EDBT 2026 Demo / reviewers in the wild / expert
Marc Ohm
dblp:224/4378
· DBLP profile ↗
12ranked-venue papers
5as first author
7since 2021 · last 2026
0000-0002-2913-5270ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 11 · 5 first-author · 6 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Dissecting Malicious VS Code Extensions: Characterization and Classification
Kotaiba Alachkar, Dirk Gaastra, Karlo Zanki, Marc Ohm, Eduardo Barbaro, Yury Zhauniarovich |
SECRYPT (1) | 4 |
| 2025 | SoK: Towards Reproducibility for Software Packages in Scripting Language Ecosystems
Timo Pohl, Pavel Novák, Marc Ohm, Michael Meier 0001 |
ARES (2) | 3 |
| 2025 | Exploring the Susceptibility to Fraud of Monetary Incentive Mechanisms for Strengthening FOSS Projects
Ben Swierzy, Timo Pohl, Marc Ohm, Michael Meier 0001 |
ARES (2) | 3 |
| 2025 | How Anonymous Is Anonymous? A Techno-Legal ExplorationabstractThis paper proposes a pragmatic exploration to facilitate the categorisation of personal data as anonymous, quasi-anonymous, or pseudonymous, emphasising contextualised threat modelling and proportionality over binary thresholds. Using an integrated legal analysis and system-level threat model, we map legal criteria to the design features and assess whether a privacy-preserving system like DROPS can credibly achieve anonymisation under the GDPR. This allows us to evaluate the discrepancy between the technical realities of maximising anonymisation techniques and the requirements for anonymisation stipulated by the EU data protection law corpus. The distinguishing feature of this paper is its grounding of the legal analysis in the technical architecture, thereby bridging the gap between abstract regulation and system-level design. This demonstration has the potential to serve as a model for enhancing data protection measures, particularly for entities that handle high-risk or otherwise sensitive data and for regulators to issue new concrete guidance on anonymisation. Stephanie von Maltzan, Daniel Vogel 0004, Marc Ohm, Florian Idelberger |
JURIX | 3 |
| 2024 | Assessing the Impact of Large Language Models on Cybersecurity Education: A Study of ChatGPT's Influence on Student PerformanceabstractThe popularity of chatbots to facilitate day-to-day business, including students and their study exercises, is on the rise. This paper investigates the extent and effects on the academic performance of students that leverage such tools. While many other approaches are hypothesized and discussed, we measure empirically. We recorded and compared the performance of cybersecurity students in weekly exercises and final exams over a period of three years. This allows us to have three groups with varying degrees of ChatGPT influence, namely no access, uncontrolled access, and controlled access. In an anonymous survey, we found that approximately 80% of our students utilize ChatGPT during the weekly assignments in 2023. However, none of them indicated this on their submission, despite it being a mandatory requirement. Through statistical analysis of achieved points in our sample groups, we identified that students perform similarly on the weekly assignments. However, their performance on the final examination deteriorates. Marc Ohm, Christian Bungartz, Felix Boes, Michael Meier 0001 |
ARES | 1 |
| 2023 | SoK: Practical Detection of Software Supply Chain AttacksabstractDetecting malicious packages used in software supply chain attacks has become increasingly important in recent years. Researchers are constantly developing and evaluating different tools and approaches. However, a comparison of all scientific publications on this topic does not yet exist. This paper examines existing publications and points out their characteristics, advantages and limitations. We identified and analyzed 20 publications that deal with malicious package detection. For those, we summarize the key points of each approach, present the experiments performed, discuss the features and limitations of each, and finally compare them to each other. We show that some tools and approaches are outdated, not fully evaluated, or not feasible for production use. Promising approaches for automatic detection of attacks in the software supply chain are outlined as well. Marc Ohm, Charlene Stuke |
ARES | 1 |
| 2022 | On the Feasibility of Supervised Machine Learning for the Detection of Malicious Software PackagesabstractModern software development heavily relies on a multitude of externally – often also open source – developed components that constitute a so-called Software Supply Chain. Over the last few years a rise of trojanized (i.e., maliciously manipulated) software packages have been observed and addressed in multiple academic publications. A central issue of this is the timely detection of such malicious packages for which typically single heuristic- or machine learning based approaches have been chosen. Especially the general suitability of supervised machine learning is currently not fully covered. In order to gain insight, we analyze a diverse set of commonly employed supervised machine learning techniques, both quantitatively and qualitatively. More precisely, we leverage a labeled dataset of known malicious software packages on which we measure the performance of each technique. This is followed by an in-depth analysis of the three best performing classifiers on unlabeled data, i.e., the whole npm package repository. Our combination of multiple classifiers indicates a good viability of supervised machine learning for the detection of malicious packages by pre-selecting a feasible number of suspicious packages for further manual analysis. This research effort includes the evaluation of over 25,210 different models which led to True Positive Rates of over 70 % and the detection and reporting of 13 previously unknown malicious packages. Marc Ohm, Felix Boes, Christian Bungartz, Michael Meier 0001 |
ARES | 1 |
| 2020 | Towards detection of software supply chain attacks by forensic artifactsabstractThird-party dependencies may introduce security risks to the software supply chain and hence yield harm to their dependent software. There are many known cases of malicious open source packages posing risks to developers and end users. However, while efforts are made to detect vulnerable open source packages, malicious packages are not yet considered explicitly. In order to tackle this problem we perform an exploratory case study on previously occurred attacks on the software supply chain with respect to observable artifacts created. Based on gained insights, we propose Buildwatch, a framework for dynamic analysis of software and its third-party dependencies. We noticed that malicious packages introduce a significant amount of new artifacts during installation when compared to benign versions of the same package. The paper presents a first analysis of observable artifacts of malicious packages as well as a possible mitigation strategy that might lead to more insight in long term. Marc Ohm, Arnold Sykosch, Michael Meier 0001 |
ARES | 1 |
| 2020 | An investigation on the feasibility of the bluetooth frequency hopping mechanism for the use as a covert channel techniqueabstractAdaptive Frequency Hopping is a mechanism included in the Bluetooth standard to minimize the effects of interference from other signals sharing the same frequency band. In this paper, several possible strategies of exploiting the frequency hopping mechanism as a covert channel are discussed. There has been some research presenting ways to make use of covert channels over Bluetooth yet none have explored frequency hopping in this context. Three groups of approaches are presented for sending hidden information by means of exploiting specific properties of the frequency hopping mechanism and the generated hopping sequence. These groups consist of strategies to transmit data hidden in protocol packets, modulated on manipulated hopping sequences or by influencing available channels through jamming, thus limiting possible hop frequencies. These approaches are compared by their bandwidth, ease of implementation as well as the detectability of a communication using these covert channels. We show that there are vast unexplored opportunities for covert communication using the adaptive frequency hopping mechanism used by Bluetooth devices. Daniel Vogel 0004, Ulugbek Akhmedjanov, Marc Ohm, Michael Meier 0001 |
ARES | 3 |
| 2020 | Backstabber's Knife Collection: A Review of Open Source Software Supply Chain Attacks
Marc Ohm, Henrik Plate, Arnold Sykosch, Michael Meier 0001 |
DIMVA | 1 |
| 2019 | Automated Pattern Inference Based on Repeatedly Observed Malware ArtifactsabstractThreat Intelligence comprises the concept of Indicators of Compromise, which are commonly used similar to classical intrusion detection signatures. However, data quality is often of limited quality with regard to this use case. The quality of these Indicators of Compromise can be increased by deriving patterns form repeated observations. A method is introduced which is capable to derive patterns from these observations automatically. Employing automatically derived pattern increases detection quality significantly. Moreover, it lead to the discovery of a previously unfamiliar type of patterns; inter-observable patterns, which capture relationships between patterns. An approach to address them in a fully STIX™ compliant fashion is proposed. Christian Doll, Arnold Sykosch, Marc Ohm, Michael Meier 0001 |
ARES | 3 |
| 2018 | Hunting Observable Objects for Indication of CompromiseabstractShared Threat Intelligence is often imperfect. Especially so called Indicator of Compromise might not be well constructed. This might either be the case if the threat only appeared recently and recordings do not allow for construction of high quality Indicators or the threat is only observed by sharing partners lesser capable to model the threat. However, intrusion detection based on imperfect intelligence yields low quality results. Within this paper we illustrate how one is able to overcome these shortcomings in data quality and is able to achieve solid intrusion detection. Arnold Sykosch, Marc Ohm, Michael Meier 0001 |
ARES | 2 |