Marko Schuba

dblp:34/1779 · DBLP profile ↗
← Back
17ranked-venue papers
3as first author
6since 2021 · last 2025
0000-0002-3302-3060ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 12 · 5 since 2021Computer networks · 3 · 2 first-authorSystems, architecture and hardware · 1 · 1 first-authorApplied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
YearPublicationVenuePosition
2025 CampusQuest: Motivating Computer Science Students for Cybersecurity from Day One
Luca Pöhler, Marko Schuba, Tim Hoener, Sacha Hack, Georg Neugebauer
ICISSP (1)2
2024 A Framework for E2E Audit Trails in System Architectures of Different Enterprise Classes
Luca Patzelt, Georg Neugebauer, Meik Döll, Sacha Hack, Tim Hoener, Marko Schuba
ICISSP6
2024 An Open-Source Approach to OT Asset Management in Industrial Environments
Luca Pöhler, Marko Schuba, Tim Hoener, Sacha Hack, Georg Neugebauer
ICISSP2
2023 Security Analysis of the KNX Smart Building Protocol
abstract
KNX is a protocol for smart building automation, e.g., for automated heating, air conditioning, or lighting. This paper analyses and evaluates state-of-the-art KNX devices from manufacturers Merten, Gira and Siemens with respect to security. On the one hand, it is investigated if publicly known vulnerabilities like insecure storage of passwords in software, unencrypted communication, or denial-of-service attacks, can be reproduced in new devices. On the other hand, the security is analyzed in general, leading to the discovery of a previously unknown and high risk vulnerability related to so-called BCU (authentication) keys.
Malte Küppers, Marko Schuba, Georg Neugebauer, Tim Hoener, Sacha Hack
ARES2
2023 Digital Forensics Triage App for Android
abstract
Digital forensics of smartphones is of utmost importance in many criminal cases. As modern smartphones store chats, photos, videos etc. that can be relevant for investigations and as they can have storage capacities of hundreds of gigabytes, they are a primary target for forensic investigators. However, it is exactly this large amount of data that is causing problems: extracting and examining the data from multiple phones seized in the context of a case is taking more and more time. This bears the risk of wasting a lot of time with irrelevant phones while there is not enough time left to analyze a phone which is worth examination. Forensic triage can help in this case: Such a triage is a preselection step based on a subset of data and is performed before fully extracting all the data from the smartphone. Triage can accelerate subsequent investigations and is especially useful in cases where time is essential. The aim of this paper is to determine which and how much data from an Android smartphone can be made directly accessible to the forensic investigator – without tedious investigations. For this purpose, an app has been developed that can be used with extremely limited storage of data in the handset and which outputs the extracted data immediately to the forensic workstation in a human- and machine-readable format.
Jannik Neth, Marko Schuba, Karsten Brodkorb, Georg Neugebauer, Tim Hoener, Sacha Hack
ARES2
2021 Challenges and Opportunities in Securing the Industrial Internet of Things
abstract
Given the tremendous success of the Internet of Things in interconnecting consumer devices, we observe a natural trend to likewise interconnect devices in industrial settings, referred to as industrial Internet of Things or Industry 4.0. While this coupling of industrial components provides many benefits, it also introduces serious security challenges. Although sharing many similarities with the consumer Internet of Things, securing the industrial Internet of Things introduces its own challenges but also opportunities, mainly resulting from a longer lifetime of components and a larger scale of networks. In this article, we identify the unique security goals and challenges of the industrial Internet of Things, which, unlike consumer deployments, mainly follow from safety and productivity requirements. To address these security goals and challenges, we provide a comprehensive survey of research efforts to secure the industrial Internet of Things, discuss their applicability, and analyze their security benefits.
Martin Serror, Sacha Hack, Martin Henze, Marko Schuba, Klaus Wehrle
IEEE Trans. Ind. Informatics4
2018 Towards In-Network Security for Smart Homes
abstract
The proliferation of the Internet of Things (IoT) in the context of smart homes entails new security risks threatening the privacy and safety of end users. In this paper, we explore the design space of in-network security for smart home networks, which automatically complements existing security mechanisms with a rule-based approach, i. e., every IoT device provides a specification of the required communication to fulfill the desired services. In our approach, the home router as the central network component then enforces these communication rules with traffic filtering and anomaly detection to dynamically react to threats. We show that in-network security can be easily integrated into smart home networks based on existing approaches and thus provides additional protection for heterogeneous IoT devices and protocols. Furthermore, in-network security relieves users of difficult home network configurations, since it automatically adapts to the connected devices and services.
Martin Serror, Martin Henze, Sacha Hack, Marko Schuba, Klaus Wehrle
ARES4
2016 Streamlining Extraction and Analysis of Android RAM Images
Simon Broenner, Hans Höfken, Marko Schuba
ICISSP3
2015 Cold Boot Attacks on DDR2 and DDR3 SDRAM
abstract
Cold boot attacks provide a means to obtain a dump of a computer's volatile memory even if the machine is locked. Such a dump can be used to reconstruct hard disk encryption keys and get access to the content of Bit locker or True crypt encrypted drives. This is even possible, if the obtained dump contains errors. Cold boot attacks have been demonstrated successfully on DDR1 and DDR2 SDRAM. They have also been tried on DDR3 SDRAM using various types of equipment but all attempts have failed so far. In this paper we describe a different hardware setup which turns out to work for DDR3 SDRAM as well. Using this setup it will be possible for digital forensic investigators to recover keys from newer machines that use DDR3 SDRAM.
Simon Lindenlauf, Hans Höfken, Marko Schuba
ARES3
2015 ICS/SCADA Security - Analysis of a Beckhoff CX5020 PLC
abstract
A secure and reliable critical infrastructure is a concern of industry and governments. SCADA systems (Supervisory Control and Data Acquisition) are a subgroup of ICS (Industrial Control Systems) and known to be well interconnected with other networks. It is not uncommon to use public networks as transport route but a rising number of incidents of industrial control systems shows the danger of excessive crosslinking. Beckhoff Automation GmbH is a German automation manufacturer that did not have bad press so far. The Beckhoff CX5020 is a typical PLC (Programmable Logic Controller) that is used in today’s SCADA systems. It is cross-linked through Ethernet and running a customized Windows CE 6.0, therefore the CX5020 is a good representative for modern PLCs which have emerged within the last years that use de facto standard operation systems and open standard communication protocols. This paper presents vulnerabilities of Beckhoff’s CX5020 PLC and shows ways to achieve rights to control the PLC program and the operation system itself. These vulnerabilities do not need in-depth knowledge of penetration testing, they demonstrate that switching to standard platforms brings hidden features and encapsulating SCADA protocols into TCP/IP might not always be a good idea – underlining that securing ICS systems is still a challenging topic.
Gregor Bonney, Hans Höfken, Benedikt Paffen, Marko Schuba
ICISSP4
2013 Artificial Aging of Mobile Devices Using a Simulated GSM/GPRS Network
abstract
The analysis of mobile devices is a fast moving area in digital forensics. Investigators frequently are challenged by devices which are not supported by existing mobile forensic tools. Low level techniques like de-soldering the flash memory chip and extracting its data provide an investigator with the exhibits internal memory, however, the interpretation of the data can be difficult as mobile device and flash chip manufacturers use their own proprietary techniques to encode and store data. The approach presented in this paper helps investigators to analyze this proprietary encoding by feeding a reference device identical to the exhibit with real data in a controlled way. This "artificial ageing" of the reference device is achieved using an isolated GSM/GPRS network plus additional software in a lab environment. After the ageing process is completed, the internal memory of the reference device can be acquired and used to reverse engineer the high level file system and the encoding of the data previously fed to the phone, like received SMS messages or calls. When sufficient knowledge about the interpretation of the memory image has been built up, it can be applied to the original evidence in order to analyze data and files relevant for the case. The successful operation of the solution is demonstrated in a proof of concept for SMS messages.
Rolf Stobe, Hans Höfken, Marko Schuba, Michael Breuer
ARES3
2012 Simplifying RAM Forensics: A GUI and Extensions for the Volatility Framework
abstract
The Volatility Framework is a collection of tools for the analysis of computer RAM. The framework offers a multitude of analysis options and is used by many investigators worldwide. Volatility currently comes with a command line interface only, which might be a hinderer for some investigators to use the tool. In this paper we present a GUI and extensions for the Volatility Framework, which on the one hand simplify the usage of the tool and on the other hand offer additional functionality like storage of results in a database, shortcuts for long Volatility Framework command sequences, and entirely new commands based on correlation of data stored in the database.
Steffen Logen, Hans Höfken, Marko Schuba
ARES3
2011 Windows Phone 7 from a Digital Forensics' Perspective
Thomas Schaefer, Hans Höfken, Marko Schuba
ICDF2C3
2000 Performance evaluation of multicast communication in packet-switched networks
Marko Schuba, Boudewijn R. Haverkort, Gaby Schneider
Perform. Evaluation1
1998 SRMT-a scalable and reliable multicast transport protocol
abstract
Many applications require reliable multicast for data transmission. A number of protocols have been proposed previously for large-scale reliable multicast. Unfortunately these protocols may suffer from the length of the retransmission paths between the source and receivers which yields a very high cost for retransmissions. Therefore we propose the SRMT protocol (scalable and reliable multicast transport protocol) as an alternative to existing approaches. In SRMT an overlay network consisting of SRMT nodes is built on top of existing multicast routing protocols. Retransmissions take place between neighbouring SRMT nodes in the multicast tree. A simple analysis shows the advantages of our method compared to two existing protocols. In the case of networks with high loss probabilities our approach is the only one applicable. For small loss probabilities our protocol (in an example) yields a reduction of more than 65% of the retransmission load caused by the other methods.
Marko Schuba
ICC1
1997 A Performance Evaluation of Connectionless Overlay Networks for ATM
abstract
Introducing the asynchronous transfer mode (ATM) causes a backwards compatibility problem, because ATM is connection-oriented whereas most of today's LANs are connectionless. Interconnection can be achieved by the use of connectionless servers (CLS). These servers together with a number of preestablished virtual circuits form a connectionless overlay network on top of ATM. In this paper we evaluate overlay networks that differ in number location and interconnection of CLSs by computation of mean cell delay and link load.
Marko Schuba
INFOCOM1
1996 Performance Investigations of the IP Multicast Architecture
Oliver Hermanns, Marko Schuba
Comput. Networks ISDN Syst.2