EDBT 2026 Demo / reviewers in the wild / expert
Robert Luh
dblp:147/1623
· DBLP profile ↗
21ranked-venue papers
9as first author
9since 2021 · last 2025
0000-0001-6536-6706ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 17 · 6 first-author · 8 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 2 first-author · 1 since 2021Databases, data management, data science and information retrieval · 2 · 1 first-authorHuman-computer interaction and ubiquitous computing · 2 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | PenQuestEnv: A Reinforcement Learning Environment for Cyber Security
Sebastian Eresheim, Simon Gmeiner, Alexander Piglmann, Thomas Petelin, Robert Luh, Paul Tavolato, Sebastian Schrittwieser |
ICISSP (1) | 5 |
| 2025 | Gamifying information security: Adversarial risk exploration for IT/OT infrastructures
Robert Luh, Sebastian Eresheim, Paul Tavolato, Thomas Petelin, Simon Gmeiner, Andreas Holzinger, Sebastian Schrittwieser |
Comput. Secur. | 1 |
| 2024 | Timestamp-based Application Fingerprinting in NTFSabstractThe NTFS file system contains crucial (meta-)information that plays a significant role in forensic analysis. Among these details are the eight file timestamps, which serve as the foundation for constructing a reliable timeline. However, beyond their temporal significance, these timestamps also harbor valuable clues. Specifically, the patterns of file handling by user programs are reflected in these timestamps. By analyzing these “fingerprint” patterns, it becomes possible to identify the applications responsible for creating and editing files. This discovery facilitates event reconstruction in digital forensics investigations. Michael Galhuber, Robert Luh |
ARES | 2 |
| 2024 | Comparing the Effectivity of Planned Cyber Defense Controls in Order to Support the Selection Process
Paul Tavolato, Robert Luh, Sebastian Eresheim, Simon Gmeiner, Sebastian Schrittwieser |
ICISSP | 2 |
| 2023 | A Game Theoretic Analysis of Cyber Threats
Paul Tavolato, Robert Luh, Sebastian Eresheim |
ICISSP | 2 |
| 2022 | WSL2 Forensics: Detection, Analysis & RevirtualizationabstractThe development and integration of the Windows Subsystem for Linux, version 2 (WSL2) into Microsoft’s operating systems has brought together two worlds that were, from a consumer’s perspective, previously disjunct. This comes with new challenges for incident handling and computer forensics in particular, since workflows rarely had to consider both ecosystems at time same time. With WSL2 now becoming an integral part of Windows 10 and 11, tools and techniques have to be revisited with the new environment in mind. Philipp Boigner, Robert Luh |
ARES | 2 |
| 2022 | PenQuest Reloaded: A Digital Cyber Defense Game for Technical EducationabstractToday’s IT and OT infrastructure is threatened by a plethora of cyber-attacks conducted by actors with different motivations and means. Furthermore, the complexity of these exposed systems as well as the adversaries’ sophisticated technical arsenal makes it increasingly difficult to plan and implement an organization’s defense. Understanding the link between specific attacks and effective mitigating measures is particularly challenging – as is understanding the underlying information security concepts. To support the training of current, and more importantly, nascent security engineers, we propose PenQuest, a digital attack and defense game where an attacker attempts to compromise an abstracted IT infrastructure and the defender works to prevent or mitigate the threat. The game is based on MITRE ATT&CK, D3FEND, and the NIST SP 800-53 security standard and incorporates a multitude of concepts such as cyber kill chains, attack vectors, network segmentation, and more. PenQuest is built to support security education and risk assessment and was evaluated with a class of engineering students as well as independent security experts. Initial results show a significant increase in knowledge retention and attest to the game’s feasibility for educational use. Robert Luh, Sebastian Eresheim, Stefanie Größbacher, Thomas Petelin, Florian Mayr, Paul Tavolato, Sebastian Schrittwieser |
EDUCON | 1 |
| 2022 | Formalizing Real-world Threat Scenarios
Paul Tavolato, Robert Luh, Sebastian Eresheim |
ICISSP | 2 |
| 2021 | Time for Truth: Forensic Analysis of NTFS TimestampsabstractTimeline forgery a widely employed technique in computer anti-forensics. Numerous freely available and easy-to-use tampering tools make it difficult for forensic scientists to collect legally valid evidence and reconstruct a credible timeline. At the same time, the large number of possible file operations performed by a genuine user can result in a wide variety of timestamp patterns that pose a challenge when reconstructing a chain of events, especially since application-specific discrepancies are often disregarded. Michael Galhuber, Robert Luh |
ARES | 2 |
| 2019 | AIDIS: Detecting and classifying anomalous behavior in ubiquitous kernel processes
Robert Luh, Helge Janicke, Sebastian Schrittwieser |
Comput. Secur. | 1 |
| 2018 | The Other Side of the Coin: A Framework for Detecting and Analyzing Web-based Cryptocurrency Mining CampaignsabstractMining for crypto currencies is usually performed on high-performance single purpose hardware or GPUs. However, mining can be easily parallelized and distributed over many less powerful systems. Cryptojacking is a new threat on the Internet and describes code included in websites that uses a visitor's CPU to mine for crypto currencies without the their consent. This paper introduces MiningHunter, a novel web crawling framework which is able to detect mining scripts even if they obfuscate their malicious activities. We scanned the Alexa Top 1 million websites for cryptojacking, collected more than 13,400,000 unique JavaScript files with a total size of 246 GB and found that 3,178 websites perform cryptocurrency mining without their visitors' consent. Furthermore, MiningHunter can be used to provide an in-depth analysis of cryptojacking campaigns. To show the feasibility of the proposed framework, three of such campaigns are examined in detail. Our results provide the most comprehensive analysis to date of the spread of cryptojacking on the Internet. Julian Rauchberger, Sebastian Schrittwieser, Tobias Dam, Robert Luh, Damjan Buhov, Gerhard Pötzelsberger, Hyoungshick Kim |
ARES | 4 |
| 2018 | APT RPG: Design of a Gamified Attacker/Defender Meta Model
Robert Luh, Marlies Temper, Simon Tjoa, Sebastian Schrittwieser |
ICISSP | 1 |
| 2017 | LLR-Based Sentiment Analysis for Kernel Event SequencesabstractBehavior-based analysis of dynamically executed binaries has become a widely used technique for the identification of suspected malware. Most solutions rely on function call patterns to determine whether a sample is exhibiting malicious behavior. These system and API calls are usually regarded individually and do not consider contextual information or process inter-dependencies. In addition, the patterns are often fixed in nature and do not adapt to changing circumstances on the system environment level. To address these shortcomings, this paper proposes a sentiment extraction and scoring system capable of learning the maliciousness inherent to n-grams of kernel events captured by a real-time monitoring agent. The approach is based on calculating the log likelihood ratio (LLR) of all identified n-grams, effectively determining neighboring sequences as well as assessing whether certain event combinations incline towards the benign or malicious. The extraction component automatically compiles a WordNet-like sentiment dictionary of events, which is subsequently used to score unknown traces of either individual processes, or a session in its entirety. The system was evaluated using a large set of real-world event traces collected on live corporate workstations as well as raw API call traces created in a dedicated malware analysis environment. While applicable to both scenarios, the introduced solution performed best for our abstracted kernel events, generating both new insight into malware- system interaction and assisting with the scoring of hitherto unknown application behavior. Robert Luh, Sebastian Schrittwieser, Stefan Marschalek |
AINA | 1 |
| 2017 | Sequitur-based Inference and Analysis Framework for Malicious System Behavior
Robert Luh, Gregor Schramm, Markus Wagner 0008, Sebastian Schrittwieser |
ICISSP | 1 |
| 2017 | Design of an Anomaly-based Threat Detection & Explication System
Robert Luh, Sebastian Schrittwieser, Stefan Marschalek, Helge Janicke |
ICISSP | 1 |
| 2017 | Longkit - A Universal Framework for BIOS/UEFI Rootkits in System Management Mode
Julian Rauchberger, Robert Luh, Sebastian Schrittwieser |
ICISSP | 2 |
| 2017 | Poster: Design of an Anomaly-based Threat Detection & Explication SystemabstractThe poster corresponding to this summary depicts a proposition of a system able to explain anomalous behavior within a user session by considering anomalies identified through their deviation from a set of baseline process graphs. We adapt star structures, a bipartite representation used to approximate the edit distance between two graphs. Relevant processes are selected from a dictionary of benign and malicious traces generated through a sentiment-like bigram extraction and scoring system based on the log likelihood ratio test. We prototypically implemented smart anomaly explication through a number of competency questions derived and evaluated by a decision tree. The determined key factors are ultimately mapped to a dedicated APT attack stage ontology that considers actions, actors, as well as target assets. Robert Luh, Sebastian Schrittwieser, Stefan Marschalek, Helge Janicke, Edgar R. Weippl |
SACMAT | 1 |
| 2016 | TAON: an ontology-based approach to mitigating targeted attacksabstractTargeted attacks on IT systems are a rising threat against the confidentiality of sensitive data and the availability of systems and infrastructures. Planning for the eventuality of a data breach or sabotage attack has become an increasingly difficult task with the emergence of advanced persistent threats (APTs), a class of highly sophisticated cyber-attacks that are nigh impossible to detect using conventional signature-based systems. Robert Luh, Sebastian Schrittwieser, Stefan Marschalek |
iiWAS | 1 |
| 2015 | Classifying malicious system behavior using event propagation treesabstractBehavior-based analysis of dynamically executed software has become an established technique to identifying and analyzing potential malware. Most solutions rely on API or system call patterns to determine whether a sample is exhibiting malicious activity. Analysis is usually performed on demand and offers little insight into the current system state. In addition, the fixed nature of behavioral patterns is known to cause false-positives whenever a certain, potentially malicious action is used in a benign context. Stefan Marschalek, Robert Luh, Manfred Kaiser, Sebastian Schrittwieser |
iiWAS | 2 |
| 2014 | Defining Malicious BehaviorabstractIn this paper we propose the use of formal methods to model malicious code behavior. The paradigm shift in malware detection from conventional, signature-based static methods to evaluating dynamic system behavior is motivated by the rising number and ever-increasing sophistication of malware currently in the wild. Because of advanced polymorphic and metamorphic techniques, a purely signature-based approach is no longer sufficient for accurate malware recognition. Automating the process of behavior analysis necessitates the use of formal methods. The modeling process is built upon two cornerstones: special system call execution traces generated through dynamic analysis of suspicious code and a self-defined taxonomy of (malicious) system activities. The formal model consists of two parts: A definition of malicious behavior in the form of combinations of tasks necessary to achieve a certain malign goal and of rules for translating each task into possible patterns of system calls. Both models are realized through formal grammars. The behavior model uses the tasks as the alphabet and the grammar rules define which patterns of activities can be used to accomplish certain high-level malicious goals. The translation model on the other hand contains an attributed context-free grammar for each task. The alphabet of each grammar consists of Windows system (API) calls, the grammar rules map each task to patterns of these calls. The attributes are used to convey information contained in the parameters of the individual calls. Hermann Dornhackl, Konstantin Kadletz, Robert Luh, Paul Tavolato |
ARES | 3 |
| 2014 | Problem characterization and abstraction for visual analytics in behavior-based malware pattern analysisabstractBehavior-based analysis of emerging malware families involves finding suspicious patterns in large collections of execution traces. This activity cannot be automated for previously unknown malware families and thus malware analysts would benefit greatly from integrating visual analytics methods in their process. However existing approaches are limited to fairly static representations of data and there is no systematic characterization and abstraction of this problem domain. Therefore we performed a systematic literature study, conducted a focus group as well as semi-structured interviews with 10 malware analysts to elicit a problem abstraction along the lines of data, users, and tasks. The requirements emerging from this work can serve as basis for future design proposals to visual analytics-supported malware pattern analysis. Markus Wagner 0008, Wolfgang Aigner, Alexander Rind, Hermann Dornhackl, Konstantin Kadletz, Robert Luh, Paul Tavolato |
VizSEC | 6 |