Harald Baier

dblp:20/151 · DBLP profile ↗
← Back
34ranked-venue papers
1as first author
13since 2021 · last 2024
0000-0002-9254-6398ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 24 · 12 since 2021Computer networks · 2Artificial intelligence and machine learning · 1 · 1 since 2021Software engineering, systems software and programming languages · 1Theory of computation · 1 · 1 first-authorApplied, interdisciplinary, general and emerging computing · 1
YearPublicationVenuePosition
2024 Towards Reducing Business-Risk of Data Theft Implementing Automated Simulation Procedures of Evil Data Exfiltration
abstract
As of today exposure and remediation technologies are mainly validated by taking the attacker’s perspective. This paradigm is often referred to as Know Your Enemy. It enables a realistic assessment of the actual attack surface of your IT infrastructure. Furthermore, the operational environment is becoming increasingly dynamic and complex. Hence a flexible and adaptable reaction to the tactics, techniques, and procedures of cyber attackers must be implemented. In this work, we present a concept and a prototypical proof of concept, which take both aspects into account. More precisely we present a simulation-based approach in the scope of data exfiltration, which improves anticipation of the attacker’s perspective and thus puts effective and adapted strategies into place. As sample use cases of data exfiltration techniques, we shed light on recent techniques like abuse of scheduled tasks, which presumably will become of increasing importance in the future. Our prototype makes use of common open-source software. During our evaluation, we simulate relevant sections of our sample attack vectors using test data and derive options for detection and protection against the respective simulated attack. Finally, we expound on the integration of our proposed technical and organisational measures into an existing Information Security Management System (ISMS) as part of a process for continuous improvement.
Michael Mundt, Harald Baier, Antje Raab-Düsterhöft
ARES2
2024 Generating Usable and Assessable Datasets Containing Anti-Forensic Traces at the Filesystem Level
Thomas Göbel, Harald Baier, Jan Türr
IFIP Int. Conf. Digital Forensics2
2023 Enhancing Incident Management by an Improved Understanding of Data Exfiltration: Definition, Evaluation, Review
Michael Mundt, Harald Baier
ICDF2C (1)2
2023 Using Perceptual Hashing for Targeted Content Scanning
Leon Twenning, Harald Baier, Thomas Göbel
IFIP Int. Conf. Digital Forensics2
2023 Applying Activity-Based Models to Integrate Labeled Preset Key Events in Intra-Day Human Mobility Scenarios
Patrik Gonçalves, Harald Baier
VEHITS2
2022 Mapping Cyber-Physical Threats for Critical Infrastructures
Michael Mundt, Harald Baier
CRITIS2
2022 Towards Efficient On-Site CSAM Triage by Clustering Images from a Source Point of View
Samantha Klier, Harald Baier
ICDF2C2
2022 Cyber Crime Undermines Data Privacy Efforts - On the Balance Between Data Privacy and Security
Michael Mundt, Harald Baier
ICDF2C2
2022 Smartphone Data Distributions and Requirements for Realistic Mobile Device Forensic Corpora
Patrik Gonçalves, Andreas Attenberger, Harald Baier
IFIP Int. Conf. Digital Forensics3
2022 Realistic and Configurable Synthesis of Malware Traces in Windows Systems
Martin Lukner, Thomas Göbel, Harald Baier
IFIP Int. Conf. Digital Forensics3
2021 Find My IoT Device - An Efficient and Effective Approximate Matching Algorithm to Identify IoT Traffic Flows
Thomas Göbel, Frieder Uhlig, Harald Baier
ICDF2C3
2021 Towards Mitigation of Data Exfiltration Techniques Using the MITRE ATT&CK Framework
Michael Mundt, Harald Baier
ICDF2C2
2021 Evaluation of Network Traffic Analysis Using Approximate Matching Algorithms
Thomas Göbel, Frieder Uhlig, Harald Baier
IFIP Int. Conf. Digital Forensics3
2020 A Novel Approach for Generating Synthetic Datasets for Digital Forensics
Thomas Göbel, Thomas Schäfer, Julien Hachenberger, Jan Türr, Harald Baier
IFIP Int. Conf. Digital Forensics5
2020 Distributed DDoS Defense: A collaborative Approach at Internet Scale
abstract
Distributed large-scale cyber attacks targeting the availability of computing and network resources still remain a serious threat. To limit the effects caused by those attacks and to provide a proactive defense, mitigation should move to the networks of Internet Service Providers (ISPs). In this context, this thesis focuses on a development of a collaborative, automated approach to mitigate the effects of Distributed Denial of Service (DDoS) attacks at Internet Scale. This thesis has the following contributions: i) a systematic and multifaceted study on mitigation of large-scale cyber attacks at ISPs. ii) A detailed guidance selecting an exchange format and protocol suitable to use to disseminate threat information. iii) To overcome the shortcomings of missing flow-based interoperability of current exchange formats, a development of the exchange format Flow-based Event Exchange Format (FLEX). iv) A communication process to facilitate the automated defense in response to ongoing network-based attacks, v) a model to select and perform a semi-automatic deployment of suitable response actions. vi) An investigation of the effectiveness of the defense techniques moving-target using Software Defined Networking (SDN) and their applicability in context of large-scale cyber attacks and the networks of ISPs. Finally, a trust model that determines a trust and a knowledge level of a security event to deploy semi-automated remediations and facilitate the dissemination of security event information using the exchange format FLEX in context of ISP networks.
Jessica Steinberger, Anna Sperotto, Harald Baier, Aiko Pras
NOMS3
2019 Revisiting Data Hiding Techniques for Apple File System
abstract
Data hiding is an important part of anti-forensic research since the continuous development of operating systems, file systems and other software may close some previously known vulnerabilities but will often inadvertently create new ones. Many of the currently used file systems such as FAT, NTFS or ext4 have been thoroughly analysed. There are quite a few theoretical approaches and also some practical tools that help us to hide data in the existing file systems in different ways. For the Apple File System (APFS), the new standard file system for all Apple devices, only part of the previous work is transferable. There are only a few published forensic analyses of APFS so far and some forensic tools like the Sleuthkit have at least partially adapted APFS functionality. However, anti-forensic techniques specific to APFS have not yet been explored.
Thomas Göbel, Jan Türr, Harald Baier
ARES3
2018 fishy - A Framework for Implementing Filesystem-Based Data Hiding Techniques
Thomas Göbel, Harald Baier
ICDF2C2
2018 On Efficiency and Effectiveness of Linear Function Detection Approaches for Memory Carving
Lorenz Liebler, Harald Baier
ICDF2C2
2018 Anti-Forensic Capacity and Detection Rating of Hidden Data in the Ext4 Filesystem
Thomas Göbel, Harald Baier
IFIP Int. Conf. Digital Forensics2
2018 DDoS defense using MTD and SDN
abstract
Distributed large-scale cyber attacks targeting the availability of computing and network resources still remains a serious threat. In order to limit the effects caused by those attacks and to provide a proactive defense, mitigation should move to the networks of Internet Service Providers. In this context, Moving Target Defense (MTD) is a technique that increases uncertainty due to an ever-changing attack surface. In combination with Software Defined Networking (SDN), MTD has the potential to reduce the effects of a large-scale cyber attack. In this paper, we combine the defense techniques moving-target using Software Defined Networking and investigate their effectiveness. We review current moving-target defense strategies and their applicability in context of large-scale cyber attacks and the networks of Internet Service Providers. Further, we enforce the implementation of moving target defense strategies using Software Defined Networks in a collaborative environment. In particular, we focus on ISPs that cooperate among trusted partners. We found that the effects of a large-scale cyber attack can be significantly reduced using the moving-target defense and Software Defined Networking. Moreover, we show that Software Defined Networking is an appropriate approach to enforce implementation of the moving target defense and thus mitigate the effects caused by large-scale cyber attacks.
Jessica Steinberger, Benjamin Kuhnert, Christian Dietz, Lisa Ball, Anna Sperotto, Harald Baier, Aiko Pras, Gabi Dreo Rodosek
NOMS6
2017 Enhancing Breeder Document Long-Term Security Using Blockchain Technology
abstract
In contrast to electronic travel documents (e.g. ePassports), the standardisation of breeder documents (e.g. birth certificates), regarding harmonisation of content and contained security features is in statu nascendi. Due to the fact that breeder documents can be used as an evidence of identity and enable the application for electronic travel documents, they pose the weakest link in the identity life cycle and represent a security gap for identity management. In this work, we present a cost efficient way to enhance the long-term security of breeder documents by utilizing blockchain technology. A conceptual architecture to enhance breeder document long-term security and an introduction of the concept's constituting system components is presented. Our investigations provide evidence that the Bitcoin blockchain is most suitable for breeder document long-term security.
Nicolas Buchmann, Christian Rathgeb, Harald Baier, Christoph Busch 0001, Marian Margraf
COMPSAC (2)3
2017 Approxis: A Fast, Robust, Lightweight and Approximate Disassembler Considered in the Field of Memory Forensics
Lorenz Liebler, Harald Baier
ICDF2C2
2016 Correlating network events and transferring labels in the presence of IP address anonymisation
abstract
The availability of labelled data, i.e. ground-truth or reference data, is typically a requirement for performing network research, especially for network security research. Labelled data, however, are sparsely available. Data sets present in repositories such as CAIDA or PREDICT are mostly missing labels and have IP addresses anonymised. Especially the latter compounds correlating these data sets with third-party information in order to assign labels a posteriori. To address this problem, we propose a scheme to anonymise IP addresses such that later correlation is still possible, without compromising security of either data sponsoring entity. The scheme we propose is based on Crypto-PAn and is able to correlate events using anonymised IP addresses as correlation keys, without restricting choice of the cryptographic secret.
Sebastian Abt, Harald Baier
CNSM2
2016 Collaborative DDoS defense using flow-based security event information
abstract
Over recent years, network-based attacks evolved to the top concerns responsible for network infrastructure and service outages. To counteract such attacks, an approach is to move mitigation from the target network to the networks of Internet Service Providers (ISP). In addition, exchanging threat information among trusted partners is used to reduce the time needed to detect and respond to large-scale network-based attacks. However, exchanging threat information is currently done on an ad-hoc basis via email or telephone, and there is still no interoperable standard to exchange threat information among trusted partners. To facilitate the exchange of security event information in conjunction with widely adopted monitoring technologies, in particular network flows, we make use of the exchange format FLEX. The goal of this paper is to present a communication process that supports the dissemination of threat information based on FLEX in context of ISPs. We show that this communication process helps organizations to speed up their mitigation and response capabilities without the need to modify the current network infrastructure, and hence make it viable to use for network operators.
Jessica Steinberger, Benjamin Kuhnert, Anna Sperotto, Harald Baier, Aiko Pras
NOMS4
2015 A research process that ensures reproducible network security research
abstract
Access to ground-truth data is limited in network security research, especially at large-scale. If data is available, sharing is typically not possible due to privacy concerns and contractual requirements. Hence, reproducibility of research and comparability of results is difficult. For a prevailing empirical domain of research, the resulting lack of transparency is a methodological problem which especially affects network security management in practice. To address this problem, in this paper we propose a research process that ensures reproducibility by embodying both, synthetic and real-world data. Our motivation for this is to combine best of both worlds: synthetic data is used to establish ground-truth and real-world data to assure validity of results. To the best of our knowledge, no such process has been formulated until today.
Sebastian Abt, Harald Baier
CNSM2
2015 Collaborative attack mitigation and response: A survey
abstract
Over recent years, network-based attacks have become one of the top causes of network infrastructure and service outages. To counteract such attacks, an approach is to move mitigation from the target network to the networks of Internet Service Providers (ISP). However, it remains unclear to what extent countermeasures are set up and which mitigation approaches are adopted by ISPs. The goal of this paper is to present the results of a survey that aims to gain insight into processes, structures and capabilities of ISPs to mitigate and respond to network-based attacks.
Jessica Steinberger, Anna Sperotto, Harald Baier, Aiko Pras
IM3
2015 How to exchange security events? Overview and evaluation of formats and protocols
abstract
Network-based attacks pose a strong threat to the Internet landscape. Recent approaches to mitigate and resolve these threats focus on cooperation of Internet service providers and their exchange of security event information. A major benefit of a cooperation is that it might counteract a network-based attack at its root and provides the possibility to inform other cooperative partners about the occurrence of anomalous events as a proactive service. In this paper we provide a structured overview of existing exchange formats and protocols. We evaluate and compare the exchange formats and protocols in context of high-speed networks. In particular, we focus on flow data. In addition, we investigate the exchange of potentially sensitive data. For our overview, we review different exchange formats and protocols with respect to their use-case scenario, their interoperability with network flow-based data, their scalability in a high-speed network context and develop a classification.
Jessica Steinberger, Anna Sperotto, Mario Golling, Harald Baier
IM4
2014 Similarity Hashing Based on Levenshtein Distances
Frank Breitinger, Georg Ziroff, Steffen Lange, Harald Baier
IFIP Int. Conf. Digital Forensics4
2014 A Small Data Approach to Identification of Individuals on the Transport Layer using Statistical Behaviour Templates
abstract
Our daily life is dominated by constant Internet connectivity. In order to retrieve up-to-date information and to share personal experiences and impressions, our computers and mobile devices periodically communicate with servers or peers. During this data exchange, we constantly leave digital traces on different systems across the communication stack. These traces can be used to compute profiles of individuals. While such profiles may be used to increase user experience and convenience, they seriously affect privacy of individuals. Typically, service providers like Google or Facebook collect gigabytes to terabytes of user payload data to compute user profiles from. That is, they make use of a big data approach. In contrast to that, this paper shows a novel small data approach to compute profiles using behaviour templates derived from IP address and port number statistics. Our use case is to increase network security through concurrent identification. Our approach is capable of identifying individuals with true- and false-positive rates of 0.995 and 0.001, respectively, without relying on payload information, significantly outperforming related work.
Sebastian Abt, Sebastian Gärtner, Harald Baier
SIN3
2014 Towards a more secure and scalable verifying PKI of eMRTD
abstract
The new electronic passport stores biometric data on a contactless readable chip to uniquely link the travel document to its holder.This sensitive data is protected by a complex protocol called Extended Access Control (EAC) against unlawful readouts.EAC is manifold and thus needs a complex public key infrastructure (PKI).Additionally EAC is known to suffer from unsolved weaknesses, e.g., stolen (mobile) passport inspection systems due to its missing revocation mechanism.The article at hand seeks for potential approaches to solve these shortcomings.As a result we present an evaluation framework with special focus on security and scalability to assess the different candidates and to give a best recommendation.Instead of creating new protocols, we focus on solutions, which are based on well-known protocols from the Internet domain like the Network Time Protocol (NTP), the Online Certificate Status Protocol (OCSP), and the Server-based Certificate Validation Protocol (SCVP).These protocols are openly standardised, thoroughly tested, interoperable, and with the exception of SCVP all widely deployed.In addition to these Internet protocols we evaluate state-of-the-art security protocols proposed by the scientific community, e.g., the Hoepman protocol, the BioPACE V2 protocol and the On-line Secure E-Passport Protocol (OSEP).Our recommendation is that the EU EAC PKI would benefit most from introducing NTP and OCSP, or if fine-grained access control of EAC are considered dispensable by introducing the BioPACE V2 protocol.
Nicolas Buchmann, Harald Baier
J. Comput. Secur.2
2013 Towards a Process Model for Hash Functions in Digital Forensics
Frank Breitinger, Huajian Liu, Christian Winter 0001, Harald Baier, Alexey Rybalchenko, Martin Steinebach
ICDF2C4
2012 Similarity Preserving Hashing: Eligible Properties and a New Algorithm MRSH-v2
Frank Breitinger, Harald Baier
ICDF2C2
2011 Performance Issues About Context-Triggered Piecewise Hashing
Frank Breitinger, Harald Baier
ICDF2C2
2001 Efficient Computation of Singular Moduli with Application in Cryptography
Harald Baier
FCT1