Stefan Marksteiner

dblp:207/7707 · also Stefan F. Marksteiner · DBLP profile ↗
← Back
9ranked-venue papers
4as first author
7since 2021 · last 2025
0000-0001-8556-1541ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 4 · 2 first-author · 2 since 2021Software engineering, systems software and programming languages · 3 · 1 first-author · 3 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Theory of computation · 1 · 1 since 2021
YearPublicationVenuePosition
2025 Learning single and compound-protocol automata and checking behavioral equivalences
abstract
Abstract This paper presents a method and a practical implementation that complements traditional conformance testing. We infer a Mealy state machine of the system-under-test using active automata learning. This automaton is checked for bisimulation with a specification automaton modeled after the standard, which provides a strong verdict of conformance or nonconformance. We further present a method to learn models of multiple communication protocols running on the same device using a dispatcher system in conjunction with the same automata learning algorithms. We subsequently use similar checking methods to compare it with separately learned models. This allows for determining whether there is some interference or interaction between those protocols. In the practical execution of the system, we concentrate on lower levels of the Near-Field Communication (NFC, ISO/IEC 14443-3) and the Bluetooth Low-Energy (BLE) protocols. As a by-product, we share some observations of the performance of different learning algorithms and calibrations in the specific setting of ISO/IEC 14443-3, which is the difficulty to learn models of systems that a) consist of two very similar structures and b) timeout very frequently, as well as the role of conformance testing for compound models and speed optimizations for time-sensitive protocols.
Stefan Marksteiner, David Schögler, Marjan Sirjani, Mikael Sjödin
Int. J. Softw. Tools Technol. Transf.1
2024 Automated Passport Control: Mining and Checking Models of Machine Readable Travel Documents
abstract
Passports are part of critical infrastructure for a very long time. They also have been pieces of automatically processable information devices, more recently through the ISO/IEC 14443 (Near-Field Communication – NFC) protocol. For obvious reasons, it is crucial that the information stored on devices are sufficiently protected. The International Civil Aviation Organization (ICAO) specifies exactly what information should be stored on electronic passports (also Machine Readable Travel Documents – MRTDs) and how and under which conditions they can be accessed. We propose a model-based approach for checking the conformance with this specification in an automated and very comprehensive manner: we use automata learning to learn a full model of passport documents and use trace equivalence and primitive model checking techniques to check the conformance with an automaton modeled after the ICAO standard. Since the full behavior is underspecified in the standard, we compare a part of the learned model and apply a primitive checking ruleset to assure proper authentication. The result is an automated (non-interactive), yet very thorough test for compliance, despite the underspecification. This approach can also be used with other applications for which a specification automaton can be modeled and is therefore broadly applicable.
Stefan Marksteiner, Marjan Sirjani, Mikael Sjödin
ARES1
2023 A Systematic Approach to Automotive Security
Masoud Ebrahimi 0002, Stefan Marksteiner, Dejan Nickovic, Roderick Bloem, David Schögler, Philipp Eisner, Samuel Sprung, Thomas Schober, Sebastian Chlup, Christoph Schmittner, Sandra König
FM2
2023 Zeroth-Order Optimization Attacks on Deep Reinforcement Learning-Based Lane Changing Algorithms for Autonomous Vehicles
Dayu Zhang, Nasser L. Azad, Sebastian Fischmeister, Stefan Marksteiner
ICINCO (1)4
2021 An Agnostic Domain Specific Language for Implementing Attacks in an Automotive Use Case
abstract
This paper presents a Domain Specific Language (DSL) for generically describing cyber attacks, agnostic to specific system-under-test (SUT). The creation of the presented DSL is motivated by an automotive use case. The concepts of the DSL are generic such that attacks on arbitrary systems can be addressed.
Christian Wolschke, Stefan Marksteiner, Tobias Braun, Markus Wolf 0003
ARES2
2021 Steering Drivers of Change: Maximising Benefits of Trustworthy IoT
Omar Veledar, Eric Armengaud, Leo Botler, Violeta Damjanovic-Behrendt, Christian Derler, Stefan Jaksic, Lukas Krammer, Christian Lettner, Georg Macher, Stefan Marksteiner, Martin Matschnig, Peter Priller, Sebastian Ramacher, Kay Römer, Christoph Schmittner, Christina Tiefnig, Heribert Vallant, Heinz Weiskirchner, Mario Drobics
EuroSPI10
2021 A Process to Facilitate Automated Automotive Cybersecurity Testing
abstract
Modern vehicles become increasingly digitalized with advanced information technology-based solutions like advanced driving assistance systems and vehicle-to-x communications. These systems are complex and interconnected. Rising complexity and increasing outside exposure has created a steadily rising demand for more cyber-secure systems. Thus, also standardization bodies and regulators issued standards and regulations to prescribe more secure development processes. This security, however, also has to be validated and verified. In order to keep pace with the need for more thorough, quicker and comparable testing, today's generally manual testing processes have to be structured and optimized. Based on existing and emerging standards for cybersecurity engineering, this paper therefore outlines a structured testing process for verifying and validating automotive cybersecurity, for which there is no standardized method so far. Despite presenting a commonly structured framework, the process is flexible in order to allow implementers to utilize their own, accustomed toolsets.
Stefan Marksteiner, Nadja Marko, Andre Smulders, Stelios Karagiannis, Florian Stahl, Hayk Hamazaryan, Rupert Schlick, Stefan Kraxberger, Alexandr Vasenev
VTC Spring1
2019 Requirements and Recommendations for IoT/IIoT Models to automate Security Assurance through Threat Modelling, Security Analysis and Penetration Testing
abstract
The factories of the future require efficient interconnection of their physical machines into the cyber space to cope with the emerging need of an increased uptime of machines, higher performance rates, an improved level of productivity and a collective collaboration along the supply chain. With the rapid growth of the Internet of Things (IoT), and its application in industrial areas, the so called Industrial Internet of Things (IIoT)/Industry 4.0 emerged. However, further to the rapid growth of IoT/IIoT systems, cyber attacks are an emerging threat and simple manual security testing can often not cope with the scale of large IoT/IIoT networks.
Ralph Ankele, Stefan Marksteiner, Kai Nahrgang, Heribert Vallant
ARES2
2019 Cyber security requirements engineering for low-voltage distribution smart grid architectures using threat modeling
abstract
Incorporating renewable energy into a grid still poses a challenge, that can only be tackled with precise measurement and control. Transferring power from producer to consumer as locally as possible in order to maximize efficiency requires measurement and control functions to be present on the low-voltage grid level. This can only be achieved by massively interconnected, ICT-enhanced sensors and actuators. Interconnecting the former, in turn exposes the grid to various threats from cyberattacks. This creates the need for a holistic, structured and comprehensive approach to engineering a low-voltage smart grid architecture that allocates its resources in such a way that cyber security is preserved. While known previous work either lacks a risk-based approach, comprehensiveness or best practices, this article provides a smart grid-specific methodology that combines risk assessment and threat modeling to generate a holistic set of security requirements. Furthermore, it presents best practices to secure an archetypal smart low-voltage grid architecture based on a concrete example. It considers threats on the architectural, protocol, and device level, while also considering environmental constraints to assure security using mainly state-of-the-art mitigation measures.
Stefan Marksteiner, Heribert Vallant, Kai Nahrgang
J. Inf. Secur. Appl.1