Luisa Lux

dblp:326/7433 · DBLP profile ↗
← Back
3ranked-venue papers
1as first author
3since 2021 · last 2026
0009-0004-6674-6742ORCID · reported

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 3 · 1 first-author · 3 since 2021
YearPublicationVenuePosition
2026 A Deep Dive into Wormhole Attacks in Underwater Acoustic Communication: From Theory to Practice
abstract
256
Luisa Lux, Eric Wagner 0003, Konrad Wolsing, Ulrike Meyer
WISEC1
2025 GeCos Replacing Experts: Generalizable and Comprehensible Industrial Intrusion Detection
Konrad Wolsing, Eric Wagner 0003, Luisa Lux, Klaus Wehrle, Martin Henze
USENIX Security Symposium3
2022 Dating Phish: An Analysis of the Life Cycles of Phishing Attacks and Campaigns
abstract
Phishing attacks are still a general and world-wide threat to users of the Internet. In the past, several approaches to detect phishing websites earlier and shorten the time frame between their creation and inclusion in a blocklist have been proposed. Understanding the life cycle of phishing attacks, in particular the time of their creation and the time span from the first to last attack in a campaign, provides additional insights into the potential success of these methods. In this paper, we present an analysis of the life cycles of 133,667 phishing websites based on the publicly available information from certificates, whois, as well as images and resources on the phishing websites themselves. While we confirm the findings from previous work, that many websites have short lifetimes of only several days, we also note that the timing information from phishing websites using public hosting or compromised infrastructure is far less accurate in dating the creation of the websites. We further cluster the phishing websites into campaigns based on patterns in their domain names, and find that the detected campaigns often take place over several weeks, with an average duration of almost 12 days. Our results showcase advantages and limitations for the early detection of phishing websites, in particular regarding the time span between the creation of a website and its inclusion in a blocklist, and how patterns in domain names remain the same over a period of up to several weeks in the phishing campaigns analyzed in this paper.
Vincent Drury, Luisa Lux, Ulrike Meyer
ARES2