Alexandra Dmitrienko

dblp:67/8264 · DBLP profile ↗
← Back
50ranked-venue papers
4as first author
31since 2021 · last 2026
0000-0001-5637-7016ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 44 · 4 first-author · 26 since 2021Computer networks · 2 · 2 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Systems, architecture and hardware · 1Software engineering, systems software and programming languages · 1 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021
YearPublicationVenuePosition
2026 FLux: Covert Channels in FL through Transposed Training
abstract
Federated learning (FL) routinely exchanges model-derived signals (e.g., logits or updates) between clients and a server, creating an attractive substrate for covert communication — especially in settings where adversaries cannot rely on direct, out-of-band coordination. Existing FL covert channels often trade off capacity, reliability under aggregation, setup requirements, or operational stealth (e.g., needing extensive pre-shared state, warm-up rounds, or leaving persistent artifacts).
Alexandra Dmitrienko, Torsten Krauß, Yisroel Mirsky
AsiaCCS1
2026 RESTing-LLAMA: Large Language Model based REST API Fuzzing
abstract
Recent advances in Large Language Models (LLMs) have introduced new opportunities in software engineering, cybersecurity, and automated testing. Despite this progress, their application to security fuzzing, particularly for REST APIs, remains largely underexplored. Fuzzing remains a fundamental technique for discovering software vulnerabilities through malformed inputs, but traditional fuzzers often struggle to interact effectively with modern REST APIs due to a lack of semantic understanding needed to generate meaningful request sequences. Yet, existing automated fuzzing approaches frequently fail to uncover vulnerabilities due to their inability to use the APIs correctly. We introduce RESTing-LLAMA, a fully automated and end-to-end fuzzing framework that operates in a black-box setting and leverages LLMs to guide the fuzzing process. By extracting semantic information from OpenAPI specifications and natural language documentation, RESTing-LLAMA generates meaningful and well-structured input sequences that align with real-world API behavior. In our evaluation on fifteen real-world APIs, RESTing-LLAMA uncovered 11 vulnerabilities, including one previously unknown vulnerability, while matching or outperforming state-of-the-art fuzzers. It achieved a 34% false positive rate compared to 45% for the next best fuzzer, while requiring 4.4x fewer requests, highlighting the significant improvement in input quality.
Varun Gadey, Christoph Sendner, Keven Zimmermann, Alexandra Dmitrienko
AsiaCCS4
2026 Automated Code Annotation with LLMs for Establishing TEE Boundaries
Varun Gadey, Melanie Gotz, Christoph Sendner, Sampo Sovio, Alexandra Dmitrienko
NDSS5
2026 Memory Backdoor Attacks on Neural Networks
Eden Luzon, Guy Amit, Roy Weiss, Torsten Krauß, Alexandra Dmitrienko, Yisroel Mirsky
NDSS5
2025 AuthentiSafe: Lightweight and Future-Proof Device-to-Device Authentication for IoT
Lukas Petzi, Torsten Krauß, Alexandra Dmitrienko, Gene Tsudik
AsiaCCS3
2025 Sibai: A Few-Shot Meta-Classifier for Poisoning Detection in Federated Learning
Melanie Gotz, Torsten Krauß, Alexandra Dmitrienko
ICCV3
2025 Time-Aware Face Anti-spoofing with Rotation Invariant Local Binary Patterns and Deep Learning
Moritz Finke, Alexandra Dmitrienko
SEC (2)2
2025 Impact Analysis of Sybil Attacks in the Tor Network
Christoph Sendner, Dominik Schreider, Alexandra Dmitrienko
SEC (2)3
2025 TwinBreak: Jailbreaking LLM Security Alignments based on Twin Prompts
Torsten Krauß, Hamid Dashtbani, Alexandra Dmitrienko
USENIX Security Symposium3
2024 Federated Learning Security: From Dusk to Dawn
abstract
The evolution of machine learning (ML) as an enabling technology has opened a new era of possibilities and applications. Among these advancements, distributed learning, specifically federated learning (FL), emerges as a significant shift in collaborative intelligence. FL's unique ability to leverage decentralized data sources promises innovation and privacy protection for local datasets across diverse domains, including healthcare, finance, object recognition, and beyond. However, despite its potential benefits, FL has shown to be vulnerable to various threats. From poisoning attacks to adversarial perturbations and information inference, malicious actors pose significant challenges to the integrity of FL systems. Effectively addressing these vulnerabilities requires the implementation of security-by-design principles within FL frameworks. In this talk, we steer through the complex landscape of FL attacks and defenses, shedding light on the ongoing arms race between adversaries and defenders. We examine their advantages and drawbacks, gaining valuable insights into the evolving nature of these threats. We conclude by outlining research challenges and directions to enhance the resilience and security of FL systems.
Alexandra Dmitrienko
AsiaCCS1
2024 Cloud-Based Machine Learning Models as Covert Communication Channels
abstract
While Machine Learning (ML) is one of the most promising technologies in our era, it is prone to a variety of attacks. One of them is covert channels, that enable two parties to stealthily transmit information through carriers intended for different purposes. Existing works only explore covert channels for federated ML. Thereby, communication is established among multiple entities that collaborate to train a model, while relying on access to model internals.
Torsten Krauß, Jasper Stang, Alexandra Dmitrienko
AsiaCCS3
2024 FreqFed: A Frequency Analysis-Based Approach for Mitigating Poisoning Attacks in Federated Learning
Hossein Fereidooni, Alessandro Pegoraro, Phillip Rieger, Alexandra Dmitrienko, Ahmad-Reza Sadeghi
NDSS4
2024 Automatic Adversarial Adaption for Stealthy Poisoning Attacks in Federated Learning
Torsten Krauß, Jan König, Alexandra Dmitrienko, Christian Kanzow
NDSS3
2024 CrowdGuard: Federated Backdoor Detection in Federated Learning
Phillip Rieger, Torsten Krauß, Markus Miettinen, Alexandra Dmitrienko, Ahmad-Reza Sadeghi
NDSS4
2024 MirageFlow: A New Bandwidth Inflation Attack on Tor
Christoph Sendner, Jasper Stang, Alexandra Dmitrienko, Raveen Wijewickrama, Murtuza Jadliwala
NDSS3
2024 Large-Scale Study of Vulnerability Scanners for Ethereum Smart Contracts
abstract
Ethereum smart contracts, which are autonomous decentralized applications on the blockchain that manage assets often exceeding millions of dollars, have become primary targets for cyberattacks. In 2023 alone, such vulnerabilities led to substantial financial losses exceeding a billion US dollars. To counter these threats, various tools have been developed by academic and commercial entities to detect and mitigate vulnerabilities in smart contracts. Our study investigates the gap between the effectiveness of existing security scanners and the vulnerabilities that still persist in practice. We compiled four distinct datasets for this analysis. The first dataset comprises 77,219 source codes extracted directly from the blockchain, while the second includes over 4 million bytecodes obtained from Ethereum Mainnet and testnets. The other two datasets consist of nearly 14,000 manually annotated smart contracts and 373 smart contracts verified through audits, providing a foundation for a rigorous ground truth analysis on bytecode and source code. Using the unlabeled datasets, we conducted a comprehensive quantitative evaluation of 18 vulnerability scanners, revealing considerable discrepancies in their findings. Our analysis of the ground truth datasets indicated poor performance across all the tools we tested. This study unveils the reasons for poor performance and underscores that the current state of the art for smart contract security falls short in effectively addressing open problems, highlighting that the challenge of effectively detecting vulnerabilities remains a significant and unresolved issue.
Christoph Sendner, Lukas Petzi, Jasper Stang, Alexandra Dmitrienko
SP4
2024 Verify your Labels! Trustworthy Predictions and Datasets via Confidence Scores
Torsten Krauß, Jasper Stang, Alexandra Dmitrienko
USENIX Security Symposium3
2024 ClearStamp: A Human-Visible and Robust Model-Ownership Proof based on Transposed Model Training
Torsten Krauß, Jasper Stang, Alexandra Dmitrienko
USENIX Security Symposium3
2023 MESAS: Poisoning Defense for Federated Learning Resilient against Adaptive Attackers
abstract
Federated Learning (FL) enhances decentralized machine learning by safeguarding data privacy, reducing communication costs, and improving model performance with diverse data sources. However, FL faces vulnerabilities such as untargeted poisoning attacks and targeted backdoor attacks, posing challenges to model integrity and security. Preventing backdoors proves especially challenging due to their stealthy nature. Existing mitigation techniques have shown efficacy but often overlook realistic adversaries and diverse data distributions.
Torsten Krauß, Alexandra Dmitrienko
CCS2
2023 Security of NVMe Offloaded Data in Large-Scale Machine Learning
Torsten Krauß, Raphael Götz, Alexandra Dmitrienko
ESORICS (4)3
2023 AuthentiSense: A Scalable Behavioral Biometrics Authentication Scheme using Few-Shot Learning for Mobile Platforms
Hossein Fereidooni, Jan König, Phillip Rieger, Marco Chilese, Bora Gökbakan, Moritz Finke, Alexandra Dmitrienko, Ahmad-Reza Sadeghi
NDSS7
2023 Smarter Contracts: Detecting Vulnerabilities in Smart Contracts with Deep Transfer Learning
Christoph Sendner, Huili Chen, Hossein Fereidooni, Lukas Petzi, Jan König, Jasper Stang, Alexandra Dmitrienko, Ahmad-Reza Sadeghi, Farinaz Koushanfar
NDSS7
2023 Contact Discovery in Mobile Messengers: Low-cost Attacks, Quantitative Analyses, and Efficient Mitigations
abstract
Contact discovery allows users of mobile messengers to conveniently connect with people in their address book. In this work, we demonstrate that severe privacy issues exist in currently deployed contact discovery methods and propose suitable mitigations. Our study of three popular messengers (WhatsApp, Signal, and Telegram) shows that large-scale crawling attacks are (still) possible. Using an accurate database of mobile phone number prefixes and very few resources, we queried 10 % of US mobile phone numbers for WhatsApp and 100 % for Signal. For Telegram, we find that its API exposes a wide range of sensitive information, even about numbers not registered with the service. We present interesting (cross-messenger) usage statistics, which also reveal that very few users change the default privacy settings. Furthermore, we demonstrate that currently deployed hashing-based contact discovery protocols are severely broken by comparing three methods for efficient hash reversal. Most notably, we show that with the password cracking tool “JTR,” we can iterate through the entire worldwide mobile phone number space in < 150 s on a consumer-grade GPU. We also propose a significantly improved rainbow table construction for non-uniformly distributed input domains that is of independent interest. Regarding mitigations, we most notably propose two novel rate-limiting schemes: our incremental contact discovery for services without server-side contact storage strictly improves over Signal’s current approach while being compatible with private set intersection, whereas our differential scheme allows even stricter rate limits at the overhead for service providers to store a small constant-size state that does not reveal any contact information.
Christoph Hagen, Christian Weinert, Christoph Sendner, Alexandra Dmitrienko, Thomas Schneider 0003
ACM Trans. Priv. Secur.4
2022 FedCRI: Federated Mobile Cyber-Risk Intelligence
Hossein Fereidooni, Alexandra Dmitrienko, Phillip Rieger, Markus Miettinen, Ahmad-Reza Sadeghi, Felix Madlener
NDSS2
2022 SCRAPS: Scalable Collective Remote Attestation for Pub-Sub IoT Networks with Untrusted Proxy Verifier
Lukas Petzi, Ala Eddine Ben Yahya, Alexandra Dmitrienko, Gene Tsudik, Thomas Prantl, Samuel Kounev
USENIX Security Symposium3
2022 An Experience Report on the Suitability of a Distributed Group Encryption Scheme for an IoT Use Case
abstract
The critical component in any IoT application is the communication between devices. This must not only function smoothly, but also be secured. An important step in securing IoT communication is its encryption. However, in order for IoT devices to encrypt their communication with each other, they must first agree on appropriate cryptographic keys. In practice, the generation and distribution of such keys is usually managed by a central authority. However, this centralized approach has the disadvantages that (i) a central authority must be trusted, (ii) the central authority represents a single point of failure, and (iii) the central authority may be far away and thus communication with it takes a long time. To overcome these drawbacks, distributed group key agreement approaches have also been proposed. Since these distributed approaches were not originally developed for IoT devices, their performance on such devices is unknown. Therefore, in this work, we investigate the performance of a distributed group encryption scheme on IoT devices. To this end, we have built a measurement environment for distributed group encryption schemes and compare centralized and distributed group encryption schemes for IoT. Our measurements show that under perfect network conditions, the distributed approach performs worse than the centralized approaches in terms of time and memory requirements. However, our measurements also show that the distributed approach allows a group of 5 members to agree on a key in less than a minute. Thus, the distributed method can be used for small IoT groups if agreeing on a key is not time-sensitive.
Thomas Prantl, Simon Engel, André Bauer 0001, Ala Eddine Ben Yahya, Stefan Herrnleben, Lukas Iffländer, Alexandra Dmitrienko, Samuel Kounev
VTC Spring7
2021 Benchmarking of Pre- and Post-Quantum Group Encryption Schemes with Focus on IoT
abstract
In the next few years, both the number of IoT devices and the performance of quantum computers will increase. Both technologies pose a challenge to our current crypto-strategies. Therefore, post-quantum n-to-n communication encryption is a crucial field of research. Here, the development of new schemes and the analysis, and comparison of existing schemes is necessary. However, current work only investigates the performance of post-quantum schemes only for 1-to-1 communication. Therefore, in this paper, we analyze existing post-quantum schemes concerning n-to-n communication and compare them with pre-quantum schemes. Our results show that the pre-quantum schemes perform better regarding computation times than the post-quantum schemes, but the differences are sometimes only marginal. However, these marginal differences in computation times lead to the lower energy efficiency of the post-quantum schemes. In terms of features, there is no difference between both scheme classes. We show that the post-quantum schemes require unicast, whereas some pre-quantum schemes also support broadcast. Deciding whether to use pre- or post-quantum schemes for n-to-n encryption in IoT use cases depends on (i) whether energy efficiency is essential – e.g., in case of limited power supply – and (ii) whether unicast or broadcast is available.
Thomas Prantl, Dominik Prantl, André Bauer 0001, Lukas Iffländer, Alexandra Dmitrienko, Samuel Kounev, Christian Krupitzer
IPCCC5
2021 Performance Evaluation for a Post-Quantum Public-Key Cryptosystem
abstract
Quantum Computing threatens security of today’s systems. Confidence in today’s security technologies largely relies on Public Key Cryptography (PKC), which depends on computational difficulty of mathematical problems that cannot be solved efficiently using any technology available today. This will, however, change once a sufficiently capable quantum computer will become available. Similarly, security of symmetric crypto algorithms will also be substantially weakened. Current progress in research proves that Quantum Computing is no longer science fiction. Hence, research and development of post-quantum cryptographic algorithms that can withstand attacks in Quantum Computing era are of paramount importance. This paper complements existing research in this domain with a performance analysis of a post-quantum cryptosystem capable of encrypting and decrypting messages either bit-wise or string-wise. Specifically, we describe a workflow for implementing the scheme, design a reproducible hardware performance evaluation testbed for an IoT and an online shopping scenario, define performance metrics, and perform performance evaluation case studies. Our performance analysis shows that bit-wise encryption and decryption and the corresponding key generation fits resource-constrained IoT microcontrollers as well as on average laptops. The encryption and decryption of a bit each take less than 30 ms and the key generation less than 300 ms.
Thomas Prantl, Dominik Prantl, Lukas Beierlieb, Lukas Iffländer, Alexandra Dmitrienko, Samuel Kounev, Christian Krupitzer
IPCCC5
2021 All the Numbers are US: Large-scale Abuse of Contact Discovery in Mobile Messengers
Christoph Hagen, Christian Weinert, Christoph Sendner, Alexandra Dmitrienko, Thomas Schneider 0003
NDSS4
2021 RIP StrandHogg: a practical StrandHogg attack detection method on Android
abstract
StrandHogg vulnerabilities affect Android's multitasking system and threaten up to 90% of Android platforms, which translates to millions of affected users. Existing countermeasures require modification of the OS, have usability drawbacks, or are limited to the detection of certain attack versions. In this work, we aim to develop a generic, efficient, and usability-friendly attack detection method, which does not require OS modifications and can be employed by apps installed on any vulnerable Android platform. To achieve our goal, we analyze StrandHogg attack techniques and develop two countermeasures, one using Machine Learning and the other one using ActivityCounter - a reliable attack indicator, which we could synthetically engineer. Our first approach achieves an average F1 score of 92% across all attack variations, while ActivityCounter shows superior performance and efficiently detects all attack versions without false positives. ActivityCounter is the first solution without practical limitations, which can be easily deployed in practice and protect millions of affected users.
Jasper Stang, Alexandra Dmitrienko, Sascha Roth
WISEC2
2021 Towards a Group Encryption Scheme Benchmark: A View on Centralized Schemes with Focus on IoT
abstract
The number of devices connected to the Internet of Things (IoT) is continuously increasing to several billion nowadays. As those devices often share sensitive data, encryption of those data is an important issue. The pure volume of data and the complexity of communication patterns increases, and, accordingly, the importanceof group encryption is recently gaining more importance. Still, the choice of the best-suited group encryption scheme for a specific application is complicated. Benchmarks can support this choice. However, while literature distinguishes three categories for theschemes (central, decentral, and hybrid), a one-fits-all benchmark seems challenging to achieve. In this paper, we go the first step towards a structured benchmark for group encryption schemes by presenting a benchmark for centralized group encryption schemes in an IoT scenario. To this end, our benchmark includes a descriptionof workloads, a baseline scheme, a measurement setup, and metrics while also considering the requirements and features of centralized group encryption schemes.
Thomas Prantl, Peter Ten, Lukas Iffländer, Stefan Herrnleben, Alexandra Dmitrienko, Samuel Kounev, Christian Krupitzer
ICPE5
2020 LegIoT: Ledgered Trust Management Platform for IoT
Jens Neureither, Alexandra Dmitrienko, David Koisser, Ferdinand Brasser, Ahmad-Reza Sadeghi
ESORICS (1)2
2020 Evaluating the Performance of a State-of-the-Art Group-oriented Encryption Scheme for Dynamic Groups in an IoT Scenario
abstract
New emerging technologies, such as autonomous driving, intelligent buildings, and smart cities, are promising to revolutionize user experience and offer new services. The world has to undergo large scale deployment of billions of things - cost-efficient intelligent sensors that will be interconnected into extensive networks and will collect and supply data to intelligent algorithms - to make it happen. To date, however, it is challenging to secure such an infrastructure for many-fold reasons, such as resource constraints of things, large scale deployment, many-to-many communication patterns, and dynamically changing communication groups. All these factors rule out most of the state-of-the-art encryption and key-management techniques. Group encryption algorithms are well-suitable for many-to-many communication patterns typical for IoT networks, and many of them can deal with dynamic groups. There are, however, very few constructions that could potentially fulfill the computational and storage constraints of IoT devices while providing sufficient scalability for large networks. The promising candidates, such as construction by Nishat et al. [1], were not evaluated using IoT platforms and under constraints typical for IoT networks. In this paper, we aim to fill this gap and present the evaluation of a state-of-the-art group-oriented encryption scheme by Nishat et al. to identify its applicability to IoT systems. In detail, we provide a measurement workflow, a revised version of the approach, and describe a reproducible hardware testbed. Using this evaluation environment, we analyze the performance of the encryption scheme in a typical IoT scenario from a group member perspective. The results show that all calculation times can be assumed to be constant and are always below 2 seconds. The memory requirement for permanent parameters can also be considered to be constant and are below 8.5 kbit in each case. However, the information that has to be stored temporarily for group updates has turned out to be the bottleneck of the scheme, since their memory requirements increase linearly with the group size.
Thomas Prantl, Peter Ten, Lukas Iffländer, Alexandra Dmitrienko, Samuel Kounev, Christian Krupitzer
MASCOTS4
2020 Mind the GAP: Security & Privacy Risks of Contact Tracing Apps
abstract
Google and Apple have jointly provided an API for exposure notification in order to implement decentralized contract tracing apps using Bluetooth Low Energy, the so-called “Google/Apple Proposal”, which we abbreviate by “GAP”. We demonstrate that in real-world scenarios the current GAP design is vulnerable to (i) profiling and possibly de-anonymizing infected persons, and (ii) relay-based wormhole attacks that basically can generate fake contacts with the potential of affecting the accuracy of an app-based contact tracing system. For both types of attack, we have built tools that can easily be used on mobile phones or Raspberry Pis (e.g., Bluetooth sniffers). The goal of our work is to perform a reality check towards possibly providing empirical real-world evidence for these two privacy and security risks. We hope that our findings provide valuable input for developing secure and privacy-preserving digital contact tracing systems.
Lars Baumgärtner, Alexandra Dmitrienko, Bernd Freisleben, Alexander Gruler, Jonas Höchst, Joshua Kühlberg, Mira Mezini, Richard Mitev, Markus Miettinen, Anel Muhamedagic, Thien Duc Nguyen, Alvar Penning, Dermot Frederik Pustelnik, Filipp Roos, Ahmad-Reza Sadeghi, Michael Schwarz 0009, Christian Uhl
TrustCom2
2019 DR.SGX: automated and adjustable side-channel protection for SGX using data location randomization
abstract
Recent research has demonstrated that Intel's SGX is vulnerable to software-based side-channel attacks. In a common attack, the adversary monitors CPU caches to infer secret-dependent data accesses patterns. Known defenses have major limitations, as they require either error-prone developer assistance, incur extremely high runtime overhead, or prevent only specific attacks.
Ferdinand Brasser, Srdjan Capkun, Alexandra Dmitrienko, Tommaso Frassetto, Kari Kostiainen, Ahmad-Reza Sadeghi
ACSAC3
2018 SmarTor: Smarter Tor with Smart Contracts: Improving resilience of topology distribution in the Tor network
abstract
In the Tor anonymity network, the distribution of topology information relies on the correct behavior of five out of the nine trusted directory authority servers. This centralization is concerning since a powerful adversary might compromise these servers and conceal information about honest nodes, leading to the full de-anonymization of all Tor users. Our work aims at distributing the work of these trusted authorities, such increasing resilience against attacks on core infrastructure components of the Tor network. In particular, we leverage several emerging technologies, such as blockchains, smart contracts, and trusted execution environments to design and prototype a system called SmarTor. This system replaces the directory authorities with a smart contract and a distributed network of untrusted entities responsible for bandwidth measurements. We prototyped SmarTor using Ethereum smart contracts and Intel SGX secure hardware. In our evaluation, we show that SmarTor produces significantly more reliable and precise measurements compared to the current measurement system. Overall, our solution improves the decentralization of the Tor network, reduces trust assumptions and increases resilience against powerful adversaries like law enforcement and intelligence services.
André Greubel, Alexandra Dmitrienko, Samuel Kounev
ACSAC2
2017 Secure Wallet-Assisted Offline Bitcoin Payments with Double-Spender Revocation
abstract
Bitcoin seems to be the most successful cryptocurrency so far given the growing real life deployment and popularity. While Bitcoin requires clients to be online to perform transactions and a certain amount of time to verify them, there are many real life scenarios that demand for offline and immediate payments (e.g., mobile ticketing, vending machines, etc). However, offline payments in Bitcoin raise non-trivial security challenges, as the payee has no means to verify the received coins without having access to the Bitcoin network. Moreover, even online immediate payments are shown to be vulnerable to double-spending attacks. In this paper, we propose the first solution for Bitcoin payments, which enables secure payments with Bitcoin in offline settings and in scenarios where payments need to be immediately accepted. Our approach relies on an offline wallet and deploys several novel security mechanisms to prevent double-spending and to verify the coin validity in offline setting. These mechanisms achieve probabilistic security to guarantee that the attack probability is lower than the desired threshold. We provide a security and risk analysis as well as model security parameters for various adversaries. We further eliminate remaining risks by detection of misbehaving wallets and their revocation.
Alexandra Dmitrienko, David Noack, Moti Yung
AsiaCCS1
2017 Secure Free-Floating Car Sharing for Offline Cars
abstract
In this paper, we present a new access control system for free-floating car sharing, which achieves a number of appealing features not available in the state-of-the-art solutions. First of all, it does not require online connection for cars, and, therefore, allows car sharing providers to expand their services to areas without reliable network coverage (e.g., with blind spots). Second, the solution is compatible to RFID cards -- the most commonly deployed authentication tokens in car sharing, and can be deployed on standard mobile platforms with various hardware features. Third, it is fully compatible with off-the-shelf cars and does not require any intrusive modifications to car's internals. These new properties can be achieved due to a novel system design which deploys two-factor authentication and combines an RFID card (the real one or emulated in software) with a "soft" authentication token stored on a mobile platform. Such a combination increases security of the solution, preserves backward compatibility to RFID technology and enables great flexibility in protection of authentication secrets on the mobile platform. To demonstrate such a flexibility, we present a platform security concept which can be instantiated in various deployment options and provides the means to achieve best possible security given available hardware.
Alexandra Dmitrienko, Christian Plappert
CODASPY1
2017 Phonion: Practical Protection of Metadata in Telephony Networks
abstract
Abstract The majority of people across the globe rely on telephony networks as their primary means of communication. As such, many of the most sensitive personal, corporate and government related communications pass through these systems every day. Unsurprisingly, such connections are subject to a wide range of attacks. Of increasing concern is the use of metadata contained in Call Detail Records (CDRs), which contain source, destination, start time and duration of a call. This information is potentially dangerous as the very act of two parties communicating can reveal significant details about their relationship and put them in the focus of targeted observation or surveillance, which is highly critical especially for journalists and activists. To address this problem, we develop the Phonion architecture to frustrate such attacks by separating call setup functions from call delivery. Specifically, Phonion allows users to preemptively establish call circuits across multiple providers and technologies before dialing into the circuit and does not require constant Internet connectivity. Since no single carrier can determine the ultimate destination of the call, it provides unlinkability for its users and helps them to avoid passive surveillance. We define and discuss a range of adversary classes and analyze why current obfuscation technologies fail to protect users against such metadata attacks. In our extensive evaluation we further analyze advanced anonymity technologies (e.g., VoIP over Tor), which do not preserve our functional requirements for high voice quality in the absence of constant broadband Internet connectivity and compatibility with landline and feature phones. Phonion is the first practical system to provide guarantees of unlinkable communication against a range of practical adversaries in telephony systems.
Stephan Heuser, Bradley Reaves, Praveen Kumar Pendyala, Henry Carter, Alexandra Dmitrienko, William Enck, Negar Kiyavash, Ahmad-Reza Sadeghi, Patrick Traynor
Proc. Priv. Enhancing Technol.5
2013 CrowdShare: Secure Mobile Resource Sharing
N. Asokan, Alexandra Dmitrienko, Marcin Nagy, Elena Reshetova, Ahmad-Reza Sadeghi, Thomas Schneider 0003, Stanislaus Stelle
ACNS2
2013 Do I know you?: efficient and privacy-preserving common friend-finder protocols and applications
abstract
The increasing penetration of Online Social Networks (OSNs) prompts the need for effectively accessing and utilizing social networking information. In numerous applications, users need to make trust and/or access control decisions involving other (possibly stranger) users, and one important factor is often the existence of common social relationships. This motivates the need for secure and privacy-preserving techniques allowing users to assess whether or not they have mutual friends.
Marcin Nagy, Emiliano De Cristofaro, Alexandra Dmitrienko, N. Asokan, Ahmad-Reza Sadeghi
ACSAC3
2013 Gadge me if you can: secure and efficient ad-hoc instruction-level randomization for x86 and ARM
abstract
Code reuse attacks such as return-oriented programming are one of the most powerful threats to contemporary software. ASLR was introduced to impede these attacks by dispersing shared libraries and the executable in memory. However, in practice its entropy is rather low and, more importantly, the leakage of a single address reveals the position of a whole library in memory. The recent mitigation literature followed the route of randomization, applied it at different stages such as source code or the executable binary. However, the code segments still stay in one block. In contrast to previous work, our randomization solution, called Xifer, (1) disperses all code (executable and libraries) across the whole address space, (2) re-randomizes the address space for each run, (3) is compatible to code signing, and (4) does neither require offline static analysis nor source-code. Our prototype implementation supports the Linux ELF file format and covers both mainstream processor architectures x86 and ARM. Our evaluation demonstrates that Xifer performs efficiently at load- and during run-time (1.2% overhead).
Lucas Davi, Alexandra Dmitrienko, Stefan Nürnberger, Ahmad-Reza Sadeghi
AsiaCCS2
2013 Smart keys for cyber-cars: secure smartphone-based NFC-enabled car immobilizer
abstract
Smartphones have become very popular and versatile devices. An emerging trend is the integration of smartphones into automotive systems and applications, particularly access control systems to unlock cars (doors and immobilizers). Smartphone-based automotive solutions promise to greatly enhance the user's experience by providing advanced features far beyond the conventional dedicated tokens/transponders.
Christoph Busold, Ahmed Taha 0002, Christian Wachsmann, Alexandra Dmitrienko, Hervé Seudie, Majid Sobhani, Ahmad-Reza Sadeghi
CODASPY4
2013 Just-In-Time Code Reuse: On the Effectiveness of Fine-Grained Address Space Layout Randomization
abstract
Fine-grained address space layout randomization (ASLR) has recently been proposed as a method of efficiently mitigating runtime attacks. In this paper, we introduce the design and implementation of a framework based on a novel attack strategy, dubbed just-in-time code reuse, that undermines the benefits of fine-grained ASLR. Specifically, we derail the assumptions embodied in fine-grained ASLR by exploiting the ability to repeatedly abuse a memory disclosure to map an application's memory layout on-the-fly, dynamically discover API functions and gadgets, and JIT-compile a target program using those gadgets -- all within a script environment at the time an exploit is launched. We demonstrate the power of our framework by using it in conjunction with a real-world exploit against Internet Explorer, and also provide extensive evaluations that demonstrate the practicality of just-in-time code reuse attacks. Our findings suggest that fine-grained ASLR may not be as promising as first thought.
Kevin Z. Snow, Fabian Monrose, Lucas Davi, Alexandra Dmitrienko, Christopher Liebchen, Ahmad-Reza Sadeghi
IEEE Symposium on Security and Privacy4
2012 Towards Taming Privilege-Escalation Attacks on Android
Sven Bugiel, Lucas Davi, Alexandra Dmitrienko, Thomas Fischer 0005, Ahmad-Reza Sadeghi, Bhargava Shastry
NDSS3
2012 MoCFI: A Framework to Mitigate Control-Flow Attacks on Smartphones
Lucas Davi, Alexandra Dmitrienko, Manuel Egele, Thomas Fischer 0005, Thorsten Holz, Ralf Hund, Stefan Nürnberger, Ahmad-Reza Sadeghi
NDSS2
2011 Poster: the quest for security against privilege escalation attacks on android
Sven Bugiel, Lucas Davi, Alexandra Dmitrienko, Thomas Fischer 0005, Ahmad-Reza Sadeghi, Bhargava Shastry
CCS3
2011 Poster: control-flow integrity for smartphones
Lucas Davi, Alexandra Dmitrienko, Manuel Egele, Thomas Fischer 0005, Thorsten Holz, Ralf Hund, Stefan Nürnberger, Ahmad-Reza Sadeghi
CCS2
2010 Return-oriented programming without returns
abstract
We show that on both the x86 and ARM architectures it is possible to mount return-oriented programming attacks without using return instructions. Our attacks instead make use of certain instruction sequences that behave like a return, which occur with sufficient frequency in large libraries on (x86) Linux and (ARM) Android to allow creation of Turing-complete gadget sets.
Stephen Checkoway, Lucas Davi, Alexandra Dmitrienko, Ahmad-Reza Sadeghi, Hovav Shacham, Marcel Winandy
CCS3
2010 Privilege Escalation Attacks on Android
Lucas Davi, Alexandra Dmitrienko, Ahmad-Reza Sadeghi, Marcel Winandy
ISC2