EDBT 2026 Demo / reviewers in the wild / expert
Johanna Ullrich
dblp:139/5512
· DBLP profile ↗
22ranked-venue papers
5as first author
10since 2021 · last 2026
0000-0003-0297-9614ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 18 · 5 first-author · 6 since 2021Computer networks · 3 · 3 since 2021Systems, architecture and hardware · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Hey there! You are using WhatsApp: Enumerating Three Billion Accounts for Security and Privacy
Gabriel K. Gegenhuber, Philipp É. Frenzel, Maximilian Günther, Johanna Ullrich, Aljosha Judmayer |
NDSS | 4 |
| 2026 | Continuous User Behavior Monitoring using DNS Cache Timing Attacks
Hannes Weissteiner, Roland Czerny, Simone Franza, Stefan Gast, Johanna Ullrich, Daniel Gruss |
NDSS | 5 |
| 2025 | Zero-Click SnailLoad: From Minimal to No User Interaction
Stefan Gast, Nora Puntigam, Simone Franza, Sudheendra Raghav Neela, Daniel Gruss, Johanna Ullrich |
ESORICS (4) | 6 |
| 2025 | Tracking Internet Disruptions in Ukraine: Insights from Three Years of Active Full Block ScansabstractNumerous disruptions to Internet access have been reported during the war in Ukraine, including large-scale outages, damage to network infrastructure, surveillance, and censorship measures. However, most observations rely on local reports or monitoring systems within Ukraine. In this paper, we investigate whether the conflict's impact on Internet connectivity can be observed externally, from a vantage point outside Ukraine. Focusing on the Kherson region, which has remained on the frontline for over three years, we conduct an active measurement campaign probing the Ukrainian address space at two-hour intervals since March 2, 2022, the 7th day of the invasion, resulting in a country-wide dataset that spans the full duration of the conflict. Extending existing outage detection approaches, we infer three signals to detect Internet disruptions and refine the mapping of ASes and address blocks to specific regions. This allows us to assign disruptions to oblasts with greater confidence. Our results demonstrate that Internet disruptions caused by the war can be measured remotely by any host connected to the Internet. Our analysis provides new insights into the resilience of small regional providers and identifies periods when Ukraine's Internet infrastructure was under significant strain. Florian Holzbauer, Sebastian Strobl, Johanna Ullrich |
IMC | 3 |
| 2025 | Careless Whisper: Exploiting Silent Delivery Receipts to Monitor Users on Mobile Instant MessengersabstractWith over 3 billion users globally, mobile instant messaging apps have become indispensable for both personal and professional communication. Besides plain messaging, many services implement additional features such as delivery and read receipts informing a user when a message has successfully reached its target. This paper highlights that delivery receipts can pose significant privacy risks to users. We use specifically crafted messages that trigger silent delivery receipts allowing any user to be pinged without their knowledge or consent. By using this technique at high frequency, we demonstrate how an attacker could extract private information such as following a user across different companion devices, inferring their daily schedule, or deducing current activities. Moreover, we can infer the number of currently active user sessions (i.e., main and companion devices) and their operating system, as well as launch resource exhaustion attacks, such as draining a user’s battery or data allowance, all without generating any notification on the target side. Due to the widespread adoption of vulnerable messengers (WhatsApp and Signal) and the fact that any user can be targeted simply by knowing their phone number, we argue for a design change to address this issue. Gabriel K. Gegenhuber, Maximilian Günther, Aljosha Judmayer, Florian Holzbauer, Philipp É. Frenzel, Johanna Ullrich |
RAID | 7 |
| 2024 | Destination Reachable: What ICMPv6 Error Messages Reveal About Their SourcesabstractThe probability of hitting an active IPv6 address by chance is virtually zero; instead, it appears more promising to analyze ICMPv6 error messages that are returned in case of an undeliverable packet. In this paper, we investigate the implementation of ICMPv6 error messages by different router vendors, whether a remote network's deployment status might be inferred from them, and analyze ICMPv6 error messaging behavior of routers in the IPv6 Internet. We find that Address Unreachable with a delay of more than a second indicates active networks, whereas Time Exceeded, Reject Route and Address Unreachable with short delays pinpoint inactive networks. Furthermore, we found that ICMPv6 rate-limiting implementations, used to protect routers, allow the fingerprinting of vendors and OS-versions. This enabled us to detect more than a million periphery routers relying on Linux kernels from 2018 (or before); these kernels have reached end of life (EOL) and no longer receive security updates. Florian Holzbauer, Johanna Ullrich |
IMC | 3 |
| 2024 | Fostering security research in the energy sector: A validation of open source intelligence for power grid model dataabstractCyber attacks against power grids, interrupting utility service and causing blackouts are on the rise, and increasingly motivate researchers to investigate this topic. Thereby, models of real-world power grids are an indispensable prerequisite, but operators do not make them available, allegedly for reasons of protection. This security-by-obscurity strategy appears futile as grid artifacts (lines, plants, substations) are large and cannot be easily hidden. It seems promising to infer real-world model data from publicly available data, and indeed, multiple models were generated through Open Source Intelligence (OSINT). Questions on the models’ quality remain, however, open but are of utter importance for research building on these models, especially as the results might have considerable impact on society and national security. This paper approaches this particular point and investigates whether OSINT leads to data on real-world power grids of sufficient quality; by the example of the European country of Austria, we investigate whether all parameters that are relevant for power flow analysis, a standard approach in power engineering, can be inferred from publicly available data (OpenStreetMap, national statistics, etc.), and validate this data against ground truths, including governmental land use plans, Google Street View and the power sector’s information material. Our validation shows that the inferred data meets reality well — among others, the extra-high voltage level is 100% (lines) rsp. 98% (substations) complete. Beyond, the inferred data is up-to-date as the construction of lines or substations is always documented in OSM, in 76% of the cases even before finalization of the construction works. An analysis of 24 other European countries revealed that electric systems, substations, and power plants are documented in OSM to a similar extent as in Austria, motivating the application of our approach also to these countries. The contribution of our OSINT-based approach is twofold: First, it facilitates the development of models of real-world power grids, fostering research and discussion that is independent of the power grid operators, in the security domain and beyond. Second, our method represents an attack itself, challenging the energy sector’s security-by-obscurity approach. Anja Klauzer, Lore Abart-Heriszt, Johanna Ullrich |
Comput. Secur. | 4 |
| 2023 | In the loop: A measurement study of persistent routing loops on the IPv4/IPv6 InternetabstractRouting loops forward packets over the same set of routers again and again. The packets, if caught in such a loop, do not only miss the intended destinations, but might also congest links between or even overload involved routers and render additional destinations whose (non-looping) paths include these routers unreachable. Given their potential impact on performance and availability, the situation of long-lasting (persistent) routing loops in today’s Internet is unknown. Comprehensive measurement studies of this phenomenon (in the IPv4 Internet) date back to 2005; studies considering the successor protocol IPv6 – already accounting for more than one third of the Internet’s total traffic – are lacking. In this paper, we conduct a comprehensive measurement study to determine the status quo of persistent routing loops in today’s Internet — the first-ever considering IPv6, and the first for IPv4 since 2005. We carefully extended the methodology from 2005, including multiple successive measurements, and adapted it for IPv6. Our results reveal that routing loops are still a matter of concern: in total, we found 23,208 persistent loops in IPv4 and 30,090 in IPv6, rendering 0.91% (IPv4), resp. 2.20% (IPv6), of the current Internet – as announced in BGP – unreachable. Another 7.18% (IPv4), resp. 23.00% (IPv6), are at risk to become unreachable in presence of an attack, yielding an overall higher threat potential for the IPv6 protocol. In comparison to the 2005 study, the situation has become more complex: As a consequence of IPv4 address scarcity, the number of ex ante unreachable addresses has decreased by 19.81% (despite the fact that the number of BGP announced addresses has more than doubled); at the same time, the number of addresses endangered by persistent routing loops has sharply increased (+1,907.58%) due to individual routers serving more addresses. Johanna Ullrich |
Comput. Networks | 2 |
| 2023 | An extended view on measuring tor AS-level adversariesabstractTor provides anonymity to millions of users around the globe which has made it a valuable target for malicious actors. As a low-latency anonymity system, it is vulnerable to traffic correlation attacks from strong passive adversaries such as large autonomous systems (ASes). In preliminary work Mayer et al.(2020), we have developed a measurement approach utilizing the RIPE Atlas framework – a network of more than 11,000 probes worldwide – to infer the risk of deanonymization for IPv4 clients in Germany and the US. In this paper, we apply our methodology to additional scenarios providing a broader picture of the potential for deanonymization in the Tor network. In particular, we (a) repeat our earlier (2020) measurements in 2022 to observe changes over time, (b) adopt our approach for IPv6 to analyze the risk of deanonymization when using this next-generation Internet protocol, and (c) investigate the current situation in Russia, where censorship has been intensified after the beginning of Russia’s full-scale invasion of Ukraine. According to our results, Tor provides user anonymity at consistent quality: While individual numbers vary in dependence of client and destination, we were able to identify ASes with the potential to conduct deanonymization attacks. For clients in Germany and the US, the overall picture, however, has not changed since 2020. In addition, the protocols (IPv4 vs. IPv6) do not significantly impact the risk of deanonymization. Russian users are able to securely evade censorship using Tor. Their general risk of deanonymization is, in fact, lower than in the other investigated countries. Beyond, the few ASes with the potential to successfully perform deanonymization are operated by Western companies, further reducing the risk for Russian users. Gabriel K. Gegenhuber, Florian Holzbauer, Wilfried Mayer, Georg Merzdovnik, Edgar R. Weippl, Johanna Ullrich |
Comput. Secur. | 7 |
| 2022 | Not that Simple: Email Delivery in the 21st Century
Florian Holzbauer, Johanna Ullrich, Martina Lindorfer, Tobias Fiebig |
USENIX ATC | 2 |
| 2019 | Measuring Cookies and Web Privacy in a Post-GDPR World
Adrian Dabrowski, Georg Merzdovnik, Johanna Ullrich, Gerald Sendera, Edgar R. Weippl |
PAM | 3 |
| 2018 | Proof-of-Blackouts? How Proof-of-Work Cryptocurrencies Could Affect Power Grids
Johanna Ullrich, Nicholas Stifter, Aljosha Judmayer, Adrian Dabrowski, Edgar R. Weippl |
RAID | 1 |
| 2017 | Lightweight Address Hopping for Defending the IPv6 IoTabstractThe rapid deployment of IoT systems on the public Internet is not without concerns for the security and privacy of consumers. Security in IoT systems is often poorly engineered and engineering for privacy does notseemtobea concern for vendors at all. Thecombination of poor security hygiene and access to valuable knowledge renders IoT systems a much-sought target for attacks. Aljosha Judmayer, Johanna Ullrich, Georg Merzdovnik, Artemios G. Voyiatzis, Edgar R. Weippl |
ARES | 2 |
| 2017 | A Trust-based Resilient Routing Mechanism for the Internet of ThingsabstractLocal-area networks comprising the Internet of Things (IoT) consist mainly of devices that have limited processing capabilities and face energy constraints. This has an implication on developing security mechanisms, as they require significant computing resources. In this paper, we design a trust-based routing solution with IoT devices in mind. Specifically, we propose a trust-based approach for managing the reputation of every node of an IoT network. The approach is based on the emerging Routing Protocol for Low power and Lossy networks (RPL). The proposed solution is simulated for its routing resilience and compared with two other variants of RPL. Zeeshan Ali Khan, Johanna Ullrich, Artemios G. Voyiatzis, Peter Herrmann |
ARES | 2 |
| 2017 | Grid Shock: Coordinated Load-Changing Attacks on Power Grids: The Non-Smart Power Grid is Vulnerable to Cyber Attacks as WellabstractElectric power grids are among the largest human-made control structures and are considered as critical infrastructure due to their importance for daily life. When operating a power grid, providers have to continuously maintain a balance between supply (i.e., production in power plants) and demand (i.e., power consumption) to keep the power grid's nominal frequency of 50 Hz or alternatively 60 Hz. Power consumption is forecast by elaborated models including multiple parameters like weather, season, and time of the day; they are based on the premise of many small consumers averaging out their energy consumption spikes. Adrian Dabrowski, Johanna Ullrich, Edgar R. Weippl |
ACSAC | 2 |
| 2016 | The Beauty or The Beast? Attacking Rate Limits of the Xen Hypervisor
Johanna Ullrich, Edgar R. Weippl |
ESORICS (2) | 1 |
| 2016 | The role and security of firewalls in cyber-physical cloud computingabstractClouds are here to stay, and the same holds for cyber-physical systems—not to forget their combination. In light of these changing paradigms, it is of utter importance to reconsider security as both introduce new challenges. Overcoming the concept of zoned networks, clouds make former internal traffic traveling the Internet. Cyber-physical systems include physical parts into computing and make them potential targets for cyber attacks—a dare as a high number of physical parts have originally been developed to be stand-alone. Cyber-physical cloud computing reinforces the need for a thoughtful security concept. Firewalls are among the basic building blocks in network security and are offered by various cloud providers; however, the question on their quality of protection arises. In this paper, we assess firewall offers of five major cloud providers with respect to cyber-physical system integration. Therefore, we study their default configuration, configuration capabilities, documentation, and filtering behavior. We developed an extendible firewall monitoring tool that enables customers to probe their provider’s filtering behavior—an information of interest for risk management or further security consideration. Re-assessing filtering behavior, we found that all offered firewalls have evolved over a time period of more than a year: Configuration possibilities have been enhanced, more illegitimate packets are filtered now, and stateful behavior was discovered at a certain provider. Johanna Ullrich, Jordan Cropper, Peter Frühwirt, Edgar R. Weippl |
EURASIP J. Inf. Secur. | 1 |
| 2015 | The Role and Security of Firewalls in IaaS Cloud ComputingabstractCloud computing is playing an ever larger role in the IT infrastructure. The migration into the cloud means that we must rethink and adapt our security measures. Ultimately, both the cloud provider and the customer have to accept responsibilities to ensure security best practices are followed. Firewalls are one of the most critical security features. Most IaaS providers make firewalls available to their customers. In most cases, the customer assumes a best-case working scenario which is often not assured. In this paper, we studied the filtering behavior of firewalls provided by five different cloud providers. We found that three providers have firewalls available within their infrastructure. Based on our findings, we developed an open-ended firewall monitoring tool which can be used by cloud customers to understand the firewall's filtering behavior. This information can then be efficiently used for risk management and further security considerations. Measuring today's firewalls has shown that they perform well for the basics, although may not be fully featured considering fragmentation or stateful behavior. Jordan Cropper, Johanna Ullrich, Peter Frühwirt, Edgar R. Weippl |
ARES | 2 |
| 2015 | QR Code Security - How Secure and Usable Apps Can Protect Users Against Malicious QR CodesabstractQR codes have emerged as a popular medium to make content instantly accessible. With their high information density and robust error correction, they have found their way to the mobile ecosystem. However, QR codes have also proven to be an efficient attack vector, e.g. To perform phishing attacks. Attackers distribute malicious codes under false pretenses in busy places or paste malicious QR codes over already existing ones on billboards. Ultimately, people depend on reader software to ascertain if a given QR code is benign or malicious. In this paper, we present a comprehensive analysis of QR code security. We determine why users are still susceptible to QR code based attacks and why currently deployed smartphone apps are unable to mitigate these attacks. Based on our findings, we present a set of design recommendations to build usable and secure mobile applications. To evaluate our guidelines, we implemented a prototype and found that secure and usable apps can effectively protect users from malicious QR codes. Katharina Krombholz, Peter Frühwirt, Thomas Rieder, Ioannis Kapsalis, Johanna Ullrich, Edgar R. Weippl |
ARES | 5 |
| 2015 | On Reconnaissance with IPv6: A Pattern-Based Scanning ApproachabstractToday's capability of fast Internet-wide scanning allows insights into the Internet ecosystem, but the on-going transition to the new Internet Protocol version 6 (IPv6) makes the approach of probing all possible addresses infeasible, even at current speeds of more than a million probes per second. As a consequence, the exploitation of frequent patterns has been proposed to reduce the search space. Current patterns are manually crafted and based on educated guesses of administrators. At the time of writing, their adequacy has not yet been evaluated. In this paper, we assess the idea of pattern-based scanning for the first time, and use an experimental set-up in combination with three real-world data sets. In addition, we developed a pattern-based algorithm that automatically discovers patterns in a sample and generates addresses for scanning based on its findings. Our experimental results confirm that pattern-based scanning is a promising approach for IPv6 reconnaissance, but also that currently known patterns are of limited benefit and are outperformed by our new algorithm. Our algorithm not only discovers more addresses, but also finds implicit patterns. Furthermore, it is more adaptable to future changes in IPv6 addressing and harder to mitigate than approaches with manually crafted patterns. Johanna Ullrich, Peter Kieseberg, Katharina Krombholz, Edgar R. Weippl |
ARES | 1 |
| 2015 | Privacy is Not an Option: Attacking the IPv6 Privacy Extension
Johanna Ullrich, Edgar R. Weippl |
RAID | 1 |
| 2014 | Towards a Hardware Trojan Detection CycleabstractIntentionally inserted malfunctions in integrated circuits, referred to as Hardware Trojans, have become an emerging threat. Recently, the scientific community started to propose technical approaches to mitigate the threat of unspecified and potentially malicious functionality. However, these detection and prevention mechanisms are still hardly integrated in the industry's Hardware development life cycles. We therefore propose in this work a secure hardware development life cycle that assembles methods from trustworthy software engineering. In addition to full traceability from specification to implementation, and down to each gate, we introduce a feedback detection cycle that systematically escorts every single step of the development process. To do so, we integrate different detection methods for each development phase that are derived from a common knowledge base. Adrian Dabrowski, Heidelinde Hobel, Johanna Ullrich, Katharina Krombholz, Edgar R. Weippl |
ARES | 3 |