Sergej Dechand

dblp:146/8228 · DBLP profile ↗
← Back
10ranked-venue papers
3as first author
1since 2021 · last 2026
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 10 · 3 first-author · 1 since 2021

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Network and information security
8 papers
Systems and software security · 64% Authentication and access control · 14% Usable security · 6%
Software engineering, system software, and programming languages
4 papers
Programming languages and type systems · 46% Empirical software engineering · 33% Compilers and program optimization · 11%

Topics — the 17 heaviest of 22, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Systems and software security
vulnerability discovery
1.222026
Jazzer: Coverage-Guided Fuzzing for Semantic Vulnerabilities in the Java Ecosystem · SP 2026
VCCFinder: Finding Potential Vulnerabilities in Open-Source Projects to Assist Code Audits · CCS 2015
Systems and software security › vulnerability discovery › fuzzing
coverage-guided fuzzing
1.012026
Jazzer: Coverage-Guided Fuzzing for Semantic Vulnerabilities in the Java Ecosystem · SP 2026
Systems and software security › vulnerability discovery
fuzzing
1.012026
Jazzer: Coverage-Guided Fuzzing for Semantic Vulnerabilities in the Java Ecosystem · SP 2026
Programming languages and type systems › object-oriented programming
java
0.312026
Jazzer: Coverage-Guided Fuzzing for Semantic Vulnerabilities in the Java Ecosystem · SP 2026
Authentication and access control
password authentication
0.312017
Why Do Developers Get Password Storage Wrong?: A Qualitative Usability Study · CCS 2017
Cryptographic primitives and cryptanalysis › hash functions
password hashing
0.312017
Why Do Developers Get Password Storage Wrong?: A Qualitative Usability Study · CCS 2017
Authentication and access control › password security
secure password storage
0.312017
Why Do Developers Get Password Storage Wrong?: A Qualitative Usability Study · CCS 2017
Systems and software security › reverse engineering
decompilation
0.212016
Helping Johnny to Analyze Malware: A Usability-Optimized Decompiler and Malware Analysis User Study · IEEE Symposium on Security and Privacy 2016
Systems and software security
reverse engineering
0.212016
Helping Johnny to Analyze Malware: A Usability-Optimized Decompiler and Malware Analysis User Study · IEEE Symposium on Security and Privacy 2016
Usable security
security tool usability
0.212016
Helping Johnny to Analyze Malware: A Usability-Optimized Decompiler and Malware Analysis User Study · IEEE Symposium on Security and Privacy 2016
Cryptographic protocols and secure computation
secure messaging
0.212015
SoK: Secure Messaging · IEEE Symposium on Security and Privacy 2015
Network security › secure communication › secure communication protocol
TLS
0.212015
To Pin or Not to Pin-Helping App Developers Bullet Proof Their TLS Connections · USENIX Security Symposium 2015
Empirical software engineering
mining software repositories
0.212015
VCCFinder: Finding Potential Vulnerabilities in Open-Source Projects to Assist Code Audits · CCS 2015
Systems and software security
software supply chain security
0.212014
Hey, NSA: Stay Away from my Market! Future Proofing App Markets against Powerful Attackers · CCS 2014
Usable security › risk communication
security indicators
0.112016
An Empirical Study of Textual Key-Fingerprint Representations · USENIX Security Symposium 2016
Network security
anonymity networks
0.112015
SoK: Secure Messaging · IEEE Symposium on Security and Privacy 2015
Software maintenance and evolution
code review
0.112015
VCCFinder: Finding Potential Vulnerabilities in Open-Source Projects to Assist Code Audits · CCS 2015

Methods — techniques the papers use, named apart from their topics

coverage-guided fuzzing · 2.0user study · 0.5semantics-preserving code transformation · 0.5support vector machine · 0.4code-metric analysis · 0.4qualitative usability study · 0.3transparency mechanism design · 0.2threat modeling · 0.2
YearPublicationVenuePosition
2026 Jazzer: Coverage-Guided Fuzzing for Semantic Vulnerabilities in the Java Ecosystem
Sergej Dechand, Tobias Wienand, Fabian Meumertzheim, Peter Samarin, Simon Resch, Khaled Yakdan, Thorsten Holz, Flavio Toffalini
SP1
2019 In Encryption We Don't Trust: The Effect of End-to-End Encryption to the Masses on User Perception
abstract
With WhatsApp's adoption of the Signal Protocol as its default, end-to-end encryption by the masses happened almost overnight. Unlike iMessage, WhatsApp notifies users that encryption is enabled, explicitly informing users about improved privacy. This rare feature gives us an opportunity to study people's understandings and perceptions of secure messaging pre-and post-mass messenger encryption (pre/post-MME). To study changes in perceptions, we compared the results of two mental models studies: one conducted in 2015 pre-MME and one in 2017 post-MME. Our primary finding is that users do not trust encryption as currently offered. When asked about encryption in the study, most stated that they had heard of encryption, but only a few understood the implications, even on a high level. Their consensus view was that no technical solution to stop skilled attackers from getting their data exists. Even with a major development, such as WhatsApp rolling out end-to-end encryption, people still do not feel well protected by their technology. Surprisingly, despite WhatsApp's end-to-end security info messages and the high media attention, the majority of the participants were not even aware of encryption. Most participants had an almost correct threat model, but don't believe that there is a technical solution to stop knowledgeable attackers to read their messages. Using technology made them feel vulnerable.
Sergej Dechand, Alena Naiakshina, Anastasia Danilova, Matthew Smith 0001
EuroS&P1
2017 Why Do Developers Get Password Storage Wrong?: A Qualitative Usability Study
abstract
Passwords are still a mainstay of various security systems, as well as the cause of many usability issues. For end-users, many of these issues have been studied extensively, highlighting problems and informing design decisions for better policies and motivating research into alternatives. However, end-users are not the only ones who have usability problems with passwords! Developers who are tasked with writing the code by which passwords are stored must do so securely. Yet history has shown that this complex task often fails due to human error with catastrophic results. While an end-user who selects a bad password can have dire consequences, the consequences of a developer who forgets to hash and salt a password database can lead to far larger problems. In this paper we present a first qualitative usability study with 20 computer science students to discover how developers deal with password storage and to inform research into aiding developers in the creation of secure password systems.
Alena Naiakshina, Anastasia Danilova, Christian Tiefenau, Marco Herzog, Sergej Dechand, Matthew Smith 0001
CCS5
2016 Helping Johnny to Analyze Malware: A Usability-Optimized Decompiler and Malware Analysis User Study
abstract
Analysis of malicious software is an essential task in computer security, it provides the necessary understanding to devise effective countermeasures and mitigation strategies. The level of sophistication and complexity of current malware continues to evolve significantly, as the recently discovered "Regin" malware family strikingly illustrates. This complexity makes the already tedious and time-consuming task of manual malware reverse engineering even more difficult and challenging. Decompilation can accelerate this process by enabling analysts to reason about a high-level, more abstract from of binary code. While significant advances have been made, state-of-the-art decompilers still produce very complex and unreadable code and malware analysts still frequently go back to analyzing the assembly code. In this paper, we present several semantics-preserving code transformations to make the decompiled code more readable, thus helping malware analysts understand and combat malware. We have implemented our optimizations as extensions to the academic decompiler DREAM. To evaluate our approach, we conducted the first user study to measure the quality of decompilers for malware analysis. Our study includes 6 analysis tasks based on real malware samples we obtained from independent malware experts. We evaluate three decompilers: the leading industry decompiler Hex-Rays, the state-of-the-art academic decompiler DREAM, and our usability-optimized decompiler DREAM++. The results show that our readability improvements had a significant effect on how well our participants could analyze the malware samples. DREAM++ outperforms both Hex-Rays and DREAM significantly. Using DREAM++ participants solved 3x more tasks than when using Hex-Rays and 2x more tasks than when using DREAM.
Khaled Yakdan, Sergej Dechand, Elmar Gerhards-Padilla, Matthew Smith 0001
IEEE Symposium on Security and Privacy2
2016 An Empirical Study of Textual Key-Fingerprint Representations
Sergej Dechand, Dominik Schürmann, Karoline Busse, Yasemin Acar, Sascha Fahl, Matthew Smith 0001
USENIX Security Symposium1
2015 VCCFinder: Finding Potential Vulnerabilities in Open-Source Projects to Assist Code Audits
abstract
Despite the security community's best effort, the number of serious vulnerabilities discovered in software is increasing rapidly. In theory, security audits should find and remove the vulnerabilities before the code ever gets deployed. However, due to the enormous amount of code being produced, as well as a the lack of manpower and expertise, not all code is sufficiently audited. Thus, many vulnerabilities slip into production systems. A best-practice approach is to use a code metric analysis tool, such as Flawfinder, to flag potentially dangerous code so that it can receive special attention. However, because these tools have a very high false-positive rate, the manual effort needed to find vulnerabilities remains overwhelming. In this paper, we present a new method of finding potentially dangerous code in code repositories with a significantly lower false-positive rate than comparable systems. We combine code-metric analysis with metadata gathered from code repositories to help code review teams prioritize their work. The paper makes three contributions. First, we conducted the first large-scale mapping of CVEs to GitHub commits in order to create a vulnerable commit database. Second, based on this database, we trained a SVM classifier to flag suspicious commits. Compared to Flawfinder, our approach reduces the amount of false alarms by over 99 % at the same level of recall. Finally, we present a thorough quantitative and qualitative analysis of our approach and discuss lessons learned from the results. We will share the database as a benchmark for future research and will also provide our analysis tool as a web service.
Henning Perl, Sergej Dechand, Matthew Smith 0001, Daniel Arp, Fabian Yamaguchi, Konrad Rieck, Sascha Fahl, Yasemin Acar
CCS2
2015 SoK: Secure Messaging
abstract
Motivated by recent revelations of widespread state surveillance of personal communication, many solutions now claim to offer secure and private messaging. This includes both a large number of new projects and many widely adopted tools that have added security features. The intense pressure in the past two years to deliver solutions quickly has resulted in varying threat models, incomplete objectives, dubious security claims, and a lack of broad perspective on the existing cryptographic literature on secure communication. In this paper, we evaluate and systematize current secure messaging solutions and propose an evaluation framework for their security, usability, and ease-of-adoption properties. We consider solutions from academia, but also identify innovative and promising approaches used "in-the-wild" that are not considered by the academic literature. We identify three key challenges and map the design landscape for each: trust establishment, conversation security, and transport privacy. Trust establishment approaches offering strong security and privacy features perform poorly from a usability and adoption perspective, whereas some hybrid approaches that have not been well studied in the academic literature might provide better trade-offs in practice. In contrast, once trust is established, conversation security can be achieved without any user involvement in most two-party conversations, though conversations between larger groups still lack a good solution. Finally, transport privacy appears to be the most difficult problem to solve without paying significant performance penalties.
Nik Unger, Sergej Dechand, Joseph Bonneau, Sascha Fahl, Henning Perl, Ian Goldberg 0001, Matthew Smith 0001
IEEE Symposium on Security and Privacy2
2015 To Pin or Not to Pin-Helping App Developers Bullet Proof Their TLS Connections
Marten Oltrogge, Yasemin Acar, Sergej Dechand, Matthew Smith 0001, Sascha Fahl
USENIX Security Symposium3
2014 Hey, NSA: Stay Away from my Market! Future Proofing App Markets against Powerful Attackers
abstract
Mobile devices are evolving as the dominant computing platform and consequently application repositories and app markets are becoming the prevalent paradigm for deploying software. Due to their central and trusted position in the software ecosystem, coerced, hacked or malicious app markets pose a serious threat to user security. Currently, there is little that hinders a nation state adversary (NSA) or other powerful attackers from using such central and trusted points of software distribution to deploy customized (malicious) versions of apps to specific users. Due to intransparencies in the current app installation paradigm, this kind of attack is extremely hard to detect.
Sascha Fahl, Sergej Dechand, Henning Perl, Felix Fischer 0001, Jaromir Smrcek, Matthew Smith 0001
CCS2
2014 Quantifiable Run-Time Kernel Attack Surface Reduction
Anil Kurmus, Sergej Dechand, Rüdiger Kapitza
DIMVA2