EDBT 2026 Demo / reviewers in the wild / expert
Marc Rennhard
dblp:51/2719
· DBLP profile ↗
6ranked-venue papers
0as first author
4since 2021 · last 2026
0000-0001-5105-3258ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 4 · 2 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Relocate and Emulate: Re-Hosting Android's Application LayerabstractDynamic analysis of Android's application layer typically relies on physical devices, limiting scalability and reproducibility. To compensate, we introduce a systematic re-hosting method that relocates the Android framework and pre-installed software from real device firmware into a fully emulated environment. Our approach integrates vendor-specific components into the Android Open Source Project (AOSP) build system using tailored extraction and injection strategies, producing vendor-flavoured emulator images that preserve system integrity and runtime compatibility. This enables dynamic execution of real-world framework and application-layer components, including proprietary binaries and pre-installed apps, across multiple SDK versions. We evaluate our method on 184 firmware samples from SDK 31-33. It achieves high build and boot success rates, with residual failures primarily occurring during core-service initialization due to baseline strategy limitations, missing dependencies, device-protection checks, or emulator constraints. However, the modular design allows injection strategies to be extended for specific firmware, supporting broader compatibility and future research on automated, adaptive re-hosting. Though we identified potential for optimization through engineering vendor-specific solutions, our research demonstrates the feasibility of vendor-flavoured emulators for scalable, reproducible dynamic analysis. Thomas Sutter, Timo Kehrer, Bernhard Tellenbach, Marc Rennhard |
SANER | 4 |
| 2025 | A Continuous Certification Readiness Framework for Cloudification of IT/OT Platforms (Vision Paper)abstractCloud-centric services are becoming the norm in modern IT and Operational Technology (OT) platforms, where cybersecurity risks are also on the rise. The evolving regulatory landscape within Europe, exemplified by the Network and Information Security 2 (NIS2) directive and the Cyber Resilience Act (CRA), further amplifies the necessity for rigorous compliance measures. The presumption of conformity for platforms certified under EU-recognized certification schemes, as outlined by the CRA, is anticipated to promote the certification of IT and OT platforms. Nevertheless, the certification process for these platforms is challenging due to the complexity of cloud architectures and the constantly evolving threats, which require continuous adaptation. Furthermore, both NIS2 and CRA introduce new mandates, including the obligation to manage risks, report incidents to relevant authorities, inform customers about vulnerabilities, and provide relevant mitigation strategies. Consequently, there exists an urgent demand for tools and frameworks that support sustained certification in the cloudification of IT/OT platforms. This paper introduces the Continuous Certification Readiness Framework (CCRF), which is engineered to automate tasks related to certification preparation and support ongoing compliance assessments, thereby enabling organizations to effectively manage risks and uphold a high level of assurance within their cloud environments. Chrystel Gaber, Nicolas Dejon, Ndeye Gagnessiry Ndiaye, Karl Waedt, Vincent Lefebvre, Gürkan Gür, Marc Rennhard, Achilleas Marinakis, Christos-Antonios Gizelis, Jean-Philippe Wary, Claire Loiseaux |
IC2E | 7 |
| 2025 | A2CT: Automated Detection of Function and Object-Level Access Control Vulnerabilities in Web ApplicationsabstractIn view of growing security risks, automated security testing of web applications is getting more and more important. There already exist capable tools to detect common vulnerability types such as SQL injection or cross-site scripting. Access control vulnerabilities, however, are still a vulnerability category that is much harder to detect in an automated fashion, while at the same time representing a highly relevant security problem in practice. In this paper, we present A2CT, a practical approach for the automated detection of access control vulnerabilities in web applications. A2CT supports most web applications and can detect vulnerabilities in the context of all HTTP request types (GET, POST, PUT, PATCH, DELETE). To demonstrate the practical usefulness of A2CT, an evaluation based on 30 publicly available web applications was done. Overall, A2CT managed to uncover 14 previously unknown vulnerabilities in two of these web applications, which resulted in six published CVE records. To encourage further research, the source code of A2CT is made available under an open-source license. Michael Schlaubitz, Onur Veyisoglu, Marc Rennhard |
ICISSP (2) | 3 |
| 2021 | Automated Black Box Detection of HTTP GET Request-based Access Control Vulnerabilities in Web ApplicationsabstractAutomated and reproducible security testing of web applications is getting more and more important, driven by short software development cycles and constraints with respect to time and budget. Some types of vulnerabilities can already be detected reasonably well by automated security scanners, e.g., SQL injection or cross-site scripting vulnerabilities. However, other types of vulnerabilities are much harder to uncover in an automated way. This includes access control vulnerabilities, which are highly relevant in practice as they can grant unauthorized users access to security-critical data or functions in web applications. In this paper, a practical solution to automatically detect access control vulnerabilities in the context of HTTP GET requests is presented. The solution is based on previously proposed ideas, which are extended with novel approaches to enable completely automated access control testing with minimal configuration effort that enables frequent and reproducible testing. An evaluation using four web applications based on different technologies demonstrates the general applicability of the solution and that it can automatically uncover most access control vulnerabilities while keeping the number of false positives relatively low. Malte Kushnir, Olivier Favre, Marc Rennhard, Damiano Esposito, Valentin Zahnd |
ICISSP | 3 |
| 2008 | Histogram Matrix: Log File Visualization for Anomaly DetectionabstractIn today's IT environments, there is an ever increasing demand for log file analysis solutions. Log files often contain important information about possible incidents, but inspecting the often large amounts of textual data is too time-consuming and tedious a task to perform manually. To address this issue, we propose a novel log file visualization technique called Histogram Matrix (HMAT). HMAT visualizes the content of a log file in order to enable a security administrator to efficiently spot anomalies. The system uses a combination of graphical and statistical techniques and allows even non-experts to interactively search for anomalous log messages. Contrary to other approaches, our proposal does not only work on certain special kinds of log files, but instead works on almost every textual log file. Additionally, the system allows to automatically generate security events if an anomaly is detected, similar to anomaly-based intrusion detection systems. This paper introduces HMAT, demonstrates its functionality using log files from a variety of services in real environments, and identifies strengths and limitations of the technique. Adrian Frei, Marc Rennhard |
ARES | 2 |
| 2001 | A Practical and Effective Approach to Large-Scale Automated Linguistic Steganography
Mark Chapman, George I. Davida, Marc Rennhard |
ISC | 3 |