Jörg Schwenk

dblp:58/5730 · DBLP profile ↗
← Back
89ranked-venue papers
4as first author
19since 2021 · last 2025
0000-0001-9315-7354ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 74 · 4 first-author · 19 since 2021Applied, interdisciplinary, general and emerging computing · 4Computer networks · 3Software engineering, systems software and programming languages · 2
YearPublicationVenuePosition
2025 Finding SSH Strict Key Exchange Violations by State Learning
abstract
SSH is an important protocol for secure remote shell access to servers on the Internet. At USENIX 2024, Bäumer et al. presented the Terrapin attack on SSH, which relies on the attacker injecting optional messages during the key exchange. To mitigate this attack, SSH vendors adopted an extension developed by OpenSSH called strict key exchange (''strict KEX''). With strict KEX, optional messages are forbidden during the handshake, preventing the attack. In practice, this should simplify the state machine of an SSH handshake to a linear message flow similar to that of TLS. In this work, we analyze the design, implementation, and security of strict KEX in popular SSH servers, using black-box state learning, which can uncover the hidden state machine of an implementation. In practice, it is limited by the number of learned messages and the complexity of the state machine. Thus, learning the complete state machine of SSH is infeasible. Previous research on SSH, therefore, excluded optional messages, learning only a partial state machine. However, these messages are a critical part of the Terrapin attack. We propose to instead learn the complete state machine of the handshake phase of an SSH server, but with strict KEX enabled. We investigate the security of ten SSH implementations supporting strict KEX for up to five key exchange algorithms. In total, we learn 33 state machines, revealing significant differences in the implementations. We show that seven implementations violate the strict KEX specification and find two critical security vulnerabilities. One results in a rogue session attack in the proprietary Tectia SSH implementation. Another affects the official SSH implementation of the Erlang Open Telecom Platform, and enables unauthenticated remote code execution in the security context of the SSH server.
Fabian Bäumer 0001, Marcel Maehren, Marcus Brinkmann, Jörg Schwenk
CCS4
2025 On the Security of SSH Client Signatures
abstract
Administrators and developers use SSH client keys and signatures for authentication, for example, to access internet backbone servers or to commit new code on platforms like GitHub. However, unlike servers, SSH clients cannot be measured through internet scans. We close this gap in two steps. First, we collect SSH client public keys. Such keys are regularly published by their owners on open development platforms like GitHub and GitLab. We systematize previous non-academic work by subjecting these keys to various security tests in a longitudinal study. Second, in a series of black-box lab experiments, we analyze the implementations of algorithms for SSH client signatures in 24 popular SSH clients for Linux, Windows, and macOS. We extracted 31,622,338 keys from three public sources in two scans. Compared to previous work, we see a clear tendency to abandon RSA signatures in favor of EdDSA signatures. Still, in January 2025, we found 98 broken short keys, 139 keys generated from weak randomness, and 149 keys with common or small factors—the large majority of the retrieved keys exposed no weakness. Weak randomness can not only compromise a secret key through its public key, but also through signatures. It is well-known that a bias in random nonces in ECDSA can reveal the secret key through public signatures. For the first time, we show that the use of deterministic nonces in ECDSA can also be dangerous: The private signing key of a PuTTY client can be recovered from just 58 valid signatures if ECDSA with NIST curve P-521 is used. PuTTY acknowledged our finding in CVE-2024-31497, and they subsequently replaced the nonce generation algorithm.
Fabian Bäumer 0001, Marcus Brinkmann, Maximilian Radoy, Jörg Schwenk, Juraj Somorovsky
CCS4
2025 Towards Internet-Based State Learning of TLS State Machines
Marcel Maehren, Nurullah Erinola, Robert Merget, Jörg Schwenk, Juraj Somorovsky
USENIX Security Symposium4
2024 Terrapin Attack: Breaking SSH Channel Integrity By Sequence Number Manipulation
Fabian Bäumer 0001, Marcus Brinkmann, Jörg Schwenk
USENIX Security Symposium3
2024 With Great Power Come Great Side Channels: Statistical Timing Side-Channel Analyses with Bounded Type-1 Errors
Martin Dunsche, Marcel Maehren, Nurullah Erinola, Robert Merget, Nicolai Bissantz, Juraj Somorovsky, Jörg Schwenk
USENIX Security Symposium7
2023 Finding All Cross-Site Needles in the DOM Stack: A Comprehensive Methodology for the Automatic XS-Leak Detection in Web Browsers
abstract
Cross-Site Leaks (XS-Leaks) are a class of vulnerabilities that allow a web attacker to infer user state from a target web application cross-origin. Fixing XS-Leaks is a cat-and-mouse game: once a published vulnerability is fixed, a variant is discovered. To end this game, we propose a methodology to find all leak techniques for a given state-dependent resource and a set of inclusion method. We translate a website's DOM at runtime into a directed graph. We execute this translation twice, once for each state. The outputs are two slightly different graphs. We then get the set of all leak techniques by computing these two graphs' differences. The remaining nodes and edges differ between the two states, and the corresponding DOM properties and objects can be observed cross-origin.
Dominik Trevor Noß, Lukas Knittel, Christian Mainka, Marcus Niemietz, Jörg Schwenk
CCS5
2023 Exploring the Unknown DTLS Universe: Analysis of the DTLS Server Ecosystem on the Internet
Nurullah Erinola, Marcel Maehren, Robert Merget, Juraj Somorovsky, Jörg Schwenk
USENIX Security Symposium5
2023 Isolated and Exhausted: Attacking Operating Systems via Site Isolation in the Browser
Matthias Gierlings, Marcus Brinkmann, Jörg Schwenk
USENIX Security Symposium3
2023 We Really Need to Talk About Session Tickets: A Large-Scale Analysis of Cryptographic Dangers with TLS Session Tickets
Sven Hebrok, Simon Nachtigall, Marcel Maehren, Nurullah Erinola, Robert Merget, Juraj Somorovsky, Jörg Schwenk
USENIX Security Symposium7
2023 Every Signature is Broken: On the Insecurity of Microsoft Office's OOXML Signatures
Simon Rohlmann, Vladislav Mladenov, Christian Mainka, Daniel Hirschberger, Jörg Schwenk
USENIX Security Symposium5
2022 DISTINCT: Identity Theft using In-Browser Communications in Dual-Window Single Sign-On
abstract
Single Sign-On (SSO) protocols like OAuth 2.0 and OpenID Connect 1.0 are cornerstones of modern web security, and have received much academic attention. Users sign in at a trusted Identity Provider (IdP) that subsequently allows many Service Providers (SPs) to verify the users' identities. Previous research concentrated on the standardized - called textbook SSO in this paper - authentication flows, which rely on HTTP redirects to transfer identity tokens between the SP and IdP. However, modern web applications like single page apps may not be able to execute the textbook flow because they lose the local state in case of HTTP redirects. By using novel browser technologies, such as postMessage, developers designed and implemented SSO protocols that were neither documented nor analyzed thoroughly. We call them dual-window SSO flows.
Louis Jannett, Vladislav Mladenov, Christian Mainka, Jörg Schwenk
CCS4
2022 TLS-Anvil: Adapting Combinatorial Testing for TLS Libraries
Marcel Maehren, Philipp Nieting, Sven Hebrok, Robert Merget, Juraj Somorovsky, Jörg Schwenk
USENIX Security Symposium6
2022 Oops... Code Execution and Content Spoofing: The First Comprehensive Analysis of OpenDocument Signatures
Simon Rohlmann, Christian Mainka, Vladislav Mladenov, Jörg Schwenk
USENIX Security Symposium4
2021 XSinator.com: From a Formal Model to the Automatic Evaluation of Cross-Site Leaks in Web Browsers
abstract
Cross-Site Leaks (XS-Leaks) describe a client-side bug that allows an attacker to collect side-channel information from a cross-origin HTTP resource. They are a significant threat to Internet privacy since simply visiting a web page may reveal if the victim is a drug addict or leak a sexual orientation. Numerous different attack vectors, as well as mitigation strategies, have been proposed, but a clear and systematic understanding of XS-Leak' root causes is still missing. Recently, Sudhodanan et al. gave a first overview of XS-Leak at NDSS 2020. We build on their work by presenting the first formal model for XS-Leaks. Our comprehensive analysis of known XS-Leaks reveals that all of them fit into this new model. With the help of this formal approach, we (1) systematically searched for new XS-Leak attack classes, (2) implemented XSinator.com, a tool to automatically evaluate if a given web browser is vulnerable to XS-Leaks, and (3) systematically evaluated mitigations for XS-Leaks. We found 14 new attack classes, evaluated the resilience of 56 different browser/OS combinations against a total of 34 XS-Leaks, and propose a completely novel methodology to mitigate XS-Leaks.
Lukas Knittel, Christian Mainka, Marcus Niemietz, Dominik Trevor Noß, Jörg Schwenk
CCS5
2021 SoK: Game-Based Security Models for Group Key Exchange
Bertram Poettering, Paul Rösler, Jörg Schwenk, Douglas Stebila
CT-RSA3
2021 Processing Dangerous Paths - On Security and Privacy of the Portable Document Format
Jens Müller 0007, Dominik Noss, Christian Mainka, Vladislav Mladenov, Jörg Schwenk
NDSS5
2021 Breaking the Specification: PDF Certification
abstract
The Portable Document Format (PDF) is the de-facto standard for document exchange. The PDF specification defines two different types of digital signatures to guarantee the authenticity and integrity of documents: approval signatures and certification signatures. Approval signatures testify one specific state of the PDF document. Their security has been investigated at CCS’19. Certification signatures are more powerful and flexible. They cover more complex workflows, such as signing contracts by multiple parties. To achieve this goal, users can make specific changes to a signed document without invalidating the signature.This paper presents the first comprehensive security evaluation on certification signatures in PDFs. We describe two novel attack classes – Evil Annotation and Sneaky Signature attacks which abuse flaws in the current PDF specification. Both attack classes allow an attacker to significantly alter a certified document’s visible content without raising any warnings. Our practical evaluation shows that an attacker could change the visible content in 15 of 26 viewer applications by using Evil Annotation attacks and in 8 applications using Sneaky Signature by using PDF specification compliant exploits. We improved both attacks’ stealthiness with applications’ implementation issues and found only two applications secure to all attacks. On top, we show how to gain high privileged JavaScript execution in Adobe.We responsibly disclosed these issues and supported the vendors to fix the vulnerabilities. We also propose concrete countermeasures and improvements to the current specification to fix the issues.
Simon Rohlmann, Vladislav Mladenov, Christian Mainka, Jörg Schwenk
SP4
2021 ALPACA: Application Layer Protocol Confusion - Analyzing and Mitigating Cracks in TLS Authentication
Marcus Brinkmann, Christian Dresen, Robert Merget, Damian Poddebniak, Jens Müller 0007, Juraj Somorovsky, Jörg Schwenk, Sebastian Schinzel
USENIX Security Symposium7
2021 Raccoon Attack: Finding and Exploiting Most-Significant-Bit-Oracles in TLS-DH(E)
Robert Merget, Marcus Brinkmann, Nimrod Aviram, Juraj Somorovsky, Johannes Mittmann, Jörg Schwenk
USENIX Security Symposium6
2020 Powerless Security
Stefan Hoffmann 0004, Jens Müller 0007, Jörg Schwenk, Gerd Bumiller
ACNS (2)3
2020 Mitigation of Attacks on Email End-to-End Encryption
abstract
OpenPGP and S/MIME are two major standards for securing email communication introduced in the early 1990s. Three recent classes of attacks exploit weak cipher modes (EFAIL Malleability Gadgets, or EFAIL-MG), the flexibility of the MIME email structure (EFAIL Direct Exfiltration, or EFAIL-DE), and the Reply action of the email client (REPLY attacks). Although all three break message confidentiality by using standardized email features, only EFAIL-MG has been mitigated in IETF standards with the introduction of AEAD algorithms. So far, no uniform and reliable countermeasures have been adopted by email clients to prevent EFAIL-DE and REPLY attacks. Instead, email clients implement a variety of different ad-hoc countermeasures which are only partially effective, cause interoperability problems, and fragment the secure email ecosystem.
Jörg Schwenk, Marcus Brinkmann, Damian Poddebniak, Jens Müller 0007, Juraj Somorovsky, Sebastian Schinzel
CCS1
2020 T0RTT: Non-Interactive Immediate Forward-Secret Single-Pass Circuit Construction
abstract
Maintaining privacy on the Internet with the presence of powerful adversaries such as nation-state attackers is a challenging topic, and the Tor project is currently the most important tool to protect against this threat. The circuit construction protocol (CCP) negotiates cryptographic keys for Tor circuits, which overlay TCP/IP by routing Tor cells over n onion routers. The current circuit construction protocol provides strong security guarantees such as forward secrecy by exchanging 𝒪(n2) messages.
Sebastian Lauer, Kai Gellert, Robert Merget, Tobias Handirk, Jörg Schwenk
Proc. Priv. Enhancing Technol.5
2019 Re: What's Up Johnny? - Covert Content Attacks on Email End-to-End Encryption
Jens Müller 0007, Marcus Brinkmann, Damian Poddebniak, Sebastian Schinzel, Jörg Schwenk
ACNS5
2019 Practical Decryption exFiltration: Breaking PDF Encryption
abstract
The Portable Document Format, better known as PDF, is one of the most widely used document formats worldwide, and in order to ensure information confidentiality, this file format supports document encryption. In this paper, we analyze PDF encryption and show two novel techniques for breaking the confidentiality of encrypted documents. First, we abuse the PDF feature of partially encrypted documents to wrap the encrypted part of the document within attacker-controlled content and therefore, exfiltrate the plaintext once the document is opened by a legitimate user. Second, we abuse a flaw in the PDF encryption specification to arbitrarily manipulate encrypted content. The only requirement is that a single block of known plaintext is needed, and we show that this is fulfilled by design. Our attacks allow the recovery of the entire plaintext of encrypted documents by using exfiltration channels which are based on standard compliant PDF properties. We evaluated our attacks on 27 widely used PDF viewers and found all of them to be vulnerable. We responsibly disclosed the vulnerabilities and supported the vendors in fixing the issues.
Jens Müller 0007, Fabian Ising, Vladislav Mladenov, Christian Mainka, Sebastian Schinzel, Jörg Schwenk
CCS6
2019 1 Trillion Dollar Refund: How To Spoof PDF Signatures
abstract
The Portable Document Format (PDF) is the de-facto standard for document exchange worldwide. To guarantee the authenticity and integrity of documents, digital signatures are used. Several public and private services ranging from governments, public enterprises, banks, and payment services rely on the security of PDF signatures. In this paper, we present the first comprehensive security evaluation on digital signatures in PDFs. We introduce three novel attack classes which bypass the cryptographic protection of digitally signed PDF files allowing an attacker to spoof the content of a signed PDF. We analyzed 22 different PDF viewers and found 21 of them to be vulnerable, including prominent and widely used applications such as Adobe Reader DC and Foxit. We additionally evaluated eight online validation services and found six to be vulnerable. A possible explanation for these results could be the absence of a standard algorithm to verify PDF signatures -- each client verifies signatures differently, and attacks can be tailored to these differences. We, therefore, propose the standardization of a secure verification algorithm, which we describe in this paper. All findings have been responsibly disclosed, and the affected vendors were supported during fixing the issues. As a result, three generic CVEs for each attack class were issued [50-52]. Our research on PDF signatures and more information is also online available at https://www.pdf-insecurity.org/.
Vladislav Mladenov, Christian Mainka, Karsten Meyer zu Selhausen, Martin Grothe, Jörg Schwenk
CCS5
2019 "Johnny, you are fired!" - Spoofing OpenPGP and S/MIME Signatures in Emails
Jens Müller 0007, Marcus Brinkmann, Damian Poddebniak, Hanno Böck, Sebastian Schinzel, Juraj Somorovsky, Jörg Schwenk
USENIX Security Symposium7
2019 Scalable Scanning and Automatic Classification of TLS Padding Oracle Vulnerabilities
Robert Merget, Juraj Somorovsky, Nimrod Aviram, Craig Young, Janis Fliegenschmidt, Jörg Schwenk, Yuval Shavitt
USENIX Security Symposium6
2018 More is Less: On the End-to-End Security of Group Chats in Signal, WhatsApp, and Threema
abstract
Secure instant messaging is utilized in two variants: one-to-one communication and group communication. While the first variant has received much attention lately (Frosch et al., EuroS Cohn-Gordon et al., EuroS Kobeissi et al., EuroS&P17), little is known about the cryptographic mechanisms and security guarantees of secure group communication in instant messaging. To approach an investigation of group instant messaging protocols, we first provide a comprehensive and realistic security model. This model combines security and reliability goals from various related literature to capture relevant properties for communication in dynamic groups. Thereby the definitions consider their satisfiability with respect to the instant delivery of messages. To show its applicability, we analyze three widely used real-world protocols: Signal, WhatsApp, and Threema. By applying our model, we reveal several shortcomings with respect to the security definition. Therefore we propose generic countermeasures to enhance the protocols regarding the required security and reliability goals. Our systematic analysis reveals that (1) the communications' integrity - represented by the integrity of all exchanged messages - and (2) the groups' closeness - represented by the members' ability of managing the group - are not end-to-end protected. We additionally show that strong security properties, such as Future Secrecy which is a core part of the one-to-one communication in the Signal protocol, do not hold for its group communication.
Paul Rösler, Christian Mainka, Jörg Schwenk
EuroS&P3
2018 PostScript Undead: Pwning the Web with a 35 Years Old Language
Jens Müller 0007, Vladislav Mladenov, Dennis Felsch, Jörg Schwenk
RAID4
2018 The Dangers of Key Reuse: Practical Attacks on IPsec IKE
Dennis Felsch, Martin Grothe, Jörg Schwenk, Adam Czubak, Marcin Szymanek
USENIX Security Symposium3
2018 Efail: Breaking S/MIME and OpenPGP Email Encryption using Exfiltration Channels
Damian Poddebniak, Christian Dresen, Jens Müller 0007, Fabian Ising, Sebastian Schinzel, Simon Friedberger, Juraj Somorovsky, Jörg Schwenk
USENIX Security Symposium8
2017 Simple Security Definitions for and Constructions of 0-RTT Key Exchange
Britta Hale, Tibor Jager, Sebastian Lauer, Jörg Schwenk
ACNS4
2017 Out of the Dark: UI Redressing and Trustworthy Events
Marcus Niemietz, Jörg Schwenk
CANS2
2017 SECRET: On the Feasibility of a Secure, Efficient, and Collaborative Real-Time Web Editor
abstract
Real-time editing tools like Google Docs, Microsoft Office Online, or Etherpad have changed the way of collaboration. Many of these tools are based on Operational Transforms (OT), which guarantee that the views of different clients onto a document remain consistent over time. Usually, documents and operations are exposed to the server in plaintext -- and thus to administrators, governments, and potentially cyber criminals. Therefore, it is highly desirable to work collaboratively on encrypted documents. Previous implementations do not unleash the full potential of this idea: They either require large storage, network, and computation overhead, are not real-time collaborative, or do not take the structure of the document into account. The latter simplifies the approach since only OT algorithms for byte sequences are required, but the resulting ciphertexts are almost four times the size of the corresponding plaintexts.
Dennis Felsch, Christian Mainka, Vladislav Mladenov, Jörg Schwenk
AsiaCCS4
2017 DOMPurify: Client-Side Protection Against XSS and Markup Injection
Mario Heiderich, Christopher Späth, Jörg Schwenk
ESORICS (2)3
2017 SoK: Single Sign-On Security - An Evaluation of OpenID Connect
abstract
OpenID Connect is the OAuth 2.0-based replacement for OpenID 2.0 (OpenID) and one of the most important Single Sign-On (SSO) protocols used for delegated authentication. It is used by companies like Amazon, Google, Microsoft, and PayPal. In this paper, we systematically analyze well-known attacks on SSO protocols and adapt these on OpenID Connect. Additionally, we introduce two novel attacks on OpenID Connect, Identity Provider Confusion and Malicious Endpoints Attack, abusing flaws in the current specification and breaking the security goals of the protocol. In 2014 we communicated with the authors of the OpenID Connect specification about these attacks and helped to repair the issue(currently an RFC Draft). We categorize the described attacks into two classes: Single-Phase Attacks abusing a lack of a single security check and Cross-Phase Attacks requiring a complex attack setup and manipulating multiple messages distributed across the whole protocol workflow. We provide an evaluation of officially referenced OpenID Connect libraries and find 75% of them vulnerable to at least one Single-Phase Attack. All libraries are susceptible to Cross-Phase Attacks, which is not surprising since the attacks abuse a logic flaw in the protocol and not an implementation error. We reported the found vulnerabilities to the developers and helped them to fix the issues. We address the existing problems in a Practical Offensive Evaluation of Single Sign-On Services (PrOfESSOS). PrOfESSOS is our open source implementation for a fully automated Evaluation-as-a-Service for SSO. PrOfESSOS introduces a generic approach to improve the security of OpenID Connect implementations by systematically detecting vulnerabilities. In collaboration with the IETF OAuth and OpenIDConnect working group, we integrate PrOfESSOS into the OpenID Connect certification process. PrOfESSOS is available at https://openid.sso-security.de.
Christian Mainka, Vladislav Mladenov, Jörg Schwenk, Tobias Wich
EuroS&P3
2017 SoK: Exploiting Network Printers
abstract
The idea of a paperless office has been dreamed of for more than three decades. However, nowadays printers are still one of the most essential devices for daily work and common Internet users. Instead of removing them, printers evolved from simple devices into complex network computer systems, installed directly into company networks, and carrying considerable confidential data in their print jobs. This makes them to an attractive attack target. In this paper we conduct a large scale analysis of printer attacks and systematize our knowledge by providing a general methodology for security analyses of printers. Based on our methodology, we implemented an open-source tool called PRinter Exploitation Toolkit (PRET). We used PRET to evaluate 20 printer models from different vendors and found all of them to be vulnerable to at least one of the tested attacks. These attacks included, for example, simple DoS attacks or skilled attacks, extracting print jobs and system files. On top of our systematic analysis we reveal novel insights that enable attacks from the Internet by using advanced cross-site printing techniques, combined with printer CORS spoofing. Finally, we show how to apply our attacks to systems beyond typical printers like Google Cloud Print or document processing websites.
Jens Müller 0007, Vladislav Mladenov, Juraj Somorovsky, Jörg Schwenk
IEEE Symposium on Security and Privacy4
2017 Same-Origin Policy: Evaluation in Modern Browsers
Jörg Schwenk, Marcus Niemietz, Christian Mainka
USENIX Security Symposium1
2017 Authenticated Confidential Channel Establishment and the Security of TLS-DHE
Tibor Jager, Florian Kohlar, Sven Schäge, Jörg Schwenk
J. Cryptol.4
2016 Your Cloud in My Company: Modern Rights Management Services Revisited
abstract
We provide a security analysis of modern Enterprise Rights Management (ERM) solutions and reveal security threats. We first take a look on Microsoft Azure, and discuss severe attack surfaces that companies enabling Azure in their own trusted infrastructure have to take care of. In addition, we analyze Tresorit, one of the most frequently used End-to-End encrypted cloud storage systems. Tresorit can use Azure and its Rights Management Services (RMS) module as an additional security layer: a user should be able to either trust Tresorit or Azure. Our systematic evaluation reveals a serious breach to their security architecture: we show that the whole security of Tresorit RMS relies on Tresorit being trusted, independent of trusting Azure.
Martin Grothe, Christian Mainka, Paul Rösler, Johanna Jupke, Jörg Schwenk
ARES6
2016 Breaking PPTP VPNs via RADIUS Encryption
Matthias Horst, Martin Grothe, Tibor Jager, Jörg Schwenk
CANS4
2016 How Secure is TextSecure?
abstract
Instant Messaging has gained popularity by users for both private and business communication as low-cost short message replacement on mobile devices. However, before releases about mass surveillance performed by intelligence services such as NSA and GCHQ and Facebook's acquisition of WhatsApp, most mobile messaging apps did not protect confidentiality or integrity of the messages. A messaging app that claims to provide secure instant messaging and has attracted a lot of attention is TextSecure. Besides numerous direct installations, its protocol is part of Android's most popular aftermarket firmware Cyanogen-Mod. TextSecure's successor Signal continues to use the underlying protocol for text messaging. In this paper, we present the first complete description of TextSecure's complex cryptographic protocol, provide a security analysis of its three main components (key exchange, key derivation and authenticated encryption), and discuss the main security claims of TextSecure. Furthermore, we formally prove that - if key registration is assumed to be secure - TextSecure's push messaging can indeed achieve most of the claimed security goals.
Tilman Frosch, Christian Mainka, Christoph Bader, Florian Bergsma, Jörg Schwenk, Thorsten Holz
EuroS&P5
2016 Do Not Trust Me: Using Malicious IdPs for Analyzing and Attacking Single Sign-on
abstract
Single Sign-On (SSO) systems simplify login procedures by using an Identity Provider (IdP) to issue authentication tokens which can be consumed by Service Providers (SPs). Traditionally, IdPs are modeled as trusted third parties. This is reasonable for centralized SSO systems like Kerberos, where each SP explicitly specifies which single IdP it trusts. However, a typical use case for SPs like Salesforce is that each customer is allowed to configure his own IdP. A malicious IdP should however only be able to compromise the security of those accounts on the SP for which it was configured. If different accounts can be compromised, this must be considered as a serious attack. Additionally, in open systems like OpenID and OpenID Connect, the IdP for each customer account is dynamically detected in a discovery phase. Our research goal was to test if this phase can be used to trick a SP into using a malicious IdP for legitimate user accounts. Thus, by introducing a malicious IdP we evaluate in detail the popular and widely deployed SSO protocol OpenID. We found two novel classes of attacks, ID Spoofing (IDS) and Key Confusion (KC), on OpenID, which were not covered by previous research. Both attack classes allow compromising the security of all accounts on a vulnerable SP, even if those accounts were not allowed to use the malicious IdP. As a result, we were able to compromise 12 out the most popular 17 existing OpenID implementations, including Sourceforge, Drupal, ownCloud and JIRA. We developed an open source tool OpenID Attacker, which enables the fully automated and fine granular testing of OpenID implementations. Our research helps to better understand the message flow in the OpenID protocol, trust assumptions in the different components of the system, and implementation issues in OpenID components. All OpenID implementations have been informed about their vulnerabilities and we supported them in fixing the issues. One year after our reports, we have evaluated 70 online websites. Some of them have upgraded their libraries and were safe from our attacks, but 26% were still vulnerable.
Christian Mainka, Vladislav Mladenov, Jörg Schwenk
EuroS&P3
2015 On the Security of TLS 1.3 and QUIC Against Weaknesses in PKCS#1 v1.5 Encryption
abstract
Encrypted key transport with RSA-PKCS#1 v1.5 is the most commonly deployed key exchange method in all current versions of the Transport Layer Security (TLS) protocol, including the most recent version 1.2. However, it has several well-known issues, most importantly that it does not provide forward secrecy, and that it is prone to side channel attacks that may enable an attacker to learn the session key used for a TLS session. A long history of attacks shows that RSA-PKCS#1 v1.5 is extremely difficult to implement securely. The current draft of TLS version 1.3 dispenses with this encrypted key transport method. But is this sufficient to protect against weaknesses in RSA-PKCS#1 v1.5?
Tibor Jager, Jörg Schwenk, Juraj Somorovsky
CCS2
2015 Waiting for CSP - Securing Legacy Web Applications with JSAgents
abstract
Markup Injection (MI) attacks, ranging from classical Cross-Site Scripting (XSS) and DOMXSS to Scriptless Attacks, pose a major threat for web applications, browser extensions, and mobile apps. To mitigate MI attacks, we propose JSAgents, a novel and flexible approach to defeat MI attacks using DOM meta-programming. Specifically, we enforce a security policy on the DOM of the browser at a place in the markup processing chain “just before” the rendering of the markup. This approach has many advantages: Obfuscation has already been removed from the markup when it enters the DOM, mXSS attack vectors are visible, and, last but not least, the (client-side) protection can be individually tailored to fit the needs of web applications. JSAgents policies look similar to CSP policies, and indeed large parts of CSP can be implemented with JSAgents. However, there are three main differences: (1) Contrary to CSP, the source code of legacy web applications needs not be modified; instead, the policy is adapted to the application. (2) Whereas CSP can only apply one policy to a complete HTML document, JSAgents is able, through a novel cascading enforcement, to apply different policies to each element in the DOM; this property is essential in dealing with JavaScript event handlers and URIs. (3) JSAgents enables novel features like coarse-grained access control: e.g. we may block read/write access to HTML form elements for all scripts, but human users can still insert data (which may be interesting for password and PIN fields). These keywords were added by machine and not by the authors. This process is experimental and the keywords may be updated as the learning algorithm improves.
Mario Heiderich, Marcus Niemietz, Jörg Schwenk
ESORICS (1)3
2015 Practical Invalid Curve Attacks on TLS-ECDH
abstract
Elliptic Curve Cryptography (ECC) is based on cyclic groups, where group elements are represented as points in a finite plane. All ECC cryptosystems implicitly assume that only valid group elements will be processed by the different cryptographic algorithms. It is well-known that a check for group membership of given points in the plane should be performed before processing. However, in several widely used cryptographic libraries we analyzed, this check was missing, in particular in the popular ECC implementations of Oracle and Bouncy Castle. We analyze the effect of this missing check on Oracle’s default Java TLS implementation (JSSE with a SunEC provider) and TLS servers using the Bouncy Castle library. It turns out that the effect on the security of TLS-ECDH is devastating. We describe an attack that allows to extract the long-term private key from a TLS server that uses such a vulnerable library. This allows an attacker to impersonate the legitimate server to any communication partner, after performing the attack only once.
Tibor Jager, Jörg Schwenk, Juraj Somorovsky
ESORICS (1)2
2015 Semi-automated Fuzzy MCDM and Lattice Solutions for WS-Policy Intersection
abstract
In order to enable a secure Business-to-Business (B2B) interaction between web services, it is essential to negotiate a common security policy by computing the policy intersection according to the web service (WS)-policy framework. For this purpose, both policies are transformed into Disjunctive Normal Form (DNF). Then the intersection of the two sets of monomials (alternatives) from the two DNFs is computed. If the intersection's output is only one compatible monomial, we are done: We have found a unique security policy supported by both parties. However, two other cases are also possible: There may be more than one compatible monomial, and there may be no intersection which means, no compatible alternatives are found. In both cases, additional processing steps are required in order to communicate: If there are more than one alternatives, we would like to find the optimum security policy amongst all. If there is no intersection, we would like to find a minimal extension of the security policies to enforce an intersection. WS-policy framework does not give any information on how the policy intersection can be calculated or found when alternatives are semi-compatible or fully incompatible. In addition to the issue of multiple compatible alternatives, which alternative to choose. Current research is focusing on how to measure the compatibility, however achieving policy agreement in term of policy intersection is far from being possible. In order to address this problem we introduce two separate solutions for the two cases. For the case of more than one compatible alternative (multiple-intersection), we present a Multiple Criteria Decision Making (MCDM) model using Fuzzy Analytical Hierarchy Process (AHP) for the WS-Security Policy assertions in order to calculate the optimum security policy alternative. For the case of (no-intersection) we provide two algorithms for calculating the least upper bound (lub) or the greatest lower bound (glb) of the ordered sets to enable compatibility. We present a case example using practical policies in order to show the output using the two concepts based on Apache axis2 rampart, Apache neethi and IBM security policies. Outputs are found similar using both concepts.
Abeer Elsafie, Jörg Schwenk
SERVICES2
2014 New Modular Compilers for Authenticated Key Exchange
Yong Li 0021, Sven Schäge, Zheng Yang 0005, Christoph Bader, Jörg Schwenk
ACNS5
2014 Multi-Ciphersuite Security of the Secure Shell (SSH) Protocol
abstract
The Secure Shell (SSH) protocol is widely used to provide secure remote access to servers, making it among the most important security protocols on the Internet. We show that the signed-Diffie--Hellman SSH ciphersuites of the SSH protocol are secure: each is a secure authenticated and confidential channel establishment (ACCE) protocol, the same security definition now used to describe the security of Transport Layer Security (TLS) ciphersuites. While the ACCE definition suffices to describe the security of individual ciphersuites, it does not cover the case where parties use the same long-term key with many different ciphersuites: it is common in practice for the server to use the same signing key with both finite field and elliptic curve Diffie--Hellman, for example. While TLS is vulnerable to attack in this case, we show that SSH is secure even when the same signing key is used across multiple ciphersuites. We introduce a new generic multi-ciphersuite composition framework to achieve this result in a black-box way.
Florian Bergsma, Benjamin Dowling, Florian Kohlar, Jörg Schwenk, Douglas Stebila
CCS4
2014 Modelling Time for Authenticated Key Exchange Protocols
Jörg Schwenk
ESORICS (2)1
2014 SIACHEN: A Fine-Grained Policy Language for the Mitigation of Cross-Site Scripting Attacks
Ashar Javed 0001, Jens Riemer, Jörg Schwenk
ISC3
2014 TTPCookie: Flexible Third-Party Cookie Management for Increasing Online Privacy
abstract
This paper deals with the problem of privacy issues caused by the tracking activities of web advertisers. Web advertisers place cookies in the browser to track users' surfing behaviour across websites, mostly without his knowledge or consent. This paper proposes a fine-grained, per-site cookie management protocol. We implement our proposal as Mozilla Firefox add-on and we call it TTPCookie. We evaluate the add-on on a data-set obtained from automated visits of 5000 websites. Further, Mozilla Firefox add-ons and other related proposals dealing with cookies and privacy are analysed and compared.
Ashar Javed 0001, Christian Merz, Jörg Schwenk
TrustCom3
2014 Revisiting SSL/TLS Implementations: New Bleichenbacher Side Channels and Attacks
Christopher Meyer, Juraj Somorovsky, Eugen Weiss, Jörg Schwenk, Sebastian Schinzel, Erik Tews
USENIX Security Symposium4
2014 Scriptless attacks: Stealing more pie without touching the sill
abstract
Due to their high practical impact, Cross-Site Scripting (XSS) attacks have attracted a lot of attention from the members of security community worldwide. In the same way, a plethora of more or less effective defense techniques have been proposed, addressing both causes and effects of XSS vulnerabi lities. As a result, an adversary often can no longer inject or even execute arbitrary scripting code in several real-life scenarios. In this article, we examine an attack surface that remains after XSS and similar scripting attacks are supposedly mitigated by preventing an attacker from executing JavaScript code. We address the question of whether an attacker really needs to execute JavaScript or similar functionality to perform attacks aiming for information theft. The surprising result is that an attacker can abuse Cascading Style Sheets (CSS) in combination with other Web techniques like plain HTML, inactive SVG images, or font files. Having employed several case studies, we discuss so called scriptless attacks and demonstrate that an adversary might not need to execute code to preserve his ability to extract sensitive information from well-protected websites. More precisely, we show that an attacker can use seemingly benign features to build side-channel attacks that measure and exfiltrate almost arbitrary data displayed on a given webpage. We conclude this article with a discussion of potential mitigation techniques against this class of attacks. In addition, we have implemented a browser patch that enables a website to make a vital determination as to being loaded in a detached view or a pop-up window. This approach proves useful for prevention of certain types of attacks we here discuss.
Mario Heiderich, Marcus Niemietz, Felix Schuster, Thorsten Holz, Jörg Schwenk
J. Comput. Secur.5
2013 mXSS attacks: attacking well-secured web-applications by using innerHTML mutations
abstract
Back in 2007, Hasegawa discovered a novel Cross-Site Scripting (XSS) vector based on the mistreatment of the backtick character in a single browser implementation. This initially looked like an implementation error that could easily be fixed. Instead, as this paper shows, it was the first example of a new class of XSS vectors, the class of mutation-based XSS (mXSS) vectors, which may occur in innerHTML and related properties. mXSS affects all three major browser families: IE, Firefox, and Chrome.
Mario Heiderich, Jörg Schwenk, Tilman Frosch, Jonas Magazinius, Edward Z. Yang
CCS2
2013 Randomly Failed! The State of Randomness in Current Java Implementations
Kai Michaelis, Christopher Meyer, Jörg Schwenk
CT-RSA3
2013 A New Approach towards DoS Penetration Testing on Web Services
abstract
SOAP-based Web services is a middleware technology marketed as the solution to easy data exchange between heterogeneous IT architectures. The large number of scenarios, in which this technology is used, has introduced demands for new extensions raising its complexity. However, this has also introduced a large variety of new attacks. In this paper, we investigate an automatic evaluation of Web service specific Denial of Service (DoS) attacks. We present a new fully automated plugin for the WS-Attacker penetration testing tool implementing major DoS attacks. Our tool determines the attack success without having physical access to the target machine, using a novel blackbox approach. We give an overview of our design decisions and present the evaluation results using common Web service frameworks and systems.
Andreas Falkenberg, Christian Mainka, Juraj Somorovsky, Jörg Schwenk
ICWS4
2013 On the Analysis of Cryptographic Assumptions in the Generic Ring Model
Tibor Jager, Jörg Schwenk
J. Cryptol.2
2012 Scriptless attacks: stealing the pie without touching the sill
abstract
Due to their high practical impact, Cross-Site Scripting (XSS) attacks have attracted a lot of attention from the security community members. In the same way, a plethora of more or less effective defense techniques have been proposed, addressing the causes and effects of XSS vulnerabilities. NoScript, and disabling scripting code in non-browser applications such as e-mail clients or instant messengers.
Mario Heiderich, Marcus Niemietz, Felix Schuster, Thorsten Holz, Jörg Schwenk
CCS5
2012 XSpRES - Robust and Effective XML Signatures for Web Services
Christian Mainka, Meiko Jensen, Luigi Lo Iacono, Jörg Schwenk
CLOSER4
2012 SeC2: Secure Mobile Solution for Distributed Public Cloud Storages
Juraj Somorovsky, Christopher Meyer, Thang Tran, Mohamad Sbeiti, Jörg Schwenk, Christian Wietfeld
CLOSER5
2012 On the Security of TLS-DHE in the Standard Model
Tibor Jager, Florian Kohlar, Sven Schäge, Jörg Schwenk
CRYPTO4
2012 Strongly Authenticated Key Exchange Protocol from Bilinear Groups without Random Oracles
Zheng Yang 0005, Jörg Schwenk
ProvSec2
2012 Penetration Testing Tool for Web Services Security
abstract
XML-based SOAP Web Services are a widely used technology, which allows the users to execute remote operations and transport arbitrary data. It is currently adapted in Service Oriented Architectures, cloud interfaces, management of federated identities, eGovernment, or millitary services. The wide adoption of this technology has resulted in an emergence of numerous - mostly complex - extension specifications. Naturally, this has been followed by a rise in large number of Web Services attacks. They range from specific Denial of Service attacks to attacks breaking interfaces of cloud providers [1], [2] or confidentiality of encrypted messages [3]. By implementing common web applications, the developers evaluate the security of their systems by applying different penetration testing tools. However, in comparison to the wellknown attacks as SQL injection or Cross Site Scripting, there exist no penetration testing tools for Web Services specific attacks. This was the motivation for developing the first automated penetration testing tool for Web Services called WS-Attacker. In this paper we give an overview of our design decisions and provide evaluation of four Web Services frameworks and their resistance against WS-Addressing spoofing and SOAPAction spoofing attacks.
Christian Mainka, Juraj Somorovsky, Jörg Schwenk
SERVICES3
2012 Technical Analysis of Countermeasures against Attack on XML Encryption - or - Just Another Motivation for Authenticated Encryption
abstract
At CCS'11 a new chosen-ciphertext attack on XML Encryption [13] has been presented. This attack is of high relevance, since it allows one to decrypt arbitrary encrypted XML payload by issuing 14 server requests per byte on average. In this paper we discuss several countermeasures against this attack, which have been considered by different framework developers for different scenarios. We analyze the scenarios and show why these countermeasures do not work. Thereby, we motivate for the application of authenticated encryption in the XML Encryption specification.
Juraj Somorovsky, Jörg Schwenk
SERVICES2
2012 On Breaking SAML: Be Whoever You Want to Be
Juraj Somorovsky, Andreas Mayer, Jörg Schwenk, Marco Kampmann, Meiko Jensen
USENIX Security Symposium3
2011 Security Prospects through Cloud Computing by Adopting Multiple Clouds
abstract
Clouds impose new security challenges, which are amongst the biggest obstacles when considering the usage of cloud services. This triggered a lot of research activities in this direction, resulting in a quantity of proposals targeting the various security threats. Besides the security issues coming with the cloud paradigm, it can also provide a new set of unique features which open the path towards novel security approaches, techniques and architectures. This paper initiates this discussion by contributing a concept which achieves security merits by making use of multiple distinct clouds at the same time.
Meiko Jensen, Jörg Schwenk, Jens-Matthias Bohli, Nils Gruschka, Luigi Lo Iacono
IEEE CLOUD2
2010 Secure Bindings of SAML Assertions to TLS Sessions
abstract
In recent research work, two approaches to protect SAML based Federated Identity Management (FIM) against man-in-the-middle attacks have been proposed. One approach is to bind the SAML assertion and the SAML artifact to the public key contained in a TLS client certificate. Another approach is to strengthen the Same Origin Policy of the browser by taking into account the security guarantees TLS gives. In this paper, we present a third approach which is of further interest beyond IDM protocols: we bind the SAML assertion to the TLS session that has been agreed upon between client and the service provider and thus provide anonymity of the browser.
Florian Kohlar, Jörg Schwenk, Meiko Jensen, Sebastian Gajek
ARES2
2010 Towards an Anonymous Access Control and Accountability Scheme for Cloud Computing
abstract
An important aspect of trust in cloud computing consists in preventing the cloud provider from misusing the user's data. In this work-in-progress paper, we propose the approach of data anonymization to solve this problem. As this directly leads to problems of cloud usage accounting, we also propose a solution for anonymous yet reliable access control and accountability based on ring and group signatures.
Meiko Jensen, Sven Schäge, Jörg Schwenk
IEEE CLOUD3
2010 Generic Compilers for Authenticated Key Exchange
Tibor Jager, Florian Kohlar, Sven Schäge, Jörg Schwenk
ASIACRYPT4
2010 Group key agreement performance in wireless mesh networks
abstract
Wireless mesh networks (WMN) are a promising technology to establish big wireless networks with little costs. What we need are security mechanisms that perform well in this special kind of network. Therefore we propose the application of group key agreement (GKA) protocols, since a common encryption key in the network will remove the need for reencryptions and enables a better performance. In this paper, we contribute a new theoretic approach to measure the performance of cryptographic protocols in WMN. We demonstrate the applicability of the new approach with three selected GKA protocols that have already been investigated regarding their WMN performance in previous work.
Andreas Noack 0002, Jörg Schwenk
LCN2
2010 Streaming-Based Verification of XML Signatures in SOAP Messages
abstract
WS-Security is a standard providing message-level security in Web Services. Therewith, it ensures their integrity, confidentiality, and authenticity. However, using sophisticated security algorithms can lead to high memory consumptions and long evaluation times. In combination with the standard DOM approach for XML processing, the Web Services servers easily become a target of Denial-of-Service attacks. We present a solution for these problems: an external streaming-based WS-Security Gateway. Our implementation is capable of processing XML Signatures in SOAP messages using a streaming-based approach. The evaluation shows that such an approach greatly enhances the performance and is much more efficient in comparison to standard DOM-based frameworks.
Juraj Somorovsky, Meiko Jensen, Jörg Schwenk
SERVICES3
2009 The Accountability Problem of Flooding Attacks in Service-Oriented Architectures
abstract
The threat of Denial of Service attacks poses a serious problem to the security of network-based services in general. For flooding attacks against service-oriented applications, this threat is dramatically amplified with potentially much higher impact and very little effort on the attacker's side. Additionally, due to the high distribution of a SOA application's components, fending such attacks becomes a far more complex task. In this paper, we present the problem of accountability, referring to the issue of resolving the attacker in a highly distributed service-oriented application. Using a general flooding attack model, we illustrate the problem's parameters, and we finally discuss some general solution approaches.
Meiko Jensen, Jörg Schwenk
ARES2
2009 On Technical Security Issues in Cloud Computing
abstract
The Cloud Computing concept offers dynamically scalable resources provisioned as a service over the Internet. Economic benefits are the main driver for the Cloud, since it promises the reduction of capital expenditure (CapEx) and operational expenditure (OpEx). In order for this to become reality, however, there are still some challenges to be solved. Amongst these are security and trust issues, since the user's data has to be released to the Cloud and thus leaves the protection-sphere of the data owner. Most of the discussions on this topics are mainly driven by arguments related to organizational means. This paper focuses on technical security issues arising from the usage of Cloud services and especially by the underlying technologies used to build these cross-domain Internet-connected collaborations.
Meiko Jensen, Jörg Schwenk, Nils Gruschka, Luigi Lo Iacono
IEEE CLOUD2
2009 On the Analysis of Cryptographic Assumptions in the Generic Ring Model
Tibor Jager, Jörg Schwenk
ASIACRYPT2
2009 Analysis of Signature Wrapping Attacks and Countermeasures
abstract
In recent research it turned out that Boolean verification of digital signatures in the context of WS-Security is likely to fail: If parts of a SOAP message are signed and the signature verification applied to the whole document returns true, then nevertheless the document may have been significantly altered.In this paper, we provide a detailed analysis on the possible scenarios that enable these signature wrapping attacks. Derived from this analysis, we propose a new solution that uses a subset of XPath instead of ID attributes to point to the signed subtree, and show that this solution is both efficient and secure.
Sebastian Gajek, Meiko Jensen, Lijun Liao, Jörg Schwenk
ICWS4
2009 Risks of the CardSpace Protocol
Sebastian Gajek, Jörg Schwenk, Michael Steiner 0001, Chen Xuan
ISC2
2009 Group key agreement for wireless mesh networks
abstract
Wireless mesh networks consist of stationary nodes that communicate over wireless connections. Since WLAN security standards are only applicable in the standard scenario where the access points are connected by a cable-bound backbone, nearly all mesh networks broadcast messages in the clear. To secure these networks, and to reduce the amount of reencryption of messages, we propose to use group key agreement (GKA) protocols to agree on a common key for all nodes. In a mesh network, a message sent by a certain node can only be received directly by nodes within the broadcast range of the first node. Thus we have neither direct point-to-point connections between nodes, nor do we have a perfect broadcast channel. We therefore compare the suitability of different GKA protocols proposed in the literature for mesh networks.
Andreas Noack 0002, Jörg Schwenk
LCN2
2009 Security model and framework for information aggregation in sensor networks
abstract
Information aggregation is an important operation in wireless sensor networks (WSNs) executed for the purpose of monitoring and reporting environmental data. Due to the performance constraints of sensor nodes the in-network form of the aggregation is especially attractive since it allows saving expensive resources during frequent network queries. Easy accessibility of networks and nodes and almost no physical protection against corruptions raise high security challenges. Protection against attacks aiming to falsify the aggregated result is considered to be of prime importance. In this article we design the first general framework for secure information aggregation in WSNs focusing on scenarios where aggregation is performed by one of its nodes. The framework achieves security against node corruptions and is based solely on the symmetric cryptographic primitives that are more suitable for WSNs in terms of efficiency. We analyze performance of the framework and unlike many previous approaches increase confidence in it by a rigorous proof of security within the specially designed formal security model.
Mark Manulis, Jörg Schwenk
ACM Trans. Sens. Networks2
2008 Enforcing User-Aware Browser-Based Mutual Authentication with Strong Locked Same Origin Policy
Sebastian Gajek, Mark Manulis, Jörg Schwenk
ACISP3
2008 Provably secure browser-based user-aware mutual authentication over TLS
abstract
The standard solution for user authentication on the Web is to establish a TLS-based secure channel in server authenticated mode and run a protocol on top of TLS where the user enters a password in an HTML form. However, as many studies point out, the average Internet user is unable to identify the server based on a X.509 certificate so that impersonation attacks (e.g., phishing) are feasible. We tackle this problem by proposing a protocol that allows the user to identify the server based on human perceptible authenticators (e.g., picture, voice). We prove the security of this protocol by refining the game-based security model of Bellare and Rogaway and present a proof of concept implementation.
Sebastian Gajek, Mark Manulis, Ahmad-Reza Sadeghi, Jörg Schwenk
AsiaCCS4
2008 A Browser-Based Kerberos Authentication Scheme
Sebastian Gajek, Tibor Jager, Mark Manulis, Jörg Schwenk
ESORICS4
2008 A Novel Solution for End-to-End Integrity Protection in Signed PGP Mail
Lijun Liao, Jörg Schwenk
ICICS2
2008 Universally Composable Security Analysis of TLS
Sebastian Gajek, Mark Manulis, Olivier Pereira, Ahmad-Reza Sadeghi, Jörg Schwenk
ProvSec5
2008 On the Equivalence of Generic Group Models
Tibor Jager, Jörg Schwenk
ProvSec2
2007 Provably Secure Framework for Information Aggregation in Sensor Networks
Mark Manulis, Jörg Schwenk
ICCSA (1)2
2006 Linkable Democratic Group Signatures
Mark Manulis, Ahmad-Reza Sadeghi, Jörg Schwenk
ISPEC3
2005 Visual Spoofing of SSL Protected Web Sites and Effective Countermeasures
André Adelsbach, Sebastian Gajek, Jörg Schwenk
ISPEC3
1996 Public Key Encryption and Signature Schemes Based on Polynomials over Zn
Jörg Schwenk, Jörg Eisfeld
EUROCRYPT1