August See

dblp:301/9435 · also Richard August See · DBLP profile ↗
← Back
9ranked-venue papers
8as first author
9since 2021 · last 2025
0009-0003-9588-7096ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 9 · 8 first-author · 9 since 2021
YearPublicationVenuePosition
2025 Enhancing Binary Code Similarity Analysis for Software Updates: A Contextual Diffing Framework
August See, Moritz Mönnich, Mathias Fischer 0001
AsiaCCS1
2025 Rubber Ducky Station: Advancing HID Attacks with Visual Data Exfiltration
August See, Thimo Grußendorf, Jona Laudan, Mathias Fischer 0001
SEC (1)1
2025 Flatdc: Automatic Schema Reverse Engineering of FlatBuffers
August See, Benedikt Ostendorf, Lilly Sell, Mathias Fischer 0001
SEC (2)1
2024 Encrypted Endpoints: Defending Online Services from Illegitimate Bot Automation
abstract
Automated usage of web services by programs, known as bots, poses risks such as data scraping, spam, and cyber attacks. For instance, X suffers from millions of bot accounts typically controlled by relatively fewer adversarial organizations to create fake likes and comments. The most widely used solution to distinguish humans from bots (CAPTCHA) is perishing due to advances in machine learning. Obfuscation techniques in binaries, applications, or websites are designed to impede the creation of bots but fail to prevent their scalability. Bypassing these measures often requires only a one-time effort. We propose encrypted endpoints as a novel strategy to combat the scalability of web bots, particularly in scenarios where bots leverage multiple accounts. For that we assign unique endpoints (URLs) to each user account, thereby restricting bot applicability across different accounts and necessitating the extraction of account-specific endpoints per bot instance. Our approach is applicable to a wide range of services utilizing endpoints, including desktop and mobile applications, web applications, and even static or HTML-only websites. We implemented our approach directly within a backend framework and observed that the latency overhead is less than 0.1ms per request, which constitutes less than 1% of the total request time. Our solution, developed as simple middleware, can be easily integrated in existing projects with low effort. Additionally, we have extended our approach to the Jinja2 template engine, thereby supporting encrypted endpoints for websites out of the box. Our analysis indicates that our approach not only effectively protects against simple bots but also, when coupled with obfuscation techniques, further impedes bot creation.
August See, Kevin Röbert, Mathias Fischer 0001
RAID1
2024 Detecting Web Bots via Keystroke Dynamics
August See, Adrian Westphal, Cornelius Weber, Mathias Fischer 0001
SEC1
2023 Binary Sight-Seeing: Accelerating Reverse Engineering via Point-of-Interest-Beacons
abstract
Reverse engineering is still a largely manual and very time-consuming process. To ease this process, beacons in the form of known instructions or code patterns are commonly used to guide reverse engineers in dissecting a binary. However, if done manually, identifying high-quality beacons can be very laborious. This paper introduces a novel method to automatically identify the so-called Points-of-Interests (POIs) in binaries. POIs are instructions that interact with data specified by the analyst known a priori, e.g., via sandbox analysis or expert knowledge. These POIs are then used as beacons to guide analysts to find interesting parts of the binary that interact with the specified data, e.g., the encryption routine. Compared to taint analysis, our approach offers simplicity while delivering a select few, yet high-quality beacons, thereby establishing clear focus points. Based on our proposed method, we implemented two types of prototypes. First, a prototype whose output can be loaded via custom plugins into IDA and Ghidra, i.e., two of the more popular reverse-engineering tools. We show the applicability of our method via the prototype by summarizing the insights of the analysis for the Locky and Wannacry ransomware as one of the potential application domains, i.e., malware reverse engineering. Second, we also introduced a prototype that monitors P2P botnets in a fully-automated manner by directly instrumenting the botnet malware without requiring manual reverse-engineering. We demonstrate the effectiveness of our prototype by applying it to the ZeroAccess, Sality, Nugache, and Kelihos botnets and summarize our findings in this paper. Using our approach, we effortlessly found the encryption function in the two analyzed ransomware. For P2P botnets, our monitoring prototype could enumerate the bots in all analyzed botnets, only relying on our POIs.
August See, Maximilian Gehring, Mathias Fischer 0001, Shankar Karuppayah
ACSAC1
2023 Detecting Web Bots via Mouse Dynamics and Communication Metadata
August See, Tatjana Wingarz, Matz Radloff, Mathias Fischer 0001
SEC1
2023 SecPassInput: Towards Secure Memory and Password Handling in Web Applications
Pascal Wichmann, August See, Hannes Federrath
SEC2
2022 Polymorphic Protocols at the Example of Mitigating Web Bots
August See, Leon Fritz, Mathias Fischer 0001
ESORICS (3)1