Demonstration venue · read-only. Every page can be browsed; the buttons that would change it are switched off. Create an account to run TaxoReview on your own data.

Stephan Kleber

dblp:161/5354 · DBLP profile ↗
← Back
5ranked-venue papers
3as first author
1since 2021 · last 2021
0000-0001-9836-4897ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 3 · 2 first-author · 1 since 2021Computer networks · 2 · 1 first-author

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Computer networks
2 papers
Network measurement and analytics · 100%
Network and information security
1 paper
Network security · 100%

Topics — the 2 heaviest of 3, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Network measurement and analytics › protocol analysis
protocol reverse engineering
0.822020
Message Type Identification of Binary Network Protocols using Continuous Segment Similarity · INFOCOM 2020
Poster: Network Message Field Type Recognition · CCS 2019
Network security
traffic analysis
0.112019
Poster: Network Message Field Type Recognition · CCS 2019

Methods — techniques the papers use, named apart from their topics

clustering · 0.8byte vector similarity · 0.8hirschberg alignment · 0.4DBSCAN clustering · 0.4
YearPublicationVenuePosition
2021 ARIstoteles - Dissecting Apple's Baseband Interface
Tobias Kröll, Stephan Kleber, Frank Kargl, Matthias Hollick, Jiska Classen
ESORICS (1)2
2020 Message Type Identification of Binary Network Protocols using Continuous Segment Similarity
abstract
Protocol reverse engineering based on traffic traces infers the behavior of unknown network protocols by analyzing observable network messages. To perform correct deduction of message semantics or behavior analysis, accurate message type identification is an essential first step. However, identifying message types is particularly difficult for binary protocols, whose structural features are hidden in their densely packed data representation. We leverage the intrinsic structural features of binary protocols and propose an accurate method for discriminating message types.Our approach uses a similarity measure with continuous value range by comparing feature vectors where vector elements correspond to the fields in a message, rather than discrete byte values. This enables a better recognition of structural patterns, which remain hidden when only exact value matches are considered. We combine Hirschberg alignment with DBSCAN as cluster algorithm to yield a novel inference mechanism. By applying novel autoconfiguration schemes, we do not require manually configured parameters for the analysis of an unknown protocol, as required by earlier approaches.Results of our evaluations show that our approach has considerable advantages in message type identification result quality and also execution performance over previous approaches.
Stephan Kleber, Rens W. van der Heijden, Frank Kargl
INFOCOM1
2019 Poster: Network Message Field Type Recognition
abstract
Existing approaches to reverse engineer network protocols based on traffic traces lack comprehensive methods to determine the data type, e. g. float, timestamp, or addresses, of segments in messages of binary protocols. We propose a novel method for the analysis of unknown protocol messages to reveal the data types contained in these messages. Therefore, we split messages into segments of bytes and interpret these as vectors of byte values. Based on the vector interpretation, we can determine similarities and characteristics of specific data types. These can be used to classify segments into clusters of the same type and to identify their data type for previously trained data types. We performed first evaluations of different applications of our method that show promising results up the a data-type-recognition precision of 100,%.
Stephan Kleber, Frank Kargl
CCS1
2018 Secure Code Execution: A Generic PUF-Driven System Architecture
Stephan Kleber, Florian Unterstein, Matthias Hiller, Frank Slomka, Matthias Matousek, Frank Kargl, Christoph Bösch 0001
ISC1
2018 An SDN-based Approach For Defending Against Reflective DDoS Attacks
abstract
Distributed Reflective Denial of Service (DRDoS) attacks are an immanent threat to Internet services. The potential scale of such attacks became apparent in March 2018 when a memcached-based attack peaked at 1.7 Tbps. Novel services built upon UDP increase the need for automated mitigation mechanisms that react to attacks without prior knowledge of the actual application protocols used. With the flexibility that software-defined networks offer, we developed a new approach for defending against DRDoS attacks; it not only protects against arbitrary DRDoS attacks but is also transparent for the attack target and can be used without assistance of the target host operator. The approach provides a robust mitigation system which is protocol-agnostic and effective in the defense against DRDoS attacks.
Thomas Lukaseder, Kevin Stölzle, Stephan Kleber, Benjamin Erb, Frank Kargl
LCN3