Sandra König

dblp:170/5700 · DBLP profile ↗
← Back
16ranked-venue papers
4as first author
12since 2021 · last 2024
0000-0003-2881-4519ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 11 · 4 first-author · 8 since 2021Software engineering, systems software and programming languages · 4 · 4 since 2021Human-computer interaction and ubiquitous computing · 1Theory of computation · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1
YearPublicationVenuePosition
2024 Learning minimal automata with recurrent neural networks
abstract
Abstract In this article, we present a novel approach to learning finite automata with the help of recurrent neural networks. Our goal is not only to train a neural network that predicts the observable behavior of an automaton but also to learn its structure, including the set of states and transitions. In contrast to previous work, we constrain the training with a specific regularization term. We iteratively adapt the architecture to learn the minimal automaton, in the case where the number of states is unknown. We evaluate our approach with standard examples from the automata learning literature, but also include a case study of learning the finite-state models of real Bluetooth Low Energy protocol implementations. The results show that we can find an appropriate architecture to learn the correct minimal automata in all considered cases.
Bernhard K. Aichernig, Sandra König, Cristinel Mateis, Andrea Pferscher, Martin Tappler
Softw. Syst. Model.2
2024 Metricizing the Euclidean Space Toward Desired Distance Relations in Point Clouds
abstract
We introduce the concept of an$\varepsilon $-semimetric that satisfies the same axioms as a topological metric, except for an arbitrarily small allowance to violate the triangle inequality. Under this modification, we demonstrate the possibility of taking arbitrary points in space, assigning arbitrary desired distances between them (independent of their geometric location relative to each other, that is, independent of their “features”), and constructing an$\varepsilon $-semimetric that measures exactly the desired distances in the point cloud. This results in a threat to fairness and objectiveness in applications of clustering algorithms: suppose that an adversary subjectively classifies people according to its whim or discriminatory preferences. Upon accusations of unethical behavior, the malicious data processor can plausibly deny these as follows: it designs a distance function (an$\varepsilon $-semimetric) that is (up to a fully controllable numeric “round-off-error”$\varepsilon $) equivalent to a standard distance like the Euclidean. However, this crafted distance will exactly reproduce the (malicious) results and thus confirm them while pretending objectivity and transparency, since only standard and explainable artificial intelligence was used. This demonstration works without any data poisoning. We illustrate the method on randomly chosen points with stochastically independent random classifications assigned to them. Then, we apply standard implementations of k-Means and DBSCAN on the data points, which both exactly reproduce the desired (randomly chosen) classes. We also discuss non-adversarial applications of$\varepsilon $-semimetrics, and corroborate the construction with examples and implementation in Octave.
Stefan Rass, Sandra König, Shahzad Ahmad 0001, Maksim Goman
IEEE Trans. Inf. Forensics Secur.2
2023 Identification and Evaluation of Cyber-Physical Threats on Interdependent Critical Infrastructures
abstract
Increasing interdependencies between critical infrastructures and digitization increase the vulnerability to cyber-attacks and cyber-physical attacks. Incidents have multiple direct and indirect consequences, including cascading effects, and a formal analysis is strongly recommended to understand these effects. This paper shows how threat identification and impact evaluation for interdependent critical infrastructures can be supported by two existing tools. The approach is illustrated with an example based on a running EU project.
Sandra König, Abdelkader Magdy Shaaban, Tamara Hadjina, Klemen Gregorc, Albert Kutej
ARES1
2023 PRAETORIAN: A Framework for the Protection of Critical Infrastructures from advanced Combined Cyber and Physical Threats
abstract
Combined cyber and physical attacks on Critical Infrastructures have disastrous consequences on economies and in social well-being. Protection and resilience of CIs under combined attacks is challenging due to their complexity, reliance on ICT systems and the interdependences between different types of CIs. The PRAETORIAN framework was designed to address these challenges, by integrating components responsible for detecting both cyber and physical threats. Additionally, it forecasts how the combined attacks will evolve and their cascading effects on interdependent CIs. The PRAETORIAN framework was demonstrated based on a realistic scenario in the Zagreb airport, combining both physical and cyber attacks.
Lazaros Papadopoulos, Antonis Karteris, Dimitrios Soudris, Eva María Muñoz Navarro, Juan Jose Hernandez-Montesinos, Stéphane Paul, Nicolas Museux, Sandra König, Manuel Egger, Stefan Schauer, Javier Hingant, Tamara Hadjina
ARES8
2023 A Systematic Approach to Automotive Security
Masoud Ebrahimi 0002, Stefan Marksteiner, Dejan Nickovic, Roderick Bloem, David Schögler, Philipp Eisner, Samuel Sprung, Thomas Schober, Sebastian Chlup, Christoph Schmittner, Sandra König
FM11
2023 Attribute Repair for Threat Prevention
Thorsten Tarrach, Masoud Ebrahimi 0002, Sandra König, Christoph Schmittner, Roderick Bloem, Dejan Nickovic
SAFECOMP3
2023 Game-theoretic APT defense: An experimental study on robotics
abstract
This paper proposes a novel game-theoretic framework for defending against Advanced Persistent Threats (APTs). It applies the original Cut-The-Rope model into an experimental study extending the previously studied attacker movements beyond the Poisson distribution to a realistic set of attack actions. More importantly, it demonstrates the value of this framework on an experimental study of an APT defense game on attack graphs, which lets a security officer establish an optimized defense policy against stealthy intrusions. The security model and algorithm under study is designed for practical use with attack graphs as threat models, possibly including vulnerability information if available. The game-theoretic optimization delivers a proactive defense policy under the following assumptions or requirements: first, we do not need to assume that the system is, or has been, clean from adversaries at any time. At the moment when the defender computes the defense policy, the attacker is assumed to already be in the system (also having penetrated it until an unknown depth). Second, the defender does not rely on any signaling or other indicators of adversarial activity, nor is there a reliable feedback mechanism to tell the defender if its actions were successful or not. Third, the model can use information on exploits, such as Common Vulnerabilities and Exposures (CVE) numbers, to refine the defense game, but can also operate without such information. We corroborate our findings on publicly documented attack graphs from the robotics domain; without and with CVE information. We run experiments against two different types of defense regimes, and compare the results against an intuitive baseline defense heuristic. The results show that the optimized defense strongly outperforms simple heuristics, like taking the shortest or easiest attack paths.
Stefan Rass, Sandra König, Jasmin Wachter, Victor Mayoral Vilches, Emmanouil A. Panaousis
Comput. Secur.2
2022 Parametrization of Probabilistic Risk Models
abstract
Probabilistic risk models are popular due to their ability to capture uncertainty. However, the parametrization of such models may be challenging, especially in the context of critical infrastructures where data is sometimes sparse. In this paper we propose different methods to parametrize a stochastic model of risk propagation depending on the amount of information available. Two of the approaches are illustrated with an example of a critical infrastructure and the application of the other methods is sketched.
Sandra König, Abdelkader Magdy Shaaban
ARES1
2022 Constrained Training of Recurrent Neural Networks for Automata Learning
Bernhard K. Aichernig, Sandra König, Cristinel Mateis, Andrea Pferscher, Dominik Schmidt, Martin Tappler
SEFM2
2022 Supervised Machine Learning with Plausible Deniability
Stefan Rass, Sandra König, Jasmin Wachter, Manuel Egger, Manuel Hobisch
Comput. Secur.2
2021 Multi-categorical Risk Assessment for Urban Critical Infrastructures
Sandra König, Stefan Schauer, Stefan Rass
CRITIS1
2021 Asset Driven ISO/SAE 21434 Compliant Automotive Cybersecurity Analysis with ThreatGet
Christoph Schmittner, Bernhard Schrammel, Sandra König
EuroSPI3
2019 Estimating Cascading Effects in Cyber-Physical Critical Infrastructures
Stefan Schauer, Thomas Grafenauer, Sandra König, Manuel Warum, Stefan Rass
CRITIS3
2018 A Simulation Tool for Cascading Effects in Interdependent Critical Infrastructures
abstract
Critical infrastructures are a core part in modern society, supplying essential goods and services for our everyday life. Therefore, any incident compromising the operation of a critical infrastructure can directly affect the social life. Moreover, due to the increasing interconnections between critical infrastructures, any incident can have cascading effects on other infrastructures as well. In this article, we present a novel simulation framework which allows to model the interdependencies and thus also the cascading effects among critical infrastructures. This framework builds upon stochastic processes describing, on the one hand, the relations between the critical infrastructures and, on the other hand, the random and sometimes arbitrary propagation of the consequences. This existing framework is extended and implemented in OMNeT++, which allows an easy and swift implementation of the mathematical algorithms and also provides a built-in visualization of the propagation of consequences within the critical infrastructure network. The goal is to support risk and security officers within the critical infrastructure in their decisions.
Thomas Grafenauer, Sandra König, Stefan Rass, Stefan Schauer
ARES2
2018 A Measure for Resilience of Critical Infrastructures
Sandra König, Thomas Schaberreiter, Stefan Rass, Stefan Schauer
CRITIS1
2016 Modelling security risk in critical utilities: The system at risk as a three player game and agent society
abstract
It becomes essential when reasoning about the security risks to critical utilities such electrical power and water distribution to recognize that the interests of producers and consumers do not fully coincide. They may have incentives to behave strategically towards each other, as well as toward some third party adversary. We therefore argue for the need to extend the prior literature, which has concentrated on the strategic, adaptive game between adversary and defender, towards 3-player games. But it becomes hard to justify modelling a population of consumers as a single, decision making actor. So we also show how we can model consumers as a group of mutually-influencing, yet not centrally co-ordinated, heterogeneous agents. And we suggest how this representation can be integrated into a game-theoretic framework. This requires a framework in which payoffs are known by the players only stochastically. We present some basic models and demonstrate the nature of the modelling commitments that need to be made in order to reason about utilities' security risk.
Jeremy Busby, Antonios Gouglidis, Stefan Rass, Sandra König
SMC4