Martin Pirker

dblp:22/1237 · DBLP profile ↗
← Back
12ranked-venue papers
6as first author
6since 2021 · last 2024
0000-0003-3517-5479ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 10 · 5 first-author · 5 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
YearPublicationVenuePosition
2024 The State of Boot Integrity on Linux - a Brief Review
abstract
With the upcoming generational change from Windows 10 to Windows 11, the Trusted Platform Module as a security supporting component will be a requirement for every common PC. While the TPM has seen use with some applications already, its near future ubiquitous presence in all PCs motivates an updated review of TPM supporting software. This paper focuses on the software ecosystem that supports secure boot, a chain of measurements for integrity assessments, and challenges in remote attestation. A brief reflection on the state of the various projects gives a rough overview, but is not an exhaustive and in-depth survey. Still, this short paper contributes to the ongoing adoption and reflection of TPM v2’s features and opportunities.
Martin Pirker
ARES2
2024 A Brief Reflection on Trusted Platform Module Support
Martin Pirker
ICISSP1
2023 DISA - A Blockchain-Based Distributed Information Security Audit
Lukas König, Martin Pirker, Herfried Geyer, Michael Feldmann 0003, Simon Tjoa, Peter Kieseberg
iiWAS2
2022 A Revisit of Attestable Nodes for Networked Applications
abstract
A core security (or trustworthiness) question for all designs of networked applications persists: If distributed nodes connect, are these nodes trustworthy? Is it possible to assess a node’s software state before sharing data, programs and/or interacting with them? This paper revisits a scenario of assembling distributed, individual nodes for networked applications, such as data science compute nodes or bridge nodes connecting established applications to novel blockchain-related applications and their ecosystem. By taking advantage of special hardware support (Intel TXT), modern boot software that supports it (Trenchboot) and a custom attestation-before-joining protocol, we report on our prototype implementation how attestable nodes can be achieved today.
Mathias Schüpany, Martin Pirker
ARES2
2021 Obstacles and Challenges in Transforming Applications for Distributed Data Ledger Integration
abstract
The application opportunities of distributed ledger technologies (DLT) for replicated, shared and synchronized data, across multiple nodes in a network, may create new possibilities in computing. There are notable differences between applications designed from scratch for being DLT-enabled and established IT applications that assume fundamentally a centralized computing architecture. This short paper reflects on the challenges in transforming established, conventional IT applications to be DLT-enabled. If such a transformation can be implemented successfully, repeatedly, and with acceptable effort, this means that today’s currently deployed IT applications may subsequently take advantage of beneficial properties of DLT. However, there are still a variety of aspects that need to be considered—this short paper contributes to that discussion.
Martin Pirker, Ernst Piller
ARES1
2021 Securing the Linux Boot Process: From Start to Finish
Jakob Hagl, Oliver Mann, Martin Pirker
ICISSP3
2020 A Curious Exploration of Malicious PDF Documents
Julian Lindenhofer, Rene Offenthaler, Martin Pirker
ICISSP3
2018 Behavioural Comparison of Systems for Anomaly Detection
abstract
The internet is a bottomless cesspool of malicious software that attacks users and their devices or servers that offer services---on a worldwide scale. A defence against this constant barrage of attacks is difficult. While knowledge of previous attacks helps to prevent some new attacks, a determined attacker will almost always succeed. This paper proposes an approach to detect novel attacks via a comparison of system behaviour. A combination of a system-wide events collection and subsequent data analysis fingerprints processes and their file access behaviour. A comparison of these fingerprints results in seven "sameness" categories for processes, sorted from completely identical behaviour to unique and therefore highly suspicious. This categorisation provides guidance for further detailed assessment, if required. Results and insights from a prototype implementation suggest that the presented approach is a strategy for the detection of novel attacks.
Martin Pirker, Patrick Kochberger, Stefan Schwandter
ARES1
2013 Trusted Identity Management for Overlay Networks
Stefan Kraxberger, Ronald Toegl, Martin Pirker, Elisa Pintado Guijarro, Guillermo Garcia Millan
ISPEC3
2012 Lightweight Distributed Attestation for the Cloud
Martin Pirker, Johannes Winter, Ronald Toegl
CLOSER1
2012 Practical Privacy Preserving Cloud Resource-Payment for Constrained Clients
Martin Pirker, Daniel Slamanig, Johannes Winter
Privacy Enhancing Technologies1
2012 A Framework for Privacy-Preserving Mobile Payment on Security Enhanced ARM TrustZone Platforms
abstract
Modern smartphones with the capability to be always online and equipped with data transfer interfaces such as NFC allow to take advantage of a wide variety of services and pave the way for new classes of services. Naturally, not every service will be available for free, some providers will charge money for the services provided. Usually, users are uniquely identified by the provider of a service for billing purposes and providers therefore maintain user profiles. This allows to personalize services with respect to user's interests and preferences. However, it is problematic regarding user's privacy since users disclose lots of sensitive information to the service provider. Different mobile payment solutions have been proposed to date, but privacy aspects are usually not considered at all. In this paper, we demonstrate how privacy friendly payment can be realized using a recent payment mechanisms in combination with an ARM processor platform with TrustZone enhancements. We discuss the public transport ticket domain as an example. Then we propose a platform framework that can be used for arbitrary applications requiring a privacy preserving online remote prepaid payment system suitable for micro as well as macro payments.
Martin Pirker, Daniel Slamanig
TrustCom1