Sebastian Poeplau

dblp:123/5395 · DBLP profile ↗
← Back
6ranked-venue papers
5as first author
1since 2021 · last 2021
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 6 · 5 first-author · 1 since 2021

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Network and information security
2 papers
Hardware security and side channels · 45% Cryptographic primitives and cryptanalysis · 30% Web and mobile security · 8%
Software engineering, system software, and programming languages
2 papers
Program analysis · 70% Runtime systems and virtual machines · 24% Software testing · 6%

Topics — the 12 heaviest of 13, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Program analysis
symbolic execution
0.922021
SymQEMU: Compilation-based symbolic execution for binaries · NDSS 2021
Symbolic execution with SymCC: Don't interpret, compile! · USENIX Security Symposium 2020
Program analysis › symbolic execution
binary symbolic execution
0.512021
SymQEMU: Compilation-based symbolic execution for binaries · NDSS 2021
Runtime systems and virtual machines › binary translation
dynamic binary translation
0.512021
SymQEMU: Compilation-based symbolic execution for binaries · NDSS 2021
Cryptographic primitives and cryptanalysis › block cipher cryptanalysis
AES key recovery
0.312018
Screaming Channels: When Electromagnetic Side Channels Meet Radio Transceivers · CCS 2018
Hardware security and side channels › side-channel attack
electromagnetic side channel
0.312018
Screaming Channels: When Electromagnetic Side Channels Meet Radio Transceivers · CCS 2018
Cryptographic primitives and cryptanalysis › cryptanalysis
key recovery attack
0.312018
Screaming Channels: When Electromagnetic Side Channels Meet Radio Transceivers · CCS 2018
Hardware security and side channels
side-channel attack
0.312018
Screaming Channels: When Electromagnetic Side Channels Meet Radio Transceivers · CCS 2018
Hardware security and side channels › side-channel attack › profiled side-channel attack
template attack
0.312018
Screaming Channels: When Electromagnetic Side Channels Meet Radio Transceivers · CCS 2018
Malware analysis
android malware
0.212014
Execute This! Analyzing Unsafe and Malicious Dynamic Code Loading in Android Applications · NDSS 2014
Systems and software security
dynamic code loading
0.212014
Execute This! Analyzing Unsafe and Malicious Dynamic Code Loading in Android Applications · NDSS 2014
Web and mobile security
mobile security
0.212014
Execute This! Analyzing Unsafe and Malicious Dynamic Code Loading in Android Applications · NDSS 2014
Software testing
test generation
0.112020
Symbolic execution with SymCC: Don't interpret, compile! · USENIX Security Symposium 2020

Methods — techniques the papers use, named apart from their topics

compilation-based symbolic execution · 0.5template attack · 0.3electromagnetic measurement · 0.3correlation attack · 0.3static analysis · 0.2dynamic analysis · 0.2
YearPublicationVenuePosition
2021 SymQEMU: Compilation-based symbolic execution for binaries
Sebastian Poeplau, Aurélien Francillon
NDSS1
2020 Symbolic execution with SymCC: Don't interpret, compile!
Sebastian Poeplau, Aurélien Francillon
USENIX Security Symposium1
2019 Systematic comparison of symbolic execution systems: intermediate representation and its generation
abstract
Symbolic execution has become a popular technique for software testing and vulnerability detection. Most implementations transform the program under analysis to some intermediate representation (IR), which is then used as a basis for symbolic execution. There is a multitude of available IRs, and even more approaches to transform target programs into a respective IR.
Sebastian Poeplau, Aurélien Francillon
ACSAC1
2018 Screaming Channels: When Electromagnetic Side Channels Meet Radio Transceivers
abstract
This paper presents a new side channel that affects mixed-signal chips used in widespread wireless communication protocols, such as Bluetooth and WiFi. This increasingly common type of chip includes the radio transceiver along with digital logic on the same integrated circuit. In such systems, the radio transmitter may unintentionally broadcast sensitive information from hardware cryptographic components or software executing on the CPU. The well-known electromagnetic (EM) leakage from digital logic is inadvertently mixed with the radio carrier, which is amplified and then transmitted by the antenna. We call the resulting leak screaming channels. Attacks exploiting such a side channel may succeed over a much longer distance than attacks exploiting usual EM side channels. The root of the problem is that mixed-signal chips include both digital circuits and analog circuits on the same silicon die in close physical proximity. While processing data, the digital circuits on these chips generate noise, which can be picked up by noise-sensitive analog radio components, ultimately leading to leakage of sensitive information. We investigate the physical reasons behind the channel, we measure it on several popular devices from different vendors (including Nordic Semiconductor nRF52832, and Qualcomm Atheros AR9271), and we demonstrate a complete key recovery attack against the nRF52832 chip. In particular, we retrieve the full key from the AES-128 implementation in tinyAES at a distance of 10 m using template attacks. Additionally, we recover the key used by the AES-128 implementation in mbedTLS at a distance of 1 m with a correlation attack. Screaming channel attacks change the threat models of devices with mixed-signal chips, as those devices are now vulnerable from a distance. More specifically, we argue that protections against side channels (such as masking or hiding) need to be used on this class of devices. Finally, chips implementing other widespread protocols (e.g., 4G/LTE, RFID) need to be inspected to determine whether they are vulnerable to screaming channel attacks.
Giovanni Camurati, Sebastian Poeplau, Marius Muench, Thomas P. Hayes, Aurélien Francillon
CCS2
2014 Execute This! Analyzing Unsafe and Malicious Dynamic Code Loading in Android Applications
Sebastian Poeplau, Yanick Fratantonio, Antonio Bianchi, Christopher Krügel, Giovanni Vigna
NDSS1
2012 A honeypot for arbitrary malware on USB storage devices
abstract
Malware is a serious threat for modern information technology. It is therefore vital to be able to detect and analyze such malicious software in order to develop contermeasures. Honeypots are a tool supporting that task - they collect malware samples for analysis. Unfortunately, existing honeypots concentrate on malware that spreads over networks, thus missing any malware that does not use a network for propagation. A popular network-independent technique for malware to spread is copying itself to USB flash drives. In this article we present Ghost, a new kind of honeypot for such USB malware. It detects malware by simulating a removable device in software, thereby tricking malware into copying itself to the virtual device. We explain the concept in detail and evaluate it using samples of wide-spread malware. We conclude that this new approach works reliably even for sophisticated malware, thus rendering the concept a promising new idea.
Sebastian Poeplau, Jan Gassen
CRiSIS1