EDBT 2026 Demo / reviewers in the wild / expert
Joachim Fabini
dblp:74/1287
· DBLP profile ↗
15ranked-venue papers
6as first author
4since 2021 · last 2024
0000-0002-8285-1591ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 8 · 4 first-author · 1 since 2021Security and privacy · 5 · 1 first-author · 2 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | Malware communication in smart factories: A network traffic data set
Bernhard Brenner, Joachim Fabini, Magnus Offermanns, Sabrina Semper, Tanja Zseby |
Comput. Networks | 2 |
| 2022 | Separating Flows in Encrypted Tunnel TrafficabstractIn many scenarios like wireless Internet access or encrypted VPN tunnels, encryption is performed on a per-packet basis. While this encryption approach effectively protects the confidentiality of the transmitted payload, it leaves traffic patterns involving inter-arrival times and packet lengths observable, e.g., to eavesdroppers on the air interface. It is a widespread belief that by only observing interleaved packets of different parallel flows, analysis and classification of the corresponding traffic by an eavesdropper is very difficult or close to impossible.In this paper, we show that it is indeed possible to separate packets belonging to different flows purely from patterns observed in the interleaved packet sequence. We devise a novel deep recurrent neural network architecture that allows us to detect individual anomalous packets in a flow. Based on this anomaly detector, we develop an algorithm to find a separation into flows that minimizes the anomaly score indicated by our model. Our experimental results obtained with synthetically crafted flows and real-world network traces indicate that our approach is indeed able to separate flows successfully with high accuracy.Being able to recover a flow's packet sequence from multiple interleaved flows, we show with this paper that the common packet-level encryption might be insufficient in scenarios where high levels of privacy have to be achieved. On the defender's side, our approach constitutes a valuable tool in encrypted traffic analysis, but also contributes a novel neural network architecture in the field of network intrusion detection in general. Alexander Hartl, Joachim Fabini, Tanja Zseby |
ICMLA | 2 |
| 2021 | SecTULab: A Moodle-Integrated Secure Remote Access Architecture for Cyber Security LaboratoriesabstractThe Covid-19 crisis has challenged cyber security teaching by creating the need for secure remote access to existing cyber security laboratory infrastructure. In this paper, we present requirements, architecture and key functionalities of a secure remote laboratory access solution that has been instantiated successfully for two existing laboratories at TU Wien. The proposed design prioritizes security and privacy aspects while integrating with existing Moodle eLearning platforms to leverage available authentication and group collaboration features. Performance evaluations of the prototype implementation for real cyber security classes support a first estimate of dimensioning and resources that must be provisioned when implementing the proposed secure remote laboratory access. Joachim Fabini, Alexander Hartl, Fares Meghdouri, Claudia Breitenfellner, Tanja Zseby |
ARES | 1 |
| 2021 | Subverting Counter Mode Encryption for Hidden Communication in High-Security InfrastructuresabstractIn highly security-critical network environments, it is a popular design decision to offload cryptographic tasks like encryption or signature generation to a dedicated trusted module or key server with paramount security features, we in this paper refer to with the general term Cryptographic Key Management Device (CKMD). While this network design yields several benefits, we demonstrate that the use of popular counter mode encryption modes like CTR or GCM can show substantial shortcomings in terms of security when used in conjunction with this network design. In particular, we show how the use of authenticated encryption using GCM enables the possibility of establishing a subliminal channel by exploiting the authentication information within messages. We show how decoding of hidden information can proceed in addition to decryption of overt information without raising authentication failures. Alexander Hartl, Joachim Fabini, Christoph Roschger, Peter Eder-Neuhauser, Marco Petrovic, Roman Tobler, Tanja Zseby |
ARES | 2 |
| 2020 | LFQ: Online Learning of Per-flow Queuing Policies using Deep Reinforcement LearningabstractThe increasing number of different, incompatible congestion control algorithms has led to an increased deployment of fair queuing. Fair queuing isolates each network flow and can thus guarantee fairness for each flow even if the flows' congestion controls are not inherently fair. So far, each queue in the fair queuing system either has a fixed, static maximum size or is managed by an Active Queue Management (AQM) algorithm like CoDel. In this paper we design an AQM mechanism (Learning Fair Qdisc (LFQ)) that dynamically learns the optimal buffer size for each flow according to a specified reward function online. We show that our Deep Learning based algorithm can dynamically assign the optimal queue size to each flow depending on its congestion control, delay and bandwidth. Comparing to competing fair AQM schedulers, it provides significantly smaller queues while achieving the same or higher throughput. Maximilian Bachl, Joachim Fabini, Tanja Zseby |
LCN | 2 |
| 2020 | synERGY: Cross-correlation of operational and contextual data to timely detect and mitigate attacks to cyber-physical systems
Florian Skopik, Max Landauer, Markus Wurzenberger, Gernot Vormayr, Jelena Milosevic, Joachim Fabini, Wolfgang Prüggler, Oskar Kruschitz, Benjamin Widmann, Kevin Truckenthanner, Stefan Rass, Michael Simmer, Christoph Zauner |
J. Inf. Secur. Appl. | 6 |
| 2019 | Rax: Deep Reinforcement Learning for Congestion ControlabstractThis paper proposes Reactive Adaptive eXperience based congestion control (Rax), a new method of congestion control (CC) that uses online reinforcement learning (RL) to maintain an optimum congestion window with respect to a given reward function and based on current network conditions. We use a neural network based approach that can be initialized either with random weights or with a previously trained neural network to improve stability and convergence time. As the processing of rewards in CC depends on the arrival of acknowledgements, which are delayed and received one by one, the problem is not suitable for current implementations of Deep RL. As a remedy we propose Partial Action Learning, a formulation of Deep RL that supports delayed and partial rewards. We show that our method converges to a stable, close-to-optimum solution within minutes and outperforms existing CC algorithms in typical networks. Thus, this paper demonstrates that Deep RL can be done online and can compete with classic CC schemes such as Cubic. Maximilian Bachl, Tanja Zseby, Joachim Fabini |
ICC | 3 |
| 2018 | To Trust or Not to Trust: Data Origin Authentication for Group Communication in 5G NetworksabstractWith the expected massive increase in high-bandwidth applications over 5G cellular networks, the efficient use of radio-network and core-network infrastructures becomes essential. Group communication is a method for transmitting data efficiently from one source to many receivers. In this paper we study the security provided in terms of authenticity and integrity for group communication in 5G networks. We identify that the current security solutions involve trusting the benignity and operational security of network operators as well as its users since the current security solutions do not provide data origin authentication. Based on this insight, we present two attack scenarios in which an adversary exploits the provided level of authenticity such that arbitrary data can be injected maliciously while receivers consider the data as if they were sent by the claimed source. We evaluate potential approaches to provide data origin authentication in 5G and show that future research is required for a general solution. Robert Annessi, Joachim Fabini, Tanja Zseby |
ARES | 2 |
| 2017 | A New Direction for Research on Data Origin Authentication in Group Communication
Robert Annessi, Tanja Zseby, Joachim Fabini |
CANS | 3 |
| 2017 | It's about Time: Securing Broadcast Time Synchronization with Data Origin AuthenticationabstractDue to the increasing dependency of critical infrastructure on synchronized clocks, network time synchronization protocols have become an attractive target for attackers. We identify data origin authentication as the key security objective and therefore conduct a comprehensive, theoretical evaluation of data origin authentication schemes from different application fields with regard to their applicability to secure broadcast time synchronization. Some evaluated schemes were found to be susceptible to message delay attacks in the context of time synchronization - including TESLA, the approach currently favored by the IETF NTP working group and also on the shortlist of the P1588 Security Subcommittee for PTP. Two of the evaluated schemes, however, come somewhat close to meeting the evaluation criteria derived from our time synchronization specific threat analysis, and therefore qualify as promising candidates to secure broadcast time synchronization. Robert Annessi, Joachim Fabini, Tanja Zseby |
ICCCN | 2 |
| 2016 | The Right Time: Reducing Effective End-to-End Delay in Time-Slotted Packet-Switched NetworksabstractModern access network technologies like Long Term Evolution (LTE) and High Speed Packet Access (HSPA) use time-slotting mechanisms to optimize resource sharing and overall network performance. In time-slotted networks, the one-way delay of all packets in a packet stream depends on the absolute point in time when the first packet of the stream is sent. With appropriate feedback signals, applications can exploit this effect to reduce their effective end-to-end delay. Time-critical applications such as real-time sensor data acquisition or voice-over-IP (VoIP) communications can shift their acquisition interval in order to adapt to the network timing. Information about the actual time-slotting periods can be gathered by active network measurements or through implementation of cross-layer information exchange. In this paper, a method is proposed to determine the optimum send time for particular destinations and to support applications in adjusting their send time accordingly. Theoretical findings are supported by the offline analysis of measurement data and by a proof-of-concept implementation that confirms the feasibility and effectiveness of the proposed solution in operational LTE and HSPA networks. Joachim Fabini, Tanja Zseby |
IEEE/ACM Trans. Netw. | 1 |
| 2009 | The Importance of Being Really Random: Methodological Aspects of IP-Layer 2G and 3G Network Delay AssessmentabstractThe accurateness of round-trip- and one way delay measurements for 2G and 3G networks rely to a much larger extent on employing a sound methodological framework than this is the case for other types of networks. Typical mobile access networks differ significantly from core networks, most prominently with respect to delay. In this paper we present payload-dependent delay measurement results for public 2G and 3G networks which illustrate that accurate IP-layer delay measurements in mobile networks must use high sample counts and randomness in start times for uplink and for downlink. Most notably this concerns ICMP round-trip delay measurements which, due to the synchronization of ICMP requests with the network clock when leaving the mobile network's uplink, fail to meet the random start time criterion for ICMP replies in the downlink (or vice-versa). This synchronization effect leads to significant clustering of one-way delay values for the reply leg and causes minor delay differences in the core network to have potential significant impact on ICMP round-trip delays. Therefore, highly accurate simulations and emulations must model uplink and downlink of time-slotted networks as two interrelated links based on a common timebase. Joachim Fabini, Lukas Wallentin, Peter Reichl |
ICC | 1 |
| 2009 | The Illusion of Being Deterministic - Application-Level Considerations on Delay in 3G HSPA Networks
Joachim Fabini, Wolfgang Karner, Lukas Wallentin, Thomas Baumgartner |
Networking | 1 |
| 2008 | Location-based assisted handover for the IP Multimedia Subsystem
Joachim Fabini, Rudolf Pailer, Peter Reichl |
Comput. Commun. | 1 |
| 2006 | Terminal-Centric Location Services for the IP Multimedia SubsystemabstractLocation-based services in 3G and beyond networks depend on high-accuracy location data. Today's 2G and 3G access networks determine user location in a network-centric manner. The accuracy of these location mechanisms depends on the radio infrastructure near the user's geographical position and is typically limited to hundreds or thousands of meters. This precision is inadequate for typical location-based services like city maps or route planners. In this paper we present a terminal-centric location enabler that integrates seamless with the existing IP multimedia subsystem presence architecture and interoperates with network-centric location mechanisms. We argue that the user terminal itself, equipped with location sources like GPS receivers, can determine the geographical position with an optimum of accuracy. In consequence, the user terminal should be used as the primary source for location information. We extend the existing and well-known concept of presence by defining location as a type of presence information that is of interest to users. Terminal-based triggers and filters reduce the amount of traffic on the air interface and enable a scalable location architecture. We present the implementation of a J2ME-based mobile terminal prototype, which uses GPS as location source and interfaces with IMS location services Joachim Fabini, Marco Happenhofer, Rudolf Pailer |
VTC Spring | 1 |