René Helmke

dblp:246/4566 · DBLP profile ↗
← Back
5ranked-venue papers
4as first author
4since 2021 · last 2025
0009-0004-2343-4044ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 4 · 3 first-author · 4 since 2021Computer networks · 1 · 1 first-author
YearPublicationVenuePosition
2025 Mens Sana In Corpore Sano: Sound Firmware Corpora for Vulnerability Research
René Helmke, Elmar Gerhards-Padilla, Nils Aschenbruck
NDSS1
2024 Using Semgrep OSS to Find OWASP Top 10 Weaknesses in PHP Applications: A Case Study
Lukas Kree, René Helmke, Eugen Winter
DIMVA2
2023 Extended Abstract: Towards Reliable and Scalable Linux Kernel CVE Attribution in Automated Static Firmware Analyses
René Helmke, Johannes vom Dorp
DIMVA1
2021 EPF: An Evolutionary, Protocol-Aware, and Coverage-Guided Network Fuzzing Framework
abstract
Network fuzzing is a complex domain requiring fuzzers to handle highly structured input and communication schemes. In fuzzer development, such protocol-dependent semantics usually cause a focus on applicability: Resulting fuzz engines provide powerful APIs to add new protocols but rarely incorporate algorithmic fuzz improvements like the successful coverage-guidance. This paper aims to combine applicability and well-established algorithms for increased network fuzzing effectiveness. We introduce EPF, a coverage-guided and protocol-aware network fuzzing framework. EPF uses population-based simulated annealing to heuristically schedule packet types during fuzzing. In conjunction with a genetic algorithm that uses coverage metrics as fitness function, the framework steers input generation towards coverage maximization. Users can add protocols by defining packet models and state graphs through a Scapy-powered API. We collect first data in a case study on fuzzing the IEC 60870-5-104 SCADA protocol and compare EPF with AFLNet. Based on a total of 600 CPU days of fuzzing, we measure effectiveness using bug and coverage metrics. We report promising results that a) indicate similar performance to AFLNet without any optimizations and b) point out the potential and shortcomings of our approach.
René Helmke, Eugen Winter, Michael Rademacher
PST1
2019 CAN't - An ISOBUS Privacy Proxy for Collaborative Smart Farming
abstract
Smart Farming is driven by the emergence of precise positioning systems and Internet of Things technologies which have already enabled site-specific applications, a sustainable resource management, and interconnected machinery. Nowadays, agricultural machines and implements are equipped with multiple embedded sensors and actors continuously producing extensive data streams. For data communication on such machinery, ISOBUS, an internal vehicle bus, is used. ISOBUS is based on the machine's Controller Area Network(CAN). However, neither CAN nor ISOBUS communication takes privacy or data sovereignty issues into account. With increasing interconnectivity of agricultural machines and their integration into farm management systems, those issues become more and more serious. In this paper, we briefly present the architecture of our modular privacy framework CAN't. Using off-the-shelf hardware, a special proxy is prototypically implemented that allows to purposefully filter and manipulate CAN data streams for the sake of privacy. The feasibility and possibilities of our approach are described in this paper. By means of a customized video game, a live demonstration will additionally show the effect of the proposed privacy filters.
René Helmke, Alexander Bothe, Nils Aschenbruck
IPCCC1