Patrick Kochberger

dblp:169/6360 · DBLP profile ↗
← Back
6ranked-venue papers
2as first author
4since 2021 · last 2026
0000-0002-0898-9824ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 5 · 2 first-author · 3 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Twenty years of the Java Virtual Machine Tool Interface: A systematic literature review
Philipp Haindl, Patrick Kochberger
Inf. Softw. Technol.2
2024 Analysis of the Windows Control Flow Guard
abstract
Cybersecurity’s constantly evolving field demands defense mechanisms’ continuous development and refinement. Memory corruption attacks, including buffer overflows and use-after-free vulnerabilities, have long been a significant threat, especially for web browsers. Microsoft introduced Control Flow Guard (CFG) as a mitigative measure against advanced exploitation techniques, like ROP and use-after-free-based exploits, to address these risks. This paper delves into the internals of CFG, its implementation, effectiveness, and possible bypasses that could undermine its security. A thorough examination of Microsoft’s CFG design principles gives the reader an in-depth understanding of how CFG enforces control flow integrity within a program’s execution. The limitations of this mitigation are highlighted by employing a direct return address overwrite to exploit the ChakraCore JavaScript engine.
Niels Pfau, Patrick Kochberger
ARES2
2023 Large Language Models for Code Obfuscation Evaluation of the Obfuscation Capabilities of OpenAI's GPT-3.5 on C Source Code
Patrick Kochberger, Maximilian Gramberger, Sebastian Schrittwieser, Caroline Lawitschka, Edgar R. Weippl
SECRYPT1
2021 SoK: Automatic Deobfuscation of Virtualization-protected Applications
abstract
Malware authors often rely on code obfuscation to hide the malicious functionality of their software, making detection and analysis more difficult. One of the most advanced techniques for binary obfuscation is virtualization-based obfuscation, which converts the functionality of a program into the bytecode of a randomly generated virtual machine which is embedded into the protected program. To enable the automatic detection and analysis of protected malware, new deobfuscation techniques against virtualization-based obfuscation are constantly being developed and proposed in the literature.
Patrick Kochberger, Sebastian Schrittwieser, Stefan Schweighofer, Peter Kieseberg, Edgar R. Weippl
ARES1
2018 Behavioural Comparison of Systems for Anomaly Detection
abstract
The internet is a bottomless cesspool of malicious software that attacks users and their devices or servers that offer services---on a worldwide scale. A defence against this constant barrage of attacks is difficult. While knowledge of previous attacks helps to prevent some new attacks, a determined attacker will almost always succeed. This paper proposes an approach to detect novel attacks via a comparison of system behaviour. A combination of a system-wide events collection and subsequent data analysis fingerprints processes and their file access behaviour. A comparison of these fingerprints results in seven "sameness" categories for processes, sorted from completely identical behaviour to unique and therefore highly suspicious. This categorisation provides guidance for further detailed assessment, if required. Results and insights from a prototype implementation suggest that the presented approach is a strategy for the detection of novel attacks.
Martin Pirker, Patrick Kochberger, Stefan Schwandter
ARES2
2015 An Open Source Code Analyzer and Reviewer (OSCAR) Framework
abstract
Due to the intense usage of IT and the growing number of fields of application, we rely more than ever on functional software components. In conjunction with this development it could be observed that in the last years the popularity of open source software was on the rise for various reasons. However, in the recent past, serious vulnerabilities have been discovered. In order to support open source developers testing their source code for security bugs, in this paper, we present the idea of a framework which combines existing open source security checkers. After presenting the architecture of the framework we demonstrate the functionality of the framework using the vulnerable application Web Goat.
Simon Tjoa, Patrick Kochberger, Christoph Malin, Andreas Schmoll
ARES2