EDBT 2026 Demo / reviewers in the wild / expert
Ludwig Englbrecht
dblp:246/5604
· DBLP profile ↗
8ranked-venue papers
4as first author
3since 2021 · last 2021
0000-0002-8546-3017ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 6 · 2 first-author · 3 since 2021Computer networks · 1 · 1 first-authorDatabases, data management, data science and information retrieval · 1 · 1 first-authorHuman-computer interaction and ubiquitous computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2021 | Enhancing Industrial Control System Forensics Using Replication-Based Digital Twins
Marietheres Dietz, Ludwig Englbrecht, Günther Pernul |
IFIP Int. Conf. Digital Forensics | 2 |
| 2021 | Visual Decision-Support for Live Digital ForensicsabstractPerforming a live digital forensics investigation on a running system is challenging due to the time pressure under which decisions have to be made. Newly proliferating and frequently applied types of malware (e.g., fileless malware) increase the need to conduct digital forensic investigations in real-time. In the course of these investigations, forensic experts are confronted with a wide range of different forensic tools. The decision, which of those are suitable for the current situation, is often based on the cyber forensics experts’ experience. Currently, there is no reliable automated solution to support this decision-making. Therefore, we derive requirements for visually supporting the decision-making process for live forensic investigations and introduce a research prototype that provides visual guidance for cyber forensic experts during a live digital forensics investigation. Our prototype collects relevant core information for live digital forensics and provides visual representations for connections between occurring events, developments over time, and detailed information on specific events. To show the applicability of our approach, we analyze an exemplary use case using the prototype and demonstrate the support through our approach. Fabian Böhm, Ludwig Englbrecht, Sabrina Friedl, Günther Pernul |
VizSec | 2 |
| 2021 | Improving data quality for human-as-a-security-sensor. A process driven quality improvement approach for user-provided incident informationabstractPurpose In the past, people were usually seen as the weakest link in the IT security chain. However, this view has changed in recent years and people are no longer seen only as a problem, but also as part of the solution. In research, this change is reflected in the fact that people are enabled to report security incidents that they have detected. During this reporting process, however, it is important to ensure that the reports are submitted with the highest possible data quality. This paper aims to provide a process-driven quality improvement approach for human-as-a-security-sensor information. Design/methodology/approach This work builds upon existing approaches for structured reporting of security incidents. In the first step, relevant data quality dimensions and influencing factors are defined. Based on this, an approach for quality improvement is proposed. To demonstrate the feasibility of the approach, it is prototypically implemented and evaluated using an exemplary use case. Findings In this paper, a process-driven approach is proposed, which allows improving the data quality by analyzing the similarity of incidents. It is shown that this approach is feasible and leads to better data quality with real-world data. Originality/value The originality of the approach lies in the fact that data quality is already improved during the reporting of an incident. In addition, approaches from other areas, such as recommender systems, are applied innovatively to the area of the human-as-a-security-sensor. Manfred Vielberth, Ludwig Englbrecht, Günther Pernul |
Inf. Comput. Secur. | 2 |
| 2020 | A privacy-aware digital forensics investigation in enterprisesabstractStricter policies, laws and regulations for companies on the handling of private information arise challenges in the handling of data for Digital Forensics investigations. This paper describes an approach that can meet necessary requirements to conduct a privacy-aware Digital Forensics investigation in an enterprise. The core of our approach is an entropy-based identification algorithm to detect specific patterns within files that can indicate non-private information. Files containing sensitive information are excluded systematically. This privacy preserving method can be integrated into a Digital Forensics examination process to prepare an image which is free from private as well as critical information for the investigation. The approach demonstrates that investigations in enterprises can be supported and improved by adapting existing algorithms and processes from related subject areas to implement privacy preserving measures into an investigation process. Ludwig Englbrecht, Günther Pernul |
ARES | 1 |
| 2020 | Designing a Decision-Support Visualization for Live Digital Forensic Investigations
Fabian Böhm, Ludwig Englbrecht, Günther Pernul |
DBSec | 2 |
| 2020 | A Serious Game-Based Peer-Instruction Digital Forensics Workshop
Ludwig Englbrecht, Günther Pernul |
WISE | 1 |
| 2020 | Towards a capability maturity model for digital forensic readiness
Ludwig Englbrecht, Stefan Meier, Günther Pernul |
Wirel. Networks | 1 |
| 2019 | Enhancing credibility of digital evidence through provenance-based incident response handlingabstractDigital forensics are becoming increasingly important for the investigation of computer-related crimes, white-collar crimes and massive hacker attacks. After an incident has been detected an appropriate incident response is usually initiated with the aim to mitigate the attack and ensure the recovery of the IT systems. Digital Forensics pursues the goal of acquiring evidence that will stand up in court for sentencing and sometimes opposes contradicting objectives of incident response approaches. The concept presented here provides a solution to strengthen the credibility of digital evidence during actions related to incident response. It adapts an approach for data provenance to accurately track the transformation of digital evidence. For this purpose, the affected system and the incident response systems are equipped with a whole system data provenance capturing mechanism and then data provenance is captured simultaneously during an incident response. Context information about the incident response is also documented. An adapted algorithm for sub-graph detection is used to identify similarities between two provenance graphs. By applying the proposed concept to a use case, the advantages are demonstrated and possibilities for further development are presented. Ludwig Englbrecht, Gregor Langner, Günther Pernul, Gerald Quirchmayr |
ARES | 1 |