EDBT 2026 Demo / reviewers in the wild / expert
Florian Fenzl
dblp:249/9068
· DBLP profile ↗
5ranked-venue papers
1as first author
5since 2021 · last 2024
0000-0002-2707-2763ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 4 · 1 first-author · 4 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | Towards Practical Hardware Fingerprinting for Remote Attestation
Michael Eckel, Florian Fenzl, Lukas Jäger |
SEC | 2 |
| 2023 | Evaluation of Decision Tree-Based Rule Derivation for Intrusion Detection in Automotive EthernetabstractThe digitization and networking of safety-critical systems also enables attacks that can have devastating consequences. Thus, appropriate security measures are required. In this work, we investigate a novel approach for security monitoring adapted to the requirements and properties of safety-critical systems. In particular, we evaluate and adapt a decision tree-based detection method that is not only explainable in the sense that the software’s internal processes can be explained to the decision maker, but we use the decision tree and the generated rules to understand exactly which attributes of a message are used for identification of the attack. This supports experts in the decision-making process and can also be used for automated countermeasure generation. We demonstrate the detection method on an Automotive Ethernet protocol that is being introduced in modern vehicles to replace or complement currently used bus communication. Felix Clemens Gail, Roland Rieke, Florian Fenzl, Christoph Krauß |
TrustCom | 3 |
| 2022 | SECPAT: Security Patterns for Resilient Automotive E / E ArchitecturesabstractAutomated driving requires increasing networking of vehicles, which in turn broadens their attack surface. In this paper, we describe several security design patterns that target critical steps in automotive attack chains and mitigate their con-sequences. These patterns enable the detection of anomalies in the firmware when booting, detect anomalies in the communication in the vehicle, prevent unauthorized control units from successfully transmitting messages, offer a way of transmitting security-related events within a vehicle network and reporting them to units external to the vehicle, and ensure that communication in the vehicle is secure. Using the example of a future high-level Electrical / Electronic (E / E) architecture, we also describe how these security design patterns can be used to become aware of the current attack situation and how to react to it. Christian Plappert, Florian Fenzl, Roland Rieke, Ilaria Matteucci, Gianpiero Costantino, Marco De Vincenzi 0001 |
PDP | 2 |
| 2022 | CAHOOT: a Context-Aware veHicular intrusiOn detectiOn sysTemabstractSoftware in modern vehicles is becoming increasingly complex and subject to vulnerabilities that an intruder can exploit to alter the functionality of vehicles. To this purpose, we introduce CAHOOT, a novel context-aware Intrusion Detection System (IDS) capable of detecting potential intrusions in both human and autonomous driving modes. In CAHOOT, context information consists of data collected at run-time by vehicle’s sensors and engine. Such information is used to determine drivers’ habits and information related to the environment, like traffic conditions. In this paper, we create and use a dataset by using a customised version of the MetaDrive simulator capable of collecting both human and AI driving data. Then we simulate several types of intrusions while driving: denial of service, spoofing and replay attacks. As a final step, we use the generated dataset to evaluate the CAHOOT algorithm by using several machine learning methods. The results show that CAHOOT is extremely reliable in detecting intrusions. Davide Micale, Gianpiero Costantino, Ilaria Matteucci, Florian Fenzl, Roland Rieke, Giuseppe Patanè 0002 |
TrustCom | 4 |
| 2021 | In-vehicle detection of targeted CAN bus attacksabstractMost vehicles use the controller area network bus for communication between their components. Attackers who have already penetrated the in-vehicle network often utilize this bus in order to take control of safety-relevant components of the vehicle. Such targeted attack scenarios are often hard to detect by network intrusion detection systems because the specific payload is usually not contained within their training data sets. In this work, we describe an intrusion detection system that uses decision trees that have been modelled through genetic programming. We evaluate the advantages and disadvantages of this approach compared to artificial neural networks and rule-based approaches. For this, we model and simulate specific targeted attacks as well as several types of intrusions described in the literature. The results show that the genetic programming approach is well suited to identify intrusions with respect to complex relationships between sensor values which we consider important for the classification of specific targeted attacks. However, the system is less efficient for the classification of other types of attacks which are better identified by the alternative methods in our evaluation. Further research could thus consider hybrid approaches. Florian Fenzl, Roland Rieke, Andreas Dominik |
ARES | 1 |