Sebastian Obermeier 0001

dblp:73/6599 · DBLP profile ↗
← Back
24ranked-venue papers
11as first author
2since 2021 · last 2024
0000-0003-2802-7427ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 11 · 3 first-author · 2 since 2021Databases, data management, data science and information retrieval · 7 · 5 first-authorSystems, architecture and hardware · 4 · 2 first-authorSoftware engineering, systems software and programming languages · 1Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author
YearPublicationVenuePosition
2024 HydroLab: A Versatile Hydroelectric Power Lab for Security Research and Education
Sebastian Obermeier 0001, Giorgio Tresoldi, Bernhard Tellenbach, Vincent Lenders
SECRYPT1
2024 Evaluating Digital Forensic Readiness: A Honeypot Approach
Philip Zimmermann 0002, Sebastian Obermeier 0001
SECRYPT2
2018 Bluetooth Low Energy Devices Security Testing Framework
Apala Ray, Vipin Raj, Manuel Oriol, Aurelien Monot, Sebastian Obermeier 0001
ICST5
2017 A security evaluation of IEC 62351
Roman Schlegel, Sebastian Obermeier 0001, Johannes Schneider 0002
J. Inf. Secur. Appl.2
2016 Subdomain and Access Pattern Privacy - Trading off Confidentiality and Performance
abstract
Homomorphic encryption and secure multi-party computation enable computations on encrypted data. However, both techniques suffer from a large performance overhead. While advances in algorithms might reduce the overhead, we show that achieving perfect (or even computational) confidentiality is not possible without increasing the running time compared to computations on plaintext more than exponentially in some cases. In practice, however, perfect confidentiality is not always required. The paper discusses mechanisms to trade off confidentiality and performance for computing on ciphertexts. It introduces a fine-grained approach to define security levels for variables called (statistical) subdomain privacy. This concept differs substantially from prior work because it treats a variable as confidential or non-confidential depending on the actual value. We further propose privacy-preserving methods for memory access patterns. We apply our techniques to improve performance of control flow logic (loops, if-then-else logic) and arithmetic operations such as multiplications. The evaluation shows that the resulting speedup can be in the order of several magnitudes depending on the privacy needs.
Johannes Schneider 0002, Thomas Locher, Yvonne-Anne Pignolet, Matús Harvan, Sebastian Obermeier 0001
SECRYPT6
2015 Structured system threat modeling and mitigation analysis for industrial automation systems
abstract
Industrial control systems are an important part of critical infrastructures and their uninterrupted operation is important for many aspects of society. In recent years these systems have come under more scrutiny, as reports about attacks on them have become more frequent. There is therefore a need to better secure them, and the first step to achieve this is to identify the threat landscape for such systems. This is typically done by creating a threat model of a system, enumerating the potential threats, and then devising mitigation options based on the discovered threats. However, many of the available threat modeling methods and tools target very specific systems (e.g., software components), and do not lend themselves well to evaluating diverse systems or abstract reference architectures of systems. In this paper we present a methodology for system threat modeling that addresses this gap, by enabling the modeling of a diverse range of systems and reference architectures of systems. Furthermore, the methodology provides additional functionality, such as guiding the user in the completion of a threat model and automatically detecting unmitigated threats in a system. In addition, our methodology also takes mitigation into account by modeling the security components in a system. We have implemented the methodology in a web-based tool, and also evaluated the tool on a reference architecture of a complex automation system, validating both the approach and the tool.
Roman Schlegel, Sebastian Obermeier 0001, Johannes Schneider 0002
INDIN2
2015 A Framework for Incident Response in Industrial Control Systems
abstract
Industrial control systems are used to control and supervise plants and critical infrastructures. They are crucial for operation of many industries and even society at large. However, despite efforts to secure such systems, there are frequent reports of incidents that lead to problems because of human error (e.g., installing unauthorized software on a mission-critical machine) or even cyber attacks. While such incidents should be prevented in the first place, it is not feasible to achieve 100% security; therefore, operators should be prepared to deal with incidents promptly and efficiently if they occur. In this paper, we present a general methodology and framework for investigating incidents in industrial control systems. The methodology is supported by a tool to automate an investigation, especially to efficiently determine the state of files on a device after an incident. This enables faster recovery from incidents by being able to identify suspicious files and focus on the files that have been modified compared to the initially installed files, or a previously taken baseline. An evaluation confirms the applicability of the methodology for an embedded industrial controller and for an industrial control system.
Roman Schlegel, Ana Hristova, Sebastian Obermeier 0001
SECRYPT3
2015 A Flexible Architecture for Industrial Control System Honeypots
abstract
While frequent reports on targeted attacks for Industrial Control Systems hit the news, the amount of untargeted attacks using standardized industrial protocols is still unclear, especially if devices are mistakenly or even knowingly connected to the Internet. To lay the foundation for a deeper insight into the interest of potential attackers, a large scale honeynet system that captures all interactions using industrial protocols is proposed. Special for the honeynet system architecture is the automated deployment on a cloud infrastructure and its modularisation of the industrial protocols. The centralized-but-redundant data collection allows correlating attacks that happen on multiple devices. A real-world experiment confirms the feasibility of the approach, and results of the observed interactions with the honeynet are presented.
Alexandru Vlad Serbanescu, Sebastian Obermeier 0001, Der-Yeuan Yu
SECRYPT2
2014 Automatic attack surface reduction in next-generation industrial control systems
abstract
Industrial control systems are often large and complex distributed systems and therefore expose a large potential attack surface. Effectively minimizing this attack surface requires security experts and significant manpower during engineering and maintenance of the system. This task, which is already difficult for today's control systems, will become significantly more complex for tomorrow's systems, which can reconfigure themselves dynamically, e.g., if hardware failures occur. In this article, we present a dynamic security system which can automatically minimize the attack surface of a control system's communication network. This security system is specifically designed for next-generation industrial control systems, but can also be applied in current generation systems. The presented security system adapts the necessary parameters of network and security controls according to the underlying changes in the control system environment. This ensures a better cyber security resilience against system compromise and reduces the attack surface because security controls will only allow data transfer that is required by the control application. Our evaluations for a next generation industrial control system and a current generation substation automation system show that the attack surface can be reduced by up to 90%, depending on the size and actual configuration of the control system.
Sebastian Obermeier 0001, Michael Wahler, Thanikesavan Sivanthi, Roman Schlegel, Aurelien Monot
CICS1
2014 Securing industrial automation and control systems using application whitelisting
abstract
Application whitelisting is a method for establishing security by restricting systems to only execute applications that are on a given list - the white list. One of the main questions when using such technology within industrial control systems is whether anti-virus software becomes obsolete, and whether security patches of the underlying system are still required. To answer these questions, we have evaluated several application whitelisting solutions and present the evaluation method and the condensed test results. In addition, we highlight the difficulties for end users to evaluate of the level of protection that is provided by such whitelisting software. As a conclusion, we have identified several benefits of application whitelisting software, but also argue why whitelisting alone is not the "silver bullet", which - once deployed - does not need attention anymore.
Sebastian Obermeier 0001, Ragnar Schierholz, Ana Hristova
ETFA1
2013 Secure design of engineering software tools in Industrial Automation and Control Systems
abstract
Industrial Automation and Control Systems (IACS) used in critical infrastructure typically perform their tasks using embedded devices. While the security of the embedded devices during the operation of the system is naturally the focus of security considerations, the security of the engineering framework is often overlooked. In this paper, we model the trust boundaries of a typical engineering tool used in an IACS, identify security risks in this context, suggest mitigation techniques for end users, and finally propose an architecture that allows to implement secure engineering frameworks.
Ana Hristova, Sebastian Obermeier 0001, Roman Schlegel
INDIN2
2009 Collaborative Security Assessments in Embedded Systems Development - The ESSAF Framework for Structured Qualitative Analysis
Friedrich Köster, Michael Klaas, Hanh Quyen Nguyen, Walter Brenner, Markus Brändle, Sebastian Obermeier 0001
SECRYPT6
2009 Tool Support for Achieving Qualitative Security Assessments of Critical Infrastructures - The ESSAF Framework for Structured Qualitative Analysis
Hanh Quyen Nguyen, Friedrich Köster, Michael Klaas, Walter Brenner, Sebastian Obermeier 0001, Markus Brändle
SECRYPT5
2009 Blocking reduction for distributed transaction processing within MANETs
Sebastian Obermeier 0001, Stefan Böttcher, Martin Hett, Panos K. Chrysanthis, George Samaras
Distributed Parallel Databases1
2009 A cross-layer atomic commit protocol implementation for transaction processing in mobile ad-hoc networks
Sebastian Obermeier 0001, Stefan Böttcher, Dominik Kleine
Distributed Parallel Databases1
2008 XML fragment caching for large-scale mobile commerce applications
abstract
We present an XML data exchange technique suitable for mobile commerce systems involving thousands of mobile users and massive data loads. A key idea of our technique is that it is based on an XML information repository that is logically split into several disjoint data fragments. Thus, each mobile user's device can determine those parts of the information repository that are required for answering a given query locally at the device. The benefit of this local query processing is that our technique allows participating user devices to make their cached data fragments available to other participating devices and relieves the central information repository, resulting in a significant reduction of the overall data transfer and improved query response times.
Sebastian Obermeier 0001, Stefan Böttcher
ICEC1
2008 Adjourn State Concurrency Control Avoiding Time-Out Problems in Atomic Commit Protocols
abstract
The use of atomic commit protocols in mobile ad-hoc networks involves difficulties in setting up reasonable time-outs for aborting a pending distributed transaction. This paper presents the non-blocking adjourn state, a concurrency control modification which makes time-outs in an atomic commit protocol for aborting a transaction unnecessary. Further, it enhances concurrency among transactions performing conflicting accesses to resources used by completed distributed transactions waiting for the commit protocol to be initiated.
Sebastian Obermeier 0001, Stefan Böttcher, Martin Hett, Panos K. Chrysanthis, George Samaras
ICDE1
2008 CLCP - A Distributed Cross-Layer Commit Protocol for Mobile Ad Hoc Networks
abstract
Transaction processing in mobile ad hoc networks must take network problems like node disconnection, message loss, and network partitioning into consideration. We present a distributed cross-layer atomic commit protocol called CLCP that uses multiple coordinators and makes use of acknowledgement messages to piggyback information. We evaluated transaction processing in mobile ad hoc networks by using two mobility models (i.e. Attraction Point and Manhattan Geometry), and compared CLCP with both atomic commit protocols, 2PC and Paxos Commit, each implemented in 3 versions, i.e. without acknowledgements, with Relay Routing, and with Nearest Forward Progress Routing. Special to our simulation environment is the use of the quasi-unit-disc model, which assumes a non-binary message reception probability that captures real-world behavior much better than the classical unit-disc-model, often used in theory. Using the quasi-unit-disc model, our evaluation shows the following results. CLCP and "2PC without acknowledement messages" have a significantly lower energy consumption than the other protocols, and CLCP is able to commit significantly more distributed transactions than all the other atomic commit protocols for each of the mobility models.
Sebastian Obermeier 0001, Stefan Böttcher, Dominik Kleine
ISPA1
2007 Secure Anonymous Union Computation Among Malicious Partners
abstract
When applications require a union calculation of different distributed datasets, two requirements are often necessary to fulfil: anonymity and security. Anonymity means for scenarios with more than 2 participants that the owner of a certain data item cannot be identified. Security means that no participant can prevent that data items of other participants will be included in the union set. In this paper, we present a union protocol that guarantees both properties: anonymity and security even if participants act malicious, i.e. to modify messages or change the protocol. We prove the correctness of protocol and give experimental results that show the applicability of our protocol in a common environment
Stefan Böttcher, Sebastian Obermeier 0001
ARES2
2007 Avoiding Infinite Blocking of Mobile Transactions
abstract
When a transaction commit decision is lost or delayed in a mobile network, most transaction protocols cannot terminate the transaction and delay conflicting transactions. In contrast to this, we present a concept called Bi-State- Termination (BST) that allows transactions to terminate into two states: one state having the changes applied, and the other state having the transaction aborted. Conflicting transactions that work on these states are not blocked. We prove that BST guarantees atomicity and serializability, and describe a possible implementation using version numbers. Furthermore, our experimental results show that BST is feasibility for mobile networks, and that it enhances the transaction throughput whenever transactions are blocked for a long time.
Sebastian Obermeier 0001, Stefan Böttcher
IDEAS1
2007 XPath Selectivity Estimation for a Mobile Auction Application
abstract
Whenever nodes in a mobile network try to access an XML database server, the offered data must be somehow queried and transported by a mobile network to the querying node. For this purpose, two mechanisms are possible: query shipping and data shipping. Which one is better depends among other aspects on the query result size, more precisely on the overhead that data shipping incorporates compared to query shipping. In this paper, we present a query result size estimator that allows each mobile user to estimate the resulting size and cardinality of an XPath query by means of special distributed meta data in order to decide between query shipping or data shipping by comparing the estimated size of the result with the data that must be requested for data shipping. We show how the meta data is generated for certain query classes, how the meta data can be used to predict the result size and cardinality, and we give experimental results on the deviation of the predicted results.
Sebastian Obermeier 0001, Stefan Böttcher, Thomas Wycisk
IDEAS1
2007 A Failure Tolerating Atomic Commit Protocol for Mobile Environments
abstract
In traditional fixed-wired networks, standard protocols like 2-Phase-Commit are used to guarantee atomicity for distributed transactions. However, within mobile networks, a higher probability of failures including node failures, message loss, and even network partitioning makes the use of these standard protocols difficult or even impossible. To use traditional database applications within a mobile scenario, we need an atomic commit protocol that reduces the chance of infinite blocking. In this paper, we present an atomic commit protocol called multi coordinator protocol (MCP) that uses a combination of the traditional 2-Phase-Commit, 3-Phase-Commit, and consensus protocols for mobile environments. Simulation experiments comparing MCP with 2PC show how MCP enhances stability for the coordination process by involving multiple coordinators, and that the additional time needed for the coordination among multiple coordinators is still reasonable.
Stefan Böttcher, Le Gruenwald, Sebastian Obermeier 0001
MDM3
2007 Secure Computation of Common Data among Malicious Partners
Sebastian Obermeier 0001, Stefan Böttcher
SECRYPT1
2005 An Integrated Commit Protocol for Mobile Network Databases
abstract
While traditional fixed-wired network protocols like 2-phase-commit guarantee atomicity, we cannot use them in mobile low bandwidth networks where network partitioning, node failure, and message loss may result in blocking. To deploy traditional database applications easily into a mobile environment, there is a demand for a protocol which guarantees an atomic commit of transactions. This paper introduces a protocol which can guarantee such atomic commitment in mobile environments using a combination of commit and consensus protocols. In addition, it takes advantage of mobile network sub-structures like single-hop environments to reduce message transfer costs.
Joos-Hendrik Böse, Stefan Böttcher, Le Gruenwald, Sebastian Obermeier 0001, Heinz Schweppe, Thorsten Steenweg
IDEAS4