Claus Vielhauer

dblp:v/CVielhauer · DBLP profile ↗
← Back
21ranked-venue papers
2as first author
5since 2021 · last 2025
0009-0007-7125-2722ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 13 · 1 first-author · 5 since 2021Graphics, computer vision, multimedia, augmented reality and games · 5Artificial intelligence and machine learning · 2 · 1 first-authorDatabases, data management, data science and information retrieval · 1 · 1 first-authorHuman-computer interaction and ubiquitous computing · 1
YearPublicationVenuePosition
2025 Towards Modeling Hidden & Steganographic Malware Communication based on Images
abstract
Recently, an increasing number of IT security incidents involving malware, which makes use of hidden and steganographic channels for malicious communication (a.k.a. as "stegomalware"), can be observed in the wild.Especially the use of images to hide malicious code is rising.In consideration of this shift, a new model is proposed in this paper, which aims to help security professionals to identify and analyze incidents revolving around steganographic malware in the future.The model focuses on practical aspects of steganalysis of communication data to elaborate linking properties to previous code analysis knowledge.The model features two distinct roles that interact with a knowledge base which stores malware features and helps building a context for the incident.For evaluation, two image steganography malware types are chosen from popular databases (malpedia and MITRE ATT&CK®), which are analyzed in multiple steps including steganalysis and code analysis.It is conceptually shown, how the extracted features can be stored in a knowledge base for later use to identify stegomalware from communication data without the need of a thorough code analysis.This allows to uncover previously hidden meta-information about the examined malicious programs, enrich the incident's forensic context traces and thus allows for thorough forensic insights, including attribution and improved preventive security measures in the future.
Claus Vielhauer, Fabian Loewe, Michael Pilgermann
IH&MMSec1
2022 Improving Performance of Machine Learning based Detection of Network Steganography in Industrial Control Systems
abstract
In view of the strong increase of targeted attacks on industrial control systems (ICS) of manufacturies and critical infrastructures, it can be noticed that for the concealment of communication, steganographic information hiding techniques become increasingly popular for attackers. Particularly in Advanced Persistent Threats, attackers focus on hiding network information flows between infected components from any possible detection mechanism in order to remain on the invaded system for as long as possible. In order to be able to detect these kinds of threats by hidden communication in future, defense concepts such as intrusion detection systems need to be supplemented by steganalytic detectors for ICS network traffic. First state-of-the-art detection mechanisms have been proposed and deliver decent but improvable results. This paper proposes a novel, convolutional neural network (CNN) based detection approach relying on a handcrafted feature space as CNN input layer. The detection approach is evaluated extensively in experiments. The evaluation results are compared to three state-of-the-art approaches in a laboratory ICS setup. We show that our novel approach is able to outperform all state-of-the-art approaches significantly. It delivers a performance of up to 94.3% correct classified test data samples.
Tom Neubert, Antonio José Caballero Morcillo, Claus Vielhauer
ARES3
2021 Artificial Steganographic Network Data Generation Concept and Evaluation of Detection Approaches to secure Industrial Control Systems against Steganographic Attacks
abstract
Since industrial control systems (ICS) play an important role in our everyday life, their protection is of great importance. At the same time, security researchers observe an increasing usage of steganographic methods in IT networks used by attackers to embed hidden communication in order to stay undetected as long as possible. This leads to a novel digital threat which includes the embedding of steganographic hidden communication in ICS networks. Thus, novel detection approaches specified for steganographic attacks have to be elaborated. Detectors are often based on machine learning approaches and require training and test data. However, the embedding of sophisticated hidden communication in an ICS is a very time consuming and challenging task which currently leads to a lack of suitable training and test data for the evaluation of detection mechanisms. To address this gap, this work presents an artificial steganographic network data (ASND) generation concept for an easy generation of sophisticated steganographic network data which can be provided for the evaluation of detection mechanisms. In this paper, an exemplary data set is created by ASND generation concept and used to evaluate a state-of-the-art detector and a novel detector, also introduced in this work. The accuracy of the detectors is determined and compared. The novel detector reaches a maximum detection accuracy of 92.5%.
Tom Neubert, Claus Vielhauer, Christian Krätzer
ARES2
2021 A Revised Taxonomy of Steganography Embedding Patterns
abstract
Steganography embraces several hiding techniques which spawn across multiple domains. However, the related terminology is not unified among the different domains, such as digital media steganography, text steganography, cyber-physical systems steganography, network steganography (network covert channels), local covert channels, and out-of-band covert channels. To cope with this, a prime attempt has been done in 2015, with the introduction of the so-called hiding patterns, which allow to describe hiding techniques in a more abstract manner. Despite significant enhancements, the main limitation of such a taxonomy is that it only considers the case of network steganography.
Steffen Wendzel, Luca Caviglione, Wojciech Mazurczyk, Aleksandra Mileva, Jana Dittmann, Christian Krätzer, Kevin Lamshöft, Claus Vielhauer, Laura Hartmann, Jörg Keller 0001, Tom Neubert
ARES8
2021 Information Hiding in Cyber Physical Systems: Challenges for Embedding, Retrieval and Detection using Sensor Data of the SWAT Dataset
abstract
In this paper, we present an Information Hiding approach that would be suitable for exfiltrating sensible information of Industrial Control Systems (ICS) by leveraging the long-term storage of process data in historian databases. We show how hidden messages can be embedded in sensor measurements as well as retrieved asynchronously by accessing the historian. We evaluate this approach at the example of water-flow and water-level sensors of the Secure Water Treatment (SWAT) dataset from iTrust. To generalize from specific cover channels (sensors and their transmitted data), we reflect upon general challenges that arise in such Information Hiding scenarios creating network covert channels and discuss aspects of cover channel selection and and sender receiver synchronisation as well as temporal aspects such as the potential persistence of hidden messages in Cyber Physical Systems (CPS). For an empirical evaluation we design and implement a covert channel that makes use of different embedding strategies to perform an adaptive approach in regards to the noise in sensor measurements, resulting in dynamic capacity and bandwidth selection to reduce detection probability. The results of this evaluation show that, using such methods, the exfiltration of sensible information in long-term scaled attacks would indeed be possible. Additionally, we present two detection approaches for the introduced hidden channel and carry out an extensive evaluation of our detectors with multiple test data sets and different parameters. We determine a detection accuracy of up to 87.8% on test data at a false positive rate (FPR) of 0%.
Kevin Lamshöft, Tom Neubert, Christian Krätzer, Claus Vielhauer, Jana Dittmann
IH&MMSec4
2020 Information Hiding in Industrial Control Systems: An OPC UA based Supply Chain Attack and its Detection
abstract
Industrial Control Systems (ICS) help to automate various cyber-physical systems in our world. The controlled processes range from rather simple traffic lights and elevators to complex networks of ICS in car manufacturing or controlling nuclear power plants. With the advent of industrial Ethernet ICS are increasingly connected to networks of Information Technology (IT). Thus, novel attack vectors on ICS are possible. In IT networks information hiding and steganography is increasingly used in advanced persistent threats to conceal the infection of the systems allowing the attacker to retain control over the compromised networks. In parallel ICS are more and more a target for attacks as well. Here, simple automated attacks as well as targeted attacks of nation state actors with the intention of damaging components or infrastructures as a part of cyber crime have already been observed. Information hiding could bring such attacks to a new level by integrating backdoors and hidden/covert communication channels that allow for attacking specific processes whenever it is deemed necessary. This paper sheds light on potential attack vectors on Programmable Logic Controllers (PLCs) using OPC Unified Architecture (OPC UA) network protocol based communication. We implement an exemplary supply chain attack consisting of an OPC UA server (Bob, B) and a Siemens S7-1500 PLC as OPC UA client (Alice, A). The hidden storage channel is using source timestamps to embed encrypted control sequences allowing for setting digital outputs to arbitrary values. The attack is solely relying on the programming of the PLC and does not require firmware level access. Due to the potential harm to life caused by attacks on cyber-physical systems any presentation of novel attack vectors need to present suitable mitigation strategies. Thus, we investigate potential approaches for the detection of the hidden storage channel for a warden W as well as potential countermeasures in order to increase the warden-compliance. Our machine learning based detection approach using a One-Class-Classifier yields a detection performance of 89.5% with zero false positives within an experiment with 46,159 OPC UA read responses without a steganographic message and 7,588 OPC UA read responses with an embedded steganographic message.
Mario Hildebrandt, Kevin Lamshöft, Jana Dittmann, Tom Neubert, Claus Vielhauer
IH&MMSec5
2020 Keystroke biometrics in the encrypted domain: a first study on search suggestion functions of web search engines
abstract
Abstract A feature of search engines is prediction and suggestion to complete or extend input query phrases, i.e. search suggestion functions (SSF). Given the immediate temporal nature of this functionality, alongside the character submitted to trigger each suggestion, adequate data is provided to derive keystroke features. The potential of such biometric features to be used in identification and tracking poses risks to user privacy.For our initial experiment, we evaluate SSF traffic with different browsers and search engines on a Linux PC and an Android mobile phone. The keystroke network traffic is captured and decrypted using mitmproxy to verify if expected keystroke information is contained, which we call quality assurance (QA). In our second experiment, we present first results for identification of five subjects searching for up to three different phrases on both PC and phone using naive Bayesian and nearest neighbour classifiers. The third experiment investigates potential for identification and verification by an external observer based purely on the encrypted traffic, thus without QA, using the Euclidean distance. Here, ten subjects search for two phrases across several sessions on a Linux virtual machine, and statistical features are derived for classification. All three test cases show positive tendencies towards the feasibility of distinguishing users within a small group. The results yield lowest equal error rates of 5.11% for the single PC and 11.37% for the mobile device with QA and 23.61% for various PCs without QA. These first tendencies motivate further research in feature analysis of encrypted network traffic and prevention approaches to ensure protection and privacy.
Nicholas Whiskerd, Nicklas Körtge, Kris Jürgens, Kevin Lamshöft, Salatiel Ezennaya-Gomez, Claus Vielhauer, Jana Dittmann, Mario Hildebrandt
EURASIP J. Inf. Secur.6
2017 Towards Automated Forensic Pen Ink Verification by Spectral Analysis
Michael Kalbitz, Tobias Scheidat, Benjamin Yüksel, Claus Vielhauer
IWDW4
2017 A First Public Research Collection of High-Resolution Latent Fingerprint Time Series for Short- and Long-Term Print Age Estimation
abstract
The creation of publicly available image databases for the signal processing community is a very time-consuming, yet immensely valuable task, enabling scientific progress by providing the opportunity of an objective comparison and reproduction of results. This paper presents for the first time a public research collection of high-resolution latent fingerprint time series for age estimation, captured from a pool of 116 different test subjects. It comprises ten different sets with a total of 2,618 time series (117,384 scans), varying between capturing devices (CWL and CLSM), data types (intensity versus topography), aging periods (short-term aging: 24 h, long-term aging: 0.5 - 3 years) and resolutions (1,270 - 180,142 ppi). Most series are annotated with donor information (age and gender) and capturing conditions (scan parameters, ambient temperature, and humidity). The data are anonymized (using partial prints only) and an organizational revocation mechanism is included to assure non-identifiability of donors in the future. Baseline results for age estimation on all ten sets are provided in the form of correlation coefficients and machine-learning based age estimation (kappa), using 19 features from prior feature spaces as well as new ones (Tamura contrast, Benford's law, and improved dust feature). Classification results exhibit kappa values between 0.51 and 0.85, highlighting the progress made in this very challenging area in recent years and also emphasizing the need of future studies on the issue.
Ronny Merkel, Jana Dittmann, Claus Vielhauer
IEEE Trans. Inf. Forensics Secur.3
2015 From classical forensics to digitized crime scene analysis
abstract
The aim of this paper is to discuss selected aspects of the emerging trend of digitization in the field of crime scene forensics, known as 'digitized crime scene forensics'. This work summarizes recent findings in the field and discusses the current state of transfer from the analogue to the digital domain. The trace types of latent fingerprints, fibers as well as firearm and lock picking related toolmarks are addressed in respect to the major steps of acquisition, preprocessing, feature extraction and decision making, as support for the subjective expert assessment. Based on the findings, challenges are identified to provide future directions on the issue and to stimulate an increased research in this area. Overall, it can be concluded that a complete digital and automated processing pipeline is missing for most of the considered trace types. The introduction of first digital processing schemes has enabled certain novel, so far not-addressed opportunities, such as separation of overlapped prints, age estimation as well as the application of topographic data and has been able to provide first promising results. But even if parts of this pipeline have been recently automated in first studies, significant challenges remain, such as selecting suitable capturing devices and processing methods, identifying characteristic features and classification strategies as well as employing comprehensive test sets. Most of all, the final classification performance is often not yet good enough to achieve the quality of results obtained in manual investigations, and a significant research effort is required to address the specific needs of numerous trace types and investigation objectives.
Ronny Merkel, Claus Vielhauer, Jana Dittmann, Robert Fischer 0001, Mario Hildebrandt, Christian Arndt
ICME2
2015 Automated Firearm Identification: On using a novel Multiple-Slice-Shape (MSS) Approach for Comparison and Matching of Firing Pin Impression Topography
abstract
The examination of firearm related toolmarks impressed to cartridges and bullets is a well known forensic discipline. The application of three dimensional imaging systems and pattern recognition techniques for automatic comparison and matching of topographic data is a central field of research in the domain of digital crime scene analysis. In this work, we introduce and evaluate a novel Multiple-Slice-Shape (MSS) approach with the objective to closer link the preprocessing and feature extraction stages and improve the automated examinations of firearm toolmark surface data. We employ two existing features which are applied to the topography of firing pin impressions and aim at an automatic matching of the shapes based on multiple line-profile measurement. We suggest several modifications of the original Multiple-Angle-Path (MAP) and Multiple-Circle-Path (MCP) features to achieve an optimal integration into the proposed processing pipeline. Our evaluation approach is three-fold. First, we aim at the determination of an initial parameterization for MSS processing and feature extraction. Second, we evaluate the accuracy of discrimination for two firearms of the same mark and model. Third, we evaluate the accuracy using six different weapons. The test set contains 72 cartridge samples including six guns and three ammunition manufactures. Regarding the first evaluation, the results indicate an improvement of the accuracy for both features. Regarding the second evaluation, the achieved accuracy ranges between 67% and 100% for the MAP feature, and between 92% and 100% for the MCP feature. With respect to the third evaluation, the best result is achieved for MAP32 with 73% and for MCP15 with 92% compared to 56% and 82% correct classification rate regarding the original versions. It is supposed that various 3D spatial features can be combined and maybe improved by using the proposed MSS approach. We motivate the evaluation of this question for future work.
Robert Fischer 0001, Claus Vielhauer
IH&MMSec2
2014 Digital crime scene analysis: automatic matching of firing pin impressions on cartridge bottoms using 2d and 3d spatial features
abstract
The examination of forensic toolmarks impressed on shot cartridges and bullets is a well known and broadly accepted forensic discipline. The underlying concept is based on two main hypotheses: every firearm owns unique toolmark characteristics which lead to consistent and reproducible impressions on cartridges and bullets. Furthermore, it is possible to differentiate between markings of two different firearms. The application of optical 2D and 3D sensing technologies for acquisition, as well as pattern recognition techniques for automated toolmark examination are currently emerging fields of research in the domain of digital crime scene analysis. In this paper we propose and evaluate a pattern recognition approach for automated firearm identification based on central-fire firing pin impressions. The entire pattern recognition chain is addressed, starting with a confocal microscope for optical data acquisition. The preprocessing covers image enhancement, as well as necessary registration and segmentation tasks for cartridge bottoms. Feature extraction involves 18 firing pin related features from 2D and 3D spatial domain. The classification accuracy is evaluated by using 10-fold stratified cross-validation. Our evaluation approach is two-fold, during the first part we examine how well it is possible to differentiate between two firearms of the same mark and model. During the second part the evaluation is extended to analyze the accuracy of discrimination using six different weapons, whereby each two guns are of the same model. The test set contains 72 cartridge samples including three different ammunition manufactures and six individual 9mm guns. Every possible combination of weapon model, instance and ammunition type is represented by four samples within the test set. Regarding the first evaluation goal a classification accuracy between 87.5% and 100% is achieved. For the second evaluation goal the achieved classification accuracy equates to 86.11%.
Robert Fischer 0001, Claus Vielhauer
IH&MMSec2
2013 First investigation of latent fingerprints long-term aging using chromatic white light sensors
abstract
Non-invasive high-resolution Chromatic White Light (CWL) measurement devices offer great potential for solving the challenge of latent fingerprints age determination. In this paper, we place 40 prints from different subjects on hard disk platters and capture them from three different indoor locations every week over 1.5 years, acquiring high-resolution time series (10 μm and 20 μm). In contrast to prior findings from Popa et al. (using glass substrates) we show that the ridge thickness of our very precise images does not significantly decrease over time (test goal 1). We furthermore show that pores exhibit a significant loss in contrast and contour, which might lead to the impression of becoming bigger and fewer (test goal 2). Computing the contrast based Binary Pixel aging feature (test goal 3), we observe very characteristic results, leading to the conclusion that the dominant aging property seems to be an overall loss of image contrast rather than a specific change of ridge thickness or pore size. Comparing our findings between three different indoor locations (test goal 4) and discussing them from a police point of view, we conclude that sweat composition, environmental influences and scan parameters have a significant impact on fingerprints long-term aging.
Ronny Merkel, Karen Otte, Robert Clausing, Jana Dittmann, Claus Vielhauer, Anja Bräutigam
IH&MMSec5
2009 Handwriting verification - Comparison of a multi-algorithmic and a multi-semantic approach
Tobias Scheidat, Claus Vielhauer, Jana Dittmann
Image Vis. Comput.2
2009 Benchmarking quality-dependent and cost-sensitive score-level multimodal biometric fusion algorithms
abstract
Automatically verifying the identity of a person by means of biometrics (e.g., face and fingerprint) is an important application in our day-to-day activities such as accessing banking services and security control in airports. To increase the system reliability, several biometric devices are often used. Such a combined system is known as a multimodal biometric system. This paper reports a benchmarking study carried out within the framework of the BioSecure DS2 (Access Control) evaluation campaign organized by the University of Surrey, involving face, fingerprint, and iris biometrics for person authentication, targeting the application of physical access control in a medium-size establishment with some 500 persons. While multimodal biometrics is a well-investigated subject in the literature, there exists no benchmark for a fusion algorithm comparison. Working towards this goal, we designed two sets of experiments: quality-dependent and cost-sensitive evaluation. The quality-dependent evaluation aims at assessing how well fusion algorithms can perform under changing quality of raw biometric images principally due to change of devices. The cost-sensitive evaluation, on the other hand, investigates how well a fusion algorithm can perform given restricted computation and in the presence of software and hardware failures, resulting in errors such as failure-to-acquire and failure-to-match. Since multiple capturing devices are available, a fusion algorithm should be able to handle this nonideal but nevertheless realistic scenario. In both evaluations, each fusion algorithm is provided with scores from each biometric comparison subsystem as well as the quality measures of both the template and the query data. The response to the call of the evaluation campaign proved very encouraging, with the submission of 22 fusion systems. To the best of our knowledge, this campaign is the first attempt to benchmark quality-based multimodal fusion algorithms. In the presence of changing image quality which may be due to a change of acquisition devices and/or device capturing configurations, we observe that the top performing fusion algorithms are those that exploit automatically derived quality measurements. Our evaluation also suggests that while using all the available biometric sensors can definitely increase the fusion performance, this comes at the expense of increased cost in terms of acquisition time, computation time, the physical cost of hardware, and its maintenance cost. As demonstrated in our experiments, a promising solution which minimizes the composite cost is sequential fusion, where a fusion algorithm sequentially uses match scores until a desired confidence is reached, or until all the match scores are exhausted, before outputting the final combined score.
Norman Poh, Thirimachos Bourlai, Josef Kittler, Lorène Allano, Fernando Alonso-Fernandez, Onkar Ambekar, John P. Baker, Bernadette Dorizzi, Omolara Fatukasi, Julian Fierrez, Harald Ganster, Javier Ortega-Garcia, Donald E. Maurer, Albert Ali Salah, Tobias Scheidat, Claus Vielhauer
IEEE Trans. Inf. Forensics Secur.16
2007 Single-Semantic Multi-Instance Fusion of Handwriting Based Biometric Authentication Systems
abstract
The fusion of biometric systems, algorithms and/or traits is a well known solution to improve authentication performance of biometric systems. In this article the fusion of two instances of the same semantic is suggested, where semantics are alternative handwritten contents such as numbers or sentences, in addition to commonly used signature. In order to fuse two instances of one semantic, a biometric authentication is carried out on both by Biometric Hash algorithm up to matching score computation. The fusion is done by combination of matching scores to a joint score as basis for authentication decision. Three individual fusion strategies are used to study to which degree the authentication performance can be improved or degraded. Therefore one pragmatic and two optimistically weighting approaches for biometric fusion are used. The best fusion result is even better than the corresponding best individual result by approximately 17%.
Tobias Scheidat, Claus Vielhauer, Jana Dittmann
ICIP (2)2
2007 Trainable Sketch Recognizer for Graphical User Interface Design
Adrien Coyette, Sascha Schimke, Jean Vanderdonckt, Claus Vielhauer
INTERACT (1)4
2005 Distance-Level Fusion Strategies for Online Signature Verification
abstract
In this paper an approach for combining online signature authentication experts will be proposed. The different experts are based on one feature extraction method presented in our earlier work, the Biometric Hash algorithm [C. Viehauer, et al., (2002)], to which different distance measurement functions are applied. We will show that by the fusion of several algorithms with an appropriately parameterized strategy an improvement of the recognition accuracy can be achieved. The best fusion strategy results in a decrease of the EER of 12.1% in comparison to the best individual algorithm. The database we used contains 1761 genuine enrollments (with 4 signatures per enrollment), 1101 genuine verification signatures and 431 well skilled forgeries (so-called "brute force attack") by 22 persons. Based on our experimental results, we further discuss usability of alternative handwriting semantics such as pass phrases or PIN
Tobias Scheidat, Claus Vielhauer, Jana Dittmann
ICME2
2003 A test tool to support brute-force online and offline signature forgery tests on mobile devices
abstract
Testing of biometric systems requires the consideration of aspects beyond technical and statistical parameters. Especially for testing biometric techniques based on behavior, human factors like intention and forgery strength need to be considered. In this paper, a test tool to support skilled forgeries by test subjects is presented for handwriting verification systems. The software tool has been implemented on two computer platforms and is based on a three level forgery quality model. First experimental results are presented, which indicate that by applying the presented system in attack tests, forgeries of gradual quality can be obtained from test persons.
Frank Zoebisch, Claus Vielhauer
ICME2
2002 Biometric applications based on handwriting
abstract
A wide variety of biometric based techniques have been proposed but it is quite difficult to classify the approaches according to their application domains and to measure their functionality. Our intention is to classify today's applications in detail for one particular biometric scheme, handwriting. To give individual users with a specific application in mind orientation and a decision tool, we have built a new classification scheme and furthermore define major characteristics for each of the application classes as an evaluation matrix.
Falko Ramann, Claus Vielhauer, Ralf Steinmetz
ICME (2)2
2001 Transitivity Based Enrollment Strategy for Signature Verification
Claus Vielhauer, Ralf Steinmetz, Astrid Mayerhöfer
ICDAR1