VLDB 2026 Research / reviewers in the wild / expert
Ulrike Meyer
dblp:m/UlrikeMeyer
· DBLP profile ↗
59ranked-venue papers
2as first author
24since 2021 · last 2026
0000-0002-2569-1042ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 44 · 22 since 2021Computer networks · 11 · 1 first-author · 1 since 2021Human-computer interaction and ubiquitous computing · 2 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 1 since 2021Software engineering, systems software and programming languages · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Dealing with Digital Risks: Online Security, Safety, and Privacy Advice provided to Children by Peers, Parents, and Teachers
Alexander Löbel, Andreas Klinger, Frederic Salmen, Clemens Bönnen, Ulrike Meyer |
EuroS&P | 5 |
| 2026 | A Deep Dive into Wormhole Attacks in Underwater Acoustic Communication: From Theory to Practiceabstract256 Luisa Lux, Eric Wagner 0003, Konrad Wolsing, Ulrike Meyer |
WISEC | 5 |
| 2025 | The Persistent Threat of DGA-Domains Used by BotnetsabstractBotnets often employ Domain Generation Algorithms (DGAs) to evade detection and maintain communication with their Command and Control (C2) servers. Despite extensive efforts to contain individual botnets and take down their C2 infrastructure, a significant knowledge gap remains regarding the extent to which their associated DGA-generated domains continue to be registered by malicious actors, posing a latent threat. In this paper, we close this gap through a comprehensive measurement study in which we quantify the threats posed by botnets, including both active botnets and those that have been subject to previous takedown operations, by analyzing the daily registered domain names included in 1165 DNS zone files, covering $80.62 \%$ of all 1445 currently valid Top-Level Domains (TLDs), over a period of $\mathbf{1 3}$ months. During our study, we observe a decade-old botnet being reactivated by new actors, allowing them to receive incoming connections from previous dormant infections and take over a number of machines. In total, we uncover malicious activities associated with 7058 domains generated by 58 different known DGAs, at least 17 of which are used by botnets that have been the target of previous takedown operations. To improve the status quo, we discuss approaches that could have prevented the malicious acts and highlight the potential of recently proposed Machine Learning (ML) techniques to uncover yet unknown DGAs, enabling a more proactive approach to threat detection. Arthur Drichel, Ulrike Meyer |
RAID | 2 |
| 2024 | Efficient Privacy-Preserving Approximation of the Kidney Exchange ProblemabstractThe kidney exchange problem (KEP) seeks to find possible exchanges among pairs of patients and their incompatible kidney donors while meeting specific optimization criteria such as maximizing the overall number of possible transplants. Recently, several privacy-preserving protocols for solving the KEP have been proposed. However, the protocols known to date lack scalability in practice since the KEP is an NP-complete problem. We address this issue by proposing a novel privacy-preserving protocol which computes an approximate solution for the KEP that scales well for the large numbers of patient-donor pairs encountered in practice. As opposed to prior work on privacy-preserving kidney exchange, our protocol is generic w.r.t. the security model that can be employed. Compared to the most efficient privacy-preserving protocols for kidney exchange existing to date, our protocol is entirely data oblivious and it exhibits a far superior run time performance. As a second contribution, we use a real-world data set to simulate the application of our protocol as part of a kidney exchange platform, where patient-donor pairs register and de-register over time, and thereby determine its approximation quality in a real-world setting. Malte Breuer, Ulrike Meyer, Susanne Wetzel |
AsiaCCS | 2 |
| 2024 | Towards Robust Domain Generation Algorithm ClassificationabstractIn this work, we conduct a comprehensive study on the robustness of domain generation algorithm (DGA) classifiers. We implement 32 white-box attacks, 19 of which are very effective and induce a false-negative rate (FNR) of ≈ 100% on unhardened classifiers. To defend the classifiers, we evaluate different hardening approaches and propose a novel training scheme that leverages adversarial latent space vectors and discretized adversarial domains to significantly improve robustness. In our study, we highlight a pitfall to avoid when hardening classifiers and uncover training biases that can be easily exploited by attackers to bypass detection, but which can be mitigated by adversarial training (AT). In our study, we do not observe any trade-off between robustness and performance, on the contrary, hardening improves a classifier's detection performance for known and unknown DGAs. We implement all attacks and defenses discussed in this paper as a standalone library, which we make publicly available1 to facilitate hardening of DGA classifiers. Arthur Drichel, Marc Meyer, Ulrike Meyer |
AsiaCCS | 3 |
| 2024 | Estimating the Runtime and Global Network Traffic of SMPC ProtocolsabstractSecure multi-party computation (SMPC) enables multiple parties to evaluate functions of their private inputs, in a way such that none of the parties can learn anything about the other parties' private input but what can be learned from their own input and its output of the function evaluation. There are various practical applications for SMPC with runtimes ranging from a few seconds to multiple days. The performance of a protocol typically depends on the number of parties, the problem size, and the network setting. Thus, evaluating the applicability and performance of an SMPC protocol requires extensive benchmarking in varying settings, which can be very time and resource consuming, especially in slow network settings. Andreas Klinger, Vincent Ehrmanntraut, Ulrike Meyer |
CODASPY | 3 |
| 2024 | Extended Abstract: A Transfer Learning-Based Training Approach for DGA Classification
Arthur Drichel, Benedikt von Querfurth, Ulrike Meyer |
DIMVA | 3 |
| 2024 | Efficient Integration of Exchange Chains in Privacy-Preserving Kidney ExchangeabstractTraditionally, kidney exchange allows patients with an incompatible living kidney donor to exchange their donors in form of exchange cycles. Today, additional transplants are achieved through so-called exchange chains. These are initiated by an altruistic donor, who donates a kidney without requiring anything in return. In practice, kidney exchange is typically facilitated through central platforms, which compute potential exchange cycles and chains for a large number of patients and donors. To overcome the severe security issues of this centralized approach, several secure multi-party computation (SMPC) protocols for kidney exchange have been proposed recently. However, the privacy-preserving protocols proposed to date either do not scale for a sufficient number of patients and donors or do not support exchange chains. In this paper, we present the first SMPC protocol that both supports exchange chains and yields efficient run times for a large number of patients and donors. We have implemented our protocol in the framework MP-SPDZ and evaluated its run time performance. Besides, we present evaluation results based on real-world data for the use of our protocol in a dynamic setting, where patient-donor pairs and altruistic donors arrive and depart over time. Malte Breuer, Ulrike Meyer, Susanne Wetzel |
PST | 2 |
| 2024 | A Comprehensive Study on Multi-Task Learning for Domain Generation Algorithm (DGA) DetectionabstractIn this work, we perform a comparative evaluation of 21 approaches to multi-task learning (MTL) for the detection of domain generation algorithms (DGAs). To this end, we train and evaluate 2300 classifiers using a combination of 14 different optimization strategies and 6 MTL architectures and compare them statistically with the state of the art. In this context, we propose a novel ResNet backbone, which already surpasses the state of the art on its own, but shines especially in combination with MTL. We evaluate the novel DGA classifiers in a real-world study that avoids temporal and spatial experimental biases to assess whether they generalize well between different networks and are robust over time. Moreover, we analyze the classifiers' capability to detect yet unknown DGAs and discuss their practical application. Our best-performing classifier surpasses the state of the art by over 5.7% in area under the curve (AUC) for practically relevant false-positive rates (FPRs) and exceeds the state of the art by over 7.3% in true-positive rate (TPR) at the same fixed FPR of 0.001 in a real-world setting. Arthur Drichel, Ulrike Meyer |
PST | 2 |
| 2023 | Easier in Reverse: Simplifying URL Reading for Phishing URLs via Reverse Domain Name NotationabstractPhishing attacks are a persistent problem to users and organizations world-wide, resulting in monetary loss and providing a first step in more complex attacks. Vincent Drury, Jakob Drees, Ulrike Meyer |
ARES | 3 |
| 2023 | Anonymous System for Fully Distributed and Robust Secure Multi-Party ComputationabstractIn secure multi-party computation (SMPC), it is considered that multiple parties that are known to each other evaluate a function over their private inputs in a secure fashion. The participating parties do not learn anything about each other's private inputs beyond what can be deduced from their own input and output. The assumption that the parties know each other, however, does not seem suitable for all potential applications of SMPC. In some applications participants may not only want to hide their private inputs and outputs, but may also want to hide the fact that they are participating in a given function evaluation in the first place. We therefore propose an anonymous system for SMPC that allows parties to anonymously evaluate a function of their private inputs in a fully distributed and secure fashion. The proposed system allows authorized parties to execute an SMPC protocol robust with penalty against a dishonest majority in the presence of a malicious adversary. During the protocol execution, the system guarantees that all participating parties stay anonymous w. r. t. each other as well as any third parties. In addition, it guarantees that in each function evaluation all participating parties are unique, i. e., no party can participate as more than one entity. Andreas Klinger, Felix Battermann, Ulrike Meyer |
CODASPY | 3 |
| 2023 | Privacy-Preserving Fully Online Matching with DeadlinesabstractIn classical secure multi-party computation (SMPC) it is assumed that a fixed and a priori known set of parties wants to securely evaluate a function of their private inputs. This assumption implies that online problems, in which the set of parties that arrive and leave over time are not a priori known, are not covered by the classical setting. Therefore, the notion of online SMPC has been introduced, and a general feasibility result has been proven that shows that any online algorithm can be implemented as a distributed protocol that is secure in this setting [22, 23]. However, so far, no online SMPC protocol that implements a concrete online algorithm has been proposed and evaluated such that the practicality of the constructive proof is an open question. Andreas Klinger, Ulrike Meyer |
CODASPY | 2 |
| 2023 | False Sense of Security: Leveraging XAI to Analyze the Reasoning and True Performance of Context-less DGA ClassifiersabstractThe problem of revealing botnet activity through Domain Generation Algorithm (DGA) detection seems to be solved, considering that available deep learning classifiers achieve accuracies of over 99.9%. However, these classifiers provide a false sense of security as they are heavily biased and allow for trivial detection bypass. In this work, we leverage explainable artificial intelligence (XAI) methods to analyze the reasoning of deep learning classifiers and to systematically reveal such biases. We show that eliminating these biases from DGA classifiers considerably deteriorates their performance. Nevertheless we are able to design a context-aware detection system that is free of the identified biases and maintains the detection rate of state-of-the art deep learning classifiers. In this context, we propose a visual analysis system that helps to better understand a classifier’s reasoning, thereby increasing trust in and transparency of detection methods and facilitating decision-making. Arthur Drichel, Ulrike Meyer |
RAID | 2 |
| 2022 | Detecting Unknown DGAs without Context InformationabstractNew malware emerges at a rapid pace and often incorporates Domain Generation Algorithms (DGAs) to avoid blocking the malware’s connection to the command and control (C2) server. Current state-of-the-art classifiers are able to separate benign from malicious domains (binary classification) and attribute them with high probability to the DGAs that generated them (multiclass classification). While binary classifiers can label domains of yet unknown DGAs as malicious, multiclass classifiers can only assign domains to DGAs that are known at the time of training, limiting the ability to uncover new malware families. In this work, we perform a comprehensive study on the detection of new DGAs, which includes an evaluation of 59,690 classifiers. We examine four different approaches in 15 different configurations and propose a simple yet effective approach based on the combination of a softmax classifier and regular expressions (regexes) to detect multiple unknown DGAs with high probability. At the same time, our approach retains state-of-the-art classification performance for known DGAs. Our evaluation is based on a leave-one-group-out cross-validation with a total of 94 DGA families. By using the maximum number of known DGAs, our evaluation scenario is particularly difficult and close to the real world. All of the approaches examined are privacy-preserving, since they operate without context and exclusively on a single domain to be classified. We round up our study with a thorough discussion of class-incremental learning strategies that can adapt an existing classifier to newly discovered classes. Arthur Drichel, Justus von Brandt, Ulrike Meyer |
ARES | 3 |
| 2022 | Dating Phish: An Analysis of the Life Cycles of Phishing Attacks and CampaignsabstractPhishing attacks are still a general and world-wide threat to users of the Internet. In the past, several approaches to detect phishing websites earlier and shorten the time frame between their creation and inclusion in a blocklist have been proposed. Understanding the life cycle of phishing attacks, in particular the time of their creation and the time span from the first to last attack in a campaign, provides additional insights into the potential success of these methods. In this paper, we present an analysis of the life cycles of 133,667 phishing websites based on the publicly available information from certificates, whois, as well as images and resources on the phishing websites themselves. While we confirm the findings from previous work, that many websites have short lifetimes of only several days, we also note that the timing information from phishing websites using public hosting or compromised infrastructure is far less accurate in dating the creation of the websites. We further cluster the phishing websites into campaigns based on patterns in their domain names, and find that the detected campaigns often take place over several weeks, with an average duration of almost 12 days. Our results showcase advantages and limitations for the early detection of phishing websites, in particular regarding the time span between the creation of a website and its inclusion in a blocklist, and how patterns in domain names remain the same over a period of up to several weeks in the phishing campaigns analyzed in this paper. Vincent Drury, Luisa Lux, Ulrike Meyer |
ARES | 3 |
| 2022 | Privacy-Preserving Maximum Matching on General Graphs and its Application to Enable Privacy-Preserving Kidney ExchangeabstractTo this day, there are still some countries where the exchange of kidneys between multiple incompatible patient-donor pairs is restricted by law. Typically, legal regulations in this context are put in place to prohibit coercion and manipulation in order to prevent a market for organ trade. Yet, in countries where kidney exchange is practiced, existing platforms to facilitate such exchanges generally lack sufficient privacy mechanisms. In this paper, we propose a privacy-preserving protocol for kidney exchange that not only addresses the privacy problem of existing platforms but also is geared to lead the way in overcoming legal issues in those countries where kidney exchange is still not practiced. In our approach, we use the concept of secret sharing to distribute the medical data of patients and donors among a set of computing peers in a privacy-preserving fashion. These computing peers then execute our new Secure Multi-Party Computation (SMPC) protocol among each other to determine an optimal set of kidney exchanges. As part of our new protocol, we devise a privacy-preserving solution to the maximum matching problem on general graphs. We have implemented the protocol in the SMPC benchmarking framework MP-SPDZ and provide a comprehensive performance evaluation. Furthermore, we analyze the practicality of our protocol when used in a dynamic setting where patients and donors arrive and depart over time) based on a data set from the United Network for Organ Sharing. Malte Breuer, Ulrike Meyer, Susanne Wetzel |
CODASPY | 2 |
| 2022 | Better the Phish You Know: Evaluating Personalization in Anti-Phishing Learning Games
René Röpke, Vincent Drury, Ulrike Meyer, Ulrik Schroeder |
CSEDU (2) | 3 |
| 2022 | Accurate Real-Time Labeling of Application TrafficabstractIn this paper, we present the design and implementation of ATLAS, a novel tool for automatically labeling network packets with the process responsible for them. Our tool is able to label all kinds of outbound packets based on Windows events and TCP stream information with ground-truth accuracy. Additionally, it is able to label DNS packets with the correct process name instead of just the DNS resolver. Using ATLAS, it is possible to create large datasets, e.g., to create software fingerprints or train machine learning classifiers. Another use-case is to inspect the network traffic of a machine to determine which application is communicating with whom. We evaluate the performance considering different load scenarios to demonstrate the real-time capacity of ATLAS. Additionally, we analyze the communication endpoints of a Windows 10 host and compare the results before and after disabling all privacy related settings. Sebastian Schäfer 0004, Alexander Löbel, Ulrike Meyer |
LCN | 3 |
| 2022 | Solving the Kidney Exchange Problem Using Privacy-Preserving Integer ProgrammingabstractThe kidney exchange problem (KEP) seeks to determine a constellation of exchanges that maximizes the number of possible transplants between a set of patients and their incompatible donors. Recently, Secure Multi-Party Computation (SMPC) techniques were used to devise privacy-preserving protocols that allow the solving of the KEP in a distributed fashion. However, these protocols lack sufficient performance in practice. In the non-privacy-preserving case, the most efficient algorithms solving the KEP are based on integer programming. It is in this context, that we propose a privacy-preserving protocol based on these integer programming techniques that efficiently solves the KEP in a privacy-preserving fashion. We prove the security of this protocol and analyze its complexity. Furthermore, we provide a comprehensive performance evaluation of an implementation of the protocol in the SMPC benchmarking framework MP-SPDZ. Malte Breuer, Pascal Hein, Leonardo Pompe, Ben Temme, Ulrike Meyer, Susanne Wetzel |
PST | 5 |
| 2021 | Finding Phish in a Haystack: A Pipeline for Phishing Classification on Certificate Transparency LogsabstractCurrent popular phishing prevention techniques mainly utilize reactive blocklists, which leave a “window of opportunity” for attackers during which victims are unprotected. One possible approach to shorten this window aims to detect phishing attacks earlier, during website preparation, by monitoring Certificate Transparency (CT) logs. Previous attempts to work with CT log data for phishing classification exist, however they lack evaluations on actual CT log data. In this paper, we present a pipeline that facilitates such evaluations by addressing a number of problems when working with CT log data. The pipeline includes dataset creation, training, and past or live classification of CT logs. Its modular structure makes it possible to easily exchange classifiers or verification sources to support ground truth labeling efforts and classifier comparisons. We test the pipeline on a number of new and existing classifiers, and find a general potential to improve classifiers for this scenario in the future. We publish the source code of the pipeline and the used datasets along with this paper [12], thus making future research in this direction more accessible. Arthur Drichel, Vincent Drury, Justus von Brandt, Ulrike Meyer |
ARES | 4 |
| 2021 | First Step Towards EXPLAINable DGA Multiclass ClassificationabstractNumerous malware families rely on domain generation algorithms (DGAs) to establish a connection to their command and control (C2) server. Counteracting DGAs, several machine learning classifiers have been proposed enabling the identification of the DGA that generated a specific domain name and thus triggering targeted remediation measures. However, the proposed state-of-the-art classifiers are based on deep learning models. The black box nature of these makes it difficult to evaluate their reasoning. The resulting lack of confidence makes the utilization of such models impracticable. In this paper, we propose EXPLAIN, a feature-based and contextless DGA multiclass classifier. We comparatively evaluate several combinations of feature sets and hyperparameters for our approach against several state-of-the-art classifiers in a unified setting on the same real-world data. Our classifier achieves competitive results, is real-time capable, and its predictions are easier to trace back to features than the predictions made by the DGA multiclass classifiers proposed in related work. Arthur Drichel, Nils Faerber, Ulrike Meyer |
ARES | 3 |
| 2021 | Towards Secure Evaluation of Online FunctionalitiesabstractTo date, ideal functionalities securely realized with secure multi-party computation (SMPC) mainly considers functions of the private input of a fixed number of a priori known parties. In this paper, we generalize these definitions such that protocols implementing online algorithms in a distributed fashion can be proven to be privacy-preserving. Online algorithms compute online functionalities that allow parties to join and leave over time, to provide multiple inputs and to obtain multiple outputs. In particular, the set of parties participating changes over time, i. e., at different points in time different sets of parties evaluate a function over their private inputs. To this end, we propose the notion of an online trusted third party that allows to prove the security of SMPC protocols implementing online functionalities or online algorithms, respectively. We show that any online functionality can be implemented perfectly secure in the presence of a semi-honest adversary, if strictly less than 1/2 of the parties participating are corrupted. We show that the same result holds in the presence of a malicious adversary if it corrupts strictly less than 1/3 of the parties and always allows the corrupted parties to arrive. Andreas Klinger, Ulrike Meyer |
ARES | 2 |
| 2021 | Introducing a Framework to Enable Anonymous Secure Multi-Party Computation in PracticeabstractSecure Multi-Party Computation (SMPC) allows a set of parties to securely compute a functionality in a distributed fashion without the need for any trusted external party. Usually, it is assumed that the parties know each other and have already established authenticated channels among each other. However, in practice the parties sometimes must stay anonymous. In this paper, we conceptualize a framework that enables the repeated execution of an SMPC protocol for a given functionality such that the parties can keep their participation in the protocol executions private and at the same time be sure that only authorized parties may take part in a protocol execution. We identify the security properties that an implementation of our framework must meet and introduce a first implementation of the framework that achieves these properties. Malte Breuer, Ulrike Meyer, Susanne Wetzel |
PST | 2 |
| 2021 | Towards Privacy-Preserving Classification-as-a-Service for DGA DetectionabstractDomain generation algorithm (DGA) classifiers can be used to detect and block the establishment of a connection between bots and their command-and-control server. Classification-as-a-service (CaaS) can separate the classification of domain names from the need for real-world training data, which are difficult to obtain but mandatory for well performing classifiers. However, domain names as well as trained models may contain privacy-critical information which should not be leaked to either the model provider or the data provider. Several generic frameworks for privacy-preserving machine learning (ML) have been proposed in the past that can preserve data and model privacy. Thus, it seems high time to combine state-of-the-art DGA classifiers and privacy-preservation frameworks to enable privacy-preserving CaaS, preserving both, data and model privacy for the DGA detection use case. In this work, we examine the real-world applicability of four generic frameworks for privacy-preserving ML using different state-of-the-art DGA detection models. Our results show that out-of-the-box DGA detection models are computationally infeasible for privacy-preserving inference in a real-world setting. We propose model simplifications that achieve a reduction in inference latency of up to 95%, and up to 97% in communication complexity while causing an accuracy penalty of less than 0.17%. Despite this significant improvement, real-time classification is still not feasible in a traditional two-party setting. Thus, more efficient secure multi-party computation (SMPC) or homomorphic encryption (HE) schemes are required to enable real-world feasibility of privacy-preserving CaaS for DGA detection. Arthur Drichel, Mehdi Akbari Gurabi, Tim Amelung, Ulrike Meyer |
PST | 4 |
| 2020 | Analyzing the real-world applicability of DGA classifiersabstractSeparating benign domains from domains generated by DGAs with the help of a binary classifier is a well-studied problem for which promising performance results have been published. The corresponding multiclass task of determining the exact DGA that generated a domain enabling targeted remediation measures is less well studied. Selecting the most promising classifier for these tasks in practice raises a number of questions that have not been addressed in prior work so far. These include the questions on which traffic to train in which network and when, just as well as how to assess robustness against adversarial attacks. Moreover, it is unclear which features lead a classifier to a decision and whether the classifiers are real-time capable. In this paper, we address these issues and thus contribute to bringing DGA detection classifiers closer to practical use. In this context, we propose one novel classifier based on residual neural networks for each of the two tasks and extensively evaluate them as well as previously proposed classifiers in a unified setting. We not only evaluate their classification performance but also compare them with respect to explainability, robustness, and training and classification speed. Finally, we show that our newly proposed binary classifier generalizes well to other networks, is time-robust, and able to identify previously unknown DGAs. Arthur Drichel, Ulrike Meyer, Samuel Schüppen, Dominik Teubert |
ARES | 2 |
| 2020 | Making use of NXt to nothing: the effect of class imbalances on DGA detection classifiersabstractNumerous machine learning classifiers have been proposed for binary classification of domain names as either benign or malicious, and even for multiclass classification to identify the domain generation algorithm (DGA) that generated a specific domain name. Both classification tasks have to deal with the class imbalance problem of strongly varying amounts of training samples per DGA. Currently, it is unclear whether the inclusion of DGAs for which only a few samples are known to the training sets is beneficial or harmful to the overall performance of the classifiers. In this paper, we perform a comprehensive analysis of various contextless DGA classifiers, which reveals the high value of a few training samples per class for both classification tasks. We demonstrate that the classifiers are able to detect various DGAs with high probability by including the underrepresented classes which were previously hardly recognizable. Simultaneously, we show that the classifiers' detection capabilities of well represented classes do not decrease. Arthur Drichel, Ulrike Meyer, Samuel Schüppen, Dominik Teubert |
ARES | 2 |
| 2020 | Towards Personalized Game-Based Learning in Anti-Phishing EducationabstractAs anti-phishing games emerge as a scalable, motivational and effective approach to anti-phishing education for non-professional end-users, problems arise due to the missing relevance of a games' content and context. If a game presents examples unknown or without relevance to the user, the learning potential is limited as users have no point of reference. To provide more meaningful, relevant game content to users, we propose a personalization pipeline for data collection, content generation and delivery for anti-phishing learning games. René Röpke, Ulrik Schroeder, Vincent Drury, Ulrike Meyer |
ICALT | 4 |
| 2019 | Privacy - Preserving Multi-Party Conditional Random SelectionabstractThe primitive of conditional random selection allows the selection of a data record uniformly at random from the subset of data records that meet a specified condition. In this paper, we extend a previously introduced privacy-preserving two-party protocol (that implements this primitive in the context of passive adversaries) to the multi-party case. Additionally, we provide a comprehensive performance analysis of the newly designed protocol and discuss application scenarios. Stefan Wüller, Benjamin Assadsolimani, Ulrike Meyer, Fabian Förg, Susanne Wetzel |
PST | 3 |
| 2018 | Privacy-Preserving Subgraph CheckingabstractA subgraph check is a variant of the common subgraph matching-operating on a reference and a test graph- determining whether a test graph is a subgraph of the reference graph. In this paper, we present two novel privacy-preserving subgraph checking protocols. In our first protocol, all subgraph checks are carried out independently of each other. The second protocol allows for a substantial performance improvement over the straight-forward approach of the first protocol by exploiting structural similarities among the test graphs to be checked against the reference graph. Stefan Wüller, Benjamin Assadsolimani, Ulrike Meyer, Susanne Wetzel |
PST | 3 |
| 2018 | FANCI : Feature-based Automated NXDomain Classification and Intelligence
Samuel Schüppen, Dominik Teubert, Patrick Herrmann, Ulrike Meyer |
USENIX Security Symposium | 4 |
| 2017 | Efficient Commodity Matching for Privacy-Preserving Two-Party BarteringabstractCurrent bartering platforms place the burden of finding simultaneously executable quotes on their users. In addition, these bartering platforms do not keep quotes private. To address these shortcomings, this paper introduces a privacy-preserving bartering protocol secure in the semi-honest model. At its core, the novel bartering protocol uses a newly-developed bipartite matching protocol which determines simultaneously executable quotes in an efficient manner. While the new privacy-preserving bipartite matching protocol does not always yield the maximal set of simultaneously executable quotes, it keeps the parties' quotes private at all times. Moreover, our new privacy-preserving bipartite matching protocol is more efficient than existing solutions in that it only requires linear communication in the number of quotes the parties specify. Fabian Förg, Susanne Wetzel, Ulrike Meyer |
CODASPY | 3 |
| 2017 | Privacy-Preserving Multi-Party Bartering Secure Against Active AdversariesabstractA majority of electronic bartering transactions is carried out via online platforms. Typically, these platforms require users to disclose sensitive information about their trade capabilities which might restrict their room for negotiation. It is in this context that we propose a novel decentralized and privacy-preserving bartering protocol for multiple parties that offers the same privacy guarantees as provided by traditional bartering and by cash payments. The proposed protocol is even secure against an active attacker who controls a majority of colluding parties. Stefan Wüller, Ulrike Meyer, Susanne Wetzel |
PST | 2 |
| 2017 | Designing privacy-preserving interval operations based on homomorphic encryption and secret sharing techniquesabstractThis paper introduces two-party protocols for various operations on two integer intervals that are privacy-preserving in the semi-honest model. Specifically, this work proposes new protocols for determining whether two intervals overlap; computing the boundaries and size of the overlap; and selecting a random sub-interval within the overlap. The protocols are presented both for homomorphic encryption and for secret sharing as basic secure multi-party computation techniques. Moreover, this paper presents a comprehensive performance evaluation of the newly-developed protocols. Stefan Wüller, Daniel A. Mayer, Fabian Förg, Samuel Schüppen, Benjamin Assadsolimani, Ulrike Meyer, Susanne Wetzel |
J. Comput. Secur. | 6 |
| 2016 | Classification of Short Messages Initiated by Mobile MalwareabstractIn this paper we show that supervised machine learning algorithms can reliably detect short messages initiated by mobile malware based on features derived from the content of short messages. In particular, we compare the detection capabilities of the classifiers Support Vector Machines, K-Nearest Neighbor, Decision Trees, Random Forests, and Multinomial Naive Bayes in three different evaluation scenarios. The first scenario is the standard k-fold cross validation, treating all short messages as independent from each other. In the second scenario, we evaluate, how the classifiers perform if only a certain portion of malware families are known during training. Here, we are able to show that training with only 50% of the the malware families already lead to an accuracy of over 90%. Finally, in the third scenario we evaluate the performance chronologically, i.e. the classifiers are trained with the short messages available at a certain point in time and tested on the newly arriving messages. Here, we show that classifiers can detect the majority of new short messages initiated by mobile malware even months after the training. Marián Kühnel, Ulrike Meyer |
ARES | 2 |
| 2016 | Anomaly-based Mobile Malware Detection: System Calls as Source for Features
Dominik Teubert, Fred Grossmann, Ulrike Meyer |
ICISSP | 3 |
| 2016 | Information Hiding in the RSA ModulusabstractThe manufacturer of an asymmetric backdoor for a public key cryptosystem manipulates the key generation process in such a way that he can extract the private key or other secret information from the user's public key by involving his own public/private key pair. All asymmetric backdoors in major public key cryptosystems including RSA differ substantially in their implementation approaches and in their quality in satisfying backdoor related properties like confidentiality and concealment. While some of them meet neither of these two properties very well, others provide a high level of confidentiality but none of them is concealing, which limits their use for covert implementation. In this paper we introduce two novel asymmetric RSA backdoors, both following the approach to embed bits of one of the RSA prime factors in the user's public RSA modulus. While our first backdoor provides confidentiality for a sufficiently large key length, it might be detected under certain circumstances. The second backdoor extends the first one such that it additionally provides concealment and is thus particularly suitable for covert implementation. Stefan Wüller, Marián Kühnel, Ulrike Meyer |
IH&MMSec | 3 |
| 2016 | B. A. T. M. A. N. Handover Extension for Routing Nodes in Infrastructure WMNsabstractIn the past, several proposals to support fast handover in wireless mesh networks have been published. However, most handover extensions are only concerned with moving stations that are unaware of the used routing protocol and assume relatively stationary routing nodes. In this paper we propose an extension to the BATMAN routing protocol to support seamless handover of routing nodes in infrastructure wireless mesh networks. We implement the new extension in our wireless mesh testbed and evaluate its performance in comparison to a standard WLAN handover followed by a route reestablishment using BATMAN. The evaluation shows that route reestablishment is more than 40 times faster with our extension when compared to standard BATMAN. Patrick Herrmann, Ulrike Meyer |
LCN | 2 |
| 2016 | Privacy-preserving two-party bartering secure against active adversariesabstractBoth B2B bartering as well as bartering between individuals is increasingly facilitated through online platforms. However, these platforms lack automation and neglect the privacy of their users by leaking crucial information about their offers and demands. It is in this context that we introduce the first privacy-preserving two-party bartering protocol which is secure against active attackers. As main building blocks, our bartering protocol uses novel protocols operating on common encrypted input for securely selecting an element out of multiple elements, securely selecting a random element out of an interval, and obliviously shrinking an interval which are of independent interest. Stefan Wüller, Wadim Pessin, Ulrike Meyer, Susanne Wetzel |
PST | 3 |
| 2015 | Privacy-preserving conditional random selectionabstractIn this paper, we introduce a new primitive - referred to as conditional random selection. This new primitive allows the random selection of a data record from the subset of data records that meet a specified condition. We present a new privacy-preserving protocol that implements the new primitive and is secure in the semi-honest model. At its core, it uses newly developed protocols for oblivious shuffling, oblivious swapping, and privacy-preserving less than comparison on binary values with shared output. We show the relevance of conditional random selection in various application scenarios. Stefan Wüller, Ulrike Meyer, Fabian Förg, Susanne Wetzel |
PST | 2 |
| 2014 | A secure two-party bartering protocol using privacy-preserving interval operationsabstractBartering plays a significant role in today's global economy-both between individuals as well as in B2B settings. However, aside from lacking automation, today's bartering solutions and supporting platforms typically neglect the privacy needs of their users. In this paper, we present a novel two-party protocol which addresses these shortcomings. The new protocol automatically determines whether the desired and offered commodities and quantities overlap in such a way that both parties are willing to barter. Throughout the protocol, the commodities and quantities as specified by the parties are kept private. We show that the protocol is privacy-preserving in the semi-honest model. As main building blocks, the new bartering protocol uses a novel privacy-preserving protocol for selecting a random subinterval out of the overlap of two intervals as well as a newly-developed secure protocol for input-symmetric strong conditional oblivious transfer. Fabian Förg, Daniel A. Mayer, Susanne Wetzel, Stefan Wüller, Ulrike Meyer |
PST | 5 |
| 2013 | 4GMOP: Mopping Malware Initiated SMS Traffic in Mobile Networks
Marián Kühnel, Ulrike Meyer |
ISC | 2 |
| 2013 | Experiences from security research using a Wireless Mesh Network testbedabstractWireless Mesh Networks (WMN) consist of a wireless infrastructure of mesh routers which are connected to the Internet via mesh gateways. In recent years many testbeds for WMNs have been implemented to test and evaluate different aspects of WMNs, however, none of these has been designed with testing and evaluating security mechanisms for WMNs in mind. In this paper we share our experience with designing a testbed dedicated to testing and evaluating security protocols in a realistic setting. We detail the hardware and software setup of our testbed, the management tools we developed to facilitate maintenance of our testbed. Finally, we show the potential of our testbed by presenting experimental results we gained using our testbed. André Egners, Patrick Herrmann, Tobias Jarmuzek, Ulrike Meyer |
LCN | 4 |
| 2013 | IP agnostic real-time traffic filtering and host identification using TCP timestampsabstractIn this work, we describe and evaluate the design and implementation of natfilterd, a flexible and lightweight extension of the Linux netfilter packet filter framework, which enables us to identify hosts completely independent of IP addresses by taking advantage of certain characteristics of TCP timestamps. As an immediate consequence, not only can we count hosts behind a NAT gateway but block TCP traffic from single hosts without blocking the gateway itself. Our work extends ideas from Bursztein, which we improve in terms of performance as well as matching quality and usability in practice. A theoretical runtime of O(log(n)) for matching packets against a database of n hosts is achieved. We empirically verify this result and conclude that our approach scales extremely well and is therefore suitable for at least medium-scale networks of a few thousand hosts. Georg Wicherski, Florian Weingarten, Ulrike Meyer |
LCN | 3 |
| 2013 | Privacy-Preserving Multi-party Reconciliation Using Fully Homomorphic Encryption
Florian Weingarten, Georg Neugebauer, Ulrike Meyer, Susanne Wetzel |
NSS | 3 |
| 2013 | Secure and efficient handover protocols for WMNsabstractWireless Mesh Networks (WMN) consist of a wireless infrastructure of mesh routers which are connected to the Internet via mesh gateways. Mesh clients on the other hand connect to these routers. To make full use of the connectivity and services offered by a WMN, users should be able to securely hand over from one router to the next. In particular, keying material has to be supplied to the new router. Handover protocols designed for infrastructure WLAN cannot be directly applied here as they have clearly been designed with a trusted backbone in mind. In this paper we propose three complementary secure, efficient, and practical proactive handover protocols, which are able to cope with the unique characteristics of WMNs such as the wireless infrastructure and untrusted intermediaries.We have also implemented and evaluated our protocols using our WMN testbed and thus show the feasibility of our solution in time critical contexts. André Egners, Patrick Herrmann, Ulrike Meyer |
WOWMOM | 3 |
| 2012 | GPU-Acceleration of Block Ciphers in the OpenSSL Cryptographic Library
Johannes Gilger, Johannes Barnickel, Ulrike Meyer |
ISC | 3 |
| 2012 | CaPTIF: Comprehensive Performance TestIng Framework
Daniel A. Mayer, Orie Steele, Susanne Wetzel, Ulrike Meyer |
ICTSS | 4 |
| 2012 | Implementing an Attack on Bluetooth 2.1+ Secure Simple Pairing in Passkey Entry ModeabstractDue to the serious security issues found in early Bluetooth revisions, Bluetooth revision 2.1 (and later) uses a new pairing process called Secure Simple Pairing (SSP). SSP allows two devices to establish a link key based on a Diffie-Hellman key agreement and supports four methods to authenticate the key agreement. One of these methods is called Passkey Entry method, which uses a PIN entered on one or both devices. The Passkey Entry method has been shown to leak this PIN to any attacker eavesdropping on the first part of the pairing process. If in addition, the attacker can prevent the pairing process to successfully complete and the user uses the same PIN twice (or a fixed PIN is used), the attacker can mount a man-in-the-middle attack on a new run of the pairing process. In this paper, we explore the practicality of this attack and show that it is should be taken very seriously. Lacking devices with a reasonably programmable Bluetooth stack to implement the attack upon, we created Bluetrial: our own implementation of the relevant Bluetooth parts using the GNU Radio platform on USRP and USRP2 devices. Johannes Barnickel, Ulrike Meyer |
TrustCom | 3 |
| 2012 | Messing with Android's Permission ModelabstractPermission models have become very common on smartphone operating systems to control the rights granted to installed third party applications (apps). Prior to installing an app, the user is typically presented with a dialog box showing the permissions requested by the app. The user has to decide either to accept all of the requested permissions, or choose not to proceed with the installation. Most regular users are not able to fully grasp which set of permissions granted to the application is potentially harmful. In addition to the knowledge gap between user and application programmer, the missing granularity and alterability of most permission model implementations help an attacker to circumvent the permission model. In this paper we focus on the permission model of Google's Android platform. We detail the permission model, and present a selection of attacks that can be composed to fully compromise a user's device using inconspicuously looking applications requesting non-suspicious permissions. André Egners, Ulrike Meyer, Björn Marschollek |
TrustCom | 2 |
| 2012 | FSASD: A framework for establishing security associations for sequentially deployed WMNabstractWireless Mesh Networks (WMN) mainly consist of an infrastructure of mesh routers (MRs) that are wirelessly interconnected. In many application scenarios these MRs are placed in publicly accessible places and may therefore be compromised by an attacker. Any security framework for WMNs should thus be able to cope with compromised mesh routers. In addition, mesh clients (MCs) are often assumed to be able to route traffic for each other. Such routing MCs, as well as compromised MRs, may try to eavesdrop on and manipulate any type of traffic flowing through them. As a consequence end-to-end protection of all communication in the mesh has to be ensured. Neither the upcoming standard 802.11s nor prior research proposals of security frameworks adequately address this challenge. In addition, many research proposals are incompatible to the upcoming standard therefore only have a slight chance of getting widely used with commercially available devices. In this paper we propose a comprehensive framework for securing wireless mesh networks that is fully compatible to the upcoming 802.11s. The framework enables the efficient establishment of all security associations required for end-to-end protection of the different traffic types in the mesh. In addition, the framework supports secure proactive handovers. We implemented the entire framework in our WMN testbed and present the performance results in this paper. André Egners, Hendrik Fabelje, Ulrike Meyer |
WOWMOM | 3 |
| 2011 | Implementation and performance evaluation of privacy-preserving fair reconciliation protocols on ordered setsabstractRecently, new protocols were proposed which allow two parties to reconcile their ordered input sets in a fair and privacy-preserving manner. In this paper we present the design and implementation of these protocols on different platforms and extensively study their performance. Daniel A. Mayer, Dominik Teubert, Susanne Wetzel, Ulrike Meyer |
CODASPY | 4 |
| 2011 | Security and privacy for WLAN roaming with per-connection tariff negotiationabstractIn this paper, we propose a novel protocol suite for roaming WLAN devices. It supports authentication, key agreement, and secure payment between roaming devices and network operators. This is achieved with the help of an integrated tick payment scheme. Our protocol suite allows operators to quickly change tariffs depending on current demand and allows users to choose between different operators and select from different tariff options on a per-connection basis. In addition, our protocol suite offers a very high degree of privacy protection by revealing only strictly required information to the participating parties. Johannes Barnickel, Ulrike Meyer |
LCN | 2 |
| 2010 | Fair and Privacy-Preserving Multi-party Protocols for Reconciling Ordered Input Sets
Georg Neugebauer, Ulrike Meyer, Susanne Wetzel |
ISC | 2 |
| 2010 | Wireless Mesh Network security: State of affairsabstractWireless Mesh Networks (WMNs) surely are one of the most prominent trends for Next Generation Networks. Their future success, however, depends on their security features. In this paper we step back to classify and characterize Wireless Mesh Networks as a whole. This high-level vantage point helps us to define general security requirements and identify unique challenges in meeting these requirements with respect to the characteristics of WMNs. We then use this framework of requirements and characteristics to evaluate state of the art proposals ranging from standardization effort of the IEEE to results from academia. André Egners, Ulrike Meyer |
LCN | 2 |
| 2010 | Efficient Mutual Authentication for Multi-domain RFID Systems Using Distributed Signatures
Ulrike Meyer, Susanne Wetzel |
WISTP | 2 |
| 2010 | Security and privacy for mobile electronic health monitoring and recording systemsabstractIn this paper we detail the security and privacy architecture and implementation of the HealthNet mobile electronic health monitoring and data collection system. HealthNet consists of a body sensor network embedded in clothing that communicates wirelessly to the wearer's mobile phone. The mobile phone is used to manage, store and transfer the data in a secure way. Data may be transferred to other parties, such as medical experts, emergency care and private parties trusted by the wearer himself, e.g. his family. The patient controls who may access his data. Only emergency physicians nearby the patient may access vital data without the patient's individual consent. We describe the unique security and privacy features of our architecture which may also be used to improve other telemonitoring solutions. Johannes Barnickel, Hakan Karahan, Ulrike Meyer |
WOWMOM | 3 |
| 2010 | Compensation: Architecture for supporting dynamicity and negotiation in accounting, charging and billing
George B. Huitema, Ralph Kühne, Ulrike Meyer, Henk Ensing, Alf Zugenmaier, Alain Bibas, Olavi Karasti, Frens Jan Rumph, Johanneke Siljee |
Comput. Commun. | 3 |
| 2007 | Distributed Privacy-Preserving Policy ReconciliationabstractOrganizations use security policies to regulate how they share and exchange information, e.g., under what conditions data can be exchanged, what protocols are to be used, who is granted access, etc. Agreement on specific policies is achieved though policy reconciliation, where multiple parties, with possibly different policies, exchange their security policies, resolve differences, and reach a consensus. Current solutions for policy reconciliation do not take into account the privacy concerns of reconciliating parties. This paper addresses the problem of preserving privacy during security policy reconciliation. We introduce new protocols that meet the privacy requirements of the organizations and allow parties to find a common policy rule which maximizes their individual preferences. Ulrike Meyer, Susanne Wetzel, Sotiris Ioannidis |
ICC | 1 |
| 2004 | On the impact of GSM encryption and man-in-the-middle attacks on the security of interoperating GSM/UMTS networksabstractGSM suffers from various security weaknesses: Just recently, Barkan, Biham and Keller presented a ciphertext-only attack on the GSM encryption algorithm A5/2 which recovers the encryption key from a few dozen milliseconds of encrypted traffic within less than a second. Furthermore, it is well-known that it is possible to mount a man-in-the-middle attack in GSM during authentication which allows an attacker to make a victim mobile station authenticate itself to a fake base station which in turn forwards the authentication traffic to the real network, thus impersonating the victim mobile station to a real network and vice versa. We discuss the impact of GSM encryption attacks, that recover the encryption key, and the man-in-the-middle attack on the security of networks, which employ UMTS and GSM base stations simultaneously. We suggest to protect UMTS connections from GSM attacks by integrating an additional authentication and key agreement on intersystem handovers between GSM and UMTS. Ulrike Meyer, Susanne Wetzel |
PIMRC | 1 |