Leon Bock

dblp:156/8964 · also Leon Böck · DBLP profile ↗
← Back
10ranked-venue papers
5as first author
2since 2021 · last 2023
0000-0003-4758-590XORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 8 · 5 first-author · 2 since 2021Computer networks · 1Applied, interdisciplinary, general and emerging computing · 1
YearPublicationVenuePosition
2023 How to Count Bots in Longitudinal Datasets of IP Addresses
Leon Bock, Dave Levin, Ramakrishna Padmanabhan, Christian Doerr, Max Mühlhäuser
NDSS1
2022 Processing of botnet tracking data under the GDPR
abstract
Botnet research is one of the many research areas affected by the coming into force of the General Data Protection Regulation (GDPR). This article aims to identify the most appropriate legal bases that would legitimise data processing in the context of botnet tracking and to give an overview of the practical implications for practitioners. First, we give a technical introduction to botnet tracking techniques and the types of processed data. Afterward, we argue that botnet tracking qualifies as ”processing of personal data” and falls under the material scope of the GDPR. We then present three scenarios where these botnet tracking techniques apply: botnet tracking research in the public interest, botnet tracking in the commercial interest and botnet tracking conducted by Internet service providers. For each scenario, we discuss the differing goals, identify the appropriate legal bases, and elaborate on the practical implications. This article concludes that the legal implications are very different for each of the three scenarios, highlighting the importance of carefully considering the legal bases before engaging in botnet tracking.
Leon Bock, Martin Fejrskov, Katerina Demetzou, Shankar Karuppayah, Max Mühlhäuser, Emmanouil Vasilomanolakis
Comput. Law Secur. Rev.1
2020 IoT dataset generation framework for evaluating anomaly detection mechanisms
abstract
Machine learning based anomaly detection mechanisms are a promising tool to detect and protect networks from previously unknown attacks. The quality of those mechanisms strongly depends on the availability of large amounts of data for their training and evaluation. However, suitable datasets are scarce, as they are rarely shared by those who possess them. This impedes progress in the development and deployment of sophisticated machine learning mechanisms. This paper aims to accelerate this thwarted development process by introducing a network simulation framework for training-data generation and evaluation of data-driven mechanisms, like anomaly detection approaches. The framework enables training, testing, and evaluating data-driven approaches in a safe and extensible environment prior to their deployment in real-world systems. We showcase the capabilities of the framework in a case study. For this, a smart home network is modeled and simulated within the framework. The generated data is used to train an anomaly detection approach, which is then used to detect various anomalies introduced by attacks on the network. This ability to train and evaluate data-driven algorithms within the framework allows users to accelerate the otherwise time-consuming cycle of deploying, modifying, and re-training in live environments, which ultimately advances the development of novel anomaly detection approaches.
Andreas Meyer-Berg, Rolf Egert, Leon Bock, Max Mühlhäuser
ARES3
2019 Limits in the data for detecting criminals on social media
abstract
Social media represent one of the most popular online tools to spread and exchange formal and informal information based on specific human interests, habits and purposes. As they are free, easy to use and widely adopted, criminals commonly exploit them to quickly disseminate information and propaganda, to recruit people and so on. Due to the vast usage and breadth of topics discussed on them, it is not trivial to identify criminals abusing of social media for their purposes. Machine learning techniques have already shown benefits in classification problems in different application domains. As a consequence, a trained classifier for the identification of potential malicious users on these platforms would represent a desirable solution. In this perspective, this work explores the possibility of using data which are extracted from public personal features in order to identify potential terrorists on social media, by showing current limits. To this aim, a public dataset on known terrorist's details is combined with a manually collected dataset of public Facebook profiles. The adopted approach is presented and then the data-related issues, which emerged from this experience, are discussed1.
Andrea Tundis, Leon Bock, Victoria Stanilescu, Max Mühlhäuser
ARES2
2019 Poster: Challenges of Accurately Measuring Churn in P2P Botnets
abstract
Peer-to-peer (P2P) botnets are known to be highly resilient to takedown attempts. Such attempts are usually carried out by exploiting vulnerabilities in the bots communication protocol. However, a failed takedown attempt may alert botmasters and allow them to patch their vulnerabilities to thwart subsequent attempts. As a promising solution, takedowns could be evaluated in simulation environments before attempting them in the real world. To ensure such simulations are as realistic as possible, the churn behavior of botnets must be understood and measured accurately. This paper discusses potential pitfalls when measuring churn in live P2P botnets and proposes a botnet monitoring framework for uniform data collection and churn measurement for P2P botnets.
Leon Bock, Shankar Karuppayah, Kory Fong, Max Mühlhäuser, Emmanouil Vasilomanolakis
CCS1
2019 Autonomously detecting sensors in fully distributed botnets
abstract
Botnet attacks have devastating effects on public and private infrastructures. The botmasters controlling these networks aim to prevent takedown attempts by using highly resilient P2P overlays to commandeer their botnets, and even harden them with countermeasures against intelligence gathering attempts. In fact, recent research indicates that advanced countermeasures can hamper the ability to gather the necessary intelligence for taking down botnets. In this article, we take the perspective of the botmaster to eventually anticipate their behavior. That said, we present a novel mechanism, namely Trust Based Botnet Monitoring Countermeasure (TrustBotMC), that combines computational trust with specially crafted bot messages to detect the presence of monitoring activity. We study and evaluate different computational trust models, to create a local and autonomous mechanism that ensures the avoidance of common botnet tracking mechanisms, such as sensors. Furthermore, we show, via our experimental results, that our approach can reduce the gathered intelligence by at least 53% compared to techniques that have been seen in botnets to date. Finally, we investigate techniques for mitigating our approach.
Leon Bock, Emmanouil Vasilomanolakis, Jan Helge Wolf, Max Mühlhäuser
Comput. Secur.1
2018 Next Generation P2P Botnets: Monitoring Under Adverse Conditions
Leon Bock, Emmanouil Vasilomanolakis, Max Mühlhäuser, Shankar Karuppayah
RAID1
2017 SensorBuster: On Identifying Sensor Nodes in P2P Botnets
abstract
The ever-growing number of cyber attacks originating from botnets has made them one of the biggest threat to the Internet ecosystem. Especially P2P-based botnets like ZeroAccess and Sality require special attention as they have been proven to be very resilient against takedown attempts. To identify weaknesses and to prepare takedowns more carefully it is thus a necessity to monitor them by crawling and deploying sensor nodes. This in turn provokes botmasters to come up with monitoring countermeasures to protect their assets. Most existing anti-monitoring countermeasures focus mainly on the detection of crawlers and not on the detection of sensors deployed in a botnet. In this paper, we propose two sensor detection mechanisms called SensorRanker and SensorBuster. We evaluate these mechanisms in two real world botnets, Sality and ZeroAccess. Our results indicate that SensorRanker and SensorBuster are able to detect up to 17 sensors deployed in Sality and four within ZeroAccess.
Shankar Karuppayah, Leon Bock, Tim Grube, Selvakumar Manickam, Max Mühlhäuser, Mathias Fischer 0001
ARES2
2014 Twitterize: Anonymous Micro-blogging
abstract
Privacy, in particular anonymity, is required to increase the acceptance of users for the Internet of Things (IoT). The IoT is built upon sensors that encompass us in each step we take. Hence, they can collect sensitive, privacy-invading data that can be used to establish complete user profiles. For this reason, sensing in the IoT needs to provide means of privacy-protection. In this paper, we discuss an approach for sharing smartphone sensor data and user-generated content in a privacy-protecting manner via the Micro-blogging platform (MbP) Twitter. For that, we discuss privacy needs of users in Micro-blogging platforms (MbPs) and that privacy should not only ensure confidentiality but also anonymity. We discuss related work and systems along these requirements and conclude that anonymity is hardly considered. We introduce our construction Twitterize that integrates well with the MbP Twitter and allows users and sensors to share information normally as well as privacy-preserving with a single application. Twitterize establishes overlay networks for hashtags over Twitters' social network and neither depends on additional infrastructure nor peer-to-peer communication.
Jörg Daubert, Leon Bock, Panayotis Kikiras, Max Mühlhäuser, Mathias Fischer 0001
AICCSA2
2014 A privacy-enhancing protocol that provides in-network data aggregation and verifiable smart meter billing
abstract
We present an innovative protocol combining innetwork data aggregation and smart meter billing for a smart grid scenario. The former enables an energy supplier to allocate and balance resources. The latter provides dynamic pricing schemes according to fine-grained consumption profiles. Moreover, smart meters and their energy supplier can prove their billing values. Since the energy supplier knows the amount of generated electricity and the consolidated consumption in a round of measurements, the energy supplier can detect energy loss and fraud. To preserve customers' privacy, we use a homomorphic commitment scheme with a homomorphic encryption scheme. All data sent from a meter to any other component in the communication network is either a commitment or an encrypted message. To provide security and privacy, we only require software modifications, leaving the hardware of the smart grid unchanged.
Fábio Borges, Denise Demirel, Leon Bock, Johannes Buchmann 0001, Max Mühlhäuser
ISCC3