Hannes Federrath

dblp:f/HannesFederrath · DBLP profile ↗
← Back
53ranked-venue papers
2as first author
18since 2021 · last 2024
0009-0000-4595-3604ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 44 · 2 first-author · 15 since 2021Computer networks · 4 · 2 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
YearPublicationVenuePosition
2024 SOVEREIGN - Towards a Holistic Approach to Critical Infrastructure Protection
abstract
In the digital age, cyber-threats are a growing concern for individuals, businesses, and governments alike. These threats can range from data breaches and identity theft to large-scale attacks on critical infrastructure. The consequences of such attacks can be severe, leading to financial losses, threats to national security, and the loss of lives. This paper presents a holistic approach to increase the security of critical infrastructures. For that, we propose an open, self-configurable, and AI-based automated cyber-defense platform that runs on specifically hardened devices and own hardware, can be deeply embedded in critical infrastructures and provides full visibility on network, endpoints, and software. In this paper, starting from a thorough analysis of related work, we describe the vision of our SOVEREIGN platform in the form of an architecture, discuss individual building blocks, and evaluate it qualitatively with respect to our requirements.
Georg T. Becker, Thomas Eisenbarth 0001, Hannes Federrath, Mathias Fischer 0001, Nils Loose, Simon Ott, Joana Pecholt, Stephan Marwedel, Dominik Meyer, Jan Stijohann, Anum Talpur, Matthias Vallentin
ARES3
2024 Reduce to the MACs - Privacy Friendly Generic Probe Requests
Johanna Ansohn McDougall, Alessandro Brighente, Anne Kunstmann, Niklas Zapatka, Hannes Federrath
SEC5
2024 Property Inference as a Regression Problem: Attacks and Defense
Joshua Stock, Lucas Lange, Erhard Rahm, Hannes Federrath
SECRYPT4
2024 You Are as You Type: Investigating the Influence of Timestamp Accuracy on the Robustness of Keystroke Biometrics
abstract
Keystroke dynamics are behavioral biometric traits that are frequently proposed to be used in novel authentication systems. Keystroke dynamics are based on the analysis of intervals between keystroke events originating from user input and thus directly depend on available timing information. However, modern web browsers limit the accuracy of timestamps to improve security and privacy. This study systematically investigates the impact of limited timestamp accuracies on the performance of keystroke dynamic analysis. By conducting multiple experiments with popular web browsers, we demonstrate that the minor timestamp modifications that mitigate timing side-channel attacks do not interfere with the effectiveness of keystroke dynamics analysis algorithms. Furthermore, they are surprisingly resilient to larger timestamp modifications, which results in a serious threat to users’ privacy. This research provides fundamental knowledge enabling researchers, privacy engineers, and browser vendors to study risks in keystroke dynamics-related systems and to develop mitigations against tracking methods that fingerprint users instead of devices or browsers.
Florian Dehling, Luigi Lo Iacono, Hannes Federrath
TrustCom4
2024 Internet Users' Willingness to Disclose Biometric Data for Continuous Online Account Protection: An Empirical Investigation
abstract
Continuous authentication has emerged as a promising approach to increase user account security for online services. Unlike traditional authentication methods, continuous authentication provides ongoing security throughout the session, protecting against session takeover attacks due to illegitimate access. The effectiveness of continuous authentication systems relies on the continuous processing of users' sensitive biometric data. To balance security and privacy trade-offs, it's crucial to understand when users are willing to disclose biometric data for enhanced account security, addressing inevitable privacy concerns and user acceptance. To address this knowledge gap, we conducted an online study with 830 participants from the U.S., aiming to investigate user perceptions towards continuous authentication across different classes of online services. Our analysis identified four groups of biometric traits that directly reflect users' willingness to disclose them. Our findings demonstrate that willingness to disclose is influenced by both the specific biometric traits and the type of online service involved. User perceptions are strongly shaped by factors such as response efficacy, perceived privacy risks associated with the biometric traits, and concerns about the service providers' handling of such data. Our results emphasize the inadequacy of one-size-fits-all solutions and provide valuable insights for the design and implementation of continuous authentication systems.
Florian Dehling, Jan Tolsdorf, Hannes Federrath, Luigi Lo Iacono
Proc. Priv. Enhancing Technol.3
2023 LoVe is in the Air - Location Verification of ADS-B Signals using Distributed Public Sensors
abstract
The Automatic Dependant Surveillance-Broadcast (ADS-B) message scheme was designed without any authentication or encryption of messages in place. It is therefore easily possible to attack it, e.g., by injecting spoofed messages or modifying the transmitted Global Navigation Satellite System (GNSS) coordinates. In order to verify the integrity of the received information, various methods have been suggested, such as multilateration, the use of Kalman filters, group certification, and many others. However, solutions based on modifications of the standard may be difficult and too slow to be implemented due to legal and regulatory issues. A vantage far less explored is the location verification using public sensor data. In this paper, we propose LoVe, a lightweight message verification approach that uses a geospatial indexing scheme to evaluate the trustworthiness of publicly deployed sensors and the ADS-B messages they receive. With LoVe, new messages can be evaluated with respect to the plausibility of their reported coordinates in a location privacy-preserving manner, while using a datadriven and lightweight approach. By testing our approach on two open datasets, we show that LoVe achieves very low false positive rates (between 0 and 0.001 06) and very low false negative rates (between 0.000 65 and 0.003 34) while providing a real-time compatible approach that scales well even with a large sensor set. Compared to currently existing approaches, LoVe neither requires a large number of sensors, nor for messages to be recorded by as many sensors as possible simultaneously in order to verify location claims. Furthermore, it can be directly applied to currently deployed systems thus being backward compatible.
Johanna Ansohn McDougall, Alessandro Brighente, Willi Großmann, Ben Ansohn McDougall, Joshua Stock, Hannes Federrath
ICC6
2023 The Applicability of Federated Learning to Official Statistics
Joshua Stock, Oliver Hauke, Julius Weißmann, Hannes Federrath
IDEAL4
2023 SecPassInput: Towards Secure Memory and Password Handling in Web Applications
Pascal Wichmann, August See, Hannes Federrath
SEC3
2023 Lessons Learned: Defending Against Property Inference Attacks
Joshua Stock, Jens Wettlaufer, Daniel Demmler, Hannes Federrath
SECRYPT4
2023 WebAppAuth: An Architecture to Protect from Compromised First-Party Web Servers
Pascal Wichmann, Sam Ansari, Hannes Federrath, Jens Lindemann 0001
SECRYPT3
2022 Web Cryptography API: Prevalence and Possible Developer Mistakes
abstract
In this paper, we analyze mistakes that web developers can make when using the Web Cryptography API. We evaluate the impact of the uncovered mistakes and discuss how they can be prevented. Furthermore, we derive best practices from these mistakes to provide guidance to developers. To assess the relevance of the Web Cryptography API, we empirically evaluate how prevalently it is used by popular web applications on the Internet and in GitHub repositories, finding that only a small proportion of web applications use it. The most widely used operation by far is the generation of cryptographically secure random values, which was not possible in browser-based JavaScript prior to the Web Cryptography API.
Pascal Wichmann, Maximilian Blochberger, Hannes Federrath
ARES3
2022 FileUploadChecker: Detecting and Sanitizing Malicious File Uploads in Web Applications at the Request Level
abstract
Improper handling of file uploads in web applications induces threats to the application and its users. In this paper, we propose FileUploadChecker, a server-side tool to automatically detect potentially malicious file uploads in web applications and reject or sanitize malicious content in files. FileUploadChecker works transparently on the web request level, using the middleware concept of web frameworks. Thus, FileUploadChecker can be deployed without modifications to the code of existing web applications, for example, if it is infeasible for server administrators to maintain patches to the underlying software or if proprietary software cannot be patched.
Pascal Wichmann, Alexander Groddeck, Hannes Federrath
ARES3
2022 Probing for Passwords - Privacy Implications of SSIDs in Probe Requests
Johanna Ansohn McDougall, Christian Burkert, Daniel Demmler, Monina Schwarz, Vincent Hubbe, Hannes Federrath
ACNS6
2022 Data Minimisation Potential for Timestamps in Git: An Empirical Analysis of User Configurations
Christian Burkert, Johanna Ansohn McDougall, Hannes Federrath
SEC3
2022 Evaluation of Circuit Lifetimes in Tor
Kevin Köster, Matthias Marx, Anne Kunstmann, Hannes Federrath
SEC4
2021 Detection of Brute-Force Attacks in End-to-End Encrypted Network Traffic
abstract
Network intrusion detection systems (NIDSs) can detect attacks in network traffic. However, the increasing ratio of encrypted connections on the Internet restricts their ability to observe such attacks. This paper proposes a completely passive method that allows to detect brute-force attacks in encrypted traffic without the need to decrypt it. For that, we propose five novel metrics for attack detection which quantify metadata like packet size or packet timing.
Pascal Wichmann, Matthias Marx, Hannes Federrath, Mathias Fischer 0001
ARES3
2021 Analysing Leakage during VPN Establishment in Public Wi-Fi Networks
abstract
The use of public Wi-Fi networks can reveal sensitive data to both operators and bystanders. A VPN can prevent this. However, a machine that initiates a connection to a VPN server might already leak sensitive data before the VPN tunnel is fully established. Furthermore, it might not be immediately possible to establish a VPN connection if the network requires authentication via a captive portal, thus increasing the leakage potential. In this paper we examine both issues. For that, we analyse the behaviour of native and third-party VPN clients on various platforms, and introduce a new method called selective VPN bypassing to avoid captive portal deadlocks.
Christian Burkert, Johanna Ansohn McDougall, Hannes Federrath, Mathias Fischer 0001
ICC3
2021 Compiling Personal Data and Subject Categories from App Data Models
Christian Burkert, Maximilian Blochberger, Hannes Federrath
SEC3
2020 Enhanced performance for the encrypted web through TLS resumption across hostnames
abstract
TLS can resume previous connections via abbreviated resumption handshakes that decrease the delay and save expensive cryptographic operations by reusing cryptographic TLS state from previous connections. TLS version 1.3 recommends avoiding resumption handshakes, when connecting to a different hostname. In this work, we reassess this recommendation, as we find that sharing cryptographic TLS state across hostnames is a common practice on the web. We propose a TLS extension that allows the server to inform the client about TLS state sharing with other hostnames. This information enables the client to efficiently resume TLS sessions across hostnames. Our evaluation indicates that our TLS extension provides performance gains for the web. For example, about 58.7% of the 20.24 full TLS handshakes that are required to retrieve an average website on the web can be converted to resumed connection establishments which reduces the CPU time consumed for TLS connection establishments by 44%. Furthermore, our TLS extension accelerates the connection establishment with an average website by up to 30.7%. Thus, our proposal significantly reduces the (energy) costs and the delay overhead in the encrypted web.
Erik Sy, Moritz Mönnich, Tobias Mueller, Hannes Federrath, Mathias Fischer 0001
ARES4
2020 Provably Privacy-Preserving Distributed Data Aggregation in Smart Grids
Marius Stübs, Tobias Mueller, Kai Bavendiek, Manuel Lösch, Sibylle Schupp, Hannes Federrath
DBSec6
2020 Enhanced Performance and Privacy for TLS over TCP Fast Open
abstract
Abstract Small TCP flows make up the majority of web flows. For them, the TCP three-way handshake induces significant delay overhead. The TCP Fast Open (TFO) protocol can significantly decrease this delay via zero round-trip time (0-RTT) handshakes for all TCP handshakes that follow a full initial handshake to the same host. However, this comes at the cost of privacy limitations and also has some performance limitations. In this paper, we investigate the TFP deployment on popular websites and browsers. We found that a client revisiting a web site for the first time fails to use an abbreviated TFO handshake in 40% of all cases due to web server load-balancing using multiple IP addresses. Our analysis further reveals significant privacy problems of the protocol design and implementation. Network-based attackers and online trackers can exploit TFO to track the online activities of users. As a countermeasure, we introduce a novel protocol called TCP Fast Open Privacy (FOP). TCP FOP prevents tracking by network attackers and impedes third-party tracking, while still allowing 0-RTT handshakes as in TFO. As a proof-of-concept, we have implemented the proposed protocol for the Linux kernel and a TLS library. Our measurements indicate that TCP FOP outperforms TLS over TFO when websites are served from multiple IP addresses.
Erik Sy, Tobias Mueller, Christian Burkert, Hannes Federrath, Mathias Fischer 0001
Proc. Priv. Enhancing Technol.4
2019 Your Cache Has Fallen: Cache-Poisoned Denial-of-Service Attack
abstract
Web caching enables the reuse of HTTP responses with the aim to reduce the number of requests that reach the origin server, the volume of network traffic resulting from resource requests, and the user-perceived latency of resource access. For these reasons, a cache is a key component in modern distributed systems as it enables applications to scale at large. In addition to optimizing performance metrics, caches promote additional protection against Denial of Service (DoS) attacks. In this paper we introduce and analyze a new class of web cache poisoning attacks. By provoking an error on the origin server that is not detected by the intermediate caching system, the cache gets poisoned with the server-generated error page and instrumented to serve this useless content instead of the intended one, rendering the victim service unavailable. In an extensive study of fifteen web caching solutions we analyzed the negative impact of the CachePoisoned DoS (CPDoS) attack-as we coined it. We show the practical relevance by identifying one proxy cache product and five CDN services that are vulnerable to CPDoS. Amongst them are prominent solutions that in turn cache high-value websites. The consequences are severe as one simple request is sufficient to paralyze a victim website within a large geographical region. The awareness of the newly introduced CPDoS attack is highly valuable for researchers for obtaining a comprehensive understanding of causes and countermeasures as well as practitioners for implementing robust and secure distributed systems.
Hoai Viet Nguyen, Luigi Lo Iacono, Hannes Federrath
CCS3
2019 Context-Aware IPv6 Address Hopping
Matthias Marx, Monina Schwarz, Maximilian Blochberger, Frederik Wille, Hannes Federrath
ICICS5
2019 Accelerating QUIC's Connection Establishment on High-Latency Access Networks
abstract
A significant amount of connection establishments on the web require a prior domain name resolution by the client. Especially on high-latency access networks, these DNS lookups cause a significant delay on the client's connection establishment with a server. To reduce the overhead of QUIC's connection establishment with prior DNS lookup on these networks, we propose a novel QuicSocks proxy. Basically, the client delegates the domain name resolution towards the QuicSocks proxy. Our results indicate, that colocating our proxy with real-world ISP-provided DNS resolvers provides great performance gains. For example, 10% of our 474 sample nodes distributed across ISP's in Germany would save at least 30 ms per QUIC connection establishment. The design of our proposal aims to be readily deployable on the Internet by avoiding IP address spoofing, anticipating Network Address Translators and using the standard DNS and QUIC protocols. In summary, our proposal fosters a faster establishment of QUIC connections for clients on high-latency access networks.
Erik Sy, Tobias Mueller, Moritz Mönnich, Hannes Federrath
IPCCC4
2019 QUICker Connection Establishment with Out-Of-Band Validation Tokens
abstract
QUIC is a secure transport protocol that improves the performance of HTTPS. An initial QUIC handshake that enforces a strict validation of the client's source address requires two round-trips. In this work, we extend QUIC's address validation mechanism by an out-of-band validation token to save one round-trip time during the initial handshake. The proposed token allows sharing an address validation between the QUIC server and trusted entities issuing these tokens. This saves a round-trip time for the address validation. Furthermore, we propose distribution mechanisms for these tokens using DNS resolvers and QUIC connections to other hostnames. Our proposal can save up to 50% of the delay overhead of an initial QUIC handshake. Furthermore, our analytical results indicate that 363.6 ms in total can be saved for all connections required to retrieve an average website, if a round-trip time of 90 ms is assumed.
Erik Sy, Christian Burkert, Tobias Mueller, Hannes Federrath, Mathias Fischer 0001
LCN4
2019 Automatically Proving Purpose Limitation in Software Architectures
Kai Bavendiek, Tobias Mueller, Florian Wittner, Thea Schwaneberg, Christian-Alexander Behrendt, Wolfgang Schulz 0002, Hannes Federrath, Sibylle Schupp
SEC7
2019 A QUIC Look at Web Tracking
abstract
Abstract QUIC has been developed by Google to improve the transport performance of HTTPS traffic. It currently accounts for approx. 7% of the global Internet traffic. In this work, we investigate the feasibility of user tracking via QUIC from the perspective of an online service. Our analysis reveals that the protocol design contains violations of privacy best practices through which a tracker can passively and uniquely identify clients across several connections. This tracking mechanisms can achieve reduced delays and bandwidth requirements compared to conventional browser fingerprinting or HTTP cookies. This allows them to be applied in resource- or time-constrained scenarios such as real-time biddings in online advertising. To validate this finding, we investigated browsers which enable QUIC by default, e.g., Google Chrome. Our results suggest that the analyzed browsers do not provide protective measures against tracking via QUIC. However, the introduced mechanisms reset during a browser restart, which clears the cached connection data and thus limits achievable tracking periods. To mitigate the identified privacy issues, we propose changes to QUIC’s protocol design, the operation of QUIC-enabled web servers, and browser implementations.
Erik Sy, Christian Burkert, Hannes Federrath, Mathias Fischer 0001
Proc. Priv. Enhancing Technol.3
2018 Tracking Users across the Web via TLS Session Resumption
abstract
User tracking on the Internet can come in various forms, e.g., via cookies or by fingerprinting web browsers. A technique that got less attention so far is user tracking based on TLS and specifically based on the TLS session resumption mechanism. To the best of our knowledge, we are the first that investigate the applicability of TLS session resumption for user tracking. For that, we evaluated the configuration of 48 popular browsers and one million of the most popular websites. Moreover, we present a so-called prolongation attack, which allows extending the tracking period beyond the lifetime of the session resumption mechanism. To show that under the observed browser configurations tracking via TLS session resumptions is feasible, we also looked into DNS data to understand the longest consecutive tracking period for a user by a particular website. Our results indicate that with the standard setting of the session resumption lifetime in many current browsers, the average user can be tracked for up to eight days. With a session resumption lifetime of seven days, as recommended upper limit in the draft for TLS version 1.3, 65% of all users in our dataset can be tracked permanently.
Erik Sy, Christian Burkert, Hannes Federrath, Mathias Fischer 0001
ACSAC3
2017 Editorial: 30th IFIP International Information Security Conference (IFIP SEC 2015)
Dominik Herrmann, Hannes Federrath
Comput. Secur.2
2015 The Effects of Cultural Dimensions on the Development of an ISMS Based on the ISO 27001
abstract
The ISO 27001 is the most adopted international information security management standard, by several countries and industries. This paper looks closely to the impacts of cultural characteristics on different phases of developing ISO 27001, based on three levels (country, organisational, and personal), which is especially helpful for Small and Medium Enterprises (SMEs). Cultural dimensions can significantly affect organisational administration and achievements such as decision-making, innovation and new practices, work motivation, negotiation, human resource practices, and leadership. The results are mainly based on a literature review, such as Hofstede and their relationship with the ISO 27001 Annex A. The outcomes of this paper illustrate that national (country level) cultural dimensions have high impact on the success and effectiveness of the ISO 27001 development phases.
Bahareh Shojaie, Hannes Federrath, Iman Saberi
ARES2
2015 Workload modelling for mix-based anonymity services
Karl-Peter Fuchs, Dominik Herrmann, Hannes Federrath
Comput. Secur.3
2015 Laribus: privacy-preserving detection of fake SSL certificates with a social P2P notary network
abstract
In this paper we present Laribus, a peer-to-peer network designed to detect local man-in-the-middle attacks against secure socket layer/transport layer security (SSL/TLS). With Laribus, clients can validate the authenticity of a certificate presented to them by retrieving it from different vantage points on the network. Unlike previous solutions, clients do not have to trust a central notary service nor do they have to rely on the cooperation of website owners. The Laribus network is based on a social network graph, which allows users to form notary groups that improve both privacy and availability. It integrates several well-known techniques, such as secret sharing, ring signatures, layered encryption, range queries, and a distributed hash table (DHT), to achieve privacy-aware queries, scalability, and decentralization. We present the design and core components of Laribus, discuss its security properties, and also provide results from a simulation-based feasibility study.
Karl-Peter Fuchs, Dominik Herrmann, Andrea Micheloni, Hannes Federrath
EURASIP J. Inf. Secur.4
2014 Evaluating the Effectiveness of ISO 27001: 2013 Based on Annex A
abstract
The part of the management system of an organization dealing with information security is called Information Security Management System (ISMS). The most adopted ISMS standard is ISO 27001:2005. The 2005 version of the standard has been updated in 2013 to provide more clarity and more freedom in implementation, based on practical experiences. This paper compares ISO 27001:2005 and the updated 2013 standard, based on Annex A controls. We classify the controls into five categories of data, hardware, software, people and network. All of the controls defined in Annex A, regardless of their objectives, can easily be allocated to at least one of these categories. Classifying the controls to known categories offers an integrated view of the updated standard and presents a suitable guide for evaluating the performance and efficiency of the updated standard.
Bahareh Shojaie, Hannes Federrath, Iman Saberi
ARES2
2014 EncDNS: A Lightweight Privacy-Preserving Name Resolution Service
Dominik Herrmann, Karl-Peter Fuchs, Jens Lindemann 0001, Hannes Federrath
ESORICS (1)4
2014 Evaluating the Security of a DNS Query Obfuscation Scheme for Private Web Surfing
Dominik Herrmann, Max Maaß, Hannes Federrath
SEC3
2014 PADAVAN: Privacy-Aware Data Accumulation for Vehicular Ad-hoc Networks
abstract
In this paper we introduce PADAVAN, a novel anonymous data collection scheme for Vehicular Ad Hoc Networks (VANETs). PADAVAN allows users to submit data anonymously to a data consumer while preventing adversaries from submitting large amounts of bogus data. PADAVAN is comprised of an n-times anonymous authentication scheme, mix cascades and various principles to protect the privacy of the submitted data itself. Furthermore, we evaluate the effectiveness of limiting an adversary to a fixed amount of messages.
Andreas Tomandl, Dominik Herrmann, Hannes Federrath
WiMob3
2013 Laribus: Privacy-Preserving Detection of Fake SSL Certificates with a Social P2P Notary Network
abstract
In this paper we present Laribus, a peer-to-peer network designed to detect local man-in-the-middle attacks against SSL/TLS. With Laribus clients can validate the authenticity of a certificate presented to them by retrieving it from different vantage points on the network. Unlike previous solutions, clients do not have to trust a central notary service, nor do they have to rely on the cooperation of website owners. The Laribus network is based on a Social Network graph, which allows users to form Notary Groups that improve both privacy and availability. It integrates several well-known techniques, such as secret sharing, ring signatures, layered encryption, range queries and a Distributed Hash Table (DHT), to achieve privacy-aware queries, scalability and decentralization. We present the design and core components of Laribus, discuss its security properties and also provide results from a simulation-based feasibility study.
Andrea Micheloni, Karl-Peter Fuchs, Dominik Herrmann, Hannes Federrath
ARES4
2013 Generating Realistic Application Workloads for Mix-Based Systems for Controllable, Repeatable and Usable Experimentation
Karl-Peter Fuchs, Dominik Herrmann, Hannes Federrath
SEC3
2013 Behavior-based tracking: Exploiting characteristic patterns in DNS traffic
Dominik Herrmann, Christian Banse, Hannes Federrath
Comput. Secur.3
2012 Introducing the gMix Open Source Framework for Mix Implementations
Karl-Peter Fuchs, Dominik Herrmann, Hannes Federrath
ESORICS3
2012 Tracking Users on the Internet with Behavioral Patterns: Evaluation of Its Practical Feasibility
Christian Banse, Dominik Herrmann, Hannes Federrath
SEC3
2012 Simulation-based evaluation of techniques for privacy protection in VANETs
abstract
In vehicular ad hoc networks (VANETs) tracking of participants is an issue that is examined by many research groups. These groups came up with several different concepts of counter measures against tracking attacks. All of these presented techniques seem to offer a pretty good protection. We pick out two very promising concepts - the Mix Zones and the Silent Periods - to examine them in a simulation environment to actually identify their strengths and weaknesses. Our simulation results show rather high success rates for attackers with relatively unsophisticated attack heuristics. Furthermore we confirm the correlation between several influencing factors and the success rates of attacks and study the connection to the common metrics k-anonymity and entropy.
Andreas Tomandl, Florian Scheuer, Hannes Federrath
WiMob3
2011 Privacy-Preserving DNS: Analysis of Broadcast, Range Queries and Mix-Based Protection Methods
Hannes Federrath, Karl-Peter Fuchs, Dominik Herrmann, Christopher Piosecny
ESORICS1
2011 A Safety-Preserving Mix Zone for VANETs
Florian Scheuer, Karl-Peter Fuchs, Hannes Federrath
TrustBus3
2010 A privacy-aware location service for VANETs using Chaum's mixes
abstract
Protecting the privacy of VANET users is an important issue. We present in this paper an architecture that aims at this goal by integrating Chaum's mix network into a distributed but infrastructure-based location service for position-based routing. In addition we enable the user to decide when he wants to reveal his position to anyone else. Thus neither entity of the VANET is in full knowledge about the location and the identity of any user at the same time. The proposed system can be integrated in most published VANET security frameworks and our evaluation shows that an implementation is feasible.
Florian Scheuer, Matthias Brecht, Hannes Federrath
WiMob3
2009 A Privacy-Preserving Platform for User-Centric Quantitative Benchmarking
Dominik Herrmann, Florian Scheuer, Philipp Feustel, Thomas Nowey, Hannes Federrath
TrustBus5
2008 Preventing Profile Generation in Vehicular Networks
abstract
VANETs have the potential to dramatically increase road safety by giving drivers more time to react adequately to dangerous situations. To prevent abuse of VANETs, a security infrastructure is needed that ensures security requirements like message integrity, confidentiality, and availability. After giving more details on our security infrastructure we discuss privacy issues and especially the problem of profile generation caused by periodically sent telematics data necessary for many road safety functions. The suggested security infrastructure, mix zones and single-use pseudonyms help to ensure privacy of VANET participants and prevent profile generation while preserving functionality.
Florian Scheuer, Klaus Poessel, Hannes Federrath
WiMob3
2007 Collection of Quantitative Data on Security Incidents
abstract
Quantitative data about security threats is a precondition for a precise assessment of security risks and consequently for an efficient management of information security. Currently such data is hardly available, especially for small and medium-sized organizations. In this paper we discuss different ways of gathering quantitative data and present a new approach for the collection of historical data on security incidents. We propose a platform that collects, aggregates and evaluates data on security incidents from multiple organizations. We identify basic requirements for such a platform and show approaches for satisfying them. We especially emphasize the aspects of security and fairness. Finally we introduce a prototype that shows how an implementation could look like
Thomas Nowey, Hannes Federrath
ARES2
2007 Performance Comparison of Low-Latency Anonymisation Services from a User Perspective
Rolf Wendolsky, Dominik Herrmann, Hannes Federrath
Privacy Enhancing Technologies3
2005 Privacy Enhanced Technologies: Methods - Markets - Misuse
Hannes Federrath
TrustBus1
2005 Protection Mechanisms Against Phishing Attacks
Klaus Plößl, Hannes Federrath, Thomas Nowey
TrustBus2
1997 Individual management of personal reachability in mobile communication
Martin Reichenbach, Herbert Damker, Hannes Federrath, Kai Rannenberg
SEC3
1996 Location management strategies increasing privacy in mobile communication
Dogan Kesdogan, Hannes Federrath, Anja Jerichow, Andreas Pfitzmann
SEC2