EDBT 2026 Demo / reviewers in the wild / expert
Mykolai Protsenko
dblp:140/0788 · also Mykola Protsenko
· DBLP profile ↗
13ranked-venue papers
4as first author
3since 2021 · last 2024
0000-0002-2706-3920ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 12 · 4 first-author · 3 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | Gateway to the Danger Zone: Secure and Authentic Remote Reset in Machine SafetyabstractThe increasing digitization of modern flexible manufacturing systems has opened up new possibilities for higher levels of automation, paving the way for innovative concepts such as Equipment-as-a-Service. Concurrently, remote access has gained traction, notably accelerated by the COVID-19 pandemic. While some areas of manufacturing have embraced these advancements, safety applications remain localized. This work aims to enable the remote reset of local safety events. To identify necessary requirements, we conducted expert-workshops and analyzed relevant standards and regulations. These requirements serve as the foundation for a comprehensive security and safety concept, built around a secure gateway. It uses secure elements, crypto agility, PQC, and certificates for secure and authentic communication. To show its applicability, we implemented a prototype, which utilizes a gateway, cameras, and light barriers to monitor the danger zone of a robot and thus enable remote reset via public Internet. The real-world limitations we faced, were used to refine our requirements and concept iteratively. Ultimately, we present a secure and safe solution that enables the remote acknowledgment of safety-critical applications. Sebastian N. Peters, Nikolai Puch, Michael P. Heinl, Philipp Zieris, Mykolai Protsenko, Thorsten Larsen-Vefring, Marcel Ely Gomes, Aliza Maftun, Thomas Zeschg |
ARES | 5 |
| 2024 | VisualAuth: Secure Transaction Authentication and Trusted UI on COTS Android DevicesabstractSecurity of critical smartphone applications, including mobile banking, e-commerce and cashless payments, can be jeopardized by kernel-level or UI-targeting malware, for instance by employing clickjacking or overlay attacks. In this work we propose a novel approach to building secure UI screens based on DRM system and demonstrate its feasibility on Android for transaction authentication use case. Security of our solution is based on a TEE thus making it resilient against privileged malware. Additionally, we introduce a detection mechanism for overlay attacks based on random background patterns. Our approach does not require any system customization and is deployable on a wide range of COTS devices. The usability of the proposed solution was validated by means of an online survey, which indicated high detection rate of overlay attacks. Aside of simple transaction authentication, similar to the Android Protected Confirmation (APC) but with a wider device support, our approach can be used to realize more general applications, for instance, secure voting input screen, document viewing, confidential news reading and social media clients, providing high security against spyware or remote forensics investigations. Mykolai Protsenko, Albert Stark, Andreas Papon, Sandra Kostic |
TrustCom | 1 |
| 2021 | Advanced System Resiliency Based on Virtualization Techniques for IoT DevicesabstractAn increasing number of powerful devices are equipped with network connectivity and are connected to the Internet of Things (IoT). Influenced by the steady growth of computing power of the devices, the paradigm of IoT-based service deployment is expected to change, following the example of cloud-based infrastructure: An embedded platform can be provided as-a-service to several independent application service suppliers. This fosters additional challenges concerning security and isolation. At the same time, recently revealed critical vulnerabilities like Ripple20 and Amnesia:33 show that embedded devices are not spared from wide-spread attacks. Jonas Röckl, Mykolai Protsenko, Monika Kamhuber, Tilo Müller, Felix C. Freiling |
ACSAC | 2 |
| 2018 | Tackling Androids Native Library Malware with Robust, Efficient and Accurate Similarity MeasuresabstractCode similarity measures create a comparison metric showing to what degree two code samples have the same functionality, e.g., to statically detect the use of known libraries in binary code. They are both an indispensable part of automated malware analysis, as well as a helper for the detection of plagiarism (IP protection) and the illegal use of open-source libraries in commercial apps. The centroid similarity metric extracts control-flow features from binary code and encodes them as geometric structures before comparing them. In our paper, we propose novel improvements to the centroid approach and apply it to the ARM architecture for the first time. We implement our approach as a plug-in for the IDA Pro disassembler and evaluate it regarding efficiency, accuracy and robustness on Android. Based on a dataset of 508,745 APKs, collected from 18 third-party app markets, we achieve a detection rate of 89% for the use of native code libraries, with an FPR of 10.8%. To test the robustness of our approach against the compiler version, optimization level, and other code transformations, we obfuscate and recompile known open-source libraries to evaluate which code transformations are resisted. Based on our results, we discuss how code re-use can be hidden by obfuscation and conclude with possible improvements. Anatoli Kalysch, Oskar Milisterfer, Mykolai Protsenko, Tilo Müller |
ARES | 3 |
| 2017 | A Cloud-Based Compilation and Hardening Platform for Android AppsabstractSoftware piracy in general and repackaged apps with attached malware in particular pose serious threats for the Android ecosystem. In this paper, we present a cloud-compilation approach enabling sophisticated hardening of apps for non-rooted stock Android. Our design is based on off-device ahead-of-time compilation made possible by the Android Runtime (ART). Due to an installer-stub-based second-stage delivery, we stay compatible to established app store distribution processes. We argue with a significant gain in security for our approach, since an adversary's toolbox is usually aimed at exploiting the type-information-rich bytecode shipped with apps, which is stripped to a large extent and almost entirely useless for reverse engineering attacks. We confirm the gain in security by comparing the output of popular reverse engineering tools for original and stripped versions of 695 real-world apps in our test set. In average 81.5 % of an app's bytecode is no longer of use to reverse engineers. Complementing existing protection approaches, we propose a platform that can integrate bytecode-targeting protection solutions and offers binary-targeting hooks to incorporate advanced protection measures for ahead-of-time compiled apps. Our evaluation shows a negligible performance impact at runtime and demonstrates the approach's compatibility on our test set. Marcel Busch, Mykolai Protsenko, Tilo Müller |
ARES | 2 |
| 2016 | ARTIST: The Android Runtime Instrumentation ToolkitabstractSmartphones are becoming more and more ubiquitous in the modern world, entrusted with such sensitive information as the user's location and banking data. Since Android is the most widespread smartphone platform, reliable and versatile means for Android application analysis are of great importance. Most of the existing code instrumentation approaches for Android suffer from two important shortcomings: the need for root access and limited support for the new Android Runtime(ART). WeaimtofillthisgapbyproposingARTIST, the Android Runtime Instrumentation Toolkit1. ARTIST is a framework that allows analysts to easily monitor the execution of Java and native code using native instrumentation techniques. ARTIST, to the best of our knowledge, is the first tool allowing monitoring of both native and Java code with the same instrumentation technique. ARTIST provides two methods to locate instrumentation targets. First, it can parse OAT executable files in memory to find classes and methods of interest. This allows monitoring a specific set of Java methods. Second, ARTIST can locate internal structures of the Android Runtime in memory. Monitoring function pointers found in these allows the user to track specific interactions of Java code with the Android Runtime. We evaluate the applicability of native instrumentation for Java code using a set of the most popular Android apps. The results show that over 80% of the tested Java methods are targetable using this approach. The performance impact, estimated with the CaffeineMark benchmark suite, does not exceed 20% and therefore can be considered generally acceptable. Lukas Dresel, Mykolai Protsenko, Tilo Müller |
ARES | 2 |
| 2015 | Dynamic Self-Protection and Tamperproofing for Android Apps Using Native CodeabstractWith over one billion sold devices, representing 80% market share, Android remains the most popular platform for mobile devices. Application piracy on this platform is a major concern and a cause of significant losses: about 97% of the top 100 paid apps were found to be hacked in terms of repackaging or the distribution of clones. Therefore new and stronger methods aiming to increase the burden on reverse engineering and modification of proprietary mobile software are required. In this paper, we propose an application of the Android native code component to implement strong software self-protection for apps. Within this scope, we present three dynamic obfuscation techniques, namely dynamic code loading, dynamic re-encryption, and tamper proofing. We provide a practical evaluation of this approach, assessing both the cost and efficiency of its achieved protection level. Our results indicate that with the proposed methods one can reach significant complication of the reverse-engineering process, while being affordable in terms of execution time and application size. Mykolai Protsenko, Sebastien Kreuter, Tilo Müller |
ARES | 1 |
| 2015 | Protecting Android Apps Against Reverse Engineering by the Use of the Native Code
Mykolai Protsenko, Tilo Müller |
TrustBus | 1 |
| 2015 | A game of Droid and Mouse: The threat of split-personality malware on Android
Dominik Christian Maier, Mykolai Protsenko, Tilo Müller |
Comput. Secur. | 2 |
| 2014 | Divide-and-Conquer: Why Android Malware Cannot Be StoppedabstractIn this paper, we demonstrate that Android malware can bypass all automated analysis systems, including AV solutions, mobile sandboxes, and the Google Bouncer. We propose a tool called Sand-Finger for the fingerprinting of Android-based analysis systems. By analyzing the fingerprints of ten unique analysis environments from different vendors, we were able to find characteristics in which all tested environments differ from actual hardware. Depending on the availability of an analysis system, malware can either behave benignly or load malicious code at runtime. We classify this group of malware as Divide-and-Conquer attacks that are efficiently obfuscated by a combination of fingerprinting and dynamic code loading. In this group, we aggregate attacks that work against dynamic as well as static analysis. To demonstrate our approach, we create proof-of-concept malware that surpasses up-to-date malware scanners for Android. We also prove that known malware samples can enter the Google Play Store by modifying them only slightly. Due to Android's lack of an API for malware scanning at runtime, it is impossible for AV solutions to secure Android devices against these attacks. Dominik Christian Maier, Tilo Müller, Mykolai Protsenko |
ARES | 3 |
| 2014 | An Empirical Evaluation of Software Obfuscation Techniques Applied to Android APKs
Felix C. Freiling, Mykolai Protsenko |
SecureComm (2) | 2 |
| 2014 | Android Malware Detection Based on Software Complexity Metrics
Mykolai Protsenko, Tilo Müller |
TrustBus | 1 |
| 2014 | Toward an Open Source Location Privacy Evaluation Framework for Vehicular NetworksabstractOutline and present building blocks for a comprehensive open source location privacy evaluation framework to enable researchers to reproducibly assess the effectiveness of a given privacy protection algorithm. We also present a proof of concept evaluation. By extending the well established Veins simulation framework [4] that couples the traffic simulator SUMO and the network simulator OMNeT++ we allow for an easy setup and integration with existing simulation scenarios or already implemented protocols. We hope that our framework lowers the complexity of privacy evaluation and thereby makes certain protection measures more likely to be considered in future vehicular networks. David Eckhoff, Mykolai Protsenko, Reinhard German |
VTC Fall | 2 |