EDBT 2026 Demo / reviewers in the wild / expert
Harm Griffioen
dblp:245/4471
· DBLP profile ↗
17ranked-venue papers
9as first author
10since 2021 · last 2025
0009-0006-7990-7802ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 10 · 5 first-author · 5 since 2021Computer networks · 6 · 3 first-author · 5 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Have you SYN What I See? Analyzing TCP SYN Payloads in the WildabstractTCP SYN packets are typically meant to initiate a three-way handshake for new connections and do not carry a payload. The only exception, according to the standards, is TCP Fast Open, where data is transmitted as TCP SYN payload. Dario Ferrero, Enrico Bassetti, Harm Griffioen, Georgios Smaragdakis |
IMC | 3 |
| 2025 | Decoy Databases: Analyzing Attacks on Public Facing DatabasesabstractDatabases often store sensitive organizational data but may be exposed to the Internet through misconfiguration or vulnerabilities. However, such databases may be unintentionally exposed to the Internet, e.g., due to misconfiguration or be vulnerable. To study real-world attacks on public-facing database management systems (DBMS), we deployed 278 honeypots over 20 days in March–April 2024. Our 220 low-interaction honeypots emulate MySQL, MSSQL, PostgreSQL, and Redis, revealing that scanning activity is relatively low (?3,000 IPs), but brute-force attempts are persistent. We also deploy 58 medium/high-interaction honeypots, which reveal three distinct types of exploitation: (i) direct attacks on the database management system to manipulate the database, (ii) ransom-driven attacks that copy and delete the targeted data, and (iii) use the database as an attack vector to take over the underlying system. Our findings highlight that DBMS-targeted attacks are distinct from those on other Internet-facing systems and deserve focused attention. Yuqian Song, Georgios Smaragdakis, Harm Griffioen |
IMC | 3 |
| 2025 | Revealing Informed Scanners by Colocating Reactive and Passive TelescopesabstractNetwork telescopes have been utilized for decades to detect scanning activity on the Internet. Such telescopes are typically passive, i.e., they do not reply to TCP SYN packets. Recently, reactive network telescopes that respond to TCP SYN packets have been proposed to unveil a new wave of scanners, namely two-phase scanners, and collect malicious payloads from TCP ACK packets. In this paper, we propose a methodology that combines the modus operandi of passive and reactive telescopes to identify an additional wave of scanners - that we call “informed scanners"that participate in attacks. Our main observation is that small reactive telescopes operating within larger passive telescopes are visited by “informed” clients that are aware of the liveness of hosts without performing scanning themselves; thus, are not visible in the passive telescope. We identify these informed clients as an additional class of highly targeted scanners and attackers. Indeed, by operating a /25 reactive telescope within a /16 passive telescope, we can filter out routine and two-phase scanning activity from informed one and identify clients that participate in service-targeted attacks. We discuss the scalability and sensitivity of our methodology and how it can be used to swiftly identify and profile malicious hosts on the Internet. We show that “mini-telescopes” of relatively smaller sizes, such as /20, can be comparably effective as larger sizes, such as a /16. Thus, our methodology can be useful to security operators that may only be able to allocate a relatively small address space to run a telescope. Dario Ferrero, Georgios Smaragdakis, Harm Griffioen |
RAID | 3 |
| 2025 | Trust but Verify: An Assessment of Vulnerability Tagging Services
Szu-Chun Huang, Harm Griffioen, Max van der Horst, Georgios Smaragdakis, Michel van Eeten, Yury Zhauniarovich |
USENIX Security Symposium | 2 |
| 2024 | Have you SYN me? Characterizing Ten Years of Internet ScanningabstractPort scanning is the de-facto method to enumerate active hosts and potentially exploitable services on the Internet. Over the last years, several studies have quantified the ecosystem of port scanning. Each work has found drastic changes in the threat landscape compared to the previous one, and since the advent of high-performance scanning tools and botnets a lot has changed in this highly volatile ecosystem. Harm Griffioen, Georgios Koursiounis, Georgios Smaragdakis, Christian Doerr |
IMC | 1 |
| 2023 | How to Operate a Meta-Telescope in your Spare TimeabstractUnsolicited traffic sent to advertised network space that does not host active services provides insights about misconfigurations as well as potentially malicious activities, including the spread of Botnets, DDoS campaigns, and exploitation of vulnerabilities. Network telescopes have been used for many years to monitor such unsolicited traffic. Unfortunately, they are limi the available address space for such tasks and, thus, limited to specific geographic and/or network regions. Sahil Ashish Ranadive, Harm Griffioen, Michael G. Kallitsis, Alberto Dainotti, Georgios Smaragdakis, Anja Feldmann |
IMC | 3 |
| 2023 | Could you clean up the Internet with a Pit of Tar? Investigating tarpit feasibility on Internet wormsabstractBotnets often spread through massive Internet-wide scanning, identifying and infecting vulnerable Internet-facing devices to grow their network. Taking down these networks is often hard for law enforcement, and some people have proposed tarpits as a defensive method because it does not require seizing infrastructure or rely on device owners to make sure their devices are well-configured and protected. These tarpits are network services that aim to keep a malware-infected device busy and slow down or eradicate the malicious behavior.This paper identifies a network-based tarpit vulnerability in stateless-scanning malware and develops a tarpitting exploit. We apply this technique against malware based on the Mirai scanning routine to identify whether tarpitting at scale is effective in containing the spread of self-propagating malware. We demonstrate that we can effectively trap thousands of devices even in a single tarpit and that this significantly slows down botnet spreading across the Internet and provide a framework to simulate malware spreading under various network conditions to apriori evaluate the effect of tarpits on a particular malware. We show that the self-propagating malware could be contained with the help of a few thousand tarpits without any measurable adverse impact on compromised routers or Internet Service Providers, and we release our tarpitting solution as an open platform to the community to realize this. Harm Griffioen, Christian Doerr |
SP | 1 |
| 2021 | Analysis and Takeover of the Bitcoin-Coordinated Pony MalwareabstractMalware, like all products and services, evolves with bursts of innovation. These advances usually happen whenever security controls get ''good enough'' to significantly impact the revenue stream of malicious actors, and in the past we have seen the malware ecosystem to adopt concepts such as code obfuscation, polymorphism, domain-generation algorithms (DGAs), as well as virtual machine and sandbox evasion whenever defenses were able to perform consistent and pervasive suppression of these threats. Tsuyoshi Taniguchi, Harm Griffioen, Christian Doerr |
AsiaCCS | 2 |
| 2021 | Scan, Test, Execute: Adversarial Tactics in Amplification DDoS AttacksabstractAmplification attacks generate an enormous flood of unwanted traffic towards a victim and are generated with the help of open, unsecured services, to which an adversary sends spoofed service requests that trigger large answer volumes to a victim. However, the actual execution of the packet flood is only one of the activities necessary for a successful attack. Adversaries need, for example, to develop attack tools, select open services to abuse, test them, and adapt the attacks if necessary, each of which can be implemented in myriad ways. Thus, to understand the entire ecosystem and how adversaries work, we need to look at the entire chain of activities. Harm Griffioen, Kris Oosthoek, Paul van der Knaap, Christian Doerr |
CCS | 1 |
| 2021 | SIP Bruteforcing in the Wild - An Assessment of Adversaries, Techniques and ToolsabstractOver the last two decades, Voice-over-IP (VoIP) and specifically SIP have become standard solutions to realize voice telephony in residential, commercial, and telecom environments. As by now, an abundance of SIP endpoints exist, it has become financially lucrative for cybercriminals to systematically search for VoIP installations, with for example the aim to abuse them for billing fraud or to hide their criminal activities behind a legitimate connection and phone number. By now, this has made SIP one of the most scanned UDP protocols on the Internet. In this paper, we take a look at the actors behind these attacks. Using a large network telescope, we collect over 822 million SIP brute-forcing attempts from 5,691 sources over 187 countries and analyze who is searching for and attacking VoIP endpoints. As each tool and campaign exhibits specific implementation differences, we can relate individual attempts into campaigns and can thereby provide a detailed view into different actors in the ecosystem, different techniques and tooling, and how these are developing over 5 years. We show that we can fingerprint different SIP scanning tools, show that actors hardly ever change their toolkit, and identify an increase in highly distributed and coordinated scanning. Harm Griffioen, Huancheng Hu, Christian Doerr |
Networking | 1 |
| 2020 | Quantifying autonomous system IP churn using attack traffic of botnetsabstractTo connect to the Internet, hosts are assigned an IP address by their network provider by which they exchange data. As such, IP addresses are frequently used as a proxy metric to count the number of hosts on a network, or to quantify particular phenomena such as the size of botnets or the infection statistics of malware. Although a single host is typically linked to a single IP address at a given moment, this relationship is frequently not stable over time due to IP churn. As network operators dynamically assign IP addresses to clients for a specific lease duration, after expiry of this lease a host obtains a new IP address, thereby leading to overestimations of active host counts or malware infections. Harm Griffioen, Christian Doerr |
ARES | 1 |
| 2020 | Quality Evaluation of Cyber Threat Intelligence Feeds
Harm Griffioen, Tim M. Booij, Christian Doerr |
ACNS (2) | 1 |
| 2020 | Examining Mirai's Battle over the Internet of ThingsabstractUsing hundreds of thousands of compromised IoT devices, the Mirai botnet emerged in late 2016 as a game changing threat actor, capable of temporarily taking down major Internet service providers and Internet infrastructure. Since then, dozens of variants of IoT-based botnets have sprung up, and in today's Internet distributed denial-of-service attacks from IoT devices have become a major attack vector. This proliferation was significantly driven by the public distribution of the Mirai source code, which other actors used to create their own, customized version of the original Mirai botnet. In this paper we provide a comprehensive view into the ongoing battle over the Internet of Things fought by Mirai and its many siblings. Using 7,500 IoT honeypots, we show that we can use 300,000,000 compromisation attempts from infected IoT devices as well as a design flaw in Mirai's random number generator to obtain insights into Mirai infections worldwide. We find that networks and the particular malware strains that plague them are tightly connected, and malware authors over time take over strategies from their competitors. The most surprising finding is that epidemiologically, IoT botnets are not self-sustaining: were it not for continuous pushes from bootstrapping, Mirai and its variants would die out. Harm Griffioen, Christian Doerr |
CCS | 1 |
| 2020 | Quantifying TCP SYN DDoS Resilience: A Longitudinal Study of Internet Services
Harm Griffioen, Christian Doerr |
Networking | 1 |
| 2020 | Discovering Collaboration: Unveiling Slow, Distributed Scanners based on Common Header Field PatternsabstractTo compromise a computer, it is first necessary to discover which hosts are active and which services they run. This reconnaissance is typically accomplished through port scanning. Defense systems monitor for these unsolicited packets and raise an alarm if a predefined threshold is exceeded. To remain undetected, adversaries can either slow down the scan, and/or distribute it over multiple hosts. With each source below the threshold, the combination of all may still complete the scan efficiently. It is especially this group that is of concern: with enough resources and knowledge to execute such a coordinated activity, they will pose a more potent threat than the noisy "script kiddie". Correlating which out of 4 billion IPs potentially collaborate is however a challenging task, hence today’s systems do not consider coordination beyond basic subnet aggregation.In this paper, we propose a method to identify and fingerprint distributed scanners based on commonalities in header fields, which are an artifact of the way fast port scanning software is built. We demonstrate that this method can effectively locate groups, and based on the monitoring logs we report on a number of new groups and tools, which have previously not been reported in the academic literature.Fingerprints generated can ultimately be used as Indicators of Compromise to detect and mitigate scanning behavior in order to deny adversaries the possibility to learn about weaknesses of a system. Harm Griffioen, Christian Doerr |
NOMS | 1 |
| 2020 | A different cup of TI? The added value of commercial threat intelligence
Xander Bouwman, Harm Griffioen, Jelle Egbers, Christian Doerr, Bram Klievink, Michel van Eeten |
USENIX Security Symposium | 2 |
| 2019 | Fingerprinting Tooling used for SSH Compromisation Attempts
Vincent Ghiëtte, Harm Griffioen, Christian Doerr |
RAID | 2 |