EDBT 2026 Demo / reviewers in the wild / expert
Oliver Jacobsen
dblp:372/6077
· DBLP profile ↗
3ranked-venue papers
3as first author
3since 2021 · last 2026
0009-0009-1276-663XORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 3 · 3 first-author · 3 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | The Fault in Our Drafts: Vulnerabilities in RPKI Specification and Softwareabstract2815 Oliver Jacobsen, Tobias Kirsch, Haya Schulmann, Niklas Vogel, Michael Waidner |
SP | 1 |
| 2024 | Poster: Patching NSEC3-Encloser: The Good, the Bad, and the UglyabstractThis paper evaluates the effectiveness of patches designed to mitigate the NSEC3-encloser attack in DNS resolvers. NSEC3, used in DNSSEC to authenticate non-existence of records, can be exploited to exhaust resolver resources through excessive SHA-1 hashing. Despite recent patches, our study reveals that major DNS resolvers remain vulnerable. We test the NSEC3 exhaustion attacks against pre- and post-patch versions of popular DNS resolvers (Unbound, BIND9, PowerDNS, and Knot Resolver), and observe a 72-fold increase in CPU instructions during attacks. PowerDNS 5.0.5 and Knot Resolver 5.7.3 showed improvements, limiting CPU load with strict hash limits. Conversely, BIND9 exhibited marginal improvement, and Unbound 1.20.0 experienced increased CPU load. At an attack rate of 150 malicious NSEC3 records per second, benign DNS request loss rates ranged from 2.7% to 30%. Our study indicates the need for robust countermeasures to address NSEC3 vulnerabilities. Oliver Jacobsen, Haya Schulmann |
CCS | 1 |
| 2024 | Poster: From Fort to Foe: The Threat of RCE in RPKIabstractIn this work, we present a novel severe buffer-overflow vulnerability in the RPKI validator Fort, that allows an attacker to achieve Remote Code Execution (RCE) on the machine running the software. We discuss the unique impact of this RCE on networks that use RPKI, illustrating that RCE vulnerabilities are especially severe in the context of RPKI. The design of RPKI makes RCE easy to exploit on a large scale, allows compromise of RPKI validation integrity, and enables a powerful vector for additional attacks on other critical components of the network, like the border routers. We analyze the vulnerability exposing to this RCE and identify indications that the discovered vulnerability could constitute an intentional backdoor to compromise systems running the software over a benign coding mistake. We disclosed the vulnerability, which has been assigned a CVE rated 9.8 critical (CVE-2024-45237). Oliver Jacobsen, Haya Schulmann, Niklas Vogel, Michael Waidner |
CCS | 1 |