Michael Meier 0001

dblp:m/MichaelMeier1 · DBLP profile ↗
← Back
30ranked-venue papers
4as first author
8since 2021 · last 2025
0009-0006-8199-5004ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 24 · 4 first-author · 5 since 2021Computer networks · 2Systems, architecture and hardware · 1Software engineering, systems software and programming languages · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
YearPublicationVenuePosition
2025 SoK: Towards Reproducibility for Software Packages in Scripting Language Ecosystems
Timo Pohl, Pavel Novák, Marc Ohm, Michael Meier 0001
ARES (2)4
2025 Exploring the Susceptibility to Fraud of Monetary Incentive Mechanisms for Strengthening FOSS Projects
Ben Swierzy, Timo Pohl, Marc Ohm, Michael Meier 0001
ARES (2)4
2024 Assessing the Impact of Large Language Models on Cybersecurity Education: A Study of ChatGPT's Influence on Student Performance
abstract
The popularity of chatbots to facilitate day-to-day business, including students and their study exercises, is on the rise. This paper investigates the extent and effects on the academic performance of students that leverage such tools. While many other approaches are hypothesized and discussed, we measure empirically. We recorded and compared the performance of cybersecurity students in weekly exercises and final exams over a period of three years. This allows us to have three groups with varying degrees of ChatGPT influence, namely no access, uncontrolled access, and controlled access. In an anonymous survey, we found that approximately 80% of our students utilize ChatGPT during the weekly assignments in 2023. However, none of them indicated this on their submission, despite it being a mandatory requirement. Through statistical analysis of achieved points in our sample groups, we identified that students perform similarly on the weekly assignments. However, their performance on the final examination deteriorates.
Marc Ohm, Christian Bungartz, Felix Boes, Michael Meier 0001
ARES4
2024 SoK: Automated Software Testing for TLS Libraries
abstract
Reusable software components, typically integrated as libraries, are a central paradigm of modern software development. By incorporating a library into their software, developers trust in its quality and its correct and complete implementation. Since errors in a library affect all applications using it, there is a need for quality assurance tools such as automated testing that can be used by library and application developers to verify the functionality. In the past decade, many different systems have been published that focus on the automated analysis of TLS implementations for finding bugs and security vulnerabilities. However, all of these systems focus only on few TLS components and lack a common analysis scenario and inter-approach comparisons. Especially, the amount of manual effort required across the whole analysis process to obtain the root cause of an error is often ignored. In this paper, we survey and categorize literature on automated testing approaches for TLS libraries. The results reveal a heterogeneous landscape of approaches with a trade-off between the manual effort required for setup and for result interpretation, along with major deficits in the considered performance metrics. These imply important future directions to advance the current state of protocol test automation.
Ben Swierzy, Felix Boes, Timo Pohl, Christian Bungartz, Michael Meier 0001
ARES5
2024 Analyzing the Potency of Pretrained Transformer Models for Automated Program Repair
abstract
Manually finding and fixing bugs is cumbersome work, which consumes valuable resources in the software development cycle. In this work, we examine the capability of pretrained transformer models to tackle the task of automated program repair. Previous research has been focused on inherently different machine learning architectures for solving this use case. Our contributions include a novel dataset for fine-tuning the models, the introduction of a windowing technique augmenting the pretrained model and the evaluation on the commonly used Defects4J benchmark along with an ablation study. The findings demonstrate that leveraging our dataset leads to enhanced model performance surpassing Bugs2Fix. Our model enhancements significantly boost overall performance, enabling resulting models to achieve parity with the current state of the art by fixing 30 bugs in 27 minutes on Defects4J. This shows that pretrained transformers are promising for the task of automated bug fixing and should be considered by future research. However, similar to the existing state-of-the-art solutions, the performance still needs be improved to provide practical benefits to end users.
Maximilian Leiwig, Ben Swierzy, Christian Bungartz, Michael Meier 0001
SEAA4
2024 I Know you were here: Leveraging Probe Request Templates for Identifying Wi-Fi Devices
abstract
Identification of Wi-Fi devices through the observation of sent probe requests (PRs) is commonly used for many different use cases. Successful device identification even when MAC address randomization is used poses a risk to privacy but could also assist law enforcement in re-identifying devices of criminals. In this paper, we examine whether MAC de-randomization techniques provide a sufficiently precise way of re-identifying handheld Wi-Fi devices that have previously been observed. In recent research, MAC address de-randomization techniques are adopted for device counting in various use cases. There, distinguishing devices is utilized without the need to specifically identify individual devices or collecting a maximized amount of data. We propose a system that leverages PR finger-printing templates which assist the selection of optimized features for fingerprinting to (re-)identify the target device from an observed anonymity group of devices. This system's performance is evaluated on publicly available as well as newly collected data for modern devices and compared to recently proposed MAC address de-randomization techniques. Using a set of experiments, we demonstrate that modern Wi-Fi devices can be perfectly isolated within the anonymity group of received PRs from nearby modern devices for 75 % of the sampled devices.
Daniel Vogel 0004, Felix Viola, Nicholas Malte Kreimeyer, Michael Meier 0001
WiMob4
2023 Analyzing the Feasibility of Privacy-Respecting Automated Tracking of Devices Fleeing a Burglary
abstract
Criminals bringing their mobile devices to a burglary and subsequently fleeing the crime scene may be tracked and re-identified by digital traces left behind by their devices, e.g., by utilizing WiFi routers listening to their communication. Currently, it is unclear how a sensor network for automated tracking of these fleeing devices should be designed, especially considering a privacy-respecting operation. While various WiFi device tracking techniques are well researched for indoor applications, tracking non-cooperative devices using a sensor network through a town or city is a unique use-case that is yet to be examined. In this paper a tracking simulator is implemented which allows for multiple parameters of both the fleeing device as well as the sensors to be thoroughly tested and its tracking performance based on these parameters to be evaluated. For this, different metrics such as device activity, detection events, and path reconstruction are gathered by running the simulation using different sensor activation strategies with the goal to have as many sensors as needed but as few as possible active. Through this approach, the device tracking success is evaluated while having minimal infringement on the privacy of devices not being involved with the criminal activity.
Ben Swierzy, Markus Krämer, Daniel Vogel 0004, Daniel Meyer, Michael Meier 0001
WiMob5
2022 On the Feasibility of Supervised Machine Learning for the Detection of Malicious Software Packages
abstract
Modern software development heavily relies on a multitude of externally – often also open source – developed components that constitute a so-called Software Supply Chain. Over the last few years a rise of trojanized (i.e., maliciously manipulated) software packages have been observed and addressed in multiple academic publications. A central issue of this is the timely detection of such malicious packages for which typically single heuristic- or machine learning based approaches have been chosen. Especially the general suitability of supervised machine learning is currently not fully covered. In order to gain insight, we analyze a diverse set of commonly employed supervised machine learning techniques, both quantitatively and qualitatively. More precisely, we leverage a labeled dataset of known malicious software packages on which we measure the performance of each technique. This is followed by an in-depth analysis of the three best performing classifiers on unlabeled data, i.e., the whole npm package repository. Our combination of multiple classifiers indicates a good viability of supervised machine learning for the detection of malicious packages by pre-selecting a feasible number of suspicious packages for further manual analysis. This research effort includes the evaluation of over 25,210 different models which led to True Positive Rates of over 70 % and the detection and reporting of 13 previously unknown malicious packages.
Marc Ohm, Felix Boes, Christian Bungartz, Michael Meier 0001
ARES4
2020 Towards detection of software supply chain attacks by forensic artifacts
abstract
Third-party dependencies may introduce security risks to the software supply chain and hence yield harm to their dependent software. There are many known cases of malicious open source packages posing risks to developers and end users. However, while efforts are made to detect vulnerable open source packages, malicious packages are not yet considered explicitly. In order to tackle this problem we perform an exploratory case study on previously occurred attacks on the software supply chain with respect to observable artifacts created. Based on gained insights, we propose Buildwatch, a framework for dynamic analysis of software and its third-party dependencies. We noticed that malicious packages introduce a significant amount of new artifacts during installation when compared to benign versions of the same package. The paper presents a first analysis of observable artifacts of malicious packages as well as a possible mitigation strategy that might lead to more insight in long term.
Marc Ohm, Arnold Sykosch, Michael Meier 0001
ARES3
2020 Generalizing the phishing principle: analyzing user behavior in response to controlled stimuli for IT security awareness assessment
abstract
Capturing behavioral data to assess users' IT security awareness is state of the art. However, recording the click rate on a company wide phishing test for IT security awareness measurement does not suffice. Perceivable artifacts, that the user might be exposed to during an attack, are manifold. We introduce a framework that allows capturing user's responses to such artifacts similar to phishing tests. A field study among 259 users shows, that the expected effect of a well-established IT security awareness intervention can be demonstrated using arbitrary artifacts. It also shows that this intervention may impair the probability of a user reporting the sighting of an artifact and therefore impair an organization's capability to detect such events and possibly decrease overall security.
Arnold Sykosch, Christian Doll, Matthias Wübbeling, Michael Meier 0001
ARES4
2020 An investigation on the feasibility of the bluetooth frequency hopping mechanism for the use as a covert channel technique
abstract
Adaptive Frequency Hopping is a mechanism included in the Bluetooth standard to minimize the effects of interference from other signals sharing the same frequency band. In this paper, several possible strategies of exploiting the frequency hopping mechanism as a covert channel are discussed. There has been some research presenting ways to make use of covert channels over Bluetooth yet none have explored frequency hopping in this context. Three groups of approaches are presented for sending hidden information by means of exploiting specific properties of the frequency hopping mechanism and the generated hopping sequence. These groups consist of strategies to transmit data hidden in protocol packets, modulated on manipulated hopping sequences or by influencing available channels through jamming, thus limiting possible hop frequencies. These approaches are compared by their bandwidth, ease of implementation as well as the detectability of a communication using these covert channels. We show that there are vast unexplored opportunities for covert communication using the adaptive frequency hopping mechanism used by Bluetooth devices.
Daniel Vogel 0004, Ulugbek Akhmedjanov, Marc Ohm, Michael Meier 0001
ARES4
2020 Backstabber's Knife Collection: A Review of Open Source Software Supply Chain Attacks
Marc Ohm, Henrik Plate, Arnold Sykosch, Michael Meier 0001
DIMVA4
2020 Track Down Identity Leaks using Threat Intelligence
abstract
96
Timo Malderle, Sven Knauer, Martin Lang 0007, Matthias Wübbeling, Michael Meier 0001
ICISSP5
2020 Utility Requirement Description for Utility-Preserving and Privacy-Respecting Data Pseudonymization
Saffija Kasem-Madani, Michael Meier 0001
TrustBus2
2019 Automated Pattern Inference Based on Repeatedly Observed Malware Artifacts
abstract
Threat Intelligence comprises the concept of Indicators of Compromise, which are commonly used similar to classical intrusion detection signatures. However, data quality is often of limited quality with regard to this use case. The quality of these Indicators of Compromise can be increased by deriving patterns form repeated observations. A method is introduced which is capable to derive patterns from these observations automatically. Employing automatically derived pattern increases detection quality significantly. Moreover, it lead to the discovery of a previously unfamiliar type of patterns; inter-observable patterns, which capture relationships between patterns. An approach to address them in a fully STIX™ compliant fashion is proposed.
Christian Doll, Arnold Sykosch, Marc Ohm, Michael Meier 0001
ARES4
2018 Hunting Observable Objects for Indication of Compromise
abstract
Shared Threat Intelligence is often imperfect. Especially so called Indicator of Compromise might not be well constructed. This might either be the case if the threat only appeared recently and recordings do not allow for construction of high quality Indicators or the threat is only observed by sharing partners lesser capable to model the threat. However, intrusion detection based on imperfect intelligence yields low quality results. Within this paper we illustrate how one is able to overcome these shortcomings in data quality and is able to achieve solid intrusion detection.
Arnold Sykosch, Marc Ohm, Michael Meier 0001
ARES3
2018 Gathering and analyzing identity leaks for a proactive warning of affected users
abstract
Identity theft is a common consequence of successful cyber-attacks. Criminals steal identity data in order to either (mis)use the data themselves or sell entire identity collections of such data to other parties. Warning the victims of identity theft is crucial to avoid or limit the damage caused by identity misuse. However, in order to provide proactive warnings to victims in a timely fashion, the leaked identity data has to be available. Within this paper we present a methodology to gather and analyze leaked identity data to enable proactive warnings of victims.
Timo Malderle, Matthias Wübbeling, Sven Knauer, Arnold Sykosch, Michael Meier 0001
CF5
2017 Reclaim Your Prefix: Mitigation of Prefix Hijacking Using IPsec Tunnels
abstract
Prefix hijacking is a serious threat in the Internet routing landscape. The Border Gateway Protocol has no origin authentication by design. Countermeasures, e.g. on-top authentication as implemented by R-PKI infrastructures, are not yet deployed on a very large scale. Being victim of prefix hijacking is a difficult situation with few options. Not only the owner of a prefix is victim but all the networks being deceived by the attacker. They are unable to communicate with the owner and corresponding traffic travels into the wrong direction. Current data from the Internet routing plane as collected by RIPE-NCC is examined to detect prefix hijacking. This paper discusses means to manipulate the partitions resulting from prefix hijacking with router inherent functionality. By this means, prefix owners become able to increase their impact and enlarge the corresponding partition, with just one assistant Autonomous System (AS). Selection strategies to find a well suited assistant AS are compared and the top three are verified in an emulation environment. Therefore, an emulation network is created on the dataset that is representative for prefix hijacking in the Internet. The presented approach can be the foundation of a (semi-)automated tool to mitigate prefix hijacking in the future.
Matthias Wübbeling, Michael Meier 0001
LCN2
2016 Covert channel-internal control protocols: attacks and defense
abstract
Abstract Network covert channels have become a sophisticated means for transferring hidden information over the network. Covert channel‐internal control protocols, also called micro protocols, have been introduced in the recent years to enhance capabilities of the network covert channels. Micro protocols are usually placed within the hidden bits of a covert channel's payload and enable features such as reliable data transfer, session management, and dynamic routing for network covert channels. These features provide adaptive and stealthy covert communication channels. Some of the micro protocol based tools exhibit vulnerabilities and are susceptible to attacks. In this paper, we demonstrate some possible attacks on micro protocols, which are capable of breaking the sophisticated covert channel communication or jeopardizing the identity of peers in such a network. These attacks are based on the attacker's interaction with the micro protocol. We also present the defense techniques to safeguard micro protocols against such attacks. By using these techniques, micro protocol‐based tools can become immune to certain attacks and lead to robust covert communication. We present our results for two micro protocol‐based tools: Ping Tunnel and smart covert channel tool. Copyright © 2016 John Wiley & Sons, Ltd.
Steffen Wendzel, Omar Eissa, Jernej Tonejc, Michael Meier 0001
Secur. Commun. Networks5
2015 Countermeasures for Covert Channel-Internal Control Protocols
abstract
Network covert channels have become a sophisticated means for transferring hidden information over the network, and thereby breaking the security policy of a system. Covert channel-internal control protocols, called micro protocols, have been introduced in the recent years to enhance capabilities of network covert channels. Micro protocols are usually placed within the hidden bits of a covert channel's payload and enable features such as reliable data transfer, session management, and dynamic routing for network covert channels. These features provide adaptive and stealthy communication channels for malware, especially bot nets. Although many techniques are available to counter network covert channels, these techniques are insufficient for countering micro protocols. In this paper, we present the first work to categorize and implement possible countermeasures for micro protocols that can ultimately break sophisticated covert channel communication. The key aspect of proposing these countermeasures is based on the interaction with the micro protocol. We implemented the countermeasures for two micro protocol-based tools: Ping Tunnel and Smart Covert Channel Tool. The results show that our techniques are able to counter micro protocols in an effective manner compared to current mechanisms, which do not target micro protocol-specific behavior.
Steffen Wendzel, Michael Meier 0001
ARES3
2015 Securing BACnet's Pitfalls
Jernej Tonejc, Steffen Wendzel, Michael Meier 0001
SEC4
2015 B.Hive: A Zero Configuration Forms Honeypot for Productive Web Applications
Christoph Pohl, Alf Zugenmaier, Michael Meier 0001, Hans-Joachim Hof
SEC3
2009 Towards Early Warning Systems - Challenges, Technologies and Architecture
Martin Apel, Joachim Biskup, Ulrich Flegel, Michael Meier 0001
CRITIS4
2009 Learning SQL for Database Intrusion Detection Using Context-Sensitive Modelling (Extended Abstract)
Christian Bockermann, Martin Apel, Michael Meier 0001
DIMVA3
2009 Measuring similarity of malware behavior
abstract
Malicious software (malware) represents a major threat for computer systems of almost all types. In the past few years the number of prevalent malware samples has increased dramatically due to the fact that malware authors started to deploy morphing (aka obfuscation) techniques in order to hinder detection of such polymorphic malware by anti-malware products. Using these techniques numerous variants of a malware can be generated. All these variants have a different syntactic representation while providing almost the same functionality and showing similar behavior. In order to effectively detect polymorphic malware it is advantageous (if not required) to know which malware samples are variants of a particular malware. Respective approaches for determining this relation between malware samples automatically are currently investigated by a number of researchers. A prerequisite for assessing this relation based on particular features of malware samples is an appropriate similarity or distance measure. In particular a number of approaches for clustering malware samples have been recently published. Thereby different similarity measures are used but without thoroughly discussing their choice. So it is an unanswered question which similarity measures are appropriate for determining respective relations between malware samples. To answer this question we study different distance measures in detail and discuss desirable properties of a distance measure for this particular purpose. We focus on behavioral features of malware and compare and experimentally evaluate different distance measures for malware behavior. Based on our results we identify a most appropriate distance measure for grouping malware samples based on similar behavior.
Martin Apel, Christian Bockermann, Michael Meier 0001
LCN3
2008 Systematic Signature Engineering by Re-use of Snort Signatures
abstract
Most intrusion detection systems deployed today apply the misuse detection approach. Misuse detection compares recorded audit data with predefined patterns denoted as signatures. A signature is usually empirically engineered based on experience and expert knowledge. This induces relatively long development times for novel signatures causing inappropriate long vulnerability windows. Methods for a systematic engineering have been scarcely reported so far. Approaches for an automated re-use of design and modeling decisions of available signatures also do not exist. In this paper we present an approach for systematic engineering of signatures which is based on the re-use of existing signatures. It exploits similarities with known attacks for the engineering process. The method applies an iterative abstraction of signatures. Based on a weighted assessment of the abstractions the signature engineer can select the most appropriate signatures or fragments of signatures for the development of the signature for a new attack. We demonstrate the usefulness of the method using Snort signatures as example.
Sebastian Schmerl, Hartmut König, Ulrich Flegel, Michael Meier 0001, René Rietz
ACSAC4
2007 Efficiency Issues of Rete-Based Expert Systems for Misuse Detection
abstract
This paper provides a general and comprehensive approach to implementing misuse detection on expert systems and an in-depth analysis of the effectiveness of the optimization strategies of the Rete algorithm wrt. the general implementation approach. General efficiency limits of Rete- based expert systems in the domain of misuse detection are determined analytically and validated experimentally. We conclude that expert systems may still have their merit in rapid prototyping of misuse detection IDSs, but they should not be considered for modern production systems.
Michael Meier 0001, Ulrich Flegel, Sebastian Schmerl
ACSAC1
2005 Improving the Efficiency of Misuse Detection
Michael Meier 0001, Sebastian Schmerl, Hartmut König
DIMVA1
2004 A Model for the Semantics of Attack Signatures in Misuse Detection Systems
Michael Meier 0001
ISC1
2002 SHEDEL-A Simple Hierarchical Event Description Language for Specifying Attack Signatures
Michael Meier 0001, Niels Bischof, Thomas Holz 0002
SEC1