EDBT 2026 Demo / reviewers in the wild / expert
Sven Bugiel
dblp:31/7561
· DBLP profile ↗
37ranked-venue papers
4as first author
11since 2021 · last 2026
0000-0002-7151-9614ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 35 · 4 first-author · 9 since 2021Human-computer interaction and ubiquitous computing · 2 · 2 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | From Discovery to Decisions: Archetypal Journeys of Mobile App Users and Their Implications on PrivacyabstractMobile permission decisions are often studied at the moment a permission request appears. However, our study shows that users’ choices are shaped much earlier, across a multi-stage journey that begins with app-need recognition and unfolds through app discovery, exploration, selection, installation, and first use. Drawing on interviews with 19 U.S. Android users, we map this process and identify four archetypal journeys that explain how early cues, such as discovery sources, app type, and social trust, shape later permission behavior. These insights align with theoretical models like Privacy Calculus, showing how users weigh perceived benefits and risks at each step, and complement Contextual Integrity theory, explaining how social norms and information flows shape expectations and constrain privacy agency across steps. We contribute an empirically grounded framework that clarifies why permission outcomes vary across contexts. Our results reframe mobile privacy as a sequential, path-dependent process, offering implications for future design and research. H. T. M. A. Riyadh, Divyanshu Bhardwaj 0001, Maria Victoria Hellenthal, Alexander Hart, Katharina Krombholz, Sven Bugiel |
CHI | 6 |
| 2026 | High Impedance: Analysis of Publicly Disclosed Vulnerabilities in FPGA IP Cores
Imtiaj A. Chowdhury, Eric G. Ackermann, Sven Bugiel |
EuroS&P | 3 |
| 2025 | Permission Rationales in the Web Ecosystem: An Exploration of Rationale Text and Design PatternsabstractModern web applications use features like camera and geolocation for personalized experiences, requiring user permission via browser prompts.To explain these requests, applications provide rationales-contextual information on why permissions are needed.Despite their importance, little is known about how often rationales appear on the web or their influence on user decisions.This paper presents the first large-scale study of how the web ecosystem handles permission rationales, covering three areas: (i) identifying webpages that use permissions, (ii) detecting and classifying permission rationales, and (iii) analyzing their attributes to understand their impact on user decisions.We examined over 770K webpages from Chrome telemetry, finding 3.6K unique rationale texts and 749 rationale UIs across 85K pages.We extracted key rationale attributes and assessed their effect on user behavior by cross-referencing them with Chrome telemetry data.Our findings reveal nine key insights, providing the first evidence of how different rationales affect user decisions. Yusra Elbitar, Soheil Khodayari, Marian Harbach, Gianluca De Stefano, Balazs Engedy, Giancarlo Pellegrino, Sven Bugiel |
CHI | 7 |
| 2025 | The Power of Words: A Comprehensive Analysis of Rationales and Their Effects on Users' Permission Decisions
Yusra Elbitar, Alexander Hart, Sven Bugiel |
NDSS | 3 |
| 2025 | Stack Overflow Meets Replication: Security Research Amid Evolving Code Snippets
Alfusainey Jallow, Sven Bugiel |
USENIX Security Symposium | 2 |
| 2024 | Measuring the Effects of Stack Overflow Code Snippet Evolution on Open-Source Software SecurityabstractThis paper assesses the effects of Stack Overflow code snippet evolution on the security of open-source projects. Users on Stack Overflow actively revise posted code snippets, sometimes addressing bugs and vulnerabilities. Accordingly, developers that reuse code from Stack Overflow should treat it like any other evolving code dependency and be vigilant about updates. It is unclear whether developers are doing so, to what extent outdated code snippets from Stack Overflow are present in GitHub projects, and whether developers miss security-relevant updates to reused snippets.To shed light on those questions, we devised a method to 1) detect outdated code snippets versions from 1.5M Stack Overflow snippets in 11,479 popular GitHub projects and 2) detect security-relevant updates to those Stack Overflow code snippets not reflected in those GitHub projects. Our results show that developers did not update dependent code snippets when those evolved on Stack Overflow. We found that 2,405 code snippet versions reused in 2,109 GitHub projects were outdated, with 43 projects missing fixes to bugs and vulnerabilities on Stack Overflow. Those 43 projects containing outdated, insecure snippets were forked on average 1,085 times (max. 16,121), indicating that our results are likely a lower bound for affected code bases. An important insight from our work is that treating Stack Overflow code as purely static code impedes holistic solutions to the problem of copying insecure code from Stack Overflow. Instead, our results suggest that developers need tools that continuously monitor Stack Overflow for security warnings and code fixes for reused code snippets and not only warn during copy-pasting. Alfusainey Jallow, Michael Schilling 0001, Michael Backes 0001, Sven Bugiel |
SP | 4 |
| 2023 | TALUS: Reinforcing TEE Confidentiality with Cryptographic Coprocessors
Dhiman Chakraborty 0001, Michael Schwarz 0001, Sven Bugiel |
FC (1) | 3 |
| 2023 | A Systematic Study of the Consistency of Two-Factor Authentication User Journeys on Top-Ranked Websites
Sanam Ghorbani Lyastani, Michael Backes 0001, Sven Bugiel |
NDSS | 3 |
| 2021 | Bringing Balance to the Force: Dynamic Analysis of the Android Application Framework
Abdallah Dawoud, Sven Bugiel |
NDSS | 2 |
| 2021 | A11y and Privacy don't have to be mutually exclusive: Constraining Accessibility Service Misuse on Android
Jie Huang 0010, Michael Backes 0001, Sven Bugiel |
USENIX Security Symposium | 3 |
| 2021 | Explanation Beats Context: The Effect of Timing & Rationales on Users' Runtime Permission Decisions
Yusra Elbitar, Michael Schilling 0001, Trung Tin Nguyen, Michael Backes 0001, Sven Bugiel |
USENIX Security Symposium | 5 |
| 2020 | Up2Dep: Android Tool Support to Fix Insecure Code DependenciesabstractThird-party libraries, especially outdated versions, can introduce and multiply security & privacy related issues to Android applications. While prior work has shown the need for tool support for developers to avoid libraries with security problems, no such a solution has yet been brought forward to Android. It is unclear how such a solution would work and which challenges need to be solved in realizing it. Duc Cuong Nguyen 0001, Erik Derr, Michael Backes 0001, Sven Bugiel |
ACSAC | 4 |
| 2020 | Is FIDO2 the Kingslayer of User Authentication? A Comparative Usability Study of FIDO2 Passwordless AuthenticationabstractThe newest contender for succeeding passwords as the incumbent web authentication scheme is the FIDO2 standard. Jointly developed and backed by the FIDO Alliance and the W3C, FIDO2 has found support in virtually every browser, finds increasing support by service providers, and has adoptions beyond browser-software on its way. While it supports MFA and 2FA, its single-factor, passwordless authentication with security tokens has received the bulk of attention and was hailed by its supporters and the media as the solution that will replace text-passwords on the web. Despite its obvious security and deployability benefits—a setting that no prior solution had in this strong combination—the paradigm shift from a familiar knowledge factor to purely a possession factor raises questions about the acceptance of passwordless authentication by end-users.This paper presents the first large-scale lab study of FIDO2 single-factor authentication to collect insights about end-users’ perception, acceptance, and concerns about passwordless authentication. Through hands-on tasks our participants gather first-hand experience with passwordless authentication using a security key, which they afterwards reflect on in a survey. Our results show that users are willing to accept a direct replacement of text-based passwords with a security key for single-factor authentication. That is an encouraging result in the quest to replace passwords. But, our results also identify new concerns that can potentially hinder the widespread adoption of FIDO2 passwordless authentication. In order to mitigate these factors, we derive concrete recommendations to try to help in the ongoing proliferation of passwordless authentication on the web. Sanam Ghorbani Lyastani, Michael Schilling 0001, Michaela Neumayr, Michael Backes 0001, Sven Bugiel |
SP | 5 |
| 2019 | Poster: Let History not Repeat Itself (this Time) - Tackling WebAuthn Developer Issues Early OnabstractThe FIDO2 open authentication standard, developed jointly by the FIDO Alliance and the W3C, provides end-users with the means to use public-key cryptography in addition to or even instead of text-based passwords for authentication on the web. Its WebAuthn protocol has been adopted by all major browser vendors and recently also by major service providers (e.g., Google, GitHub, Dropbox, Microsoft, and others). Thus, FIDO2 is a very strong contender for finally tackling the problem of insecure user authentication on the web. However, there remain a number of open questions to be answered for FIDO2 to succeed as expected. In this poster, we focus specifically on the critical question of how well web-service developers can securely roll out WebAuthn in their own services and which issues have to be tackled to help developers in this task. The past has unfortunately shown that software developers struggle with correctly implementing or using security-critical APIs, such as TLS/SSL, password storage, or cryptographic APIs. We report here on ongoing work that investigates potential problem areas and concrete pitfalls for adopters of WebAuthn and tries to lay out a plan of how our community can help developers. We believe that raising awareness for foreseeable developer problems and calling for action to support developers early on is critical on the path for establishing FIDO2 as a de-facto authentication solution. Katharina Krombholz, Sven Bugiel |
CCS | 3 |
| 2019 | simFIDO: FIDO2 User Authentication with simTPMabstractWebAuthn as part of FIDO2 is a new standard for two-factor and even password-less user authentication to web-services. Leading browsers, like Google Chrome, Microsoft Edge, and Mozilla Firefox, support the WebAuthn API. Unfortunately, the availability of hardware authenticators that support FIDO2 authentication is still focused heavily on desktop computers, while for mobile devices, only a limited choice of suitable authenticators is available to users (few roaming authenticators with wireless connectivity and even fewer built-in platform authenticators on mobile devices). This creates a void for users, in particular users of older device generations that lack platform authenticators and the right connectivity, to authenticate themselves with WebAuthn to web-services. In this poster, we present the idea ofsimFIDO, a FIDO2 setup using a recently developed simTPM as (platform) authenticator for mobile devices and even as roaming authenticator offered by mobile devices to connected computers. The move-ability property of the key storage of simTPM makes the users' lives easier for credential portability between devices. In particular, a seamless integration of simTPM with non-mobile devices through phones will help to create a kind of universal authentication setup using FIDO2. Although we present the concrete design and implementation of a SIM card-based FIDO2 authenticator, we hope this poster will contribute to the discussion about how and in which form hardware authenticators can be made available to users. Dhiman Chakraborty 0001, Sven Bugiel |
CCS | 2 |
| 2019 | Up-To-Crash: Evaluating Third-Party Library Updatability on AndroidabstractBuggy and flawed third-party libraries increase their host app's attack surface and put the users' privacy at risk. To avert this risk, libraries have to be kept updated to their newest versions by the app developers that integrate them into their projects. Recent researches revealed that the prevalence of outdated third-party libraries in Android apps is indeed a rampant problem, but also suggested that there is a great opportunity for drop-in replacements of outdated libraries, which would not even require cooperation by the app developers to update the libraries. However, all those conclusions are based on static app analysis, which can only provide an abstract view. In this work, we extend the updatability analysis to the runtime of apps. We implement a solution to update third-party libraries with drop-in replacements by their newer versions. To verify the feasibility of this developer-independent update mechanism, we dynamically test 3,000 real world apps for 3 popular libraries (78 library versions) for runtime failures stemming from incompatible library updates. To investigate the updatability of libraries in-depth, exploration enhanced dynamic testing is adopted to monitor the runtime behaviors of 15 apps before and after library updating. From our test, we find that the prior reported updatability rate is under real conditions overestimated by a factor of 1.57-2.06. Through root cause analysis, we find that the underlying problems prohibiting easy updates are intricate, such as deprecated functions, changed data structures, or entangled dependencies between different libraries and even the host app. We think our results not only put a more realistic light on the library updatability problem in Android, but also provide valuable insights for future solutions that provide automatic library updates or that try to support the app developers in better maintaining their external dependencies. Jie Huang 0010, Nataniel P. Borges, Sven Bugiel, Michael Backes 0001 |
EuroS&P | 3 |
| 2019 | DroidCap: OS Support for Capability-based Permissions in Android
Abdallah Dawoud, Sven Bugiel |
NDSS | 2 |
| 2019 | Short Text, Large Effect: Measuring the Impact of User Reviews on Android App Security & PrivacyabstractApplication markets streamline the end-users' task of finding and installing applications. They also form an immediate communication channel between app developers and their end-users in form of app reviews, which allow users to provide developers feedback on their apps. However, it is unclear to which extent users employ this channel to point out their security and privacy concerns about apps, about which aspects of apps users express concerns, and how developers react to such security- and privacy-related reviews. In this paper, we present the first study of the relationship between end-user reviews and security- & privacy-related changes in apps. Using natural language processing on 4.5M user reviews for the top 2,583 apps in Google Play, we identified 5,527 security and privacy relevant reviews (SPR). For each app version mentioned in the SPR, we use static code analysis to extract permission-protected features mentioned in the reviews. We successfully mapped SPRs to privacy-related changes in app updates in 60.77% of all cases. Using exploratory data analysis and regression analysis we are able to show that preceding SPR are a significant factor for predicting privacy-related app updates, indicating that user reviews in fact lead to privacy improvements of apps. Our results further show that apps that adopt runtime permissions receive a significantly higher number of SPR, showing that runtime permissions put privacy-jeopardizing actions better into users' minds. Further, we can attribute about half of all privacy-relevant app changes exclusively to third-party library code. This hints at larger problems for app developers to adhere to users' privacy expectations and markets' privacy regulations. Our results make a call for action to make app behavior more transparent to users in order to leverage their reviews in creating incentives for developers to adhere to security and privacy best practices, while our results call at the same time for better tools to support app developers in this endeavor. Duc Cuong Nguyen 0001, Erik Derr, Michael Backes 0001, Sven Bugiel |
IEEE Symposium on Security and Privacy | 4 |
| 2019 | simTPM: User-centric TPM for Mobile Devices
Dhiman Chakraborty 0001, Lucjan Hanzlik, Sven Bugiel |
USENIX Security Symposium | 3 |
| 2018 | The Rise of the Citizen Developer: Assessing the Security Impact of Online App GeneratorsabstractMobile apps are increasingly created using online application generators (OAGs) that automate app development, distribution, and maintenance. These tools significantly lower the level of technical skill that is required for app development, which makes them particularly appealing to citizen developers, i.e., developers with little or no software engineering background. However, as the pervasiveness of these tools increases, so does their overall influence on the mobile ecosystem's security, as security lapses by such generators affect thousands of generated apps. The security of such generated apps, as well as their impact on the security of the overall app ecosystem, has not yet been investigated. We present the first comprehensive classification of commonly used OAGs for Android and show how to fingerprint uniquely generated apps to link them back to their generator. We thereby quantify the market penetration of these OAGs based on a corpus of 2,291,898 free Android apps from Google Play and discover that at least 11.1% of these apps were created using OAGs. Using a combination of dynamic, static, and manual analysis, we find that the services' app generation model is based on boilerplate code that is prone to reconfiguration attacks in 7/13 analyzed OAGs. Moreover, we show that this boilerplate code includes well-known security issues such as code injection vulnerabilities and insecure WebViews. Given the tight coupling of generated apps with their services' backends, we further identify security issues in their infrastructure. Due to the blackbox development approach, citizen developers are unaware of these hidden problems that ultimately put the end-users sensitive data and privacy at risk and violate the user's trust assumption. A particular worrisome result of our study is that OAGs indeed have a significant amplification factor for those vulnerabilities, notably harming the health of the overall mobile app ecosystem. Marten Oltrogge, Erik Derr, Christian Stransky, Yasemin Acar, Sascha Fahl, Christian Rossow, Giancarlo Pellegrino, Sven Bugiel, Michael Backes 0001 |
IEEE Symposium on Security and Privacy | 8 |
| 2018 | Better managed than memorized? Studying the Impact of Managers on Password Strength and Reuse
Sanam Ghorbani Lyastani, Michael Schilling 0001, Sascha Fahl, Michael Backes 0001, Sven Bugiel |
USENIX Security Symposium | 5 |
| 2017 | Keep me Updated: An Empirical Study of Third-Party Library Updatability on AndroidabstractThird-party libraries in Android apps have repeatedly been shown to be hazards to the users' privacy and an amplification of their host apps' attack surface. A particularly aggravating factor to this situation is that the libraries' version included in apps are very often outdated. Erik Derr, Sven Bugiel, Sascha Fahl, Yasemin Acar, Michael Backes 0001 |
CCS | 2 |
| 2017 | The ART of App Compartmentalization: Compiler-based Library Privilege Separation on Stock AndroidabstractThird-party libraries are commonly used by app developers for alleviating the development efforts and for monetizing their apps. On Android, the host app and its third-party libraries reside in the same sandbox and share all privileges awarded to the host app by the user, putting the users' privacy at risk of intrusions by third-party libraries. In this paper, we introduce a new privilege separation approach for third-party libraries on stock Android. Our solution partitions Android applications at compile-time into isolated, privilege-separated compartments for the host app and the included third-party libraries. A particular benefit of our approach is that it leverages compiler-based instrumentation available on stock Android versions and thus abstains from modification of the SDK, the app bytecode, or the device firmware. A particular challenge for separating libraries from their host apps is the reconstruction of the communication channels and the preservation of visual fidelity between the now separated app and its libraries. We solve this challenge through new IPC-based protocols to synchronize layout and lifecycle management between different sandboxes. Finally, we demonstrate the efficiency and effectiveness of our solution by applying it to real world apps from the Google Play Store that contain advertisements. Jie Huang 0010, Oliver Schranz, Sven Bugiel, Michael Backes 0001 |
CCS | 3 |
| 2017 | ARTist: The Android Runtime Instrumentation and Security ToolkitabstractWith the introduction of Android 5 Lollipop, the Android Runtime (ART) superseded the Dalvik Virtual Machine (DVM) by introducing ahead-of-time compilation and native execution of applications, effectively deprecating seminal works such as TaintDroid that hitherto depend on the DVM. In this paper, we discuss alternatives to overcome those restrictions and highlight advantages for the security community that can be derived from ART's novel on-device compiler dex2oat and its accompanying runtime components. To this end, we introduce ARTist, a compiler-based application instrumentation solution for Android that does not depend on operating system modifications and solely operates on the application layer. Since dex2oat is yet uncharted, our approach required first and foremost a thorough study of the compiler suite's internals and in particular of the new default compiler backend called Optimizing. We document the results of this study in this paper to facilitate independent research on this topic and exemplify the viability of ARTist by realizing two use cases. In particular, we conduct a case study on whether taint tracking can be re-instantiated using a compiler-based app instrumentation framework. Overall, our results provide compelling arguments for the community to choose compiler-based approaches over alternative bytecode or binary rewriting approaches for security solutions on Android. Michael Backes 0001, Sven Bugiel, Oliver Schranz, Philipp von Styp-Rekowsky, Sebastian Weisgerber |
EuroS&P | 2 |
| 2016 | Reliable Third-Party Library Detection in Android and its Security ApplicationsabstractThird-party libraries on Android have been shown to be security and privacy hazards by adding security vulnerabilities to their host apps or by misusing inherited access rights. Correctly attributing improper app behavior either to app or library developer code or isolating library code from their host apps would be highly desirable to mitigate these problems, but is impeded by the absence of a third-party library detection that is effective and reliable in spite of obfuscated code. This paper proposes a library detection technique that is resilient against common code obfuscations and that is capable of pinpointing the exact library version used in apps. Libraries are detected with profiles from a comprehensive library database that we generated from the original library SDKs. We apply our technique to the top apps on Google Play and their complete histories to conduct a longitudinal study of library usage and evolution in apps. Our results particularly show that app developers only slowly adapt new library versions, exposing their end-users to large windows of vulnerability. For instance, we discovered that two long-known security vulnerabilities in popular libs are still present in the current top apps. Moreover, we find that misuse of cryptographic APIs in advertising libs, which increases the host apps' attack surface, affects 296 top apps with a cumulative install base of 3.7bn devices according to Play. To the best of our knowledge, our work is first to quantify the security impact of third-party libs on the Android ecosystem. Michael Backes 0001, Sven Bugiel, Erik Derr |
CCS | 2 |
| 2016 | R-Droid: Leveraging Android App Analysis with Static Slice OptimizationabstractToday's feature-rich smartphone apps intensively rely on access to highly sensitive (personal) data. This puts the user's privacy at risk of being violated by overly curious apps or libraries (like advertisements). Central app markets conceptually represent a first line of defense against such invasions of the user's privacy, but unfortunately we are still lacking full support for automatic analysis of apps' internal data flows and supporting analysts in statically assessing apps' behavior. In this paper we present a novel slice-optimization approach to leverage static analysis of Android applications. Building on top of precise application lifecycle models, we employ a slicing-based analysis to generate data-dependent statements for arbitrary points of interest in an application. As a result of our optimization, the produced slices are, on average, 49% smaller than standard slices, thus facilitating code understanding and result validation by security analysts. Moreover, by re-targeting strings, our approach enables automatic assessments for a larger number of use-cases than prior work. We consolidate our improvements on statically analyzing Android apps into a tool called R-Droid and conducted a large-scale data-leak analysis on a set of 22,700 Android apps from Google Play. R-Droid managed to identify a significantly larger set of potential privacy-violating information flows than previous work, including 2,157 sensitive flows of password-flagged UI widgets in 256 distinct apps. Michael Backes 0001, Sven Bugiel, Erik Derr, Sebastian Gerling, Christian Hammer 0001 |
AsiaCCS | 2 |
| 2016 | POSTER: The ART of App CompartmentalizationabstractOn Android, advertising libraries are commonly integrated with their host apps. Since the host and advertising components share the application's sandbox, advertisement code inherits all permissions and can access host resources with no further approval needed. Motivated by the privacy risks of advertisement libraries as already shown in the literature, this poster introduces an Android Runtime (ART) based app compartmentalization mechanism to achieve separation between trusted app code and untrusted library code without system modification and application rewriting. With our approach, advertising libraries will be isolated from the host app and the original app will be partitioned into two sub-apps that run independently, with the host app's resources and permissions being protected by Android's app sandboxing mechanism. ARTist [1], a compiler-based Android app instrumentation framework, is utilized here to recreate the communication channels between host and advertisement library. The result is a robust toolchain on device which provides a clean separation of developer-written app code and third-party advertisement code, allowing for finer-grained access control policies and information flow control without OS customization and application rebuilding. Michael Backes 0001, Sven Bugiel, Jie Huang 0010, Oliver Schranz |
CCS | 2 |
| 2016 | SoK: Lessons Learned from Android Security Research for Appified Software PlatformsabstractAndroid security and privacy research has boomed in recent years, far outstripping investigations of other appified platforms. However, despite this attention, research efforts are fragmented and lack any coherent evaluation framework. We present a systematization of Android security and privacy research with a focus on the appification of software systems. To put Android security and privacy research into context, we compare the concept of appification with conventional operating system and software ecosystems. While appification has improved some issues (e.g., market access and usability), it has also introduced a whole range of new problems and aggravated some problems of the old ecosystems (e.g., coarse and unclear policy, poor software development practices). Some of our key findings are that contemporary research frequently stays on the beaten path instead of following unconventional and often promising new routes. Many security and privacy proposals focus entirely on the Android OS and do not take advantage of the unique features and actors of an appified ecosystem, which could be used to roll out new security mechanisms less disruptively. Our work highlights areas that have received the larger shares of attention, which attacker models were addressed, who is the target, and who has the capabilities and incentives to implement the countermeasures. We conclude with lessons learned from comparing the appified with the old world, shedding light on missed opportunities and proposing directions for future research. Yasemin Acar, Michael Backes 0001, Sven Bugiel, Sascha Fahl, Patrick D. McDaniel, Matthew Smith 0001 |
IEEE Symposium on Security and Privacy | 3 |
| 2016 | On Demystifying the Android Application Framework: Re-Visiting Android Permission Specification Analysis
Michael Backes 0001, Sven Bugiel, Erik Derr, Patrick D. McDaniel, Damien Octeau, Sebastian Weisgerber |
USENIX Security Symposium | 2 |
| 2015 | Boxify: Full-fledged App Sandboxing for Stock Android
Michael Backes 0001, Sven Bugiel, Christian Hammer 0001, Oliver Schranz, Philipp von Styp-Rekowsky |
USENIX Security Symposium | 2 |
| 2014 | Scippa: system-centric IPC provenance on AndroidabstractGoogle's Android OS provides a lightweight IPC mechanism called Binder, which enables the development of feature-rich apps that seamlessly integrate services and data of other apps. Whenever apps can act both as service consumers and service providers, it is inevitable that the IPC mechanism provides message receivers with message provenance information to establish trust. However, the Android OS currently fails in providing sufficient provenance information, which has led to a number of attacks. Michael Backes 0001, Sven Bugiel, Sebastian Gerling |
ACSAC | 2 |
| 2014 | Android security framework: extensible multi-layered access control on AndroidabstractWe introduce the Android Security Framework (ASF), a generic, extensible security framework for Android that enables the development and integration of a wide spectrum of security models in form of code-based security modules. The design of ASF reflects lessons learned from the literature on established security frameworks (such as Linux Security Modules or the BSD MAC Framework) and intertwines them with the particular requirements and challenges from the design of Android's software stack. ASF provides a novel security API that supports authors of Android security extensions in developing their modules. This overcomes the current unsatisfactory situation to provide security solutions as separate patches to the Android software stack or to embed them into Android's mainline codebase. This system security extensibility is of particular benefit for enterprise or government solutions that require deployment of advanced security models, not supported by vanilla Android. We present a prototypical implementation of ASF and demonstrate its effectiveness and efficiency by modularizing different security models from related work, such as dynamic permissions, inlined reference monitoring, and type enforcement. Michael Backes 0001, Sven Bugiel, Sebastian Gerling, Philipp von Styp-Rekowsky |
ACSAC | 2 |
| 2013 | Client-Controlled Cryptography-as-a-Service in the Cloud
Sören Bleikertz, Sven Bugiel, Hugo Ideler, Stefan Nürnberger, Ahmad-Reza Sadeghi |
ACNS | 2 |
| 2013 | Flexible and Fine-grained Mandatory Access Control on Android for Diverse Security and Privacy Policies
Sven Bugiel, Stephan Heuser, Ahmad-Reza Sadeghi |
USENIX Security Symposium | 1 |
| 2012 | Towards Taming Privilege-Escalation Attacks on Android
Sven Bugiel, Lucas Davi, Alexandra Dmitrienko, Thomas Fischer 0005, Ahmad-Reza Sadeghi, Bhargava Shastry |
NDSS | 1 |
| 2011 | Poster: the quest for security against privilege escalation attacks on android
Sven Bugiel, Lucas Davi, Alexandra Dmitrienko, Thomas Fischer 0005, Ahmad-Reza Sadeghi, Bhargava Shastry |
CCS | 1 |
| 2011 | AmazonIA: when elasticity snaps backabstractCloud Computing is an emerging technology promising new business opportunities and easy deployment of web services. Much has been written about the risks and benefits of cloud computing in the last years. The literature on clouds often points out security and privacy challenges as the main obstacles, and proposes solutions and guidelines to avoid them. However, most of these works deal with either malicious cloud providers or customers, but ignore the severe threats caused by unaware users. Sven Bugiel, Stefan Nürnberger, Thomas Pöppelmann, Ahmad-Reza Sadeghi, Thomas Schneider 0003 |
CCS | 1 |