Thomas Schreck

dblp:71/1928 · DBLP profile ↗
← Back
9ranked-venue papers
3as first author
5since 2021 · last 2026
0000-0002-8960-6986ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 7 · 1 first-author · 5 since 2021Software engineering, systems software and programming languages · 2 · 2 first-author
YearPublicationVenuePosition
2026 All You Need is Trust: A Longitudinal Analysis of Italy's OpenID Federation Journey
Tobias Hilbig, Erwin Kupris, Thomas Schreck
EuroS&P3
2026 The Passkey Promise: A Comparative Usability Study of MFA Methods
Erwin Kupris, Thomas Schreck
SP2
2024 The "Big Beast to Tackle": Practices in Quality Assurance for Cyber Threat Intelligence
abstract
The quality of Cyber Threat Intelligence (CTI) has a profound impact on the efficacy of an organization’s defense against cyber threats, directly influencing its ability to safeguard critical assets and sensitive data. Despite its critical importance, the domain of CTI quality remains a multifaceted and evolving field, often operating at the intersection of theory and practice. Many organizations recognize the need for high-quality intelligence but may struggle to establish systematic processes for assessing and enhancing its quality.
Thomas Geras, Thomas Schreck
RAID2
2024 Do You Play It by the Books? A Study on Incident Response Playbooks and Influencing Factors
abstract
Incident response "playbooks" are structured sets of operational procedures organizations use to instruct humans or machines on performing countermeasures against cybersecurity threats. These playbooks generally combine information about a given threat and organizational aspects relevant within the context of an organization. Both types of information are crucial for using, maintaining, and sharing playbooks across organizations as they ensure effectiveness and confidentiality. While practitioners show great interest in playbooks, their characteristics have not yet been thoroughly investigated from a research perspective. For this reason, we explore the topic by analyzing what is inside a playbook. Our approach consists of a comprehensive empirical assessment of available data (1217 playbooks), an online study with 147 participants, and final in-depth interviews with nine security professionals to consolidate and validate our findings. We notably find intrinsic ambiguities in the way practitioners and organizations define their playbooks. Furthermore, we notice that available playbooks cannot be used outright which might currently impair their wide use across different cybersecurity actors. As a result, we can conclude that organizations do "play it by the books" but individually define what is inside their playbooks and which areas of incident response they might address.
Daniel Schlette, Philip Empl, Marco Caselli, Thomas Schreck, Günther Pernul
SP4
2023 Sharing Communities: The Good, the Bad, and the Ugly
abstract
There are many mysteries surrounding sharing communities, mainly due to their hidden workings and the complexity of joining. Nevertheless, these communities are critical to the security ecosystem, so a more profound understanding is necessary. In addition, they face challenges such as building trust, communicating effectively, and addressing social problems.
Thomas Geras, Thomas Schreck
CCS2
2017 Mining Attributed Graphs for Threat Intelligence
abstract
Understanding and fending off attack campaigns against organizations, companies and individuals, has become a global struggle. As today's threat actors become more determined and organized, isolated efforts to detect and reveal threats are no longer effective. Although challenging, this situation can be significantly changed if information about security incidents is collected, shared and analyzed across organizations. To this end, different exchange data formats such as STIX, CyBOX, or IODEF have been recently proposed and numerous CERTs are adopting these threat intelligence standards to share tactical and technical threat insights. However, managing, analyzing and correlating the vast amount of data available from different sources to identify relevant attack patterns still remains an open problem.
Hugo Gascon, Bernd Grobauer, Thomas Schreck, Lukas Rist, Daniel Arp, Konrad Rieck
CODASPY3
2012 BISSAM: Automatic Vulnerability Identification of Office Documents
Thomas Schreck, Stefan Berger, Jan Göbel
DIMVA1
2000 Branch grafting method for R-tree implementation
Thomas Schreck, Zhengxin Chen
J. Syst. Softw.1
1997 Implementation of locking schemes in extended dependency graphs
Thomas Schreck, Zhengxin Chen
Inf. Softw. Technol.1