks, where a compromised node sends a false endorsement that invalidates the collaboratively generated report. A formerly proposed scheme addresses such an attack, thereby enabling the detection and exclusion of false endorsing nodes. However, a jamming attack can result in a false exclusion of non-compromised nodes. In this paper, we discuss possible solutions to prevent false exclusions of non-compromised nodes and propose an extended scheme. Christoph Krauß, Markus Schneider 0002, Claudia Eckert 0001 |
WiMob | 3 |
| 2008 | Defending against false-endorsement-based dos attacks in wireless sensor networksabstractNode compromise is a serious threat in wireless sensor networks. An adversary can use compromised sensor nodes to inject false data to deceive the base station or he can try to deplete the energy resources of the sensor nodes. One approach to mitigate the impact of node compromise exploits the redundancy property of many wireless sensor networks. If a node initiates a report generation for the base station, then this report must be endorsed by multiple neighboring sensor nodes. Already proposed schemes using this approach introduce a new possible attack, called False-Endorsement-Based Denial of Service attack, where a compromised node sends a false endorsement which invalidates the collaboratively generated report. We propose an extension scheme, which enables the detection and exclusion of false endorsing nodes and is efficient in terms of storage and energy consumption. Christoph Krauß, Markus Schneider 0002, Claudia Eckert 0001 |
WISEC | 3 |
| 2008 | On handling insider attacks in wireless sensor networks
Christoph Krauß, Markus Schneider 0002, Claudia Eckert 0001 |
Inf. Secur. Tech. Rep. | 3 |
| 2007 | STEF: A Secure Ticket-Based En-route Filtering Scheme for Wireless Sensor NetworksabstractNode compromise is a serious threat in wireless sensor networks. An adversary can use compromised nodes to inject false data into the network forging events to deceive the base station. Furthermore, an adversary can cause serious damage by injecting a large amount of false messages to deplete the scarce energy resources of the forwarding en-route sensor nodes. In this paper, we propose a Secure Ticket-Based Enroute Filtering Scheme (STEF) that drops false messages enroute. We propose a ticket concept where reply messages are only forwarded if they contain a valid ticket originally issued by the base station. Messages containing no ticket, or an replayed ticket, are immediately filtered out by not compromised sensor nodes. The ticket concept is based on lightweight one-way functions. This enables every en-route node to verify the tickets. Furthermore, our scheme does not need symmetric key sharing between message generating nodes and en-route nodes, which results in a high resiliency against node compromises. Our security and performance analysis shows that STEF provides a high security level and is very efficient in saving energy. Furthermore, the required storage capacity on the sensor nodes is very low. Christoph Krauß, Markus Schneider 0002, Kpatcha M. Bayarou, Claudia Eckert 0001 |
ARES | 4 |
| 2007 | An Approach to a Trustworthy System Architecture Using Virtualization
Frederic Stumpf, Michael Benz, Martin Hermanowski, Claudia Eckert 0001 |
ATC | 4 |
| 2007 | History-based access control for XML documentsabstractXML is a widely used standard for information storage and exchange in today's IT systems. Therefore, it is essential to protect XML documents from unauthorized access. For this purpose, we present a model for access control for XML documents with three key features. First, we record the effects of the operations on the documents in a history, depending on which we can grant or deny access. Second, we use the history information to define permissions for the operations of our model including the transfer of document parts. Third, since the text content of an element can be composed of parts of text from different sources, we consider units smaller than the XML element as a protection unit. Therefore, we keep track of these parts and allow to define access to them individually. Patrick Röder, Omid Tafreschi, Claudia Eckert 0001 |
AsiaCCS | 3 |
| 2007 | A System Architecture for History-Based Access Control for XML Documents
Patrick Röder, Omid Tafreschi, Fredrik Mellgren, Claudia Eckert 0001 |
ICICS | 4 |
| 2007 | Situation-Based Policy Enforcement
Thomas Buntrock, Hans-Christian Esperer, Claudia Eckert 0001 |
TrustBus | 3 |
| 2006 | The Link between r-contiguous Detectors and k-CNF SatisfiabilityabstractIn the context of generating detectors using the r-contiguous matching rule, questions have been raised at the efficiency of the process. We show that the problem of generating r-contiguous detectors can be transformed in a k-CNF satisfiability problem. This insight allows for the wider understanding of the problem of generating r-contiguous detectors. Moreover, we apply this result to consider questions relating to the complexity of generating detectors, and when detectors are generable. Thomas Stibor, Jonathan Timmis, Claudia Eckert 0001 |
IEEE Congress on Evolutionary Computation | 3 |
| 2005 | On the appropriateness of negative selection defined over Hamming shape-space as a network intrusion detection systemabstractArtificial immune systems have become popular in recent years as a new approach for intrusion detection systems. Indeed, the (natural) immune system applies very effective mechanisms to protect the body against foreign intruders. We present empirical and theoretical arguments, that the artificial immune system negative selection principle, which is primarily used for network intrusion detection systems, has been copied to naively and is not appropriate and not applicable for network intrusion detection systems. Thomas Stibor, Jonathan Timmis, Claudia Eckert 0001 |
Congress on Evolutionary Computation | 3 |
| 2005 | Is negative selection appropriate for anomaly detection?abstractNegative selection algorithms for hamming and real-valued shape-spaces are reviewed. Problems are identified with the use of these shape-spaces, and the negative selection algorithm in general, when applied to anomaly detection. A straightforward self detector classification principle is proposed and its classification performance is compared to a real-valued negative selection algorithm and to a one-class support vector machine. Earlier work suggests that real-value negative selection requires a single class to learn from. The investigations presented in this paper reveal, however, that when applied to anomaly detection, the real-valued negative selection and self detector classification techniques require positive and negative examples to achieve a high classification accuracy. Whereas, one-class SVMs only require examples from a single class. Thomas Stibor, Philipp H. Mohr, Jonathan Timmis, Claudia Eckert 0001 |
GECCO | 4 |
| 2004 | An Investigation of R-Chunk Detector Generation on Higher Alphabets
Thomas Stibor, Kpatcha M. Bayarou, Claudia Eckert 0001 |
GECCO (1) | 3 |
| 2001 | Internet Anonymity: Problems and Solutions
Claudia Eckert 0001, A. Pircher |
SEC | 1 |
| 2000 | GSFS - A New Group-Aware Cryptographic File System
Claudia Eckert 0001, Florian Erhard, Johannes Geiger |
SEC | 1 |
| 1999 | Improving Resource Management in Distributed Systems using Language-Level Structuring Concepts
Claudia Eckert 0001, Markus Pizka |
J. Supercomput. | 1 |
| 1997 | Developing secure applications: a systematic approach
Claudia Eckert 0001, D. Marek |
SEC | 1 |
| 1997 | MVS-SAT: a security administration tool to support SMF protocol data evaluation
Claudia Eckert 0001, Th. Stoesslein |
SEC | 1 |
| 1996 | On security models
Claudia Eckert 0001 |
SEC | 1 |