Lisa Gebauer

dblp:321/3976 · DBLP profile ↗
← Back
5ranked-venue papers
3as first author
5since 2021 · last 2025
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Systems, architecture and hardware · 5 · 3 first-author · 5 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2025 Automated Documentation of Security Risk Assessments with Large Language Models
abstract
The general development of Industry 4.0 and the highly dynamic threat landscape extend the need for continuous security engineering of industrial components, especially during the development phase. Security risk assessments play an important role to ensure the secure and safe development of Industrial Automation and Control Systems (IACSs), but they are based on sophisticated manual and typically time-consuming tasks for human experts. Therefore, this publication identifies and analyzes the information required to document the results of the security risk assessment throughout the development phase. Furthermore, the currently present concepts for documentation are integrated and aligned towards the initially automated and tool-based results by the utilization of Large Language Models (LLMs).
Marco Ehrlich, Lisa Gebauer, Uwe Mönks, Henning Trsek
ETFA2
2024 Evaluation of an Automated Security Risk Assessment Based on a Manual Reference
abstract
The overall Industry 4.0 developments and the highly dynamic threat landscape enhance the need for continuous security engineering of industrial components, modules, and systems. Security risk assessments play a major role to ensure a secure operation of Industrial Automation and Control Systems (IACSs) but are often neglected due to missing resources and a lack of human experts for the sophisticated manual tasks. To relieve this situation and to increase the degree of automation of security risk assessments, a method for information and process modelling was developed in a previous work. The approach was also implemented prototypically as an expert system but has not been validated, yet. This work therefore presents the validation as an integral part of the overall evaluation of the automated security risk assessment concept. For a systematic validation, a reference security risk assessment is manually defined as a set of data for the comparison with the results of the automated expert system. In addition, the two main hypotheses with regard to the result quality and the process automation evaluated.
Marco Ehrlich, Georg Lukas, Lisa Gebauer, Henning Trsek, Jürgen Jasperneite, Wolfgang Kastner, Christian Diedrich
ETFA3
2024 Concept for Software-Supported Automated Security Risk Assessments for Industrial Components
abstract
In view of the dynamic cybersecurity threat land-scape and the increasingly interconnected information technol-ogy (IT) and operational technology (OT) environments, the management of security risks to both IT and OT systems becomes paramount, including efficient and comprehensive risk assessment. Such risk assessments, however, require extensive manual work, the availability of trained security personnel as well as considerable time and financial resources. Additionally, a consistent quality of results often cannot be guaranteed due to a dependency on individual expert knowledge and experience. A promising approach to alleviate these challenges is to use software-based support to automate risk assessment processes and increase efficiency and consistency. This work proposes a con-cept for software-supported automated security risk assessments with a focus on industrial components and the manufacturing industry. It presents key challenges, solution approaches, and further research directions that need to be considered in order to practically implement the concept. Additionally, current research that is already in process towards a practical implementation and a preliminary software prototype are presented.
Lisa Gebauer, Marco Ehrlich, Dimitri Harder, Luca Schäfer, Henning Trsek, Natalia Moriz
ETFA1
2022 Evil SteVe: An Approach to Simplify Penetration Testing of OCPP Charge Points
abstract
The reduction of CO2 emissions caused by auto-mobile traffic relies on the development of electric mobility infrastructure which in turn relies on efficient communication between charge points, used to connect electric vehicles to the power network, and central systems, used to manage users and transactions. The Open Charge Point Protocol (OCPP) is an open communication protocol designed to connect charge points to a central system. An important aspect of the communication between these entities is the security of the connection. It is conceivable, for instance, that an adversary could compromise a central system to attack charge points.This work devises three different attack scenarios which could be executed by a malicious OCPP central system to attack an OCPP charge point. It also assesses the feasibility and potential consequences of such attacks. Additionally, it presents an approach of an "evil" OCPP server implementation, based on the SteVe server which was originally developed at the RWTH Aachen. The "evil" OCPP server implements various attack scenarios and is intended to be used for penetration testing of OCPP charge points that connect to the central system via WebSockets/JSON or SOAP/XML.
Lisa Gebauer, Henning Trsek, Georg Lukas
ETFA1
2022 Secure Communication in Factories - Benchmarking Elliptic Curve Diffie-Hellman Key Exchange Implementations on an Embedded System
abstract
Securing factory communication to protect corporate data is an important concern in the context of the Industrial Internet of Things (IIoT). Various cryptographic protocols can be used to establish secure communication channels. One of these protocols is the Transport Layer Security 1.3 (TLS 1.3) protocol. A key component of the TLS handshake protocol is the Elliptic Curve Diffie-Hellman Key Exchange (ECDHKE), a public key cryptosystem used to exchange keys over insecure channels which can be based on a number of standardized elliptic curves. A special form of elliptic curves are Montgomery curves which are advantageous compared to more traditional Weierstrass curves due to their fast arithmetic. This is especially important when the ECDHKE is performed on embedded devices and in time-critical situations. In this work, the performance of ECDHKE implementations using standardized Montgomery curves Curve25519 and Curve448 included in the wolfSSL library are evaluated on an embedded 32-bit STM32L476RG Nucleo development board designed by STMicroelectronics. The benchmark results show that using Curve25519 with around 220ms for the key pair generation and the key agreement respectively is approximately 75% faster than using Curve448 with around 900ms for each of the algorithms, which can be attributed to their differing security levels. These results suggest that the algorithms might not be fast enough for time critical situations.
Lisa Gebauer, Henning Trsek, Stefan Heiss
WFCS1