Konrad Weiss

dblp:199/7081 · DBLP profile ↗
← Back
6ranked-venue papers
2as first author
4since 2021 · last 2024
0000-0002-1282-2162ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 3 · 1 first-author · 2 since 2021Computer networks · 1 · 1 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
YearPublicationVenuePosition
2024 Analyzing the Impact of Copying-and-Pasting Vulnerable Solidity Code Snippets from Question-and-Answer Websites
abstract
Ethereum smart contracts are executable programs deployed on a blockchain. Once deployed, they cannot be updated due to their inherent immutability. Moreover, they often manage valuable assets that are worth millions of dollars, making them attractive targets for attackers. The introduction of vulnerabilities in programs due to the reuse of vulnerable code posted on Q&A websites such as Stack Overflow is not a new issue. However, little effort has been made to analyze the extent of this issue on deployed smart contracts.
Konrad Weiss, Christof Ferreira Torres, Florian Wendland
IMC1
2023 Privacy Property Graph: Towards Automated Privacy Threat Modeling via Static Graph-based Analysis
abstract
Privacy threat modeling should be done frequently throughout development and production to be able to quickly mitigate threats. Yet, it can also be a very time-consuming activity. In this paper, we use an enhanced code property graph to partly automate the privacy threat modeling process: It automatically generates a data flow diagram from source code which exhibits privacy properties of data flows, and which can be analyzed semi-automatically via queries. We provide a list of such reusable queries that can be used to detect various privacy threats. To enable this analysis, we integrate a taint-tracking mechanism into the graph using privacy-specific labels. Since no benchmark for such an approach exists, we also present a test suite for privacy threat implementations which comprises implementations for 22 privacy threats in multiple programming languages. We expect that our approach significantly reduces time consumption of threat modeling and show that it also has potential beyond the threat categories defined by LINDDUN, e.g. to detect privacy anti-patterns and verify compliance to privacy policies.
Immanuel Kunz, Konrad Weiss, Angelika Schneider, Christian Banse
Proc. Priv. Enhancing Technol.2
2022 Poster: Patient Community - A Test Bed for Privacy Threat Analysis
abstract
Research and development of privacy analysis tools currently suffers from a lack of test beds for evaluation and comparison of such tools. In this work, we propose a benchmark application that implements an extensive list of privacy weaknesses based on the LINDDUN methodology. It represents a social network for patients whose architecture has first been described in an example analysis conducted by one of the LINDDUN authors. We have implemented this architecture and extended it with more privacy threats to build a test bed that enables comprehensive and independent testing of analysis tools.
Immanuel Kunz, Angelika Schneider, Christian Banse, Konrad Weiss, Andreas Binder
CCS4
2021 Cloud Property Graph: Connecting Cloud Security Assessments with Static Code Analysis
abstract
In this paper, we present the Cloud Property Graph (CloudPG), which bridges the gap between static code analysis and runtime security assessment of cloud services. The CloudPG is able to resolve data flows between cloud applications deployed on different resources, and contextualizes the graph with runtime information, such as encryption settings. To provide a vendorand technology-independent representation of a cloud service's security posture, the graph is based on an ontology of cloud resources, their functionalities and security features. We show, using an example, that our CloudPG framework can be used by security experts to identify weaknesses in their cloud deployments, spanning multiple vendors or technologies, such as AWS, Azure and Kubernetes. This includes misconfigurations, such as publicly accessible storages or undesired data flows within a cloud service, as restricted by regulations such as GDPR.
Christian Banse, Immanuel Kunz, Angelika Schneider, Konrad Weiss
CLOUD4
2019 Annotary: A Concolic Execution System for Developing Secure Smart Contracts
Konrad Weiss, Julian Schütte
ESORICS (1)1
2017 Ariadnima - Android Component Flow Reconstruction and Visualization
abstract
Android applications are built with a set of different component types that serve specific purposes. Thanks to Android's system design they can interact with each other in a variety of ways, which makes it possible to complete complex tasks. The downside of the flexible interconnectivity of system components is that the relationship between them can be very complex and hard to understand. To give a better understanding of the interconnectivity of components, this work focuses on the reconstruction of relationships between the components of an app. Our approach focusses on real world applications by minimizing the need for complex calculations (e.g., flow analysis) where possible. On the basis of static code analysis component transitions will be reconstructed, and in a second step these transitions are then visualized to allow an analyst to easily understand the relationships of the app's components.
Dennis Titze, Konrad Weiss, Julian Schütte
AINA2