EDBT 2026 Demo / reviewers in the wild / expert
Martin Strohmeier
dblp:117/8959
· DBLP profile ↗
41ranked-venue papers
6as first author
31since 2021 · last 2026
0000-0002-1936-0933ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 29 · 3 first-author · 23 since 2021Computer networks · 4 · 1 first-author · 1 since 2021Artificial intelligence and machine learning · 3 · 3 since 2021Human-computer interaction and ubiquitous computing · 3 · 3 since 2021Databases, data management, data science and information retrieval · 1 · 1 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | SatBleed: Security of Commoditized Communication Modules in Satellites
Ulysse Planta, Julian Rederlechner, Martin Strohmeier, Mathias Fischer 0001, Ali Abbasi 0002 |
SP | 3 |
| 2026 | OpenSky: How a Security Project Became Global Infrastructure
Ivan Martinovic, Martin Strohmeier |
WISEC | 2 |
| 2026 | SideDish: Low-Cost Anti-Spoofing Countermeasure for Satellite Data CommunicationsabstractSatellite systems are increasingly vulnerable to spoofing attacks at the physical layer, where adversaries use inexpensive radio equipment to interfere with and replace legitimate signals. While cryptographic countermeasures are common in other wireless systems, their adoption in new space programs is slow due to concerns about the associated implications on robustness, cost, weight, power, and the challenges of updating existing systems. In this paper we introduce SideDish, a novel anti-spoofing countermeasure that combines a secondary receiver colocated at the satellite receiver with decoded signal comparison to detect out-of-beam unauthentic interference. The system is retrofittable into existing ground station deployments, cheap by using only low-cost components, and is robust against denial of service attacks. We verify this through simulations and real-world experiments that show SideDish spatially constraints attackers by between 70-99.84% in the angular domain, even considering scattering effects of the primary antenna. Targeting SideDish to deny service is not feasible within practical constraints, requiring microsecond-order timing accuracy to overcome. Edd Salkield, Louis-Emile Ploix, Martin Strohmeier, Sebastian Köhler 0005, Simon Birnbach, Ivan Martinovic |
WISEC | 3 |
| 2026 | SatIQ: Extensible and Stable Satellite Authentication using Hardware FingerprintingabstractAs satellite systems become a greater part of critical infrastructure, they have become a significantly more appealing target for attacks. The availability of cheap off-the-shelf radio hardware has made signal spoofing and physical layer attacks more accessible than ever to a wide range of adversaries, from hobbyists to nation-state actors. Legacy systems are particularly vulnerable due to their lack of cryptographic security, and cannot be patched to support novel security measures. In this article, we use radio transmitter fingerprinting to authenticate satellite downlinks, using characteristics of the transmitter hardware expressed as impairments on the physical layer radio signal. Our SatIQ system employs a Siamese neural network and an autoencoder to extract an efficient encoding of message headers that preserves identifying information. We focus on high sample rate fingerprinting, making device fingerprints difficult to forge without similarly high sample rate transmitting hardware. We collected 10290000 messages from the Iridium satellite constellation at 25 MS/s, and demonstrate that the SatIQ model trained on this data maintains performance over time without retraining, and can be used on new transmitters with no impact on performance. We analyze the system’s robustness against weather and signal factors, and demonstrate its effectiveness under attack, achieving an Equal Error Rate of 0.072 and ROC AUC of 0.960. We conclude that our techniques are useful for building fingerprinting systems that are effective at authenticating satellite communication, maintain performance over time and across satellite replacement, and provide robustness against spoofing and replay by raising the required budget for attacks. Joshua Smailes, Sebastian Köhler 0005, Simon Birnbach, Martin Strohmeier, Ivan Martinovic |
ACM Trans. Priv. Secur. | 4 |
| 2025 | It's a Match - Enhancing the Fit between Users and Phishing Training through PersonalisationabstractEffective training is essential for enhancing users’ ability to detect phishing attempts. Personalised training offers huge potential to more closely align training content with individuals’ needs and skill levels. In an online study, we assigned N=342 participants to personalised training or a random training variant to compare their effectiveness. The personalisation was based on a phishing proficiency score calculated from factors such as detection ability, knowledge, and security attitude. After training, the participants demonstrated greater proficiency, with an increased ability to detect phishing emails and higher security attitudes. These effects were most pronounced in the personalised condition, demonstrating the potential of personalisation to improve training outcomes. Overall, personalised training levelled the playing field, efficiently bringing all groups, regardless of their initial proficiency, to a comparable and desired post-training phishing proficiency level. Finally, we derived recommendations for designing personalised phishing training content and assigning users to suitable training programmes. Lorin Schöni, Neele Roch, Hannah Sievers, Martin Strohmeier, Peter Mayer 0001, Verena Zimmermann |
CHI | 4 |
| 2025 | Stop the Clock - Counteracting Bias Exploited by Attackers through an Interactive Augmented Reality Phishing Training
Lorin Schöni, Martin Strohmeier, Ivo Sluganovic, Verena Zimmermann |
CHI | 2 |
| 2025 | SpaceJam: Protocol-aware Jamming Attacks against Space CommunicationsabstractMotivated by the growing prevalence of increasingly advanced satellite jamming attacks, we introduce and systematically analyze protocol-aware jammers: the worst-case scenario that maximally exploits the protocol to deny service whilst remaining as difficult to detect as possible. This extends existing satellite jamming and anti-jamming literature, which to date considers only conventional jamming waveforms. We find that protocol-aware jammers are significantly more effective than conventional jammers against all major standardized satellite protocols, including when anti-jamming countermeasures in the form of interleaving and adaptive coding and modulation are employed. This performance is possible since current protocols have a cyclic and predictable nature. We assess the required capabilities in terms of synchronization, and show that many of these performance gains can be realized even by completely desynchronized jammers. We experimentally evaluate protocol-aware strategies against both a hardware and software receiver. The results show that over 15dB of performance gains over Gaussian jamming are possible against all tested satellite protocols. Furthermore, we find that the attack can be optimized in simulation and deployed against the hardware receiver without performance degradation. We conclude with a discussion of countermeasures, primarily at the protocol level, to improve the availability of these systems. Edd Salkield, Sebastian Köhler 0005, Simon Birnbach, Martin Strohmeier, Ivan Martinovic |
WISEC | 4 |
| 2025 | Universal Spoofing of Real-World Aircraft Multilaterationabstractpeer reviewed Oliver Senn, Giorgio Tresoldi, Daniel Moser, Vincent Lenders, Martin Strohmeier |
WISEC | 5 |
| 2025 | Collective victim counting in post-disaster response: A distributed, power-efficient algorithm via BLE spontaneous networksabstractAccurately determining the number of people affected by emergencies is essential for deploying effective response measures during disasters. Traditional solutions like cellular and Wi-Fi networks are often rendered ineffective during such emergencies due to widespread infrastructure damage or non-functional connectivity, prompting the exploration of more resilient methods. This paper proposes a novel solution utilizing Bluetooth Low Energy (BLE) technology and decentralized networks composed entirely of mobile and wearable devices to count individuals autonomously without reliance on external communication equipment or specialized personnel. This count leverages uncoordinated relayed communication among devices within these networks, enabling us to extend our counting capabilities well beyond the direct range of rescuers. A formally evaluated, experimentally validated, and privacy-preserving counting algorithm that demonstrates rapid convergence and high accuracy even in large-scale scenarios is employed. Giacomo Longo, Alessandro Cantelli-Forti, Enrico Russo 0001, Francesco Lupia, Martin Strohmeier, Andrea Pugliese 0001 |
Pervasive Mob. Comput. | 5 |
| 2024 | Assault and Battery: Evaluating the Security of Power Conversion Systems Against Electromagnetic Injection AttacksabstractMany modern devices, including critical infrastructure, depend on the reliable operation of electrical power conversion systems. The small size and versatility of switched-mode power converters has led to their widespread use. While transformer-based systems passively convert voltage, switched-mode power converters have an actively controlled feedback loop that relies on accurate sensor measurements. Previous academic work has shown that many types of sensors are vulnerable to Intentional Electromagnetic Interference (IEMI) attacks, and it has been speculated that power converters are also susceptible.In this paper, we present the first detailed and practical evaluation of IEMI attacks against switched-mode power converters as a whole by manipulating the voltage and current sensors in their feedback loops. We develop a novel multi-frequency IEMI attack technique to effectively target devices with multiple sensors. We experimentally validate our theoretical predictions by analyzing multiple AC-DC and DC-DC converters, automotive-grade current sensors, dedicated battery chargers, and a real-world electric vehicle charger. Our attack is reliably effective at overcharging and permanently damaging Li-ion cells, and causing the EV charger to output 50 V more than it reports. Marcell Szakály, Sebastian Köhler 0005, Martin Strohmeier, Ivan Martinovic |
ACSAC | 3 |
| 2024 | Secret Collusion among AI Agents: Multi-Agent Deception via SteganographyabstractRecent advancements in generative AI suggest the potential for large-scale interaction between autonomous agents and humans across platforms such as the internet. While such interactions could foster productive cooperation, the ability of AI agents to circumvent security oversight raises critical multi-agent security problems, particularly in the form of unintended information sharing or undesirable coordination. In our work, we establish the subfield of secret collusion, a form of multi-agent deception, in which two or more agents employ steganographic methods to conceal the true nature of their interactions, be it communicative or otherwise, from oversight. We propose a formal threat model for AI agents communicating steganographically and derive rigorous theoretical insights about the capacity and incentives of large language models (LLMs) to perform secret collusion, in addition to the limitations of threat mitigation measures. We complement our findings with empirical evaluations demonstrating rising steganographic capabilities in frontier single and multi-agent LLM setups and examining potential scenarios where collusion may emerge, revealing limitations in countermeasures such as monitoring, paraphrasing, and parameter optimization. Our work is the first to formalize and investigate secret collusion among frontier foundation models, identifying it as a critical area in AI Safety and outlining a comprehensive research agenda to mitigate future risks of collusion between generative AI systems. Sumeet Ramesh Motwani, Mikhail Baranchuk, Martin Strohmeier, Vijay Bolina, Philip Torr 0001, Lewis Hammond, Christian Schröder de Witt |
NeurIPS | 3 |
| 2024 | Wireless Signal Injection Attacks on VSAT Satellite Modems
Robin Bisping, Johannes Willbold, Martin Strohmeier, Vincent Lenders |
USENIX Security Symposium | 3 |
| 2024 | RECORD: A RECeption-Only Region Determination Attack on LEO Satellite Users
Eric Jedermann, Martin Strohmeier, Vincent Lenders, Jens B. Schmitt |
USENIX Security Symposium | 2 |
| 2024 | On a Collision Course: Unveiling Wireless Attacks to the Aircraft Traffic Collision Avoidance System (TCAS)
Giacomo Longo, Martin Strohmeier, Enrico Russo 0001, Alessio Merlo, Vincent Lenders |
USENIX Security Symposium | 2 |
| 2024 | VSAsTer: Uncovering Inherent Security Issues in Current VSAT System PracticesabstractRecent geopolitical events have exposed our critical dependence on the wireless infrastructure used to facilitate worldwide communication. State-sponsored groups are actively attacking and exploiting space-based communication networks, causing outages and serious economic damage. Despite initial research findings pointing out a lack of security, such networks enjoy growing adoption and are still placed at the heart of today's communication infrastructure, ranging form the transportation sector over oil rigs to consumer internet. Worryingly, the command and control networks that support this satellite-based communication have received little attention from the security community so far. Johannes Willbold, Moritz Schloegel, Robin Bisping, Martin Strohmeier, Thorsten Holz, Vincent Lenders |
WISEC | 4 |
| 2023 | Watch This Space: Securing Satellite Communication through Resilient Transmitter FingerprintingabstractDue to an increase in the availability of cheap off-the-shelf radio hardware, signal spoofing and replay attacks on satellite ground systems have become more accessible than ever. This is particularly a problem for legacy systems, many of which do not offer cryptographic security and cannot be patched to support novel security measures. Joshua Smailes, Sebastian Köhler 0005, Simon Birnbach, Martin Strohmeier, Ivan Martinovic |
CCS | 4 |
| 2023 | Perfectly Secure Steganography Using Minimum Entropy Coupling
Christian Schröder de Witt, Samuel Sokota, J. Zico Kolter, Jakob N. Foerster, Martin Strohmeier |
ICLR | 5 |
| 2023 | Brokenwire : Wireless Disruption of CCS Electric Vehicle Charging
Sebastian Köhler 0005, Richard Baker 0008, Martin Strohmeier, Ivan Martinovic |
NDSS | 3 |
| 2023 | FABRID: Flexible Attestation-Based Routing for Inter-Domain Networks
Cyrill Krähenbühl, Marc Wyss, David A. Basin, Vincent Lenders, Adrian Perrig, Martin Strohmeier |
USENIX Security Symposium | 6 |
| 2023 | Satellite Spoofing from A to Z: On the Requirements of Satellite Downlink Overshadowing AttacksabstractSatellite communications are increasingly crucial for telecommunications, navigation, and Earth observation. However, many widely used satellites do not cryptographically secure the downlink, opening the door for radio spoofing attacks. Recent developments in software-defined radio hardware have enabled attacks on wireless systems including GNSS, which can be effectively spoofed using only cheap hardware available off the shelf. However, these conclusions do not generalize well to other satellite systems such as high data rate backhauls or satellite-to-customer connections, where the spoofing requirements are currently unknown. In this paper, we present a systematic review of spoofing attacks against satellite downlink communications systems. We establish a threat model linking attack feasibility and impact to required budget through real-world experiments and channel simulations. Our results show that nearly all evaluated satellite systems were overshadowable at a distance of 1 km in the worst case, for a budget of ~2000 USD or less. We evaluate how key challenges surrounding modulation schemes, antenna directionality, and legitimate satellite signal strength can be overcome in practice through antenna sidelobe targeting, overshadowing, and automatic gain control takeover. We also show that, surprisingly, protocols designed to be more robust against channel noise are significantly less robust against an overshadowing attacker. We conclude with a discussion of physical-layer countermeasures specifically applicable to satellite systems which can not be cryptographically upgraded. Edd Salkield, Marcell Szakály, Joshua Smailes, Sebastian Köhler 0005, Simon Birnbach, Martin Strohmeier, Ivan Martinovic |
WISEC | 6 |
| 2022 | On the Security of the FLARM Collision Warning SystemabstractIn the past decade, the vulnerability of aircraft communications against low-resourced attackers has received significant attention both in the information security community and from aviation industry and regulators. Until now, research on attacks against such communications technologies has focused on larger aircraft, neglecting the technologies used in light aircraft and unmanned aerial vehicles (UAV). As such lighter aircraft make up a large and growing majority of both airspace users and casualties, this is a glaring oversight from a security and safety perspective. Boya Wang, Giorgio Tresoldi, Martin Strohmeier, Vincent Lenders |
AsiaCCS | 3 |
| 2022 | Demo: End-to-End Wireless Disruption of CCS EV ChargingabstractThe shift from vehicles with internal combustion engines (ICE) to fully Electric Vehicles (EVs) is happening at a rapid pace. To be competitive with ICEs and ensure a smooth rollout, the charging process of EVs needs to be as fast and convenient as possible. Modern DC fast-charging standards achieve this by implementing a high-level charging communication (HLC), which enables a safe, efficient, and convenient charging experience. Sebastian Köhler 0005, Richard Baker 0008, Martin Strohmeier, Ivan Martinovic |
CCS | 3 |
| 2022 | Building Collaborative Cybersecurity for Critical Infrastructure Protection: Empirical Evidence of Collective Intelligence Information Sharing Dynamics on ThreatFoxabstractAbstract This article describes three collective intelligence dynamics observed on ThreatFox, a free platform operated by abuse.ch that collects and shares indicators of compromise. These three dynamics are empirically analyzed with an exclusive dataset provided by the sharing platform. First, participants’ onboarding dynamics are investigated and the importance of building collaborative cybersecurity on an established network of trust is highlighted. Thus, when a new sharing platform is created by abuse.ch, an existing trusted community with ’power users’ will migrate swiftly to it, in order to enact the first sparks of collective intelligence dynamics. Second, the platform publication dynamics are analyzed and two different superlinear growths are observed. Third, the rewarding dynamics of a credit system is described - a promising incentive mechanism that could improve cooperation and information sharing in open-source intelligence communities through the gamification of the sharing activity. Overall, our study highlights future avenues of research to study the institutional rules enacting collective intelligence dynamics in cybersecurity. Thus, we show how the platform may improve the efficiency of information sharing between critical infrastructures, for example within Information Sharing and Analysis Centers using ThreatFox. Finally, a broad agenda for future empirical research in the field of cybersecurity information sharing is presented - an important activity to reduce information asymmetry between attackers and defenders. Eric Jollès, Sébastien Gillard, Dimitri Percia David, Martin Strohmeier, Alain Mermoud |
CRITIS | 4 |
| 2022 | Communicating via Markov Decision ProcessesabstractWe consider the problem of communicating exogenous information by means of Markov decision process trajectories. This setting, which we call a Markov coding game (MCG), generalizes both source coding and a large class of referential games. MCGs also isolate a problem that is important in decentralized control settings in which cheap-talk is not available—namely, they require balancing communication with the associated cost of communicating. We contribute a theoretically grounded approach to MCGs based on maximum entropy reinforcement learning and minimum entropy coupling that we call MEME. Due to recent breakthroughs in approximation algorithms for minimum entropy coupling, MEME is not merely a theoretical algorithm, but can be applied to practical settings. Empirically, we show both that MEME is able to outperform a strong baseline on small MCGs and that MEME is able to achieve strong performance on extremely large MCGs. To the latter point, we demonstrate that MEME is able to losslessly communicate binary images via trajectories of Cartpole and Pong, while simultaneously achieving the maximal or near maximal expected returns, and that it is even capable of performing well in the presence of actuator noise. Samuel Sokota, Christian Schröder de Witt, Maximilian Igl, Luisa M. Zintgraf, Philip Torr 0001, Martin Strohmeier, J. Zico Kolter, Shimon Whiteson, Jakob N. Foerster |
ICML | 6 |
| 2022 | Aggregate-based congestion control for pulse-wave DDoS defenseabstractPulse-wave DDoS attacks are a new type of volumetric attack formed by short, high-rate traffic pulses. Such attacks target the Achilles' heel of state-of-the-art DDoS defenses: their reaction time. By continuously adapting their attack vectors, pulse-wave attacks manage to render existing defenses ineffective. Albert Gran Alcoz, Martin Strohmeier, Vincent Lenders, Laurent Vanbever |
SIGCOMM | 2 |
| 2022 | An Experimental Study of GPS Spoofing and Takeover Attacks on UAVs
Harshad Sathaye, Martin Strohmeier, Vincent Lenders, Aanjhan Ranganathan |
USENIX Security Symposium | 2 |
| 2021 | Studying Neutrality in Cyber-Space: a Comparative Geographical Analysis of Honeypot Responses
Martin Strohmeier, James Pavur, Ivan Martinovic, Vincent Lenders |
CRITIS | 1 |
| 2021 | QPEP: An Actionable Approach to Secure and Performant Broadband From Geostationary Orbit
James Pavur, Martin Strohmeier, Vincent Lenders, Ivan Martinovic |
NDSS | 2 |
| 2021 | SLAP: Improving Physical Adversarial Examples with Short-Lived Adversarial Perturbations
Giulio Lovisotto, Henry Turner, Ivo Sluganovic, Martin Strohmeier, Ivan Martinovic |
USENIX Security Symposium | 4 |
| 2021 | Orbit-based authentication using TDOA signatures in satellite networksabstractGiven the nature of satellites orbiting the Earth on a fixed trajectory, in principle, it is interesting to investigate how this invariant can be exploited for security purposes. In particular, satellite orbit information can be retrieved from public databases. Using time difference of arrival (TDOA) measurements from multiple receivers, we can check this orbit information against a corresponding TDOA-based signature of the satellite. In that sense, we propose an orbit-based authentication scheme for down-link satellite communications in this paper. To investigate the properties and fundamentals of our novel TDOA signature scheme we study two satellite systems at different altitudes: Iridium and Starlink. Eric Jedermann, Martin Strohmeier, Matthias Schäfer 0002, Jens B. Schmitt, Vincent Lenders |
WISEC | 2 |
| 2021 | Classi-Fly: Inferring Aircraft Categories from Open DataabstractIn recent years, air traffic communication data has become easy to access, enabling novel research in many fields. Exploiting this new data source, a wide range of applications have emerged, from weather forecasting to stock market prediction, or the collection of intelligence about military and government movements. Typically, these applications require knowledge about the metadata of the aircraft, specifically its operator and the aircraft category. armasuisse Science + Technology, the R&D agency for the Swiss Armed Forces, has been developing Classi-Fly, a novel approach to obtain metadata about aircraft based on their movement patterns. We validate Classi-Fly using several hundred thousand flights collected through open source means, in conjunction with ground truth from publicly available aircraft registries containing more than 2 million aircraft. We show that we can obtain the correct aircraft category with an accuracy of greater than 88%. In cases, where no metadata is available, this approach can be used to create the data necessary for applications working with air traffic communication. Finally, we show that it is feasible to automatically detect particular sensitive aircraft such as police and surveillance aircraft using this method. Martin Strohmeier, Matthew Smith 0006, Vincent Lenders, Ivan Martinovic |
ACM Trans. Intell. Syst. Technol. | 1 |
| 2020 | A View from the Cockpit: Exploring Pilot Reactions to Attacks on Avionic Systems
Matthew Smith 0006, Martin Strohmeier, Jon Harman, Vincent Lenders, Ivan Martinovic |
NDSS | 2 |
| 2020 | A Tale of Sea and Sky On the Security of Maritime VSAT CommunicationsabstractVery Small Aperture Terminals (VSAT) have revolutionized maritime operations. However, the security dimensions of maritime VSAT services are not well understood. Historically, high equipment costs have acted as a barrier to entry for both researchers and attackers. In this paper we demonstrate a substantial change in threat model, proving practical attacks against maritime VSAT networks with less than $400 of widely-available television equipment. This is achieved through GSExtract, a purpose-built forensic tool which enables the extraction of IP traffic from highly corrupted VSAT data streams.The implications of this threat are assessed experimentally through the analysis of more than 1.3 TB of real-world maritime VSAT recordings encompassing 26 million square kilometers of coverage area. The underlying network platform employed in these systems is representative of more than 60% of the global maritime VSAT services market. We find that sensitive data belonging to some of the world's largest maritime companies is regularly leaked over VSAT ship-to-shore communications. This threat is contextualized through illustrative case studies ranging from the interception and alteration of navigational charts to theft of passport and credit card details. Beyond this, we demonstrate the ability to arbitrarily intercept and modify TCP sessions under certain network configurations, enabling man-in-the-middle and denial of service attacks against ships at sea. The paper concludes with a brief discussion of the unique requirements and challenges for encryption in VSAT environments. James Pavur, Daniel Moser, Martin Strohmeier, Vincent Lenders, Ivan Martinovic |
SP | 3 |
| 2018 | The Real First Class? Inferring Confidential Corporate Mergers and Government Relations from Air Traffic CommunicationabstractThis paper exploits publicly available aircraft meta data in conjunction with unfiltered air traffic communication gathered from a global collaborative sensor network to study the privacy impact of large-scale aircraft tracking on governments and public corporations. First, we use movement data of 542 verified aircraft used by 113 different governments to identify events and relationships in the real world. We develop a spatio-temporal clustering method which returns 47 public and 18 non-public meetings attended by dedicated government aircraft over the course of 18 months. Additionally, we illustrate the ease of analyzing the long-term behavior and relationships of aviation users through the example of foreign governments visiting Europe. Secondly, we exploit the same types of data to predict potential merger and acquisition (M&A) activities by 36 corporations listed on the US and European stock markets. We identify seven M&A cases, in all of which the buyer has used corporate aircraft to visit the target prior to the official announcement, on average 61 days before. Finally, we analyze five existing technical and non-technical mitigation options available to the individual stakeholders. We quantify their popularity and effectiveness, finding that despite their current widespread use, they are ineffective against the presented exploits. Consequently, we argue that regulatory and technical changes are required to be able to protect the privacy of non-commercial aviation users in the future. Martin Strohmeier, Matthew Smith 0006, Vincent Lenders, Ivan Martinovic |
EuroS&P | 1 |
| 2018 | Undermining Privacy in the Aircraft Communications Addressing and Reporting System (ACARS)abstractAbstract Despite the Aircraft Communications, Addressing and Reporting System (ACARS) being widely deployed for over twenty years, little scrutiny has been applied to it outside of the aviation community. Whilst originally utilized by commercial airlines to track their flights and provide automated timekeeping on crew, today it serves as a multi-purpose air-ground data link for many aviation stakeholders including private jet owners, state actors and military. Such a change has caused ACARS to be used far beyond its original mandate; to date no work has been undertaken to assess the extent of this especially with regard to privacy and the various stakeholder groups which use it. In this paper, we present an analysis of ACARS usage by privacy sensitive actors-military, government and business. We conduct this using data from the VHF (both traditional ACARS, and VDL mode 2) and satellite communications subnetworks. Based on more than two million ACARS messages collected over the course of 16 months, we demonstrate that current ACARS usage systematically breaches location privacy for all examined aviation stakeholder groups, explaining the types of messages used to cause this problem.We illustrate the challenges with three case studies-one for each stakeholder group-to show how much privacy sensitive information can be constructed with a handful of ACARS messages. We contextualize our findings with opinions on the issue of privacy in ACARS from 40 aviation industry professionals. From this, we explore recommendations for how to address these issues, including use of encryption and policy measures. Matthew Smith 0006, Daniel Moser, Martin Strohmeier, Vincent Lenders, Ivan Martinovic |
Proc. Priv. Enhancing Technol. | 3 |
| 2017 | On Perception and Reality in Wireless Air Traffic Communication SecurityabstractMore than a dozen wireless technologies are used by air traffic communication systems during different flight phases. From a conceptual perspective, all of them are insecure, as security was never part of their design. Recent contributions from academic and hacking communities have exploited this inherent vulnerability to demonstrate attacks on some of these technologies. However, not all of these contributions have resonated widely within aviation circles. At the same time, the security community lacks certain aviation domain knowledge, preventing aviation authorities from giving credence to their findings. In this survey, we aim to reconcile the view of the security community and the perspective of aviation professionals concerning the safety of air traffic communication technologies. To achieve this, we first provide a systematization of the applications of wireless technologies upon which civil aviation relies. Based on these applications, we comprehensively analyze vulnerabilities and existing attacks. We further survey the existing research on countermeasures and categorize it into approaches that are applicable in the short term and research of secure new technologies deployable in the long term. Since not all of the required aviation knowledge is codified in academic publications, we additionally examine the existing aviation standards and survey 242 international aviation experts. Besides their domain knowledge, we also analyze the awareness of members of the aviation community concerning the security of wireless systems and collect their expert opinions on the potential impact of concrete attack scenarios using these technologies. Martin Strohmeier, Matthias Schäfer 0002, Rui Pinheiro, Vincent Lenders, Ivan Martinovic |
IEEE Trans. Intell. Transp. Syst. | 1 |
| 2015 | Intrusion Detection for Airborne Communication Using PHY-Layer Information
Martin Strohmeier, Vincent Lenders, Ivan Martinovic |
DIMVA | 1 |
| 2014 | Bringing up OpenSky: a large-scale ADS-B sensor network for research
Matthias Schäfer 0002, Martin Strohmeier, Vincent Lenders, Ivan Martinovic, Matthias Wilhelm 0001 |
IPSN | 2 |
| 2014 | Demonstration abstract: OpenSky: a large-scale ADS-B sensor network for research
Matthias Schäfer 0002, Martin Strohmeier, Vincent Lenders, Ivan Martinovic, Matthias Wilhelm 0001 |
IPSN | 2 |
| 2013 | Neighborhood watch: On network coding throughput and key sharingabstractNetwork coding (NC) has frequently been promoted as an approach for improving throughput in wireless networks. Existing work has mostly focused on the fundamental aspects of NC, while constraints arising in real-world network deployments have not received much attention. In particular, NC requires network nodes to overhear each other's packets, which oftentimes contradicts many security standards that attempt to provide link-layer confidentiality, e.g., by utilizing pairwise encryption keys as is the case IEEE 802.11i and ZigBee. There is an inherent trade-off between gains from NC and link-layer security: if many nodes share the secret link-layer key, NC will improve throughput, yet a leakage of the key will affect many nodes. On the other hand, having distinct secret keys will increase resilience against key compromise, but will also minimize the coding gain. We formulate this security vs. performance trade-off as an optimization problem and evaluate the effectiveness of NC under different sizes of key-sharing groups and network topologies. Our results show that increasing the key-sharing group by a single node can result in a maximum coding gain between 1.3% and 13.7%. Martin Strohmeier, Ivan Martinovic, Utz Roedig, Karim M. El Defrawy, Jens B. Schmitt |
GLOBECOM | 1 |
| 2012 | A Practical Man-In-The-Middle Attack on Signal-Based Key Generation Protocols
Simon Eberz, Martin Strohmeier, Matthias Wilhelm 0001, Ivan Martinovic |
ESORICS | 2 |