EDBT 2026 Demo / reviewers in the wild / expert
Luigi Lo Iacono
dblp:66/4381
· DBLP profile ↗
42ranked-venue papers
5as first author
17since 2021 · last 2026
0000-0002-7863-0622ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 25 · 2 first-author · 13 since 2021Applied, interdisciplinary, general and emerging computing · 7 · 2 first-authorSoftware engineering, systems software and programming languages · 4 · 1 since 2021Human-computer interaction and ubiquitous computing · 4 · 2 since 2021Artificial intelligence and machine learning · 2 · 1 since 2021Systems, architecture and hardware · 1 · 1 since 2021Computer networks · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | LISA: A Scale-Optimized and Psychometrically-Validated Instrument for the Lightweight Assessment of Organizational Information Security Awareness in Heterogeneous Organizations
David Langer, Jan Tolsdorf, Luigi Lo Iacono |
SP | 3 |
| 2025 | SoK: Continuous Authentication Beyond Error Rates: Reviewing General System Properties
Florian Dehling, Sebastian Kawelke, Luigi Lo Iacono |
ACNS (3) | 3 |
| 2025 | Phishing Susceptibility and the (In-)Effectiveness of Common Anti-Phishing Interventions in a Large University HospitalabstractPhishing attacks via email remain a major entry point for security and privacy breaches in hospitals. In the European Union, faced with both regulatory pressure to act and limited resources for cybersecurity, hospitals may resort to minimal-effort, off-the-shelf anti-phishing interventions such as warning banners in enterprise email systems. However, their effectiveness remains uncertain, particularly given the highly diverse workforce comprising medical, nursing, functional, administrative, IT, and other staff groups. We conducted a large-scale phishing simulation at a German university hospital, targeting 7,044 email accounts, to analyze how phishing susceptibility varies across staff groups, how email characteristics---such as timing, tone, context, and persuasive framing---influence susceptibility, and how 11 common in-situ anti-phishing interventions affect risky staff behavior. We found that susceptibility but also intervention effectiveness differed markedly across staff groups. Even a small number of phishing emails posed a substantial risk that persisted for about three days. The most effective interventions involved robust technical detection, including spam filtering and in-email phishing warnings. Friction-based measures, such as disabling links and active warning pages, showed mixed but promising effects. In contrast, display name suppression and the widely used method of generic [EXTERNAL] email tagging had no or inconsistent effects. Surveys revealed that some staff reacted with fear, shame, guilt, and hostility, highlighting the ethical challenges of such simulations. Our findings provide actionable guidance for phishing resilience in healthcare and similarly complex organizations. Jan Tolsdorf, David Langer, Luigi Lo Iacono |
CCS | 3 |
| 2024 | A Privacy Measure Turned Upside Down? Investigating the Use of HTTP Client Hints on the WebabstractHTTP client hints are a set of standardized HTTP request headers designed to modernize and potentially replace the traditional user agent string. While the user agent string exposes a wide range of information about the client’s browser and device, client hints provide a controlled and structured approach for clients to selectively disclose their capabilities and preferences to servers. Essentially, client hints aim at more effective and privacy-friendly disclosure of browser or client properties than the user agent string. Stephan Wiefling, Marian Hönscheid, Luigi Lo Iacono |
ARES | 3 |
| 2024 | You Can't Touch This: Detecting Typosquatting Packages for Enhanced Malware Prevention in Software Supply Chains
Minh Tien Truong, Nils Gruschka, Luigi Lo Iacono |
NSS | 3 |
| 2024 | You Are as You Type: Investigating the Influence of Timestamp Accuracy on the Robustness of Keystroke BiometricsabstractKeystroke dynamics are behavioral biometric traits that are frequently proposed to be used in novel authentication systems. Keystroke dynamics are based on the analysis of intervals between keystroke events originating from user input and thus directly depend on available timing information. However, modern web browsers limit the accuracy of timestamps to improve security and privacy. This study systematically investigates the impact of limited timestamp accuracies on the performance of keystroke dynamic analysis. By conducting multiple experiments with popular web browsers, we demonstrate that the minor timestamp modifications that mitigate timing side-channel attacks do not interfere with the effectiveness of keystroke dynamics analysis algorithms. Furthermore, they are surprisingly resilient to larger timestamp modifications, which results in a serious threat to users’ privacy. This research provides fundamental knowledge enabling researchers, privacy engineers, and browser vendors to study risks in keystroke dynamics-related systems and to develop mitigations against tracking methods that fingerprint users instead of devices or browsers. Florian Dehling, Luigi Lo Iacono, Hannes Federrath |
TrustCom | 3 |
| 2024 | Internet Users' Willingness to Disclose Biometric Data for Continuous Online Account Protection: An Empirical InvestigationabstractContinuous authentication has emerged as a promising approach to increase user account security for online services. Unlike traditional authentication methods, continuous authentication provides ongoing security throughout the session, protecting against session takeover attacks due to illegitimate access. The effectiveness of continuous authentication systems relies on the continuous processing of users' sensitive biometric data. To balance security and privacy trade-offs, it's crucial to understand when users are willing to disclose biometric data for enhanced account security, addressing inevitable privacy concerns and user acceptance. To address this knowledge gap, we conducted an online study with 830 participants from the U.S., aiming to investigate user perceptions towards continuous authentication across different classes of online services. Our analysis identified four groups of biometric traits that directly reflect users' willingness to disclose them. Our findings demonstrate that willingness to disclose is influenced by both the specific biometric traits and the type of online service involved. User perceptions are strongly shaped by factors such as response efficacy, perceived privacy risks associated with the biometric traits, and concerns about the service providers' handling of such data. Our results emphasize the inadequacy of one-size-fits-all solutions and provide valuable insights for the design and implementation of continuous authentication systems. Florian Dehling, Jan Tolsdorf, Hannes Federrath, Luigi Lo Iacono |
Proc. Priv. Enhancing Technol. | 4 |
| 2023 | Risk-Based Authentication for OpenStack: A Fully Functional Implementation and Guiding ExampleabstractOnline services have difficulties to replace passwords with more secure user authentication mechanisms, such as Two-Factor Authentication (2FA). This is partly due to the fact that users tend to reject such mechanisms in use cases outside of online banking. Relying on password authentication alone, however, is not an option in light of recent attack patterns such as credential stuffing. Risk-Based Authentication (RBA) can serve as an interim solution to increase password-based account security until better methods are in place. Unfortunately, RBA is currently used by only a few major online services, even though it is recommended by various standards and has been shown to be effective in scientific studies. This paper contributes to the hypothesis that the low adoption of RBA in practice can be due to the complexity of implementing it. We provide an RBA implementation for the open source cloud management software OpenStack, which is the first fully functional open source RBA implementation based on the Freeman et al. algorithm, along with initial reference tests that can serve as a guiding example and blueprint for developers. Vincent Unsel, Stephan Wiefling, Nils Gruschka, Luigi Lo Iacono |
CODASPY | 4 |
| 2023 | Analysing the Safety and Security of a UV-C Disinfection RobotabstractSafety is paramount for robots used in environments they share with humans. In such scenarios, security is also growing in importance. However, conventional approaches to analysing safety requirements are aimed at identifying hazards only. Security-related aspects such as cyber threats, cyber attacks and vulnerabilities have hardly been integrated into analysis and design methods to date. The methods available so far for the joint analysis of safety and security are based on established methods of safety engineering, where the amount of information is very large and usually stored in text- and table-based documents. This makes it challenging for engineers to systematically assess and maintain safety and security information. Thus, adequate tool support for robot engineers is required to cope with the increased complexity and to manage the safety and security risks. In this paper, we demonstrate that robot's safety and security information can be expressed, stored, analysed and queried in a knowledge graph representation paving the way to automated analysis. More specifically, we apply an integrated, systems-oriented safety and security co-analysis approach, namely STPA-Safesec, to a robot performing disinfection tasks in domestic environments. By querying the resulting graph of safety and security artefacts, we automatically retrieve hazardous scenarios, identify gaps in the analysis and increase our understanding of the overall risks of the robot. Desiana Nurchalifah, Sebastian Blumenthal, Luigi Lo Iacono, Nico Hochgeschwender |
ICRA | 3 |
| 2023 | Pump Up Password Security! Evaluating and Enhancing Risk-Based Authentication on a Real-World Large-Scale Online ServiceabstractRisk-based authentication (RBA) aims to protect users against attacks involving stolen passwords. RBA monitors features during login, and requests re-authentication when feature values widely differ from those previously observed. It is recommended by various national security organizations, and users perceive it more usable than and equally secure to equivalent two-factor authentication. Despite that, RBA is still used by very few online services. Reasons for this include a lack of validated open resources on RBA properties, implementation, and configuration. This effectively hinders the RBA research, development, and adoption progress. To close this gap, we provide the first long-term RBA analysis on a real-world large-scale online service. We collected feature data of 3.3 million users and 31.3 million login attempts over more than 1 year. Based on the data, we provide (i) studies on RBA’s real-world characteristics plus its configurations and enhancements to balance usability, security, and privacy; (ii) a machine learning–based RBA parameter optimization method to support administrators finding an optimal configuration for their own use case scenario; (iii) an evaluation of the round-trip time feature’s potential to replace the IP address for enhanced user privacy; and (iv) a synthesized RBA dataset to reproduce this research and to foster future RBA research. Our results provide insights on selecting an optimized RBA configuration so that users profit from RBA after just a few logins. The open dataset enables researchers to study, test, and improve RBA for widespread deployment in the wild. Stephan Wiefling, Paul René Jørgensen, Sigurd Thunem, Luigi Lo Iacono |
ACM Trans. Priv. Secur. | 4 |
| 2022 | A quarter century of usable security and privacy research: transparency, tailorability, and the road aheadabstractIn the last decades, research has shown that both technical solutions and user perceptions are important to improve security and privacy in the digital realm. The field of ‘usable security’ already started to emerge in the mid-90s, primarily focussed on password and email security. Later on, the research field of ”usable security and privacy” evolved and broadened the aim to design concepts and tools to assist users in enhancing their behaviour with regard to both privacy and security. Nevertheless, many user interventions are not as effective as desired. Because of highly diverse usage contexts, leading to different privacy and security requirements and not always to one-size-fits-all approaches, tailorability is necessary to address this issue. Furthermore, transparency is a crucial requirement, as providing comprehensible information may counter reactance towards security interventions. This article first provides a brief history of the research field in its first quarter-century and then highlights research on the transparency and tailorability of user interventions. Based on this, this article then presents six contributions with regard to (1) privacy concerns in times of COVID-19, (2) authentication on mobile devices, (3) GDPR-compliant data management, (4) privacy notices on websites, (5) data disclosure scenarios in agriculture, as well as (6) rights under data protection law and the concrete process should data subjects want to claim those rights. This article concludes with several research directions on user-centred transparency and tailorability. Christian Reuter 0001, Luigi Lo Iacono, Alexander Benlian |
Behav. Inf. Technol. | 2 |
| 2022 | Data cart - designing a tool for the GDPR-compliant handling of personal data by employeesabstractEmployees who process personal data as part of their job play a critical role in protecting privacy. They are expected to follow strict data protection guidelines and protect personal data adequately. However, few studies have addressed the needs of these employees in terms of appropriate tools to assist them in complying with privacy laws. To develop a suitable tool, we used a human-centred design approach and held a series of eight workshops with 19 employees from two German public institutions. Based on the metaphor of a data cart, we developed a concept for a tool that supports employees in data management and data protection compliance. Qualitative usability testing revealed that participants expected the tool to raise their data protection awareness, reduce errors, and increase work efficiency. Our findings also suggest that if Privacy by Design becomes an integral part of digitalisation, employee perceptions of data protection may be positively altered. Employers, IT engineers, and researchers benefit from gaining insights into ways to improve the usability of data protection compliant personal data management tools. Simultaneously, we highlight how they can improve and promote compliance. Jan Tolsdorf, Florian Dehling, Luigi Lo Iacono |
Behav. Inf. Technol. | 3 |
| 2022 | Employees' privacy perceptions: exploring the dimensionality and antecedents of personal data sensitivity and willingness to discloseabstractAbstract The processing of employees’ personal data is dramatically increasing, yet there is a lack of tools that allow employees to manage their privacy. In order to develop these tools, one needs to understand what sensitive personal data are and what factors influence employees’ willingness to disclose. Current privacy research, however, lacks such insights, as it has focused on other contexts in recent decades. To fill this research gap, we conducted a cross-sectional survey with 553 employees from Germany. Our survey provides multiple insights into the relationships between perceived data sensitivity and willingness to disclose in the employment context. Among other things, we show that the perceived sensitivity of certain types of data differs substantially from existing studies in other contexts. Moreover, currently used legal and contextual distinctions between different types of data do not accurately reflect the subtleties of employees’ perceptions. Instead, using 62 different data elements, we identified four groups of personal data that better reflect the multi-dimensionality of perceptions. However, previously found common disclosure antecedents in the context of online privacy do not seem to affect them. We further identified three groups of employees that differ in their perceived data sensitivity and willingness to disclose, but neither in their privacy beliefs nor in their demographics. Our findings thus provide employers, policy makers, and researchers with a better understanding of employees’ privacy perceptions and serve as a basis for future targeted research on specific types of personal data and employees. Jan Tolsdorf, Delphine Reinhardt, Luigi Lo Iacono |
Proc. Priv. Enhancing Technol. | 3 |
| 2022 | "I just looked for the solution!"On Integrating Security-Relevant Information in Non-Security API Documentation to Support Secure Coding PracticesabstractSoftware developers build complex systems using plenty of third-party libraries. Documentation is key to understand and use the functionality provided via the libraries’ APIs. Therefore, functionality is the main focus of contemporary API documentation, while cross-cutting concerns such as security are almost never considered at all, especially when the API itself does not provide security features. Documentations of JavaScript libraries for use in web applications, e.g., do not specify how to add or adapt a Content Security Policy (CSP) to mitigate content injection attacks like Cross-Site Scripting (XSS). This is unfortunate, as security-relevant API documentation might have an influence on secure coding practices and prevailing major vulnerabilities such as XSS. For the first time, we study the effects of integrating security-relevant information in non-security API documentation. For this purpose, we took CSP as an exemplary study object and extended the official Google Maps JavaScript API documentation with security-relevant CSP information in three distinct manners. Then, we evaluated the usage of these variations in a between-group eye-tracking lab study involving N=49 participants. Our observations suggest: (1) Developers are focused on elements with code examples. They mostly skim the documentation while searching for a quick solution to their programming task. This finding gives further evidence to results of related studies. (2) The location where CSP-related code examples are placed in non-security API documentation significantly impacts the time it takes to find this security-relevant information. In particular, the study results showed that the proximity to functional-related code examples in documentation is a decisive factor. (3) Examples significantly help to produce secure CSP solutions. (4) Developers have additional information needs that our approach cannot meet. Overall, our study contributes to a first understanding of the impact of security-relevant information in non-security API documentation on CSP implementation. Although further research is required, our findings emphasize that API producers should take responsibility for adequately documenting security aspects and thus supporting the sensibility and training of developers to implement secure systems. This responsibility also holds in seemingly non-security relevant contexts. Peter Leo Gorski, Sebastian Möller 0001, Stephan Wiefling, Luigi Lo Iacono |
IEEE Trans. Software Eng. | 4 |
| 2021 | Less is Often More: Header Whitelisting as Semantic Gap Mitigation in HTTP-Based Software Systems
Andre Büttner, Hoai Viet Nguyen, Nils Gruschka, Luigi Lo Iacono |
SEC | 4 |
| 2021 | XML Signature Wrapping Still Considered Harmful: A Case Study on the Personal Health Record in Germany
Paul Höller, Alexander Krumeich, Luigi Lo Iacono |
SEC | 3 |
| 2021 | Exploring mental models of the right to informational self-determination of office workers in GermanyabstractAbstract Applied privacy research has so far focused mainly on consumer relations in private life. Privacy in the context of employment relationships is less well studied, although it is subject to the same legal privacy framework in Europe. The European General Data Protection Regulation (GDPR) has strengthened employees’ right to privacy by obliging that employers provide transparency and intervention mechanisms. For such mechanisms to be effective, employees must have a sound understanding of their functions and value. We explored possible boundaries by conducting a semi-structured interview study with 27 office workers in Germany and elicited mental models of the right to informational self-determination, which is the European proxy for the right to privacy. We provide insights into (1) perceptions of different categories of data, (2) familiarity with the legal framework regarding expectations for privacy controls, and (3) awareness of data processing, data flow, safeguards, and threat models. We found that legal terms often used in privacy policies used to describe categories of data are misleading. We further identified three groups of mental models that differ in their privacy control requirements and willingness to accept restrictions on their privacy rights. We also found ignorance about actual data flow, processing, and safeguard implementation. Participants’ mindsets were shaped by their faith in organizational and technical measures to protect privacy. Employers and developers may benefit from our contributions by understanding the types of privacy controls desired by office workers and the challenges to be considered when conceptualizing and designing usable privacy protections in the workplace. Jan Tolsdorf, Florian Dehling, Delphine Reinhardt, Luigi Lo Iacono |
Proc. Priv. Enhancing Technol. | 4 |
| 2020 | More Than Just Good Passwords? A Study on Usability and Security Perceptions of Risk-based AuthenticationabstractRisk-based Authentication (RBA) is an adaptive security measure to strengthen password-based authentication. RBA monitors additional features during login, and when observed feature values differ significantly from previously seen ones, users have to provide additional authentication factors such as a verification code. RBA has the potential to offer more usable authentication, but the usability and the security perceptions of RBA are not studied well. Stephan Wiefling, Markus Dürmuth, Luigi Lo Iacono |
ACSAC | 3 |
| 2020 | Listen to Developers! A Participatory Design Study on Security Warnings for Cryptographic APIsabstractThe positive effect of security information communicated to developers through API warnings has been established. However, current prototypical designs are based on security warnings for end-users. To improve security feedback for developers, we conducted a participatory design study with 25 professional software developers in focus groups. We identify which security information is considered helpful in avoiding insecure cryptographic API use during development. Concerning console messages, participants suggested five core elements, namely message classification, title message, code location, link to detailed external resources, and color. Design guidelines for end-user warnings are only partially suitable in this context. Participants emphasized the importance of tailoring the detail and content of security information to the context. Console warnings call for concise communication; further information needs to be linked externally. Therefore, security feedback should transcend tools and should be adjustable by software developers across development tools, considering the work context and developer needs. Peter Leo Gorski, Yasemin Acar, Luigi Lo Iacono, Sascha Fahl |
CHI | 3 |
| 2020 | CREHMA: Cache-aware REST-ful HTTP Message AuthenticationabstractScalability and security are two important elements of contemporary distributed software systems. The Web vividly shows that while complying with the constraints defined by the architectural style REST, the layered design of software with intermediate systems enables to scale at large. Intermediaries such as caches, however, interfere with the security guarantees of the industry standard for protecting data in transit on the Web, TLS, as in these circumstances the TLS channel already terminates at the intermediate system's server. For more in-depth defense strategies, service providers require message-oriented security means in addition to TLS. These are hardly available and only in the form of HTTP signature schemes that do not take caches into account either. In this paper we introduce CREHMA, a REST-ful HTTP message signature scheme that guarantees the integrity and authenticity of Web assets from end-to-end while simultaneous allowing service providers to enjoy the benefits of Web caches. Decisively, CREHMA achieves these guarantees without having to trust on the integrity of the cache and without requiring making changes to existing Web caching systems. In extensive experiments we evaluated CREHMA and found that it only introduces marginal impacts on metrics such as latency and data expansion while providing integrity protection from end to end. CREHMA thus extends the possibilities of service providers to achieve an appropriate balance between scalability and security. Hoai Viet Nguyen, Luigi Lo Iacono |
CODASPY | 2 |
| 2020 | Evaluation of Risk-Based Re-Authentication Methods
Stephan Wiefling, Tanvi Patil, Markus Dürmuth, Luigi Lo Iacono |
SEC | 4 |
| 2019 | Your Cache Has Fallen: Cache-Poisoned Denial-of-Service AttackabstractWeb caching enables the reuse of HTTP responses with the aim to reduce the number of requests that reach the origin server, the volume of network traffic resulting from resource requests, and the user-perceived latency of resource access. For these reasons, a cache is a key component in modern distributed systems as it enables applications to scale at large. In addition to optimizing performance metrics, caches promote additional protection against Denial of Service (DoS) attacks. In this paper we introduce and analyze a new class of web cache poisoning attacks. By provoking an error on the origin server that is not detected by the intermediate caching system, the cache gets poisoned with the server-generated error page and instrumented to serve this useless content instead of the intended one, rendering the victim service unavailable. In an extensive study of fifteen web caching solutions we analyzed the negative impact of the CachePoisoned DoS (CPDoS) attack-as we coined it. We show the practical relevance by identifying one proxy cache product and five CDN services that are vulnerable to CPDoS. Amongst them are prominent solutions that in turn cache high-value websites. The consequences are severe as one simple request is sufficient to paralyze a victim website within a large geographical region. The awareness of the newly introduced CPDoS attack is highly valuable for researchers for obtaining a comprehensive understanding of causes and countermeasures as well as practitioners for implementing robust and secure distributed systems. Hoai Viet Nguyen, Luigi Lo Iacono, Hannes Federrath |
CCS | 2 |
| 2019 | Is This Really You? An Empirical Study on Risk-Based Authentication Applied in the Wild
Stephan Wiefling, Luigi Lo Iacono, Markus Dürmuth |
SEC | 2 |
| 2017 | Guidelines for adopting frontend architectures and patterns in microservices-based systemsabstractMicroservice-based systems enable the independent development, deployment, and scalability for separate system components of enterprise applications. A significant aspect during development is the microservice integration in frontends of web, mobile, and desktop applications. One challenge here is the selection of an adequate frontend architecture as well as suitable patterns that satisfy the application requirements. This paper analyses available strategies for organizing and implementing microservices frontends. These approaches are then evaluated based on a quality model and various prototypes of the same application implemented using the distinct approaches. The results of this analysis are generalized to a guideline that supports the selection of a suitable architecture. Holger Harms, Collin Rogowski, Luigi Lo Iacono |
ESEC/SIGSOFT FSE | 3 |
| 2017 | Mobile Personal Identity Provider Based on OpenID Connect
Luigi Lo Iacono, Nils Gruschka, Peter Nehren |
TrustBus | 1 |
| 2017 | On the Security Expressiveness of REST-Based API Definition Languages
Hoai Viet Nguyen, Jan Tolsdorf, Luigi Lo Iacono |
TrustBus | 3 |
| 2017 | Signalling over-privileged mobile applications using passive security indicators
Luigi Lo Iacono, Peter Leo Gorski, Josephine Grosse, Nils Gruschka |
J. Inf. Secur. Appl. | 1 |
| 2016 | Adaptive Push-based Media Streaming in the WebabstractOnline media consumption is the main driving force for the recent growth of the Web. As especially realtime media is becoming more and more accessible from a wide range of devices, with contrasting screen resolutions, processing resources and network connectivity, a necessary requirement is providing users with a seamless multimedia experience at the best possible quality, henceforth being able to adapt to the specific device and network conditions. This paper introduces a novel approach for adaptive media streaming in the Web. Despite the pervasive pullbased designs based on HTTP, this paper builds upon a Web-native push-based approach by which both the communication and processing overheads are reduced significantly in comparison to the pull-based counterparts. In order to maintain these properties when enhancing the scheme by adaptation features, a server-side monitoring and control needs to be developed as a consequence. Such an adaptive push-based media streaming approach is intr oduced as main contribution of this work. Moreover, the obtained evaluation results provide the evidence that with an adaptive push-based media delivery, on the one hand, an equivalent quality of experience can be provided at lower costs than by adopting pull-based media streaming. On the other hand, an improved responsiveness in switching between quality levels can be obtained at no extra costs. Luigi Lo Iacono, Silvia Santano Guillén |
WEBIST (1) | 1 |
| 2016 | Methods of Data Processing and Communication for a Web-based Wind Flow VisualizationabstractThis paper presents methods for the reduction and compression of meteorological data for web-based wind flow visualizations, which are tailored to the flow visualization technique. Flow data sets represent a large amount of data and are therefore not well suited for mobile networks with low data throughput rates and high latency. Using the mechanisms introduced in this paper, an efficient transfer of thinned out and compressed data can be achieved, while keeping the accuracy of the visualized information almost at the same quality level as for the original data. Marc Skutnik, Luigi Lo Iacono, Christian Neuhaus |
WEBIST (1) | 2 |
| 2015 | Towards Conformance Testing of REST-based Web ServicesabstractDespite the lack of standardisation for building REST-ful HTTP applications, the deployment of REST-based Web Services has attracted an increased interest. This gap causes, however, an ambiguous interpretation of REST and induces the design and implementation of REST-based systems following proprietary approaches instead of clear and agreed upon definitions. Issues arising from these shortcomings have an influence on service properties such as the loose coupling of REST-based services via a unitary service contract and the automatic generation of code. To overcome such limitations, at least two prerequisites are required: the availability of specifications for implementing REST-based services and auxiliaries for auditing the compliance of those services with such specifications. This paper introduces an approach for conformance testing of REST-based Web Services. This appears conflicting at the first glance, since there are no specifications available for implementing REST by, e.g., t he prevalent technology set HTTP/URI to test against. Still, by providing a conformance test tool and leaning it on the current practice, the exploration of service properties is enabled. Moreover, the real demand for standardisation gets explorable by such an approach. First investigations conducted with the developed conformance test system targeting major Cloud-based storage services expose inconsistencies in many respects which emphasizes the necessity for further research and standardisation. Luigi Lo Iacono, Hoai Viet Nguyen |
WEBIST | 1 |
| 2014 | Analysis of the current state in website certificate validationabstractABSTRACT This paper presents an in‐depth analysis of the certificate validation process employed in current web browsers. It discusses the shortcomings especially arising from the inappropriate management of the certificate status. Various improvements proposed so far are presented and analyzed with the aid of a threat model. The results are further enriched by some empirical studies. Finally, the outcomes of the aforementioned analysis are used to sketch an extended website certificate validation process with the aim of allowing for a better protection. Copyright © 2013 John Wiley & Sons, Ltd. Nils Gruschka, Luigi Lo Iacono, Christoph Sorge |
Secur. Commun. Networks | 2 |
| 2013 | Security and Privacy-Enhancing Multicloud ArchitecturesabstractSecurity challenges are still among the biggest obstacles when considering the adoption of cloud services. This triggered a lot of research activities, resulting in a quantity of proposals targeting the various cloud security threats. Alongside with these security issues, the cloud paradigm comes with a new set of unique features, which open the path toward novel security approaches, techniques, and architectures. This paper provides a survey on the achievable security merits by making use of multiple distinct clouds simultaneously. Various distinct architectures are introduced and discussed according to their security and privacy capabilities and prospects. Jens-Matthias Bohli, Nils Gruschka, Meiko Jensen, Luigi Lo Iacono, Ninja Marnau |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2012 | XSpRES - Robust and Effective XML Signatures for Web Services
Christian Mainka, Meiko Jensen, Luigi Lo Iacono, Jörg Schwenk |
CLOSER | 3 |
| 2012 | How Much Network Security Must Be Visible in Web Browsers?
Tobias Hirsch, Luigi Lo Iacono, Ina Wechsung |
TrustBus | 2 |
| 2011 | Security Prospects through Cloud Computing by Adopting Multiple CloudsabstractClouds impose new security challenges, which are amongst the biggest obstacles when considering the usage of cloud services. This triggered a lot of research activities in this direction, resulting in a quantity of proposals targeting the various security threats. Besides the security issues coming with the cloud paradigm, it can also provide a new set of unique features which open the path towards novel security approaches, techniques and architectures. This paper initiates this discussion by contributing a concept which achieves security merits by making use of multiple distinct clouds at the same time. Meiko Jensen, Jörg Schwenk, Jens-Matthias Bohli, Nils Gruschka, Luigi Lo Iacono |
IEEE CLOUD | 5 |
| 2011 | Server-Side Streaming Processing of WS-SecurityabstractWith SOAP-based web services leaving the stadium of being an explorative set of new technologies and entering the stage of mature and fundamental building blocks for service-driven business processes—and in some cases even for mission-critical systems—the demand for nonfunctional requirements including efficiency as well as security and dependability commonly increases rapidly. Although web services are capable of coupling heterogeneous information systems in a flexible and cost-efficient way, the processing efficiency and robustness against certain attacks do not fulfill industry-strength requirements. In this paper, a comprehensive stream-based WS-Security processing system is introduced, which enables a more efficient processing in service computing and increases the robustness against different types of Denial-of-Service (DoS) attacks. The introduced engine is capable of processing all standard-conforming applications of WS-Security in a streaming manner. It can handle, e.g., any order, number, and nesting degree of signature and encryption operations, closing the gap toward more efficient and dependable web services. Nils Gruschka, Meiko Jensen, Luigi Lo Iacono, Norbert Luttenberger |
IEEE Trans. Serv. Comput. | 3 |
| 2010 | A Design Pattern for Event-Based Processing of Security-Enriched SOAP MessagesabstractFor Web Services in Cloud Computing contexts, the efficient processing of XML documents is a major topic of interest. Especially for WS-Security-enriched messages, processing performance nowadays tends to become a major issue. Streaming XML processing approaches lead to valuable optimization due to lower resource consumption, but their adoption requires major conceptional changes in the processing application.In this paper, we present a pattern for architectural concepts that employ the SAX-based streaming processing approach. Its major benefit--apart from providing the performance advantage--consists in a convenient, modular architecture that can easily be extended with new modules and new types of events without modification of existing modules. Nils Gruschka, Meiko Jensen, Luigi Lo Iacono |
ARES | 3 |
| 2010 | @neurIST: Infrastructure for Advanced Disease Management Through Integration of Heterogeneous Data, Computing, and Complex Processing ServicesabstractThe increasing volume of data describing human disease processes and the growing complexity of understanding, managing, and sharing such data presents a huge challenge for clinicians and medical researchers. This paper presents the @neurIST system, which provides an infrastructure for biomedical research while aiding clinical care, by bringing together heterogeneous data and complex processing and computing services. Although @neurIST targets the investigation and treatment of cerebral aneurysms, the system's architecture is generic enough that it could be adapted to the treatment of other diseases. Innovations in @neurIST include confining the patient data pertaining to aneurysms inside a single environment that offers clinicians the tools to analyze and interpret patient data and make use of knowledge-based guidance in planning their treatment. Medical researchers gain access to a critical mass of aneurysm related data due to the system's ability to federate distributed information sources. A semantically mediated grid infrastructure ensures that both clinicians and researchers are able to seamlessly access and work on data that is distributed across multiple sites in a secure way in addition to providing computing resources on demand for performing computationally intensive simulations for treatment planning and research. Siegfried Benkner, Antonio Arbona, Guntram Berti, Alessandro Chiarini, Robert Dunlop, Gerhard Engelbrecht, Alejandro F. Frangi, Christoph M. Friedrich, S. Hanser, Peer Hasselmeyer, Rod D. Hose, Jimison Iavindrasana, Martin Koehler, Luigi Lo Iacono, Guy Lonsdale, Rodolphe Meyer, Bob Moore, Hariharan Rajasekaran, Paul E. Summers, Alexander Wöhrer, Steven Wood |
IEEE Trans. Inf. Technol. Biomed. | 14 |
| 2009 | On Technical Security Issues in Cloud ComputingabstractThe Cloud Computing concept offers dynamically scalable resources provisioned as a service over the Internet. Economic benefits are the main driver for the Cloud, since it promises the reduction of capital expenditure (CapEx) and operational expenditure (OpEx). In order for this to become reality, however, there are still some challenges to be solved. Amongst these are security and trust issues, since the user's data has to be released to the Cloud and thus leaves the protection-sphere of the data owner. Most of the discussions on this topics are mainly driven by arguments related to organizational means. This paper focuses on technical security issues arising from the usage of Cloud services and especially by the underlying technologies used to build these cross-domain Internet-connected collaborations. Meiko Jensen, Jörg Schwenk, Nils Gruschka, Luigi Lo Iacono |
IEEE CLOUD | 4 |
| 2009 | Secure Browser-Based Access to Web ServicesabstractAccess to Web services via Web front-ends provides all the advantages related to browser-based thin clients and is therefore a common setting. However, providing end-to-end security between Web browsers and Web services is currently not feasible due to the inadequate support for Web service security in Web browsers. Moreover, the current SOAP APIs offered by the major browsers are incompatible with one another making the task of providing a uniform solution to address this problem difficult. This paper describes a method by which the Web service communication between a Web browser and a Web service is protected end-to-end using Web service security thereby providing a means to overcome this limitation. Luigi Lo Iacono, Hariharan Rajasekaran |
ICC | 1 |
| 2009 | Vulnerable Cloud: SOAP Message Security Validation RevisitedabstractThe service-oriented architecture paradigm is influencing modern software systems remarkably and Web services are a common technology to implement such systems. However, the numerous Web service standard specifications and especially their ambiguity result in a high complexity which opens the door for security-critical mistakes.This paper aims on raising awareness of this issue while discussing a vulnerability in Amazonpsilas Elastic Compute Cloud (EC2) services to XML wrapping attacks, which has since been resolved as a result of our findings and disclosure. More importantly, this paper discusses the verification steps required to effectively validate an incoming SOAP request. It reviews the available work in the light of the discovered Amazon EC2 vulnerability and provides a practical guideline for achieving a robust and effective SOAP message security validation mechanism. Nils Gruschka, Luigi Lo Iacono |
ICWS | 2 |
| 2008 | @neurIST - Towards a System Architecture for Advanced Disease Management through Integration of Heterogeneous Data, Computing, and Complex Processing ServicesabstractThis paper presents the system architecture of the @neurIST project, which aims at supporting the research and treatment of cerebral aneurysms by bringing together heterogeneous data, computing and complex processing services. The architecture is generic enough to adapt it to the treatment of other diseases beyond cerebral aneurysms. The paper describes the generic requirements of the system and presents the architecture, applications and middleware technologies used to realise the system and highlights the innovations in @neurIST. Hariharan Rajasekaran, Luigi Lo Iacono, Peer Hasselmeyer, Jochen Fingberg, Paul E. Summers, Siegfried Benkner, Gerhard Engelbrecht, Antonio Arbona, Alessandro Chiarini, Christoph M. Friedrich, Martin Hofmann-Apitius, Kai Kumpf, Bob Moore, Philippe Bijlenga, Jimison Iavindrasana, Henning Müller, Rod D. Hose, Robert Dunlop, Alejandro F. Frangi |
CBMS | 2 |