EDBT 2026 Demo / reviewers in the wild / expert
Manuel Andreas
dblp:260/5542
· DBLP profile ↗
3ranked-venue papers
1as first author
2since 2021 · last 2026
—ORCID · none
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 3 · 1 first-author · 2 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | HyperMirage: Direct State Manipulation in Hybrid Virtual CPU Fuzzing
Manuel Andreas, Fabian Specht, Marius Momeu |
NDSS | 1 |
| 2022 | Katana: Robust, Automated, Binary-Only Forensic Analysis of Linux Memory SnapshotsabstractThe development and research of tools for forensically analyzing Linux memory snapshots have stalled in recent years as they cannot deal with the high degree of configurability and fail to handle security advances like structure layout randomization. Existing tools such as Volatility and Rekall require a pre-generated profile of the operating system, which is not always available, and can be invalidated by the smallest source code or configuration changes in the kernel. Fabian Franzen, Tobias Holl, Manuel Andreas, Julian Kirsch, Jens Grossklags |
RAID | 3 |
| 2020 | FridgeLock: Preventing Data Theft on Suspended Linux with Usable Memory EncryptionabstractTo secure mobile devices, such as laptops and smartphones, against unauthorized physical data access, employing Full Disk Encryption (FDE) is a popular defense. This technique is effective if the device is always shut down when unattended. However, devices are often suspended instead of switched off. This leaves confidential data such as the FDE key, passphrases and user data in RAM which may be read out using cold boot, JTAG or DMA attacks. These attacks can be mitigated by encrypting the main memory during suspend. While this approach seems promising, it is not implemented on Windows or Linux. We present FridgeLock to add memory encryption on suspend to Linux. Our implementation as a Linux Kernel Module (LKM) does not require an admin to recompile the kernel. Using Dynamic Kernel Module Support (DKMS) allows for easy and fast deployment on existing Linux systems, where the distribution provides a prepackaged kernel and kernel updates. We tested our module on a range of 4.19 to 5.3 kernels and experienced a low performance impact, sustaining the system's usability. We hope that our tool leads to a more detailed evaluation of memory encryption in real world usage scenarios. Fabian Franzen, Manuel Andreas, Manuel Huber 0001 |
CODASPY | 2 |