Lennart Bader

dblp:236/3403 · DBLP profile ↗
← Back
9ranked-venue papers
3as first author
8since 2021 · last 2026
0000-0001-8549-1344ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 5 · 1 first-author · 4 since 2021Systems, architecture and hardware · 1 · 1 since 2021Computer networks · 1 · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 first-author · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2026 PRepChain: A versatile privacy-preserving reputation system for dynamic supply chain environments
abstract
Despite their significant added value in the context of consumer-oriented e-commerce, reputation systems have seen limited adoption in other business settings and models these days. Yet, reliable reputation scores are essential in such settings for easing the establishment of new business relationships—an aspect that is particularly crucial in dynamic supply chain environments, where business partners change frequently. Existing approaches, however, usually target other application domains and fall short in addressing the specific challenges of dynamic supply chains—–especially with respect to reliability (incl. availability) and privacy preservation (incl. confidentiality). To close this research gap and to support novel directions in this important research area, we propose PRepChain, our highly-configurable approach that leverages fully homomorphic encryption and distributed competences to provide businesses with a versatile reputation-enriched ecosystem. PRepChain is specifically designed to operate in dynamic environments by also offering a trade-off between data availability and confidentiality guarantees. We make contributions in four primary directions: (i) It offers performant privacy preservation even in large-scale settings, (ii) ensures availability of computed reputation scores, (iii) seamlessly integrates with existing supply chain information systems, and (iv) in addition to subjective reputation scores, it also supports reliably-calculated, i.e., objective, ones, thereby strengthening the reliability of third-party-sourced information. Our evaluation of PRepChain documents its performance—based on a real-world use case—, security, and privacy preservation, hence, its applicability. We conclude that it is indeed destined for practical deployments in modern supply networks.
Jan Pennekamp, Lennart Bader, Emildeon Thevaraj, Stefanie Berninger, Martin Perau, Tobias Schröer, Wolfgang Boos, Salil S. Kanhere, Klaus Wehrle
Future Gener. Comput. Syst.2
2025 Sherlock: A Dataset for Process-aware Intrusion Detection Research on Power Grid Networks: Dataset Paper
abstract
419
Eric Wagner 0003, Lennart Bader, Konrad Wolsing, Martin Serror
CODASPY2
2023 Comprehensively Analyzing the Impact of Cyberattacks on Power Grids
abstract
The increasing digitalization of power grids and especially the shift towards IP-based communication drastically increase the susceptibility to cyberattacks, potentially leading to blackouts and physical damage. Understanding the involved risks, the interplay of communication and physical assets, and the effects of cyberattacks are paramount for the uninterrupted operation of this critical infrastructure. However, as the impact of cyberattacks cannot be researched in real-world power grids, current efforts tend to focus on analyzing isolated aspects at small scales, often covering only either physical or communication assets. To fill this gap, we present Wattson, a comprehensive research environment that facilitates reproducing, implementing, and analyzing cyberattacks against power grids and, in particular, their impact on both communication and physical processes. We validate Wattson’s accuracy against a physical testbed and show its scalability to realistic power grid sizes. We then perform authentic cyberattacks, such as Industroyer, within the environment and study their impact on the power grid’s energy and communication side. Besides known vulnerabilities, our results reveal the ripple effects of susceptible communication on complex cyber-physical processes and thus lay the foundation for effective countermeasures.
Lennart Bader, Martin Serror, Olav Lamberts, Ömer Sen, Dennis van der Velde, Immanuel Hacker, Julian Filter, Elmar Gerhards-Padilla, Martin Henze
EuroS&P1
2023 Retrofitting Integrity Protection into Unused Header Fields of Legacy Industrial Protocols
abstract
Industrial networks become increasingly interconnected, which opens the floodgates for cyberattacks on legacy networks designed without security in mind. Consequently, the vast landscape of legacy industrial communication protocols urgently demands a universal solution to integrate security features retroactively. However, current proposals are hardly adaptable to new scenarios and protocols, even though most industrial protocols share a common theme: Due to their progressive development, previously important legacy features became irrelevant and resulting unused protocol fields now offer a unique opportunity for retrofitting security. Our analysis of three prominent protocols shows that headers offer between 36 and 63 bits of unused space. To take advantage of this space, we designed the REtrofittable ProtEction Library (RePeL), which supports embedding authentication tags into arbitrary combinations of unused header fields. We show that RePeL incurs negligible overhead beyond the cryptographic processing, which can be adapted to hit performance targets or fulfill legal requirements.
Eric Wagner 0003, Nils Rothaug, Konrad Wolsing, Lennart Bader, Klaus Wehrle, Martin Henze
LCN4
2023 Reputation Systems for Supply Chains: The Challenge of Achieving Privacy Preservation
Lennart Bader, Jan Pennekamp, Emildeon Thevaraj, Maria Spiß, Salil S. Kanhere, Klaus Wehrle
MobiQuitous (1)1
2022 Poster: INSIDE - Enhancing Network Intrusion Detection in Power Grids with Automated Facility Monitoring
abstract
Advances in digitalization and networking of power grids have increased the risks of cyberattacks against such critical infrastructures, where the attacks often originate from within the power grid's network. Adequate detection must hence consider both physical access violations and network anomalies to identify the attack's origin. Therefore, we propose INSIDE, combining network intrusion detection with automated facility monitoring to swiftly detect cyberattacks on power grids based on unauthorized access. Besides providing an initial design for INSIDE, we discuss potential use cases illustrating the benefits of such a comprehensive methodology.
Martin Serror, Lennart Bader, Martin Henze, Arne Schwarze, Kai Nürnberger
CCS2
2022 Scalable and Privacy-Focused Company-Centric Supply Chain Management
abstract
Blockchain technology promises to overcome trust and privacy concerns inherent to centralized information sharing. However, current decentralized supply chain management systems do either not meet privacy and scalability requirements or require a trustworthy consortium, which is challenging for increasingly dynamic supply chains with constantly changing participants. In this paper, we propose CCChain, a scalable and privacy-aware supply chain management system that stores all information locally to give companies complete sovereignty over who accesses their data. Still, tamper protection of all data through a permissionless blockchain enables on-demand tracking and tracing of products as well as reliable information sharing while affording the detection of data inconsistencies. Our evaluation confirms that CCChain offers superior scalability in comparison to alternatives while also enabling near real-time tracking and tracing for many, less complex products.
Eric Wagner 0003, Roman Matzutt, Jan Pennekamp, Lennart Bader, Irakli Bajelidze, Klaus Wehrle, Martin Henze
ICBC4
2021 Blockchain-based privacy preservation for supply chains supporting lightweight multi-hop information accountability
Lennart Bader, Jan Pennekamp, Roman Matzutt, David Hedderich, Markus Kowalski, Volker Lücken, Klaus Wehrle
Inf. Process. Manag.1
2020 Cybersecurity Research and Training for Power Distribution Grids - A Blueprint
abstract
Mitigating cybersecurity threats in power distribution grids requires a testbed for cybersecurity, e.g., to evaluate the (physical) impact of cyberattacks, generate datasets, test and validate security approaches, as well as train technical personnel. In this paper, we present a blueprint for such a testbed that relies on network emulation and power flow computation to couple real network applications with a simulated power grid. We discuss the benefits of our approach alongside preliminary results and various use cases for cybersecurity research and training for power distribution grids.
Martin Henze, Lennart Bader, Julian Filter, Olav Lamberts, Simon Ofner, Dennis van der Velde
CCS2