Robert Altschaffel

dblp:22/7693 · DBLP profile ↗
← Back
6ranked-venue papers
3as first author
3since 2021 · last 2025
0009-0007-6843-7021ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 6 · 3 first-author · 3 since 2021
YearPublicationVenuePosition
2025 Traces Left by the Originator: Forensic Fingerprinting Hidden Malware in Images to Enable Attribution on the Example of SteganoAmor
abstract
Information Hiding used in malware is a recent trend.Its detection as well as origin attribution is of interest to hold actors responsible and provide well tuned prevention and reaction.We propose a Forensic Fingerprint for images to individualize traces left from malicious actors.The idea is to define feature spaces to structure artefacts in the stego objects caused by embedding code into a cover image as StegoFingerprint to describe Parameter-based-Artefacts and artefacts included in embedded malicious payloads as PayloadFingerprint to collect Payload-based-Artefacts.The approach is exemplary applied on 11 live samples (AV-Test cases) from the SteganoAmor campaign (appending code into JPEG meta data) and compared with a simulation using the known steganographic algorithm StegHide with an embedding into media data.We investigate how a first feature space of 10 StegoFingerprint and 32 PayloadFingerprint features can answer the questions: (1) Enable-Detection (EDE): How many incidents can be detected?, (2) Enable-Attribution (EAT): How many different attackers are active in detected cases? and (3) Enable-Discrimination of Identity (EDI): Can traces be used to attribute digital or real identities by using found trace knowledge in context searches.In summary results for the live samples and our simulations show that the Fingerprint can differentiate between attacks and derive for one live sample an attacker identity, pseudonymized in this paper.
Jana Dittmann, Stefan Kiltz, Robert Altschaffel, Judith Antal
IH&MMSec3
2022 Hidden in Plain Sight - Persistent Alternative Mass Storage Data Streams as a Means for Data Hiding With the Help of UEFI NVRAM and Implications for IT Forensics
abstract
This article presents a first study on the possibility of hiding data using the UEFI NVRAM of today's computer systems as a storage channel. Embedding and extraction of executable data as well as media data are discussed and demonstrated as a proof of concept. This is successfully evaluated using 10 different systems. This paper further explores the implications of data hiding within UEFI NVRAM for computer forensic investigations and provides forensics measures to address this new challenge.
Stefan Kiltz, Robert Altschaffel, Jana Dittmann
IH&MMSec2
2021 Meta and Media Data Stream Forensics in the Encrypted Domain of Video Conferences
abstract
Our paper presents a systematic approach to investigate whether and how events can be identified and extracted during the use of video conferencing software. Our approach is based on the encrypted meta and multimedia data exchanged during video conference sessions. It relies on the network data stream which contains data interpretable without decryption (plain data) and encrypted data (encrypted content) some of which is decrypted using our approach (decrypted content). This systematic approach uses a forensic process model and the fission of network data streams before applying methods on the specific individual data types. Our approach is applied exemplary to the Zoom Videoconferencing Service with Client Version 5.4.57862.0110 [4], the mobile Android App Client Version 5.5.2 (1328) [4], the webbased client and the servers (accessed between Jan 21st and Feb 4th). The investigation includes over 50 different configurations. For the heuristic speaker identification, two series of nine sets for eight different speakers are collected. The results show that various user data can be derived from characteristics of encrypted media streams, even if end-to-end encryption is used. The findings suggest user privacy risks. Our approach offers the identification of various events, which enable activity tracking (e.g. camera on/off, increased activity in front of camera) by evaluating heuristic features of the network streams. Further research into user identification within the encrypted audio stream based on pattern recognition using heuristic features of the corresponding network data stream is conducted and suggests the possibility to identify users within a specific set.
Robert Altschaffel, Jonas Hielscher, Stefan Kiltz, Jana Dittmann
IH&MMSec1
2019 Digital Forensics in Industrial Control Systems
Robert Altschaffel, Mario Hildebrandt, Stefan Kiltz, Jana Dittmann
SAFECOMP1
2015 Simulation of Automotive Security Threat Warnings to Analyze Driver Interpretations and Emotional Transitions
Robert Altschaffel, Tobias Hoppe, Sven Kuhlmann, Jana Dittmann
SAFECOMP1
2011 Fingerprint Forensics Application Protocol: Semi-automated Modeling and Verification of Watermark-Based Communication Using CASPER and FDR
Ronny Merkel, Christian Krätzer, Robert Altschaffel, Eric Clausing, Maik Schott, Jana Dittmann
IWDW3