Merlin Chlosta

dblp:241/1466 · DBLP profile ↗
← Back
5ranked-venue papers
3as first author
4since 2021 · last 2024
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 5 · 3 first-author · 4 since 2021
YearPublicationVenuePosition
2024 SIMurai: Slicing Through the Complexity of SIM Card Security Research
Tomasz Piotr Lisowski, Merlin Chlosta, Marius Muench
USENIX Security Symposium2
2023 Drone Security and the Mysterious Case of DJI's DroneID
Nico Schiller, Merlin Chlosta, Moritz Schloegel, Nils Bars, Thorsten Eisenhofer, Tobias Scharnowski, Felix Domke, Lea Schönherr, Thorsten Holz
NDSS2
2021 On the challenges of automata reconstruction in LTE networks
abstract
Mobile networks are a crucial part of our digital lives and require adequate security measures. The 4G and 5G network standards are complex and challenging to implement, which led to several implementation issues being discovered over the last years. Consequently, we aim to strengthen automation in testing and increase test coverage to spot issues and potential security vulnerabilities.
Merlin Chlosta, David Rupprecht, Thorsten Holz
WISEC1
2021 5G SUCI-catchers: still catching them all?
abstract
In mobile networks, IMSI-Catchers identify and track users simply by requesting all users' permanent identities (IMSI) in range. The 5G standard attempts to fix this issue by encrypting the permanent identifier (now SUPI) and transmitting the SUCI. Since the encrypted SUCI is re-generated with an ephemeral key for each use, an attacker can no longer derive the user's identity. However, this scheme does not prevent all tracking and linking: if the identity of a user is already known, an attacker can probe users for that identity.
Merlin Chlosta, David Rupprecht, Christina Pöpper, Thorsten Holz
WISEC1
2019 LTE security disabled: misconfiguration in commercial networks
abstract
Long Term Evolution (LTE) is the de-facto standard for mobile communication. It provides effective security features but leaves room for misunderstandings in its configuration and implementation. In particular, providers face difficulties when maintaining network configurations.
Merlin Chlosta, David Rupprecht, Thorsten Holz, Christina Pöpper
WiSec1