EDBT 2026 Demo / reviewers in the wild / expert
Lukas Bechtel
dblp:384/5189
· DBLP profile ↗
8ranked-venue papers
4as first author
8since 2021 · last 2025
0000-0003-2635-8572ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 8 · 4 first-author · 8 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 1 first-author · 2 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Detecting QoS Degradation in Time-Critical Networks due to Misconfiguration or AttacksabstractCommunication in Industrial Control Systems (ICSs) depends on predictable timing to ensure reliable operation. In converged networks, this timing can be disrupted not only by cyber attacks but also by misconfiguration or benign misbehavior of devices. Such issues degrade Quality of Service (QoS) through delays or jitter, without altering packet content, making it hard to detect them with traditional monitoring systems.This paper presents a configuration-agnostic monitoring system that detects QoS degradation using statistical anomaly detection. We evaluate three detection methods, single-value thresholds, exponential moving averages, and distribution-based analysis, and show that distribution-based detection offers the most robust results. The system supports both passive and active timing measurement to balance accuracy and overhead. By operating independently of network configuration, the proposed approach enables early detection of timing anomalies caused by misbehavior, misconfiguration, or attacks, demonstrating applicability in real-world industrial networks. Lukas Bechtel, Lukas Popperl, Michael Menth, Tobias Heer |
ETFA | 1 |
| 2025 | Time-Limited Software Firewall Based on DPDK Supporting TSN and DetNet TrafficabstractThe convergence of IT and OT networks introduces strict latency and security requirements, especially in virtualized industrial environments. While TSN and DetNet provide bounded-latency traffic delivery, traditional software firewalls break determinism due to variable rule evaluation times. Hence, we propose a time-limited firewall design that limits per-packet rule evaluation time to a fixed budget, ensuring deterministic processing even under high load. To preserve security despite partial rule checks, we propose that a deferred filtering stage verifies and, if necessary, retroactively corrects earlier forwarding decisions. We implement this design in a software firewall prototype and evaluate it under maximum packet rate. The system guarantees limited latency for all packets, maintains high throughput, and ensures eventual security consistency, all without requiring specialized hardware. Lukas Bechtel, Markus Schramm, Michael Menth, Tobias Heer |
ETFA | 1 |
| 2025 | Security Gateway for Automated Micro-Segmentation and VPN Encryption in Industrial Legacy SystemsabstractIn today’s industrial networks, secure communication among participants is crucial. Security measures commonly employed in IT networks, e.g., network segmentation and Virtual Private Networks (VPN), prevent unauthorized access by restricting communication flows within logical segments and ensure data confidentiality by encryption, respectively. In industrial networks, however, security measures are often not used due to legacy devices lacking the required capabilities to implement them. Thus, maintaining network security is particularly difficult. In this work, we take up the concept of retrofitting security measures using a security gateway. The gateway is placed in front of a legacy device and takes over tasks such as micro-segmentation and VPN encryption. A resulting challenge is the derivation of appropriate micro-segments and VPN tunnels. We address this challenge using heuristics based on observed network traffic. We demonstrate the feasibility of the approach through a Proof-of-Concept (PoC). The proposed semi-automated approach allows for retrofitting of security measures, thereby ensuring a seamless migration from the existing to a more secure infrastructure and contributing to the secure integration of legacy devices. Sabrina Kaniewski, Lukas Bechtel, Pascal Kneisel, Michael Menth, Tobias Heer |
ETFA | 2 |
| 2025 | Transforming the Network into a Filter: Distributed Firewall Rules for Time-Critical TrafficabstractIndustrial networks require strict security policies while supporting time-sensitive communication for automation and control processes. Traditional centralized firewalls enforce security by filtering traffic between network segments but introduce unacceptable delays for real-time applications. This paper presents a novel approach that distributes firewall rules across industrial switches, leveraging their Access Control Lists (ACLs) to transform the entire network into a unified, low-latency filtering system. The proposed algorithm accounts for challenges such as rule semantics adaptation, dynamic end-device locations, network redundancy, and ACL resource constraints. It systematically analyzes network topology, calculates rule placement strategies, and ensures correct filtering behavior across distributed enforcement points. Evaluation results demonstrate that our approach significantly reduces filtering delays while maintaining security, enabling real-time communication in industrial environments. Lukas Bechtel, Samuel Müller 0007, Michael Menth, Tobias Heer |
WFCS | 1 |
| 2025 | IoTWall: An Efficient Host-Based Firewall for Resource-Constrained IoT DevicesabstractIn areas such as the industrial sector, IoT devices have become an important component. For example, they serve as temperature sensors or switches. Often, IoT devices share the wireless network with other devices, increasing the potential for attacks through compromised hosts in the network. IoT devices typically lack a packet filtering mechanism that network administrators can configure to limit access to the IoT device by trusted hosts. To enhance IoT device security, we present IoTWall, a lightweight host firewall designed to run on resourceconstrained IoT devices. IoTWall is easy to integrate into existing IoT software projects with only a few code changes to encourage developers to adopt stronger security measures. A REST API enables easy configuration by network administrators without requiring code changes. We also show that IoTWall operates efficiently within the constraints of resource-constrained devices with acceptable latency and energy consumption. Markus Schramm, Lukas Bechtel, Florian Hoss, Michael Menth, Tobias Heer |
WFCS | 2 |
| 2024 | GeNESIS: Generator for Network Evaluation Scenarios of Industrial SystemsabstractThe lack of standardized, realistic industrial net-work scenarios hinders the comparative evaluation of scientific research for industrial networks. Current evaluations often use non-public or synthetic scenarios, making it difficult to compare results across different studies. This paper introduces GeNESIS, a tool designed to generate and exchange realistic, reproducible industrial network evaluation scenarios. GeNESIS produces comprehensive topologies formatted according to IETF standards, including network devices and connections. Additionally, it gen-erates configurations for network devices, supporting evaluations such as algorithm comparisons or network simulations. GeNESIS was created to evaluate firewall configurations but is designed to further support other use cases, such as QoS or reliability. By providing a standardized exchange format, GeNESIS ensures the simple availability of evaluation scenarios, promoting compara-bility and reproducibility in industrial network research. Lukas Bechtel, Samuel Müller 0007, Michael Menth, Tobias Heer |
ETFA | 1 |
| 2024 | Monitoring IP- ID Behavior for Spoofed IPv4 Traffic DetectionabstractMonitoring network traffic and devices is crucial for ensuring secure network operation, particularly in industrial networks, which operate for a long time and contain a mix of devices, i.e., devices with state-of-the-art security and legacy devices whose security features are often insufficient. Such legacy devices require additional compensating security measures for secure operation, especially due to increasing connectivity, exposing legacy devices to new security threats, such as spoofing. For this purpose, we propose an anomaly detection mechanism based on the IPv4 Identifier (IP-ID) field that provides hints for spoofed IPv4 devices. The IP-ID field is a 16-bit value in the IPv4 header. Receiving hosts use it to identify and reassemble parts of a fragmented IP packet. Multiple variants for assigning IP-IDs exist. For example, many legacy devices use a global counter with a fixed increment between subsequent packets. The proposed mechanism is based on the observation that IP-IDs in spoofed traffic may not comply with the previously observed IP-ID assignment behavior of the device. Such deviations can be detected as an anomaly and taken as a hint for spoofing. We provide an overview of existing assignment behaviors and present a classification algorithm using captured traffic. Likewise, we present a simple monitoring algorithm for detecting deviations in a host's classified IP-ID assignment behavior. We address various challenges, such as incomplete captures and unsuited deployment positions, and how to deal with them. We evaluate the feasibility of the algorithms on real-world traces. Further, we present a proof-of-concept implementation that detects various spoofing attacks in a testbed. The proposed mechanism improves security in industrial and related brownfield networks by passively detecting spoofed devices. Sabrina Kaniewski, Lukas Bechtel, Michael Menth, Tobias Heer |
ETFA | 2 |
| 2024 | Secure Resource Allocation Protocol (SecRAP) for Time-Sensitive NetworkingabstractThe convergence of operational technology (OT) and information technology (IT) networks through Time-Sensitive Networking (TSN) promises enhanced efficiency and new use cases in industrial settings. However, ensuring security in this shared infrastructure is crucial to prevent potential attacks that could compromise Quality of Service (QoS) of real-time streams and pose risks to operations and safety. This paper focuses on auditing the security of the Resource Allocation Protocol (RAP), a distributed QoS signaling protocol for TSN. We analyze the vulnerability of RAP to attacks during admission control, where end stations request network resources for data transmission. We leverage the Dolev-Yao attacker model to assess the security properties of RAP in both distributed hop-by-hop admission control and hybrid admission control with a central controller. We introduce novel security extensions to RAP, called Secure Resource Allocation Protocol (SecRAP), to mitigate the identified attack vectors. Finally, we present a prototype and discuss the security properties of SecRAP. Lukas Osswald, Steffen Lindner, Lukas Bechtel, Tobias Heer, Michael Menth |
ETFA | 3 |