EDBT 2026 Demo / reviewers in the wild / expert
Valentin Zahnd
dblp:286/7385
· DBLP profile ↗
3ranked-venue papers
0as first author
3since 2021 · last 2025
—ORCID · none
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 3 · 3 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Scrooge: Detection of Changes in Web Applications to Enhance Security TestingabstractDue to the complexity of modern web applications, security testing is a time-consuming process that heavily relies on manual interaction with various analysis tools. This process often needs to be repeated for newer versions of previously tested applications, as new functionalities frequently introduce security vulnerabilities. This paper introduces scrooge, a tool that automates change detection in web application functionality to enhance the efficiency and focus of the security testing process. We evaluate scrooge on various platforms, demonstrating its ability to reliably detect a range of changes. Scrooge successfully identifies different types of changes, showcasing its applicability across diverse scenarios with high accuracy. Fabio Büsser, Jan Kressebuch, Martín Ochoa, Valentin Zahnd, Ariane Trammell |
ICISSP (2) | 4 |
| 2024 | Towards Automated Information Security GovernanceabstractSecuring a company is not an easy task. Many organizations such as NIST, CIS, or ISO offer frameworks that offer comprehensive security measures. However, those frameworks are generally large and require expert knowledge to be tailored to a given organization. Since such experts are rare, we propose an automated solution that selects security controls and prioritizes them according to an organizations need. We performed initial steps towards the implementation of the proposed solution by evaluating how Natural Language Processing can be used to select security controls that are relevant for the assets of a company and by showing that we can prioritize the selected controls based on the current threat landscape. We expect the proposed solution to be a major benefit for all organizations that intend to improve their security posture but are limited in specialized personnel. Ariane Trammell, Benjamin Gehring, Marco Isele, Yvo Spielmann, Valentin Zahnd |
ICISSP | 5 |
| 2021 | Automated Black Box Detection of HTTP GET Request-based Access Control Vulnerabilities in Web ApplicationsabstractAutomated and reproducible security testing of web applications is getting more and more important, driven by short software development cycles and constraints with respect to time and budget. Some types of vulnerabilities can already be detected reasonably well by automated security scanners, e.g., SQL injection or cross-site scripting vulnerabilities. However, other types of vulnerabilities are much harder to uncover in an automated way. This includes access control vulnerabilities, which are highly relevant in practice as they can grant unauthorized users access to security-critical data or functions in web applications. In this paper, a practical solution to automatically detect access control vulnerabilities in the context of HTTP GET requests is presented. The solution is based on previously proposed ideas, which are extended with novel approaches to enable completely automated access control testing with minimal configuration effort that enables frequent and reproducible testing. An evaluation using four web applications based on different technologies demonstrates the general applicability of the solution and that it can automatically uncover most access control vulnerabilities while keeping the number of false positives relatively low. Malte Kushnir, Olivier Favre, Marc Rennhard, Damiano Esposito, Valentin Zahnd |
ICISSP | 5 |