VLDB 2026 Research / reviewers in the wild / expert
Felix C. Freiling
dblp:f/FCFreiling · also Felix C. Gärtner
· DBLP profile ↗
68ranked-venue papers
13as first author
6since 2021 · last 2025
0000-0002-8279-8401ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 46 · 8 first-author · 6 since 2021Systems, architecture and hardware · 6 · 2 first-authorTheory of computation · 3Databases, data management, data science and information retrieval · 2Artificial intelligence and machine learning · 1Computer networks · 1Software engineering, systems software and programming languages · 1Human-computer interaction and ubiquitous computing · 1Applied, interdisciplinary, general and emerging computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | TrustLeech: Privileged System Analysis using Nested VirtualizationabstractPrivileged system analysis, i.e., the analysis of a running virtual machine (VM) from the hypervisor, is a common and robust technique employed in digital forensics, incident response, and malware analysis. Its robustness stems from the analysis system running with higher privileges than the target. However, the complexity of modern hypervisors has increased the probability of vulnerabilities allowing privilege escalation, which may allow a VM to take over the hypervisor. To counter this threat, analysis tools are deployed at even higher privilege levels, such as the firmware level on ARMv8-A systems. However, moving complex software to the firmware merely shifts the dangers of vulnerabilities to another layer. To solve this dilemma, we propose using nested virtualization to introduce an additional analysis layer below the hypervisor but above the firmware. This layer can be initiated on demand using only minor modifications to the firmware. As a proof of concept, we present TrustLeech, which only adds a small loader consisting of 327 lines of code to the firmware. On-demand at runtime, TrustLeech virtualizes the existing hypervisor and its VMs using ARM's nested virtualization extensions, inserting an analysis hypervisor. TrustLeech therefore combines the advantages of firmware level initialization with a hypervisor's access to all hardware debugging features, allowing precise analysis. We show its applicability by integrating TrustLeech with LibVMI and analyzing rootkits in a running hypervisor. Matti Schulze, Paul Bergmann, Jonas Röckl, Felix C. Freiling |
ACSAC | 4 |
| 2025 | Increasing the Resilience of Secure Multiparty Computation Using Security ModulesabstractWe investigate the problem of Secure Multiparty Computation (SMC) in a synchronous system with Byzantine failures where processes have access to trusted hardware. While previous solutions needed a majority of well-behaving processes to solve SMC, we construct an algorithm that solves SMC for an arbitrary number of Byzantine processes. We do this by refining and combining multiple established concepts from the literature: (1) We introduce a dynamic association between processes and trusted hardware modules in the hybrid system model of Fort et al. (TrustedPals model), (2) we utilize the primitive of Uniform Reliable Broadcast for information dissemination between trusted hardware modules, and (3) we use (and slightly adapt) the concept of Sealed Computation as an abstraction of trusted hardware modules. Lamya Abdullah, Felix C. Freiling, Dominique Schröder |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2025 | Poor Sanitization Practices and Questionable Digital Evidence: A Comprehensive Study of Scope and Impact of Recycled NAND Flash ChipsabstractIn digital forensics, the provenance of data being used as digital evidence in court is frequently challenged. This is often done to raise doubts about whether the possession of some piece of illegal data was intentional. However, there may also be situations where the provenance of data is legitimately questioned, such as in the case of second-hand devices that were not well sanitized. This may also lead to the disclosure of personal or corporate data. While poor sanitization practices have already been observed for second-hand hard disk drives, this has not yet been reported for new storage devices based on flash technology. Based on insights into the second-hand chip market in certain countries, we report on the results of the first large-scale study on the effects of chip reuse for USB flash drives. We provide clear evidence of poor sanitization practices for USB flash drives from the low-cost market that were sold as new. More specifically, we forensically analyzed 1211 low-cost USB flash drives and were able to recover non-trivial data on a total of 76 devices (6%). Furthermore, we forensically analyzed 435 high-cost USB flash drives on which we could not find any evidence of chip recycling in this market sector. Janine Schneider, Aya Fukami, Immanuel Lautner, Maximilian Eichhorn, Denise Moussa, Julian Wolf 0003, Nicole Scheler, Dominic Deuber, Felix C. Freiling, Jaap Haasnoot, Hans Henseler, Simon Malik, Holger Morgenstern, Martin Westman |
IEEE Trans. Dependable Secur. Comput. | 9 |
| 2024 | An Experimental Assessment of Inconsistencies in Memory ForensicsabstractMemory forensics is concerned with the acquisition and analysis of copies of volatile memory (memory dumps). Based on an empirical assessment of observable inconsistencies in 360 memory dumps of a running Linux system, we confirm a state of overwhelming inconsistency in memory forensics: almost a third of these dumps had an empty process list and was therefore obviously incomplete. Out of those dumps that were analyzable, almost every second dump showed some form of inconsistency that potentially impacts the interpretation of the dump in a forensic investigation. These results are based on a new way to estimate the level of causal consistency of a memory dump. The factors influencing these inconsistencies are less clear but in general correlate with the level of concurrency (system load and number of threads). Jenny Ottmann, Frank Breitinger, Felix C. Freiling |
ACM Trans. Priv. Secur. | 3 |
| 2021 | Advanced System Resiliency Based on Virtualization Techniques for IoT DevicesabstractAn increasing number of powerful devices are equipped with network connectivity and are connected to the Internet of Things (IoT). Influenced by the steady growth of computing power of the devices, the paradigm of IoT-based service deployment is expected to change, following the example of cloud-based infrastructure: An embedded platform can be provided as-a-service to several independent application service suppliers. This fosters additional challenges concerning security and isolation. At the same time, recently revealed critical vulnerabilities like Ripple20 and Amnesia:33 show that embedded devices are not spared from wide-spread attacks. Jonas Röckl, Mykolai Protsenko, Monika Kamhuber, Tilo Müller, Felix C. Freiling |
ACSAC | 5 |
| 2021 | Towards GDPR-compliant data processing in modern SIEM systems
Florian Menges, Tobias Latzo, Manfred Vielberth, Sabine Sobola, Henrich Christopher Pöhls, Benjamin Taubmann, Johannes Köstler, Alexander Puchta, Felix C. Freiling, Hans P. Reiser, Günther Pernul |
Comput. Secur. | 9 |
| 2020 | Make Remote Forensic Investigations Forensic Again: Increasing the Evidential Value of Remote Forensic Investigations
Marcel Busch, Florian Nicolai, Fabian Fleischer 0001, Christian Rückert, Christoph Safferling, Felix C. Freiling |
ICDF2C | 6 |
| 2020 | HyperLeech: Stealthy System Virtualization with Minimal Target Impact through DMA-Based Hypervisor Injection
Ralph Palutke, Simon Ruderich, Matthias Wild, Felix C. Freiling |
RAID | 4 |
| 2020 | Security Update Labels: Establishing Economic Incentives for Security Patching of IoT Consumer ProductsabstractWith the expansion of the Internet of Things (IoT), the number of security incidents due to insecure and misconfigured IoT devices is increasing. Especially on the consumer market, manufacturers focus on new features and early releases at the expense of a comprehensive security strategy. Hence, experts have started calling for regulation of the IoT consumer market, while policymakers are seeking for suitable regulatory approaches. We investigate how manufacturers can be incentivized to increase sustainable security efforts for IoT products. We propose mandatory security update labels that inform consumers during buying decisions about the willingness of the manufacturer to provide security updates in the future. Mandatory means that the labels explicitly state when security updates are not guaranteed. We conducted a user study with more than 1,400 participants to assess the importance of security update labels for the consumer choice by means of a conjoint analysis. The results show that the availability of security updates (until which date the updates are guaranteed) accounts for 8% to 35% impact on overall consumers' choice, depending on the perceived security risk of the product category. For products with a high perceived security risk, this availability is twice as important as other high-ranked product attributes. Moreover, provisioning time for security updates (how quickly the product will be patched after a vulnerability is discovered) additionally accounts for 7% to 25% impact on consumers' choices. The proposed labels are intuitively understood by consumers, do not require product assessments by third parties before release, and have a potential to incentivize manufacturers to provide sustainable security support. Philipp Morgner, Christoph Mai, Nicole Koschate-Fischer, Felix C. Freiling, Zinaida Benenson |
SP | 4 |
| 2019 | Atlas: Application Confidentiality in Compromised Embedded SystemsabstractDue to the requirements of the Internet-of-Things, modern embedded systems have become increasingly complex, running different applications. In order to protect their intellectual property as well as the confidentiality of sensitive data they process, these applications have to be isolated from each other. Traditional memory protection and memory management units provide such isolation, but rely on operating system support for their configuration. However, modern operating systems tend to be vulnerable and cannot guarantee confidentiality when compromised. We present Atlas, a hardware-based security architecture, complementary to traditional memory protection mechanisms, ensuring code and data confidentiality through transparent encryption, even when the system software has been exploited. Atlas relies on its zero-software trusted computing base to protect against system-level attackers and also supports secure shared memory. We implemented Atlas based on the LEON3 softcore processor, including toolchain extensions for developers. Our FPGA-based evaluation shows minimal cycle overhead at the cost of a reduced maximum frequency. Pieter Maene, Johannes Götzfried, Tilo Müller, Ruan de Clercq, Felix C. Freiling, Ingrid Verbauwhede |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2018 | Opinion: Security Lifetime Labels - Overcoming Information Asymmetry in Security of IoT Consumer ProductsabstractThe installed base of Internet of Things (IoT) consumer products is steadily increasing, in conjunction with the number of disclosed security vulnerabilities in these devices. In this paper, we share the opinion that strong security measures are necessary but IoT security cannot solely be improved by means of sophisticated technical solutions. From our point of view, economic incentives for the manufacturers have to be established through enabling consumers to reward security. This is currently not the case, as an asymmetric information barrier prevents consumers from assessing the level of security that is provided by IoT products. As a result, consumers are not willing to pay for a comprehensive security design as they cannot distinguish it from insufficient security measures. Learning from regulatory approaches that overcame information asymmetries about other non-functional properties in consumer products, e.g., energy labels to compare the power consumption, we propose security lifetime labels, a mechanism that transforms security into an accessible feature and enables consumers to make informed buying decisions. Focusing on the delivering of security updates as an important aspect of enforcing IoT security, we aim to transform the asymmetric information about the manufacturers' willingness to provide security updates into a label that can be assessed by the consumers. Philipp Morgner, Felix C. Freiling, Zinaida Benenson |
WISEC | 2 |
| 2018 | Hardware-Based Trusted Computing Architectures for Isolation and AttestationabstractAttackers target many different types of computer systems in use today, exploiting software vulnerabilities to take over the device and make it act maliciously. Reports of numerous attacks have been published, against the constrained embedded devices of the Internet of Things, mobile devices like smartphones and tablets, high-performance desktop and server environments, as well as complex industrial control systems. Trusted computing architectures give users and remote parties like software vendors guarantees about the behaviour of the software they run, protecting them against software-level attackers. This paper defines the security properties offered by them, and presents detailed descriptions of twelve hardware-based attestation and isolation architectures from academia and industry. We compare all twelve designs with respect to the security properties and architectural features they offer. The presented architectures have been designed for a wide range of devices, supporting different security properties. Pieter Maene, Johannes Götzfried, Ruan de Clercq, Tilo Müller, Felix C. Freiling, Ingrid Verbauwhede |
IEEE Trans. Computers | 5 |
| 2017 | Sancus 2.0: A Low-Cost Security Architecture for IoT DevicesabstractThe Sancus security architecture for networked embedded devices was proposed in 2013 at the USENIX Security conference. It supports remote (even third-party) software installation on devices while maintaining strong security guarantees. More specifically, Sancus can remotely attest to a software provider that a specific software module is running uncompromised and can provide a secure communication channel between software modules and software providers. Software modules can securely maintain local state and can securely interact with other software modules that they choose to trust. Over the past three years, significant experience has been gained with applications of Sancus, and several extensions of the architecture have been investigated—both by the original designers as well as by independent researchers. Informed by these additional research results, this journal version of the Sancus paper describes an improved design and implementation, supporting additional security guarantees (such as confidential deployment) and a more efficient cryptographic core. We describe the design of Sancus 2.0 (without relying on any prior knowledge of Sancus) and develop and evaluate a prototype FPGA implementation. The prototype extends an MSP430 processor with hardware support for the memory access control and cryptographic functionality required to run Sancus. We report on our experience using Sancus in a variety of application scenarios and discuss some important avenues of ongoing and future work. Job Noorman, Jo Van Bulck, Jan Tobias Mühlberg, Frank Piessens, Pieter Maene, Bart Preneel, Ingrid Verbauwhede, Johannes Götzfried, Tilo Müller, Felix C. Freiling |
ACM Trans. Priv. Secur. | 10 |
| 2016 | Towards Cycle-Accurate Emulation of Cortex-M Code to Detect Timing Side ChannelsabstractLeakage of information through timing side channels is a problem for all sorts of computing machinery, but the impact of such channels is especially dramatic on embedded systems. The reason for this is that these environments allow attackers to exploit small timing differences down to clock cycle accuracy. On the defensive side it is therefore advisable to evaluate cautiously if security-critical code contains data dependent timing discrepancies. When working with real hardware, testing for such vulnerabilities is a tedious process. In order to reduce the burden of vetting, we study approaches that allow cycle-accurate behavioral emulation of relevant CPU behavior such as instruction pipeline flushes and bus contention. We show that our approach is feasible and efficient by implementing an emulator of the popular ARM Cortex-M core. Then we give an overview about the problems of cycle-accurate emulation and demonstrate our approach towards a cycle-accurate ARM Thumb-2 simulator. Finally, we show how this simulator can be integrated into the build process of firmware to check for the presence of timing side channels before the system is deployed. Johannes Bauer 0004, Felix C. Freiling |
ARES | 2 |
| 2016 | Design-Time/Run-Time Mapping of Security-Critical Applications in Heterogeneous MPSoCsabstractDifferent applications concurrently running on modern MPSoCs can interfere with each other when they use shared resources. This interference can cause side channels, i.e., sources of unintended information flow between applications. To prevent such side channels, we propose a hybrid mapping methodology that attempts to ensure spatial isolation, i.e., a mutually-exclusive allocation of resources to applications in the MPSoC. At design time and as a first step, we compute compact and connected application mappings (called shapes). In a second step, run-time management uses this information to map multiple spatially segregated shapes to the architecture. We present and evaluate a (fast) heuristic and an (exact) SAT-based mapper, demonstrating the viability of the approach. Andreas Weichslgartner, Stefan Wildermann, Johannes Götzfried, Felix C. Freiling, Michael Glaß, Jürgen Teich |
SCOPES | 4 |
| 2016 | Fingerprinting Mobile Devices Using Personalized ConfigurationsabstractAbstract Recently, Apple removed access to various device hardware identifiers that were frequently misused by iOS third-party apps to track users. We are, therefore, now studying the extent to which users of smartphones can still be uniquely identified simply through their personalized device configurations. Using Apple’s iOS as an example, we show how a device fingerprint can be computed using 29 different configuration features. These features can be queried from arbitrary thirdparty apps via the official SDK. Experimental evaluations based on almost 13,000 fingerprints from approximately 8,000 different real-world devices show that (1) all fingerprints are unique and distinguishable; and (2) utilizing a supervised learning approach allows returning users or their devices to be recognized with a total accuracy of 97% over time Andreas Kurtz 0001, Hugo Gascon, Tobias Becker, Konrad Rieck, Felix C. Freiling |
Proc. Priv. Enhancing Technol. | 5 |
| 2015 | Soteria: Offline Software Protection within Low-cost Embedded DevicesabstractProtecting the intellectual property of software that is distributed to third-party devices which are not under full control of the software author is difficult to achieve on commodity hardware today. Modern techniques of reverse engineering such as static and dynamic program analysis with system privileges are increasingly powerful, and despite possibilities of encryption, software eventually needs to be processed in clear by the CPU. To anyhow be able to protect software on these devices, a small part of the hardware must be considered trusted. In the past, general purpose trusted computing bases added to desktop computers resulted in costly and rather heavyweight solutions. In contrast, we present Soteria, a lightweight solution for low-cost embedded systems. At its heart, Soteria is a program-counter based memory access control extension for the TI MSP430 microprocessor. Based on our open implementation of Soteria as an openMSP430 extension, and our FPGA-based evaluation, we show that the proposed solution has a minimal performance, size and cost overhead while effectively protecting the confidentiality and integrity of an application's code against all kinds of software attacks including attacks from the system level. Johannes Götzfried, Tilo Müller, Ruan de Clercq, Pieter Maene, Felix C. Freiling, Ingrid Verbauwhede |
ACSAC | 5 |
| 2015 | Secure garbage collection: Preventing malicious data harvesting from deallocated Java objects inside the Dalvik VM
Maxim Anikeev, Felix C. Freiling, Johannes Götzfried, Tilo Müller |
J. Inf. Secur. Appl. | 2 |
| 2015 | A Systematic Assessment of the Security of Full Disk EncryptionabstractOrganizations as well as private users frequently report the loss and theft of mobile devices such as laptops and smartphones. The threat of data exposure in such scenarios can be mitigated by protection mechanisms based on encryption. Full disk encryption (FDE) is an effective method to protect data against unauthorized access. FDE can generally be classified into software- and hardware-based solutions. We assess the practical security that users can expect from these FDE solutions regarding physical access threats. We assume that strong cryptography like AES cannot be broken but focus on vulnerabilities arising from practical FDE implementations. We present the results of a comprehensive and systematic comparison of the security of software- and hardware-based FDE. Thereby, we exhibit attacks on widespread FDE standards in many common scenarios and different system configurations. As a result, we show that neither software- nor hardware-based FDE provides perfect security, nor is one clearly superior to the other. Tilo Müller, Felix C. Freiling |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2014 | An Empirical Evaluation of Software Obfuscation Techniques Applied to Android APKs
Felix C. Freiling, Mykolai Protsenko |
SecureComm (2) | 1 |
| 2013 | Preventing malicious data harvesting from deallocated memory areasabstractThe possibility of unauthorized data exposure caused by memory deallocation flaws in various software products has been accentuated by some IT-security experts several years ago [1, 2, 3, 4]. However, no feasible and universal strategies have been proposed so far to reduce that risk. In this paper we discuss possible approaches to reducing the chances of undesirable exposure of sensible information caused by unreasonably long data lifetime in main memory. We offer several directions of how current development platforms and runtime environments could be improved to minimize the lifetime of confidential data on the software design stage. Maxim Anikeev, Felix C. Freiling |
SIN | 2 |
| 2012 | TreVisor - OS-Independent Software-Based Full Disk Encryption Secure against Main Memory Attacks
Tilo Müller, Benjamin Taubmann, Felix C. Freiling |
ACNS | 3 |
| 2012 | Using memory management to detect and extract illegitimate code for malware analysisabstractExploits that successfully attack computers are typically based on some form of shellcode, i.e., illegitimate code that is injected by the attacker to take control of the system. Detecting and gathering such code is the first step to its detailed analysis. The amount and sophistication of modern malware calls for automated mechanisms that perform such detection and extraction. Carsten Willems, Felix C. Freiling, Thorsten Holz |
ACSAC | 2 |
| 2012 | Comparing Sources of Location Data from Android Smartphones
Michael Spreitzenbarth, Sven Schmitt, Felix C. Freiling |
IFIP Int. Conf. Digital Forensics | 3 |
| 2012 | Secure Failure Detection and Consensus in TrustedPalsabstractWe present a modular redesign of TrustedPals, a smart card-based security framework for solving Secure Multiparty Computation (SMC). Originally, TrustedPals assumed a synchronous network setting and allowed to reduce SMC to the problem of fault-tolerant consensus among smart cards. We explore how to make TrustedPals applicable in environments with less synchrony and show how it can be used to solve asynchronous SMC. Within the redesign we investigate the problem of solving consensus in a general omission failure model augmented with failure detectors. To this end, we give novel definitions of both consensus and the class \diamond {\cal P} of failure detectors in the omission model, which we call \diamond {\cal P}({ om}), and show how to implement \diamond {\cal P}({ om}) and have consensus in such a system with very weak synchrony assumptions. The integration of failure detection and consensus into the TrustedPals framework uses tools from privacy enhancing techniques such as message padding and dummy traffic. Roberto Cortiñas, Felix C. Freiling, Marjan Ghajar-Azadanlou, Alberto Lafuente, Mikel Larrea, Lucia Draque Penso, Iratxe Soraluze Arriola |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2011 | Evaluating the Forensic Image Generator Generator
Christian Moch, Felix C. Freiling |
ICDF2C | 2 |
| 2011 | A Case Study in Practical Security of Cable Networks
Amir Alsbih, Felix C. Freiling, Christian Schindelhauer |
SEC | 2 |
| 2011 | Detecting Hidden Storage Side Channel Vulnerabilities in Networked Applications
Felix C. Freiling, Sebastian Schinzel |
SEC | 1 |
| 2011 | Mobile Security Catching Up? Revealing the Nuts and Bolts of the Security of Mobile DevicesabstractWe are currently moving from the Internet society to a mobile society where more and more access to information is done by previously dumb phones. For example, the number of mobile phones using a full blown OS has risen to nearly200% from Q3/2009 to Q3/2010. As a result, mobile security is no longer immanent, but imperative. This survey paper provides a concise overview of mobile network security, attack vectors using the back end system and the web browser, but also the hardware layer and the user as attack enabler. We show differences and similarities between "normal" security and mobile security, and draw conclusions for further research opportunities in this area. Michael Becher, Felix C. Freiling, Thorsten Holz, Sebastian Uellenbeck, Christopher Wolf |
IEEE Symposium on Security and Privacy | 2 |
| 2011 | TrumanBox: Improving Dynamic Malware Analysis by Emulating the Internet
Christian Gorecki, Felix C. Freiling, Marc Kührer, Thorsten Holz |
SSS | 2 |
| 2011 | TRESOR Runs Encryption Securely Outside RAM
Tilo Müller, Felix C. Freiling, Andreas Dewald |
USENIX Security Symposium | 2 |
| 2011 | Communication-efficient failure detection and consensus in omission environments
Iratxe Soraluze Arriola, Roberto Cortiñas, Alberto Lafuente, Mikel Larrea, Felix C. Freiling |
Inf. Process. Lett. | 5 |
| 2010 | A structured approach to anomaly detection for in-vehicle networksabstractThe complexity and connectivity of modern vehicles has constantly increased over the past years. Within the scope of this development the security risk for the in-vehicle network and its components has risen massively. Apart from threats for comfort and confidentiality, these attacks can also affect safety critical systems of the vehicle and therefore endanger the driver and other road users. In this paper the introduction of anomaly detection systems to the automotive in-vehicle network is discussed. Based on properties of typical vehicular networks, like the Controller Area Network (CAN), a set of anomaly detection sensors is introduced which allow the recognition of attacks during the operation of the vehicle without causing false positives. Moreover, important design and application criteria for a vehicular attack detection system are explained and discussed. Michael Müter, André Groll, Felix C. Freiling |
IAS | 3 |
| 2009 | Learning More about the Underground Economy: A Case-Study of Keyloggers and Dropzones
Thorsten Holz, Markus Engelberth, Felix C. Freiling |
ESORICS | 3 |
| 2009 | Cooperative Intrusion Detection in Wireless Sensor Networks
Ioannis Krontiris, Zinaida Benenson, Thanassis Giannetsos, Felix C. Freiling, Tassos Dimitriou |
EWSN | 4 |
| 2009 | Message-efficient omission-tolerant consensus with limited synchronyabstractWe study the problem of consensus in the general omission failure model, i.e., in systems where processes can crash and omit messages while sending or receiving. This failure model is motivated from a smart card-based security framework in which certain security problems can be reduced to consensus in that model. We propose an algorithm that solves consensus based on very weak timing assumptions. More precisely, we show that consensus is solvable using an eventual bisource and a majority of fault-free processes. An eventual bisource is a fault-free process that can eventually communicate with all other processes in a timely manner. In contrast to previous work, we use timing assumptions directly in the algorithm and do not employ the notion of a failure detector. We argue that this is helpful in reducing the message complexity, a critical aspect of algorithms which run on smart cards. Carole Delporte-Gallet, Hugues Fauconnier, Andreas Tielmann, Felix C. Freiling, Mahir Kilic |
IPDPS | 4 |
| 2009 | Modular Consensus Algorithms for the Crash-Recovery ModelabstractIn the crash-recovery failure model of asynchronous distributed systems, processes can temporarily stop to execute steps and later restart their computation from a predefined local state. The crash-recovery model is much more realistic than the crash-stop failure model in which processes merely are allowed to stop executing steps. The additional complexity is reflected in the multitude of assumptions and the technical complexity of algorithms which have been developed for that model. We focus on the problem of consensus in the crash-recovery model, but instead of developing completely new algorithms from scratch, our approach aims at re-using existing crash-stop consensus algorithms in a modular way using the abstraction of failure detectors. As a result, we present three new consensus algorithms for the crash-recovery model for different types of assumptions. Felix C. Freiling, Christian Lambertz, Mila E. Majster-Cederbaum |
PDCAT | 1 |
| 2009 | Return-Oriented Rootkits: Bypassing Kernel Code Integrity Protection Mechanisms
Ralf Hund, Thorsten Holz, Felix C. Freiling |
USENIX Security Symposium | 3 |
| 2009 | Visual analysis of malware behavior using treemaps and thread graphsabstractWe study techniques to visualize the behavior of malicious software (malware). Our aim is to help human analysts to quickly assess and classify the nature of a new malware sample. Our techniques are based on a parametrized abstraction of detailed behavioral reports automatically generated by sandbox environments. We then explore two visualization techniques: treemaps and thread graphs. We argue that both techniques can effectively support a human analyst (a) in detecting maliciousness of software, and (b) in classifying malicious behavior. Philipp Trinius, Thorsten Holz, Jan Göbel, Felix C. Freiling |
VizSEC | 4 |
| 2009 | Safe termination detection in an asynchronous distributed system when processes may crash and recover
Neeraj Mittal, Kuppahalli L. Phaneesh, Felix C. Freiling |
Theor. Comput. Sci. | 3 |
| 2008 | Measuring and Detecting Fast-Flux Service Networks
Thorsten Holz, Christian Gorecki, Konrad Rieck, Felix C. Freiling |
NDSS | 4 |
| 2008 | Easy Consensus Algorithms for the Crash-Recovery Model
Felix C. Freiling, Christian Lambertz, Mila E. Majster-Cederbaum |
DISC | 1 |
| 2008 | On termination detection in crash-prone distributed systems with failure detectors
Neeraj Mittal, Felix C. Freiling, S. Venkatesan 0001, Lucia Draque Penso |
J. Parallel Distributed Comput. | 2 |
| 2007 | On Detecting Termination in the Crash-Recovery Model
Felix C. Freiling, Matthias Majuntke, Neeraj Mittal |
Euro-Par | 1 |
| 2007 | Advanced Evasive Data Storage in Sensor NetworksabstractIn case the data which is stored and processed in a sensor network has some value, it needs to be protected from unauthorized access through a security mechanism. The idea of evasive data storage is that data moves around the sensor network instead of remaining at a fixed location. In this way, an adversary, who has once (through node capture) had access to the data stored at some particular node, must compromise more sensors in order to maintain his illegitimate access to the sensor data. We refine the previously published simple evasive data storage techniques in two ways: (1) we improve the efficiency of data retrieval by bounding the area in which data may move, (2) we introduce data splitting as a technique to protect against sleeper attacks in which the adversary simply takes over a subset of nodes and waits for valuable data to pass by. We demonstrate the effectiveness of our approach using extensive simulations. Zinaida Benenson, Felix C. Freiling, Peter M. Cholewinski |
MDM | 2 |
| 2007 | Secure Failure Detection in TrustedPals
Roberto Cortiñas, Felix C. Freiling, Marjan Ghajar-Azadanlou, Alberto Lafuente, Mikel Larrea, Lucia Draque Penso, Iratxe Soraluze Arriola |
SSS | 2 |
| 2007 | Global Predicate Detection in Distributed Systems with Small Faults
Felix C. Freiling, Arshad Jhumka |
SSS | 1 |
| 2007 | From Crash-Stop to Permanent Omission: Automatic Transformation and Weakest Failure Detectors
Carole Delporte-Gallet, Hugues Fauconnier, Felix C. Freiling, Lucia Draque Penso, Andreas Tielmann |
DISC | 3 |
| 2006 | TrustedPals: Secure Multiparty Computation Implemented with Smart Cards
Milan Fort, Felix C. Freiling, Lucia Draque Penso, Zinaida Benenson, Dogan Kesdogan |
ESORICS | 2 |
| 2006 | Safe Termination Detection in an Asynchronous Distributed System When Processes May Crash and Recover
Neeraj Mittal, Kuppahalli L. Phaneesh, Felix C. Freiling |
OPODIS | 3 |
| 2006 | The Nepenthes Platform: An Efficient Approach to Collect Malware
Paul Baecher, Markus Koetter, Thorsten Holz, Maximillian Dornseif, Felix C. Freiling |
RAID | 5 |
| 2006 | Authenticated Query Flooding in Sensor NetworksabstractWe propose a novel mechanism for authentication of queries in a sensor network in case these queries are flooded. In our protocol, the base station appends an authenticator to every query, such that each sensor can verify with certain probability that the query is sent by the base station. Implicit cooperation between sensor nodes during the flooding process ensures that legitimate queries propagate quickly in the network, whereas the propagation of illegitimate queries is limited to only a small part of the network. Zinaida Benenson, Felix C. Freiling, Ernest Hammerschmidt, Stefan Lucks, Lexi Pimenidis |
SEC | 2 |
| 2006 | Solving Consensus Using Structural Failure ModelsabstractFailure models characterise the expected component failures in fault-tolerant computing. In the context of distributed systems, a failure model usually consists of two parts: a functional part specifying in what way individual processing entities may fail and a structural part specifying the potential scope of failures within the system. Such models must be expressive enough to cover all relevant practical situations, but must also be simple enough to allow uncomplicated reasoning about fault-tolerant algorithms. Usually, an increase in expressiveness complicates formal reasoning, but enables more accurate models that allow to improve the assumption coverage and resilience of solutions. In this paper, we introduce the structural failure model class DiDep that allows to specify directed dependent failures, which, for example, occur in the area of intrusion tolerance and security. DiDep is a generalisation of previous classes for undirected dependent failures, namely the general adversary structures, the fail-prone systems, and the core and survivor sets, which we show to be equivalent. We show that the increase in expressiveness of DiDep does not significantly penalise the simplicity of corresponding models by giving an algorithm that transforms any consensus algorithm for undirected dependent failures into a consensus algorithm for a DiDep model. We characterise the improved resilience obtained with DiDep and show that certain models even allow to circumvent the famous FLP impossibility result Timo Warns, Felix C. Freiling, Wilhelm Hasselbring |
SRDS | 2 |
| 2006 | Brief Announcement: Termination Detection in an Asynchronous Distributed System with Crash-Recovery Failures
Felix C. Freiling, Matthias Majuntke, Neeraj Mittal |
SSS | 1 |
| 2005 | Botnet Tracking: Exploring a Root-Cause Methodology to Prevent Distributed Denial-of-Service Attacks
Felix C. Freiling, Thorsten Holz, Georg Wicherski |
ESORICS | 1 |
| 2005 | Topic 8 - Distributed Systems and Algorithms
Marc Shapiro 0001, Idit Keidar, Felix C. Freiling, Luís E. T. Rodrigues |
Euro-Par | 3 |
| 2005 | Revisiting Failure Detection and Consensus in Omission Failure Environments
Carole Delporte-Gallet, Hugues Fauconnier, Felix C. Freiling |
ICTAC | 3 |
| 2005 | Optimal Randomized Fair Exchange with Secret Shared Coins
Felix C. Freiling, Maurice Herlihy, Lucia Draque Penso |
OPODIS | 1 |
| 2005 | Efficient Reduction for Wait-Free Termination Detection in a Crash-Prone Distributed System
Neeraj Mittal, Felix C. Freiling, S. Venkatesan 0001, Lucia Draque Penso |
DISC | 2 |
| 2003 | PoDSy 2003: Principles of Dependable Systems
Felix C. Freiling, Klaus Kursawe, Levente Buttyán |
DSN | 1 |
| 2003 | Supporting Mobility in Content-Based Publish/Subscribe Middleware
Ludger Fiege, Felix C. Freiling, Oliver Kasten, Andreas Zeidler |
Middleware | 2 |
| 2003 | Fair ExchangeabstractThe growing importance of electronic commerce and the increasing number of applications in this area has led research into studying methods of how to perform safe and secure online business transactions over the Internet. A central problem in this context is that of fair exchange, i.e. how to exchange two electronic items in a fair manner. We give a general introduction into the research area of fair exchange and discuss several formalizations of fairness. We find that although a considerable number of fair exchange protocols exist, they usually have been defined for special scenarios and thus only work under particular assumptions. Furthermore, these protocols provide different degrees of fairness and cause different communication overhead. To alleviate this, we present a generalizing framework defining a suite of protocol modules which allows us to implement different fair exchange protocols. Depending on the properties of the exchanged items an appropriate fair exchange protocol can be selected and applied. Our study is accompanied by a comprehensive survey of the relevant literature. Henning Pagnia, Holger Vogt, Felix C. Freiling |
Comput. J. | 3 |
| 2003 | Supporting Fair Exchange in Mobile Environments
Holger Vogt, Felix C. Freiling, Henning Pagnia |
Mob. Networks Appl. | 2 |
| 2002 | Failure Detection Sequencers: Necessary and Sufficient Information about Failures to Solve Predicate Detection
Felix C. Freiling, Stefan Pleisch |
DISC | 1 |
| 2000 | Consistent Detection of Global Predicates under a Weak Fault AssumptionabstractWe study the problem of detecting general global predicates in distributed systems where all application processes and at most t Felix C. Freiling, Sven Kloppenburg |
SRDS | 1 |
| 2000 | A case study in the mechanical verification of fault toleranceabstractTo date, there is little evidence that modular reasoning about fault-tolerant systems can simplify the verification process in practice. This question is studied using a prominent example from the fault tolerance literature: the problem of reliable broadcast in point-to-point networks subject to crash failures of processes. The experiences from this case study show how modular specification techniques and rigorous proof re-use can indeed help in such undertakings. Heiko Mantel, Felix C. Freiling |
J. Exp. Theor. Artif. Intell. | 2 |
| 1999 | Modular Fair Exchange Protocols for Electronic CommerceabstractRecently, research has focused on enabling fair exchange between payment and electronically shipped items. The reason for this is the growing importance of electronic commerce and the increasing number of applications in this area. Although a considerable number of fair exchange protocols exist, they usually have been defined for special scenarios and thus only work under particular assumptions. Furthermore, these protocols provide different degrees of fairness and cause different communication overhead. The purpose of the paper is to present a unifying solution to the problem. We do this by defining a suite of protocol modules which allow us to compose protocols where the achieved degree of fairness can be enhanced step by step. The advantage of the stepwise approach is that after each step one can decide if the provided degree of fairness is acceptable or if one is willing to spend more in order to reach a higher degree of fairness. We show the applicability of our approach by deriving a novel efficient fair exchange protocol. Holger Vogt, Henning Pagnia, Felix C. Freiling |
ACSAC | 3 |
| 1999 | Approaching a Formal Definition of Fairness in Electronic CommerceabstractThe notion of fairness is a very general concept and can be used to coin terms in many different application areas. Recently the term fairness has appeared in the context of electronic commerce. Here, the term fair exchange refers to the problem that two parties want to swap some distinct items in a way which ensures that no participant can gain advantage over the other. Many protocols for fair exchange have been proposed but comparing or formally verifying them has remained rather difficult. The reason for this is that the notion of fairness they use is often different, and exact (i.e., formal) fairness definitions do not exist. We make a first attempt to approach a formal definition of fairness in electronic commerce. We do this by reviewing the established terminology regarding the notion of fairness in concurrency theory and adapting the formal apparatus to derive three precisely separable definitions of fairness in electronic commerce which we call strong, eventually strong and weak fairness. Felix C. Freiling, Henning Pagnia, Holger Vogt |
SRDS | 1 |