Nils Gruschka

dblp:67/4948 · DBLP profile ↗
← Back
26ranked-venue papers
9as first author
9since 2021 · last 2025
0000-0001-7360-8314ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 17 · 4 first-author · 8 since 2021Software engineering, systems software and programming languages · 4 · 3 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 4 · 2 first-authorArtificial intelligence and machine learning · 1 · 1 first-authorDatabases, data management, data science and information retrieval · 1 · 1 first-authorTheory of computation · 1 · 1 since 2021
YearPublicationVenuePosition
2025 Device-Bound vs. Synced Credentials: A Comparative Evaluation of Passkey Authentication
Andre Büttner, Nils Gruschka
ICISSP (2)2
2025 Qualitative In-Depth Analysis of GDPR Data Subject Access Requests and Responses from Major Online Services
abstract
The European General Data Protection Regulation (GDPR) grants European users the right to access their data processed and stored by organizations. Although the GDPR contains requirements for data processing organizations (e.g., understandable data provided within a month), it leaves much flexibility. In-depth research on how online services handle data subject access request is sparse. Specifically, it is unclear whether online services comply with the individual GDPR requirements, if the privacy policies and the data subject access responses are coherent, and how the responses change over time. To answer these questions, we perform a qualitative structured review of the processes and data exports of significant online services to (1) analyze the data received in 2023 in detail, (2) compare the data exports with the privacy policies, and (3) compare the data exports from November 2018 and November 2023. The study concludes that the quality of data subject access responses varies among the analyzed services, and none fulfills all requirements completely.
Daniela Pöhn, Nils Gruschka
ICISSP (1)2
2024 Evaluating the Influence of Multi-Factor Authentication and Recovery Settings on the Security and Accessibility of User Accounts
abstract
Nowadays, most online services offer different authentication methods that users can set up for multi-factor authentication but also as a recovery method. This configuration must be done thoroughly to prevent an adversary's access while ensuring the legitimate user does not lose access to their account. This is particularly important for fundamental everyday services, where either failure would have severe consequences. Nevertheless, little research has been done on the authentication of actual users regarding security and the risk of being locked out of their accounts. To foster research in this direction, this paper presents a study on the account settings of Google and Apple users. Considering the multi-factor authentication configuration and recovery options, we analyzed the account security and lock-out risks. Our results provide insights into the usage of multi-factor authentication in practice, show significant security differences between Google and Apple accounts, and reveal that many users would miss access to their accounts when losing a single authentication device.
Andre Büttner, Nils Gruschka
ICISSP2
2024 You Can't Touch This: Detecting Typosquatting Packages for Enhanced Malware Prevention in Software Supply Chains
Minh Tien Truong, Nils Gruschka, Luigi Lo Iacono
NSS2
2023 Risk-Based Authentication for OpenStack: A Fully Functional Implementation and Guiding Example
abstract
Online services have difficulties to replace passwords with more secure user authentication mechanisms, such as Two-Factor Authentication (2FA). This is partly due to the fact that users tend to reject such mechanisms in use cases outside of online banking. Relying on password authentication alone, however, is not an option in light of recent attack patterns such as credential stuffing. Risk-Based Authentication (RBA) can serve as an interim solution to increase password-based account security until better methods are in place. Unfortunately, RBA is currently used by only a few major online services, even though it is recommended by various standards and has been shown to be effective in scientific studies. This paper contributes to the hypothesis that the low adoption of RBA in practice can be due to the complexity of implementing it. We provide an RBA implementation for the open source cloud management software OpenStack, which is the first fully functional open source RBA implementation based on the Freeman et al. algorithm, along with initial reference tests that can serve as a guiding example and blueprint for developers.
Vincent Unsel, Stephan Wiefling, Nils Gruschka, Luigi Lo Iacono
CODASPY3
2023 A framework for analyzing authentication risks in account networks
abstract
Our everyday life depends more and more on online services and, therefore, access to related user accounts. The security of user accounts, again, is tied to the security of the corresponding primary and fallback authentication methods. Accounts can be linked to each other – by fallback authentication, through SSO, or by using the same authentication devices – creating an account network. These account networks enhance login comfort and are needed in case of account recovery, but they also increase each account's attack surface. In addition, misconfigurations might result in account inaccessibility. However, these problems can only be detected by analyzing single accounts first and then the resulting account networks. Despite the importance to understand account security and accessibility, almost no analysis methods exist. To address this need, this article presents the Authentication Analysis Framework (AAF). AAF evaluates account types and primary and fallback authentication methods for each account, before analyzing the overall account network. By detecting transitive risks, weak links can be discovered and subsequently strengthened. We further propose maturity models to rank the primary and fallback authentication methods based on risks and a description language to exchange the required information. AAF is implemented as a plugin for the password manager KeePass to assist end users and as a standalone tool for researchers.
Daniela Pöhn, Nils Gruschka, Leonhard Ziegler, Andre Büttner
Comput. Secur.2
2022 Multi-Account Dashboard for Authentication Dependency Analysis
abstract
User authentication is necessary for the majority of online services. If users fail to authenticate due to the loss of an authentication factor, fallback processes allow users to regain access to their accounts. However, most of the proposed and deployed fallback methods have substantial weaknesses that degrade security, e.g., guessable security questions. This is even more serious since through account dependencies (e.g., password reset via email), additional accounts can be compromised. On the other hand, misconfiguration of (fallback) authentication might result in locking a user out of an account.
Daniela Pöhn, Nils Gruschka, Leonhard Ziegler
ARES2
2022 A Policy Language to Capture Compliance of Data Protection Requirements
Chinmayi Prabhu Baramashetru, Silvia Lizeth Tapia Tarifa, Olaf Owe, Nils Gruschka
IFM4
2021 Less is Often More: Header Whitelisting as Semantic Gap Mitigation in HTTP-Based Software Systems
Andre Büttner, Hoai Viet Nguyen, Nils Gruschka, Luigi Lo Iacono
SEC3
2019 Towards Aligning GDPR Compliance with Software Development: A Research Agenda
abstract
The General Data Protection Regulation (GDPR) caused several new legal requirements software systems in Europe have to comply to. Support for these requirements given by proprietary software systems is limited. Here, an integrative approach of combining software development with GDPR-specific demands is necessary. In this paper, we outline such an approach on the level of software source code. We illustrate how to annotate data in complex software systems and how to use such annotations for task like data visualization, data exchange standardization, and GDPR-specific consent and purpose management systems. Thereby, we outline a research agenda for subsequent efforts in aligning software development and GDPR requirements.
Meiko Jensen, Sahil Kapila, Nils Gruschka
ICISSP3
2018 Privacy Issues and Data Protection in Big Data: A Case Study Analysis under GDPR
abstract
Big data has become a great asset for many organizations, promising improved operations and new business opportunities. However, big data has increased access to sensitive information that when processed can directly jeopardize the privacy of individuals and violate data protection laws. As a consequence, data controllers and data processors may be imposed tough penalties for non-compliance that can result even to bankruptcy. In this paper, we discuss the current state of the legal regulations and analyse different data protection and privacy-preserving techniques in the context of big data analysis. In addition, we present and analyse two real-life research projects as case studies dealing with sensitive data and actions for complying with the data regulation laws. We show which types of information might become a privacy risk, the employed privacy-preserving techniques in accordance with the legal requirements, and the influence of these techniques on the data processing phase and the research results.
Nils Gruschka, Vasileios Mavroeidis, Kamer Vishi, Meiko Jensen
IEEE BigData1
2017 Mobile Personal Identity Provider Based on OpenID Connect
Luigi Lo Iacono, Nils Gruschka, Peter Nehren
TrustBus2
2017 Signalling over-privileged mobile applications using passive security indicators
Luigi Lo Iacono, Peter Leo Gorski, Josephine Grosse, Nils Gruschka
J. Inf. Secur. Appl.4
2015 Privacy-Preserving Detection of Plagiarism in Scientific Documents
abstract
Scientific documents need to be checked for plagiarism before publication. On the other hand, authors do not want to reveal their document's contents prior to successful publication. In this paper, we propose a novel approach for plagiarism detection in scientific digital libraries, which does not reveal contents of unpublished documents, but allows for early detection of plagiarism attempts. Based on the popular PDF document format, we illustrate the technical feasibility of our approach in detail.
Meiko Jensen, Nils Gruschka
SERVICES2
2014 Analysis of the current state in website certificate validation
abstract
ABSTRACT This paper presents an in‐depth analysis of the certificate validation process employed in current web browsers. It discusses the shortcomings especially arising from the inappropriate management of the certificate status. Various improvements proposed so far are presented and analyzed with the aid of a threat model. The results are further enriched by some empirical studies. Finally, the outcomes of the aforementioned analysis are used to sketch an extended website certificate validation process with the aim of allowing for a better protection. Copyright © 2013 John Wiley & Sons, Ltd.
Nils Gruschka, Luigi Lo Iacono, Christoph Sorge
Secur. Commun. Networks1
2013 Security and Privacy-Enhancing Multicloud Architectures
abstract
Security challenges are still among the biggest obstacles when considering the adoption of cloud services. This triggered a lot of research activities, resulting in a quantity of proposals targeting the various cloud security threats. Alongside with these security issues, the cloud paradigm comes with a new set of unique features, which open the path toward novel security approaches, techniques, and architectures. This paper provides a survey on the achievable security merits by making use of multiple distinct clouds simultaneously. Various distinct architectures are introduced and discussed according to their security and privacy capabilities and prospects.
Jens-Matthias Bohli, Nils Gruschka, Meiko Jensen, Luigi Lo Iacono, Ninja Marnau
IEEE Trans. Dependable Secur. Comput.2
2011 Security Prospects through Cloud Computing by Adopting Multiple Clouds
abstract
Clouds impose new security challenges, which are amongst the biggest obstacles when considering the usage of cloud services. This triggered a lot of research activities in this direction, resulting in a quantity of proposals targeting the various security threats. Besides the security issues coming with the cloud paradigm, it can also provide a new set of unique features which open the path towards novel security approaches, techniques and architectures. This paper initiates this discussion by contributing a concept which achieves security merits by making use of multiple distinct clouds at the same time.
Meiko Jensen, Jörg Schwenk, Jens-Matthias Bohli, Nils Gruschka, Luigi Lo Iacono
IEEE CLOUD4
2011 Server-Side Streaming Processing of WS-Security
abstract
With SOAP-based web services leaving the stadium of being an explorative set of new technologies and entering the stage of mature and fundamental building blocks for service-driven business processes—and in some cases even for mission-critical systems—the demand for nonfunctional requirements including efficiency as well as security and dependability commonly increases rapidly. Although web services are capable of coupling heterogeneous information systems in a flexible and cost-efficient way, the processing efficiency and robustness against certain attacks do not fulfill industry-strength requirements. In this paper, a comprehensive stream-based WS-Security processing system is introduced, which enables a more efficient processing in service computing and increases the robustness against different types of Denial-of-Service (DoS) attacks. The introduced engine is capable of processing all standard-conforming applications of WS-Security in a streaming manner. It can handle, e.g., any order, number, and nesting degree of signature and encryption operations, closing the gap toward more efficient and dependable web services.
Nils Gruschka, Meiko Jensen, Luigi Lo Iacono, Norbert Luttenberger
IEEE Trans. Serv. Comput.1
2010 A Design Pattern for Event-Based Processing of Security-Enriched SOAP Messages
abstract
For Web Services in Cloud Computing contexts, the efficient processing of XML documents is a major topic of interest. Especially for WS-Security-enriched messages, processing performance nowadays tends to become a major issue. Streaming XML processing approaches lead to valuable optimization due to lower resource consumption, but their adoption requires major conceptional changes in the processing application.In this paper, we present a pattern for architectural concepts that employ the SAX-based streaming processing approach. Its major benefit--apart from providing the performance advantage--consists in a convenient, modular architecture that can easily be extended with new modules and new types of events without modification of existing modules.
Nils Gruschka, Meiko Jensen, Luigi Lo Iacono
ARES1
2010 Attack Surfaces: A Taxonomy for Attacks on Cloud Services
abstract
The new paradigm of cloud computing poses severe security risks to its adopters. In order to cope with these risks, appropriate taxonomies and classification criteria for attacks on cloud computing are required. In this work-in-progress paper we present one such taxonomy based on the notion of attack surfaces of the cloud computing scenario participants.
Nils Gruschka, Meiko Jensen
IEEE CLOUD1
2009 On Technical Security Issues in Cloud Computing
abstract
The Cloud Computing concept offers dynamically scalable resources provisioned as a service over the Internet. Economic benefits are the main driver for the Cloud, since it promises the reduction of capital expenditure (CapEx) and operational expenditure (OpEx). In order for this to become reality, however, there are still some challenges to be solved. Amongst these are security and trust issues, since the user's data has to be released to the Cloud and thus leaves the protection-sphere of the data owner. Most of the discussions on this topics are mainly driven by arguments related to organizational means. This paper focuses on technical security issues arising from the usage of Cloud services and especially by the underlying technologies used to build these cross-domain Internet-connected collaborations.
Meiko Jensen, Jörg Schwenk, Nils Gruschka, Luigi Lo Iacono
IEEE CLOUD3
2009 Vulnerable Cloud: SOAP Message Security Validation Revisited
abstract
The service-oriented architecture paradigm is influencing modern software systems remarkably and Web services are a common technology to implement such systems. However, the numerous Web service standard specifications and especially their ambiguity result in a high complexity which opens the door for security-critical mistakes.This paper aims on raising awareness of this issue while discussing a vulnerability in Amazonpsilas Elastic Compute Cloud (EC2) services to XML wrapping attacks, which has since been resolved as a result of our findings and disclosure. More importantly, this paper discusses the verification steps required to effectively validate an incoming SOAP request. It reviews the available work in the light of the discovered Amazon EC2 vulnerability and provides a practical guideline for achieving a robust and effective SOAP message security validation mechanism.
Nils Gruschka, Luigi Lo Iacono
ICWS1
2008 The Impact of Flooding Attacks on Network-based Services
abstract
One of the most severe threats to Internet security are Denial of Service attacks. Intended to annihilate the availability of a network-based service, this kind of attack troubles all service providers. In this paper we focus on a special type of Denial of Service attacks that relies on message flooding techniques, overloading the victim's service with invalid requests. We describe some well- known and some rather new attacks, discuss commonalities and approaches for countermeasures. A main focus of this paper is directed towards Denial of Service attacks on Web Services and Web Service Compositions. We resume these threats by illustrating some possible attacks, and we relate our experimental results to the well-known attack impact of the TCP SYN Flooding attack.
Meiko Jensen, Nils Gruschka, Norbert Luttenberger
ARES2
2007 A Stateful Web Service Firewall for BPEL
abstract
Today, the Business Process Execution Language (BPEL) is the most emerging specification for Web Service Composition, which is an important part of the SOA paradigm. Defining a stateful communication protocol, BPEL enables potential for new security vulnerabilities. In this paper, we present a severe Denial-of-Service attack on a leading BPEL engine, illustrating new threats on availability in the context of BPEL. Derived from our observations, we developed a protection concept and implemented an application level firewall fending these types of attacks.
Nils Gruschka, Meiko Jensen, Norbert Luttenberger
ICWS1
2006 Protecting Web Services from DoS Attacks by SOAP Message Validation
abstract
Though Web Services become more and more popular, not only inside closed intranets but also for inter-enterprise communications, few efforts have been made so far to secure a Web Service’s availability. Existing security standards like e.g. WS-Security only address message integrity and confidentiality, and user authentication and authorization. In this article we present a system for protecting Web Services from Denial-of-Service (DoS) attacks. DoS attacks often rely on misformed and/or overly long messages that engage a server in resource-consuming computations. Therefore, a suitable means to prevent such kinds of attacks is the full grammatical validation of messages by an application level gateway before forwarding them to the server. We discuss specific kinds of DoS attacks against Web Services, show how message grammars can automatically be derived from formal Web Service descriptions (written in the Web Service Description Language), and present an application level gateway solution called “Checkway” that uses these grammars to filter Web service messages. The paper closes by giving some performance figures for full grammatical validation. These keywords were added by machine and not by the authors. This process is experimental and the keywords may be updated as the learning algorithm improves.
Nils Gruschka, Norbert Luttenberger
SEC1
2004 Checking and Signing XML Documents on Java Smart Cards - Challenges and Opportunities
Nils Gruschka, Florian Reuter, Norbert Luttenberger
CARDIS1