EDBT 2026 Demo / reviewers in the wild / expert
Benjamin Taubmann
dblp:34/11538
· DBLP profile ↗
9ranked-venue papers
2as first author
3since 2021 · last 2021
—ORCID · none
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 7 · 1 first-author · 3 since 2021Software engineering, systems software and programming languages · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2021 | RapidVMI: Fast and multi-core aware active virtual machine introspectionabstractVirtual machine introspection (VMI) is a technique for the external monitoring of virtual machines. Through previous work, it became apparent that VMI can contribute to the security of distributed systems and cloud architectures by facilitating stealthy intrusion detection, malware analysis, and digital forensics. The main shortcomings of active VMI-based approaches such as program tracing or process injection in production environments result from the side effects of writing to virtual address spaces and the parallel execution of shared main memory on multiple processor cores. Thomas Dangl, Benjamin Taubmann, Hans P. Reiser |
ARES | 2 |
| 2021 | Introspect Virtual Machines Like It Is the Linux Kernel!
Ahmed Abdelraoof, Benjamin Taubmann, Thomas Dangl, Hans P. Reiser |
DIMVA | 2 |
| 2021 | Towards GDPR-compliant data processing in modern SIEM systems
Florian Menges, Tobias Latzo, Manfred Vielberth, Sabine Sobola, Henrich Christopher Pöhls, Benjamin Taubmann, Johannes Köstler, Alexander Puchta, Felix C. Freiling, Hans P. Reiser, Günther Pernul |
Comput. Secur. | 6 |
| 2020 | Towards Hypervisor Support for Enhancing the Performance of Virtual Machine Introspection
Benjamin Taubmann, Hans P. Reiser |
DAIS | 1 |
| 2018 | Introspection for ARM TrustZone with the ITZ LibraryabstractTrustZone is an extension of the ARM architecture that allows software executed in ARM processors to be split in two environments: the normal world that runs a common operating system (e.g., Android or Linux) and its applications, and the secure world that runs security services or others that need to be isolated from the normal world. This work aims to provide support for analyzing the security status of the normal world from the secure world. For this purpose, we present a Virtual Machine Introspection (VMI) library that leverages the TrustZone architecture. VMI tools and the library run in the secure world and inspect the normal world. We present an experimental evaluation of the library in an i.MX53 development board. Miguel Guerra, Benjamin Taubmann, Hans P. Reiser, Sileshi Demesie Yalew, Miguel Correia 0001 |
QRS | 2 |
| 2016 | Geographic Localization of an Anonymous Social Network Message Data SetabstractNowadays, privacy and anonymity are becoming more and more important for users of social networks. Thus, it is of particular interest for user of an anonymous, location-based social network if the network is able to provided the anonymity that it appears to provide. In this work, we present an approach to obtain the geographic location of users of the popular Jodel social network. We are able to reconstruct the exact location from which a message was sent with an accuracy of 10 meters, using only 20 requests sent from virtual clients at different locations to the social network service. Alexander Böhm 0004, Benjamin Taubmann, Hans P. Reiser |
ARES | 2 |
| 2016 | A flexible framework for mobile device forensics based on cold boot attacksabstractMobile devices, like tablets and smartphones, are common place in everyday life. Thus, the degree of security these devices can provide against digital forensics is of particular interest. A common method to access arbitrary data in main memory is the cold boot attack. The cold boot attack exploits the remanence effect that causes data in DRAM modules not to lose the content immediately in case of a power cut-off. This makes it possible to restart a device and extract the data in main memory.In this paper, we present a novel framework for cold boot-based data acquisition with a minimal bare metal application on a mobile device. In contrast to other cold boot approaches, our forensics tool overwrites only a minimal amount of data in main memory. This tool requires no more than three kilobytes of constant data in the kernel code section. We hence sustain all of the data relevant for the analysis of the previously running system. This makes it possible to analyze the memory with data acquisition tools. For this purpose, we extend the memory forensics tool Volatility in order to request parts of the main memory dynamically from our bare metal application. We show the feasibility of our approach on the Samsung Galaxy S4 and Nexus 5 mobile devices along with an extensive evaluation. First, we compare our framework to a traditional memory dump-based analysis. In the next step, we show the potential of our framework by acquiring sensitive user data. Manuel Huber 0001, Benjamin Taubmann, Sascha Wessel, Hans P. Reiser, Georg Sigl |
EURASIP J. Inf. Secur. | 2 |
| 2015 | A Lightweight Framework for Cold Boot Based Forensics on Mobile DevicesabstractMobile devices, like tablets and smartphones, are common place in everyday life. Thus, the degree of security these devices can provide against digital forensics is of particular interest. A common method to access arbitrary data in main memory is the cold boot attack. The cold boot attack exploits theremanence effect that causes data in DRAM modules not to lose the content immediately in case of a power cut-off. This makes it possible to restart a device and extract the data in main memory. In this paper, we present a novel framework for cold boot based data acquisition with a minimal bare metal application on a mobile device. In contrast to other cold boot approaches, our forensics tool overwrites only a minimal amount of data in main memory. This tool requires no more than five kilobytes of constant data in the kernel code section. We hence sustain all of the data relevant for the analysis of the previously running system. This makes it possible to analyze the memory with data acquisition tools. For this purpose, we extend the memory forensics tool Volatility in order to request parts of the main memory dynamically from our bare metal application. We show the feasibility of our approach by comparing it to a traditional memory dump based analysis using the Samsung Galaxy S4 mobile device. Benjamin Taubmann, Manuel Huber 0001, Sascha Wessel, Lukas Heim, Hans P. Reiser, Georg Sigl |
ARES | 1 |
| 2012 | TreVisor - OS-Independent Software-Based Full Disk Encryption Secure against Main Memory Attacks
Tilo Müller, Benjamin Taubmann, Felix C. Freiling |
ACNS | 2 |