EDBT 2026 Demo / reviewers in the wild / expert
Robert Altschaffel
dblp:22/7693
· DBLP profile ↗
6ranked-venue papers
3as first author
3since 2021 · last 2025
0009-0007-6843-7021ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 6 · 3 first-author · 3 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Traces Left by the Originator: Forensic Fingerprinting Hidden Malware in Images to Enable Attribution on the Example of SteganoAmorabstractInformation Hiding used in malware is a recent trend.Its detection as well as origin attribution is of interest to hold actors responsible and provide well tuned prevention and reaction.We propose a Forensic Fingerprint for images to individualize traces left from malicious actors.The idea is to define feature spaces to structure artefacts in the stego objects caused by embedding code into a cover image as StegoFingerprint to describe Parameter-based-Artefacts and artefacts included in embedded malicious payloads as PayloadFingerprint to collect Payload-based-Artefacts.The approach is exemplary applied on 11 live samples (AV-Test cases) from the SteganoAmor campaign (appending code into JPEG meta data) and compared with a simulation using the known steganographic algorithm StegHide with an embedding into media data.We investigate how a first feature space of 10 StegoFingerprint and 32 PayloadFingerprint features can answer the questions: (1) Enable-Detection (EDE): How many incidents can be detected?, (2) Enable-Attribution (EAT): How many different attackers are active in detected cases? and (3) Enable-Discrimination of Identity (EDI): Can traces be used to attribute digital or real identities by using found trace knowledge in context searches.In summary results for the live samples and our simulations show that the Fingerprint can differentiate between attacks and derive for one live sample an attacker identity, pseudonymized in this paper. Jana Dittmann, Stefan Kiltz, Robert Altschaffel, Judith Antal |
IH&MMSec | 3 |
| 2022 | Hidden in Plain Sight - Persistent Alternative Mass Storage Data Streams as a Means for Data Hiding With the Help of UEFI NVRAM and Implications for IT ForensicsabstractThis article presents a first study on the possibility of hiding data using the UEFI NVRAM of today's computer systems as a storage channel. Embedding and extraction of executable data as well as media data are discussed and demonstrated as a proof of concept. This is successfully evaluated using 10 different systems. This paper further explores the implications of data hiding within UEFI NVRAM for computer forensic investigations and provides forensics measures to address this new challenge. Stefan Kiltz, Robert Altschaffel, Jana Dittmann |
IH&MMSec | 2 |
| 2021 | Meta and Media Data Stream Forensics in the Encrypted Domain of Video ConferencesabstractOur paper presents a systematic approach to investigate whether and how events can be identified and extracted during the use of video conferencing software. Our approach is based on the encrypted meta and multimedia data exchanged during video conference sessions. It relies on the network data stream which contains data interpretable without decryption (plain data) and encrypted data (encrypted content) some of which is decrypted using our approach (decrypted content). This systematic approach uses a forensic process model and the fission of network data streams before applying methods on the specific individual data types. Our approach is applied exemplary to the Zoom Videoconferencing Service with Client Version 5.4.57862.0110 [4], the mobile Android App Client Version 5.5.2 (1328) [4], the webbased client and the servers (accessed between Jan 21st and Feb 4th). The investigation includes over 50 different configurations. For the heuristic speaker identification, two series of nine sets for eight different speakers are collected. The results show that various user data can be derived from characteristics of encrypted media streams, even if end-to-end encryption is used. The findings suggest user privacy risks. Our approach offers the identification of various events, which enable activity tracking (e.g. camera on/off, increased activity in front of camera) by evaluating heuristic features of the network streams. Further research into user identification within the encrypted audio stream based on pattern recognition using heuristic features of the corresponding network data stream is conducted and suggests the possibility to identify users within a specific set. Robert Altschaffel, Jonas Hielscher, Stefan Kiltz, Jana Dittmann |
IH&MMSec | 1 |
| 2019 | Digital Forensics in Industrial Control Systems
Robert Altschaffel, Mario Hildebrandt, Stefan Kiltz, Jana Dittmann |
SAFECOMP | 1 |
| 2015 | Simulation of Automotive Security Threat Warnings to Analyze Driver Interpretations and Emotional Transitions
Robert Altschaffel, Tobias Hoppe, Sven Kuhlmann, Jana Dittmann |
SAFECOMP | 1 |
| 2011 | Fingerprint Forensics Application Protocol: Semi-automated Modeling and Verification of Watermark-Based Communication Using CASPER and FDR
Ronny Merkel, Christian Krätzer, Robert Altschaffel, Eric Clausing, Maik Schott, Jana Dittmann |
IWDW | 3 |