EDBT 2026 Demo / reviewers in the wild / expert
Mathias Fischer 0001
dblp:76/3402-1
· DBLP profile ↗
71ranked-venue papers
6as first author
35since 2021 · last 2026
0000-0002-6254-8288ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 33 · 1 first-author · 16 since 2021Computer networks · 29 · 4 first-author · 16 since 2021Systems, architecture and hardware · 4 · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | SatBleed: Security of Commoditized Communication Modules in Satellites
Ulysse Planta, Julian Rederlechner, Martin Strohmeier, Mathias Fischer 0001, Ali Abbasi 0002 |
SP | 4 |
| 2025 | C2 Beaconing Detection via AI-Based Time-Series Analysis
Jeetesh Gupta, Jan Pfeifer, Anum Talpur, Mathias Fischer 0001 |
ARES (2) | 4 |
| 2025 | Enhancing Binary Code Similarity Analysis for Software Updates: A Contextual Diffing Framework
August See, Moritz Mönnich, Mathias Fischer 0001 |
AsiaCCS | 3 |
| 2025 | QUIC-Aware Load Balancing: Attacks and MitigationsabstractQUIC is widely used on the web and is seen as a successor to TCP, with significant improvements to speed, reliability, and security. However, as IP addresses and ports no longer identify QUIC connections but use Connection Identifiers (CIDs), load balancing becomes challenging. In this work, we introduce two novel attacks for revealing the server count behind QUIC-aware load balancers and breaking the unlinkability guarantees that prevent tracking of structured CIDs. We conducted tests on real-world deployments to assess the feasibility of existing and novel attacks. Our results indicate that our attack is more effective in estimating the number of servers behind load balancers than existing work. Furthermore, the data of our second novel attack suggests that almost all observed load balancers are vulnerable, allowing user tracking across networks. This work also introduces novel countermeasures to mitigate these attacks while being faster than existing approaches for enabling secure load balancing. Liliana Kistenmacher, Anum Talpur, Mathias Fischer 0001 |
DSN | 3 |
| 2025 | MITHRIL: Multi-Objective Topology Synthesis with Reinforcement Learning for Critical NetworksabstractMission-critical systems (MCSs) have evolving latency and reliability requirements, even under challenging conditions such as node and link failures and cyberattacks. To fulfill these requirements, emerging networking technologies like the IEEE 802.1 Time-Sensitive Networking standards provide several protocols for deterministic communication on top of off-the-shelf Ethernet equipment. While Ethernet-based networks offer better configurability than legacy fieldbus systems, they still require the design of adequate topologies for MCSs that fulfill various design objectives such as optimal quality of service and increased resilience against challenges. In this paper, we propose MITHRIL, a multi-objective topology synthesis model with reinforcement learning. It leverages deep reinforcement learning to optimize Ethernet-based topologies in terms of resilience and effectiveness, while adhering to realistic MCS constraints. Our evaluation indicates that MITHRIL enhances the failure and attack tolerance of network topologies while reducing the associated costs, compared to well-connected topologies and other heuristics from the literature. Oliver Wandschneider, Anum Talpur, Mathias Fischer 0001, Doganalp Ergenç |
LCN | 3 |
| 2025 | Rubber Ducky Station: Advancing HID Attacks with Visual Data Exfiltration
August See, Thimo Grußendorf, Jona Laudan, Mathias Fischer 0001 |
SEC (1) | 4 |
| 2025 | Flatdc: Automatic Schema Reverse Engineering of FlatBuffers
August See, Benedikt Ostendorf, Lilly Sell, Mathias Fischer 0001 |
SEC (2) | 4 |
| 2025 | Simplifying distributed application deployment at the edge through software-defined overlay networksabstractThe need for low latency, bandwidth efficiency, and privacy has driven the deployment of distributed applications to the network edge. However, edge environments introduce concrete challenges such as limited infrastructure control, constrained connectivity due to NAT or firewalls, and the heterogeneity of devices and network conditions. This paper introduces a software-defined overlay networking (SDON) middleware that addresses these issues by simplifying the development and deployment of edge applications through centralized control and dynamic overlay management. SDON allows applications to define high-level requirements, such as node and link characteristics and the network topology. These requirements are translated into device-specific configurations and enforced across suitable edge devices. We implemented our SDON middleware as a fully functional software and evaluated it in two edge computing use cases: i) routing for video streaming across middleboxed edge devices and ii) computation offloading on heterogeneous edge devices. Our results show that deployments via SDON, with centrally enforced optimizations, improve application performance by reducing mean streaming latency by 20 % and computation times by 22 %. Heiko Bornholdt, Kevin Röbert, Stefan Schulte 0002, Janick Edinger, Mathias Fischer 0001 |
Comput. Commun. | 5 |
| 2024 | SOVEREIGN - Towards a Holistic Approach to Critical Infrastructure ProtectionabstractIn the digital age, cyber-threats are a growing concern for individuals, businesses, and governments alike. These threats can range from data breaches and identity theft to large-scale attacks on critical infrastructure. The consequences of such attacks can be severe, leading to financial losses, threats to national security, and the loss of lives. This paper presents a holistic approach to increase the security of critical infrastructures. For that, we propose an open, self-configurable, and AI-based automated cyber-defense platform that runs on specifically hardened devices and own hardware, can be deeply embedded in critical infrastructures and provides full visibility on network, endpoints, and software. In this paper, starting from a thorough analysis of related work, we describe the vision of our SOVEREIGN platform in the form of an architecture, discuss individual building blocks, and evaluate it qualitatively with respect to our requirements. Georg T. Becker, Thomas Eisenbarth 0001, Hannes Federrath, Mathias Fischer 0001, Nils Loose, Simon Ott, Joana Pecholt, Stephan Marwedel, Dominik Meyer, Jan Stijohann, Anum Talpur, Matthias Vallentin |
ARES | 4 |
| 2024 | DTN-Core: Towards a Framework for Designing and Operating Digital Twin NetworksabstractThis work presents, DTN-Core, a flexible and verifiable approach to create a network of digital twin models. The goal is to provide a generic design that supports location-independency and heterogeneity of messaging protocols, data formats, and data granularity. We also analyze data compatibility issues that may arise when coupling digital twins. A combination of data and behavioral coupling is used to represent each digital twin. A Timed automata approach is used as a real-time model that describes the behavior of the Digital Twin Network (DTN). System properties are defined using Timed Computation Tree Logic (TCTL) and the model is verified using an existing model-checking tool UPPAAL. Majd Latah, Mathias Fischer 0001 |
CNSM | 2 |
| 2024 | Transparent TSN for Agnostic End-hosts via P4-based Traffic Characterization at SwitchesabstractMission-critical networks currently face a transition from legacy network protocols to advanced time-sensitive networking (TSN) standards. TSN guarantees reliable and deterministic communication using off-the-shelf Ethernet equipment. However, end-hosts must be TSN-aware and may pose security risks by arbitrarily over-allocating resources. Integrating central instances like a software-defined networking (SDN) controller into TSN networks to streamline network management presents a promising solution. This raises concerns regarding latency in communication between switches and the controller, as well as among switches themselves. To address this, we propose an approach that renders TSN transparent to end-hosts, eliminating the need for their involvement in resource reservations. We embed packet processing logic in P4-enabled TSN switches to characterize network traffic intelligently. This enables switches to allocate network resources autonomously and adjust real-time traffic handling mechanisms. Leveraging P4 storage structures introduces statefulness for traffic characterization computing within the inherently stateless P4 language. Our experiments demonstrate that our P4-enhanced switches require a minimal 0.014 MB of switch memory to distinguish between periodic and non-periodic traffic with an 80% precision while incurring a mere 0.2 ms forwarding latency per packet. Cornelia Brülhart, Nurefsan Sertbas Bülbül, Nils Ole Tippenhauer, Mathias Fischer 0001 |
LCN | 4 |
| 2024 | Encrypted Endpoints: Defending Online Services from Illegitimate Bot AutomationabstractAutomated usage of web services by programs, known as bots, poses risks such as data scraping, spam, and cyber attacks. For instance, X suffers from millions of bot accounts typically controlled by relatively fewer adversarial organizations to create fake likes and comments. The most widely used solution to distinguish humans from bots (CAPTCHA) is perishing due to advances in machine learning. Obfuscation techniques in binaries, applications, or websites are designed to impede the creation of bots but fail to prevent their scalability. Bypassing these measures often requires only a one-time effort. We propose encrypted endpoints as a novel strategy to combat the scalability of web bots, particularly in scenarios where bots leverage multiple accounts. For that we assign unique endpoints (URLs) to each user account, thereby restricting bot applicability across different accounts and necessitating the extraction of account-specific endpoints per bot instance. Our approach is applicable to a wide range of services utilizing endpoints, including desktop and mobile applications, web applications, and even static or HTML-only websites. We implemented our approach directly within a backend framework and observed that the latency overhead is less than 0.1ms per request, which constitutes less than 1% of the total request time. Our solution, developed as simple middleware, can be easily integrated in existing projects with low effort. Additionally, we have extended our approach to the Jinja2 template engine, thereby supporting encrypted endpoints for websites out of the box. Our analysis indicates that our approach not only effectively protects against simple bots but also, when coupled with obfuscation techniques, further impedes bot creation. August See, Kevin Röbert, Mathias Fischer 0001 |
RAID | 3 |
| 2024 | Detecting Web Bots via Keystroke Dynamics
August See, Adrian Westphal, Cornelius Weber, Mathias Fischer 0001 |
SEC | 4 |
| 2024 | Privacy-aware data aggregation using Functional Encryption
Sehrish Shafeeq, Mathias Fischer 0001 |
TrustCom | 2 |
| 2023 | Binary Sight-Seeing: Accelerating Reverse Engineering via Point-of-Interest-BeaconsabstractReverse engineering is still a largely manual and very time-consuming process. To ease this process, beacons in the form of known instructions or code patterns are commonly used to guide reverse engineers in dissecting a binary. However, if done manually, identifying high-quality beacons can be very laborious. This paper introduces a novel method to automatically identify the so-called Points-of-Interests (POIs) in binaries. POIs are instructions that interact with data specified by the analyst known a priori, e.g., via sandbox analysis or expert knowledge. These POIs are then used as beacons to guide analysts to find interesting parts of the binary that interact with the specified data, e.g., the encryption routine. Compared to taint analysis, our approach offers simplicity while delivering a select few, yet high-quality beacons, thereby establishing clear focus points. Based on our proposed method, we implemented two types of prototypes. First, a prototype whose output can be loaded via custom plugins into IDA and Ghidra, i.e., two of the more popular reverse-engineering tools. We show the applicability of our method via the prototype by summarizing the insights of the analysis for the Locky and Wannacry ransomware as one of the potential application domains, i.e., malware reverse engineering. Second, we also introduced a prototype that monitors P2P botnets in a fully-automated manner by directly instrumenting the botnet malware without requiring manual reverse-engineering. We demonstrate the effectiveness of our prototype by applying it to the ZeroAccess, Sality, Nugache, and Kelihos botnets and summarize our findings in this paper. Using our approach, we effortlessly found the encryption function in the two analyzed ransomware. For P2P botnets, our monitoring prototype could enumerate the bots in all analyzed botnets, only relying on our POIs. August See, Maximilian Gehring, Mathias Fischer 0001, Shankar Karuppayah |
ACSAC | 3 |
| 2023 | Preemptive DoS attacks on Time Sensitive NetworksabstractTime-sensitive networking (TSN) is a promising technology for real-time communication in industrial and automotive networks. One of its key features is frame preemption, which allows high-priority traffic to interrupt the transmission of low-priority traffic, thereby reducing the delay of high-priority critical traffic. However, the deterministic nature of TSN frame preemption also makes it vulnerable to denial of service (DoS) attacks, which can severely impact flow quality of service (QoS) by increasing delays and packet loss. In this paper, we introduce the concept of preemptive DoS attacks and evaluate their impact on TSN QoS performance. We describe a strategy that attackers can use to estimate the preemption scheme configured in the switch and then demonstrate how an active attacker can use this information to degrade TSN QoS. Our simulation results indicate that even a single attacker can significantly deteriorate the QoS of TSN traffic. It is important to address this vulnerability in TSN and develop countermeasures to prevent preemptive DoS attacks from occurring. Nurefsan Sertbas Bülbül, Mathias Fischer 0001 |
GLOBECOM | 2 |
| 2023 | Low-Latency TLS 1.3-Aware Hole PunchingabstractCurrent P2P applications using real-time communication often waste 1–2 RTTs when communicating via TLS-secured protocols. This waste is caused by middleboxes such as firewalls and network address translators that make up to 87 % of nodes non-routable from the Internet. Middlebox traversal protocols like hole punching must be applied first to establish a connection to these nodes. Only then-after a node has become routable-protocols such as DTLS or QUIC can start securing the connection with a TLS-based handshake. This sequential use of hole punching and TLS introduces a redundant handshake overhead that delays connection establishment. This paper presents a middlebox traversal approach that piggybacks TLS 1.3-based handshakes to reduce connection establishment time. The approach does not require changes to the actual TLS-based handshake and thus does not negatively impact the protocol's security. As a result, our approach saves 1–2 RTTs for setting up TLS-secured communication through middleboxes and prevents attacks on the actual middlebox traversal process. Heiko Bornholdt, Kevin Röbert, Mathias Fischer 0001 |
ICC | 3 |
| 2023 | Tell Me More: Black Box Explainability for APT Detection on System Provenance GraphsabstractNowadays, companies, critical infrastructure and governments face cyber attacks every day ranging from simple denial-of-service and password guessing attacks to complex nationstate attack campaigns, so-called advanced persistent threats (APTs). Defenders employ intrusion detection systems (IDSs) among other tools to detect malicious activity and protect network assets. With the evolution of threats, detection techniques have followed with modern systems usually relying on some form of artificial intelligence (AI) or anomaly detection as part of their defense portfolio. While these systems are able to achieve higher accuracy in detecting APT activity, they cannot provide much context about the attack, as the underlying models are often too complex to interpret. This paper presents an approach to explain single predictions (i. e., detected attacks) of any graphbased anomaly detection systems. By systematically modifying the input graph of an anomaly and observing the output, we leverage a variation of permutation importance to identify parts of the graph that are likely responsible for the detected anomaly. Our approach treats the anomaly detection function as a black box and is thus applicable to any whole-graph explanation problems. Our results on two established datasets for APT detection (StreamSpot & DARPA TC Engagement Three) indicate that our approach can identify nodes that are likely part of the anomaly. We quantify this through our area under baseline (AuB) metric and show how the AuB is higher for anomalous graphs. Further analysis via the Wilcoxon rank-sum test confirms that these results are statistically significant with a p-value of 0.0041%. Felix Welter, Florian Wilkens, Mathias Fischer 0001 |
ICC | 3 |
| 2023 | Moving Target Defense for Service-Oriented Mission-Critical NetworksabstractModern mission-critical systems (MCS) are increasingly softwarized and interconnected. As a result, their complexity increased, and so their vulnerability against cyber-attacks. The current adoption of virtualization and service-oriented architectures (SOA) in MCSs provides additional flexibility that can be leveraged to withstand and mitigate attacks, e.g., by moving critical services or data flows. This enables the deployment of strategies for moving target defense (MTD), which allows stripping attackers of their asymmetric advantage from the long reconnaissance of MCSs. However, it is challenging to design MTD strategies, given the diverse threat landscape, resource limitations, and potential degradation in service availability. In this paper, we combine two optimization models to explore feasible service configurations for SOA-based systems and to derive subsequent MTD actions with their time schedule based on an attacker-defender game. Our results indicate that even for challenging and diverse attack scenarios, our models can defend the system by up to 90% of the system operation time with a limited MTD defender budget. Doganalp Ergenç, Florian Schneider 0001, Peter Kling, Mathias Fischer 0001 |
ICCCN | 4 |
| 2023 | Towards Developing Resilient and Service-oriented Mission-critical SystemsabstractMission-critical systems (MCSs) have embraced new design paradigms such as service-oriented architecture (SOA) and IEEE 802.1 Time-sensitive Networking (TSN). These approaches tackle the static and closed-loop design and configuration of MCSs to address their strict performance and resilience requirements. While SOA enables the dynamic placement of critical services over virtualized hardware, TSN provides several protocols to establish deterministic communication over standard Ethernet equipment. This paper presents a prototype utilizing SOA and TSN to design flexible and fault-tolerant MCSs. It demonstrates the benefits of dynamic service migration and time-sensitive redundancy protocols to increase the resilience of MCSs against node and link failures, respectively. Moreover, it presents additional advanced functionalities like optimal service distribution and security monitoring for new TSN protocols. Doganalp Ergenç, Cornelia Brülhart, Mathias Fischer 0001 |
NetSoft | 3 |
| 2023 | Detecting Web Bots via Mouse Dynamics and Communication Metadata
August See, Tatjana Wingarz, Matz Radloff, Mathias Fischer 0001 |
SEC | 4 |
| 2023 | SEBDA: A Secure and Efficient Blockchain Based Data Aggregation Scheme
Sehrish Shafeeq, Mathias Fischer 0001 |
SECRYPT | 2 |
| 2022 | Polymorphic Protocols at the Example of Mitigating Web Bots
August See, Leon Fritz, Mathias Fischer 0001 |
ESORICS (3) | 3 |
| 2022 | Reinforcement Learning assisted Routing for Time Sensitive NetworksabstractRecent developments in real-time critical systems pave the way for different application scenarios such as Industrial IoT with various quality-of-service (QoS) requirements. The most critical common feature of such applications is that they are sensitive to latency and jitter. Thus, it is desired to perform flow placements strategically considering application requirements due to limited resource availability. In this paper, path computation for time-sensitive networks is investigated while satisfying individual end-to-end delay requirements of critical traffic. The problem is formulated as a mixed-integer linear program (MILP) which is NP-hard with exponentially increasing computational complexity as the network size expands. To solve the MILP with high efficiency, we propose a reinforcement learning (RL) algorithm that learns the best routing policy by continuously interacting with the network environment. The proposed learning algorithm determines the variable action set at each decision-making state and captures different execution times of the actions. The reward function in the proposed algorithm is carefully designed for meeting individual flow deadlines. Simulation results indicate that the proposed reinforcement learning algorithm can produce near-optimal flow allocations (close by ~1.5 %) and scales well even with large topology sizes. Nurefsan Sertbas Bülbül, Mathias Fischer 0001 |
GLOBECOM | 2 |
| 2022 | Distributed Bio-inspired Configuration of Virtualized Mission-critical NetworksabstractModern mission-critical embedded systems such as autonomous cars and avionics consist of a multitude of intercon-nected nodes and services with various QoS requirements. Virtu-alization provides further flexibility, configurability, and isolation to such systems by enabling dynamic service placement to off-the-shelf virtualized hardware. Although the service-oriented systems usually rely on a single centralized controller for the service configuration and maintenance as well as establishing their inter-communication, more autonomous and self-driven control schemes are required to cope with their increasing scalability and heterogeneity. Accordingly, bio-inspired algorithms (BIAs) offer distributed self-organization methods by adapting the natural phenomena such as collaborating bee and ant colonies for the requirements of modern networked systems. In this paper, we leverage ant-colony optimization to solve the joint service allocation and routing (JSAR) problem distributedly, where mixed-criticality services should be distributed and communicated under strict QoS requirements on a virtualized, physical network. We also introduce an integer linear program (ILP) to find the optimal solution for JSAR that can be computed by a centralized controller. Our experiments show that our heuristics successfully solve JSAR for even scaling scenarios. Besides, utilizing different redeployment strategies, they can be adapted to obtain near-optimal results in terms of resource efficiency. Doganalp Ergenç, David Sorejevic, Mathias Fischer 0001 |
GLOBECOM | 3 |
| 2022 | Deep Learning-based Multi-PLC Anomaly Detection in Industrial Control SystemsabstractIndustrial control systems (ICSs) have become more complex due to their increasing connectivity, heterogeneity and, autonomy. As a result, cyber-threats against such systems have been significantly increased as well. Since a compromised industrial system can easily lead to hazardous safety and security consequences, it is crucial to develop security countermeasures to protect coexisting IT systems and industrial physical processes being involved in modern ICSs. Accordingly, in this study, we propose a deep learning-based semantic anomaly detection framework to model the complex behavior of ICSs. In contrast to the related work assuming only simpler security threats targeting individual controllers in an ICS, we address multi-PLC attacks that are harder to detect as requiring to observe the overall system state alongside single-PLC attacks. Using industrial simulation and emulation frameworks, we create a realistic setup representing both the production and networking aspects of industrial systems and conduct some potential attacks. Our experimental results indicate that our model can detect single-PLC attacks with ~95% accuracy and multi-PLC attacks with 80% accuracy and nearly 1% false positive rate. Philip Gawehn, Doganalp Ergenç, Mathias Fischer 0001 |
GLOBECOM | 3 |
| 2022 | Towards SDN-based Dynamic Path Reconfiguration for Time Sensitive NetworkingabstractFuture networks will need to support a large number of low-latency flows. In time-sensitive networks (TSN), paths for data flows are usually established at startup time of an application and remain untouched until the flow ends. There is no way to migrate existing flows easily to alternative paths without inducing significant additional delay or wasting resources. Therefore, the resource-utilization of TSN might degrade over time leading to a sub-optimal flow assignment. In this paper we address this problem by combining Software-defined Networking (SDN) that provides better control on network flows with TSN to be able to seamlessly migrate time-sensitive flows. We propose a SDN-based dynamic path reconfiguration algorithm for accommodating TSN flows and formulate it as optimization problem. By exploiting the control plane’s global view, we evaluate different dynamic path configuration strategies under deterministic communication requirements. Our simulation results indicate that reconfiguring the flow assignments from time to time can improve the latency of time-sensitive flows and can increase the number of flows embedded in the network in worst-case scenarios. Nurefsan Sertbas Bülbül, Doganalp Ergenç, Mathias Fischer 0001 |
NOMS | 3 |
| 2022 | Passive, Transparent, and Selective TLS Decryption for Network Security Monitoring
Florian Wilkens, Steffen Haas, Johanna Amann, Mathias Fischer 0001 |
SEC | 4 |
| 2022 | Introduction to the Special Section on Recent Advances in Networks and Distributed Systemsabstractintroduction Share on Introduction to the Special Section on Recent Advances in Networks and Distributed Systems Authors: Mathias Fischer Universität Hamburg, Hamburg, Germany Universität Hamburg, Hamburg, GermanySearch about this author , Winfried Lamersdorf Universität Hamburg, Hamburg, Germany Universität Hamburg, Hamburg, GermanySearch about this author , Jörg Liebeherr University of Toronto, Toronto, Ontario, Canada University of Toronto, Toronto, Ontario, CanadaSearch about this author , Max Mühlhäuser TU Darmstadt, Darmstadt, Germany TU Darmstadt, Darmstadt, GermanySearch about this author Authors Info & Claims ACM Transactions on Internet TechnologyVolume 22Issue 4November 2022 Article No.: 93pp 1–3https://doi.org/10.1145/3584743Published:15 March 2023Publication History 0citation0DownloadsMetricsTotal Citations0Total Downloads0Last 12 Months0Last 6 weeks0 Get Citation AlertsNew Citation Alert added!This alert has been successfully added and will be sent to:You will be notified whenever a record that you have chosen has been cited.To manage your alert preferences, click on the button below.Manage my AlertsNew Citation Alert!Please log in to your account Save to BinderSave to BinderCreate a New BinderNameCancelCreateExport CitationPublisher SiteGet Access Mathias Fischer 0001, Winfried Lamersdorf, Jörg Liebeherr, Max Mühlhäuser |
ACM Trans. Internet Techn. | 1 |
| 2021 | Detection of Brute-Force Attacks in End-to-End Encrypted Network TrafficabstractNetwork intrusion detection systems (NIDSs) can detect attacks in network traffic. However, the increasing ratio of encrypted connections on the Internet restricts their ability to observe such attacks. This paper proposes a completely passive method that allows to detect brute-force attacks in encrypted traffic without the need to decrypt it. For that, we propose five novel metrics for attack detection which quantify metadata like packet size or packet timing. Pascal Wichmann, Matthias Marx, Hannes Federrath, Mathias Fischer 0001 |
ARES | 4 |
| 2021 | Mitigation of IPv6 Router Spoofing Attacks with P4abstractThe IPv6 protocol will sooner or later replace IPv4 to cope with an exponentially increasing number of connected devices. Some of the most significant functions of IPv6 networks are network discovery, maintenance, and routing mechanisms to promote auto-configuration of the network with less manual effort. Network Discovery Protocol (NDP) is an important protocol in IPv6 to identify the relationships between different neighboring devices in a network. However, it is also subject to spoofing and man-in-the-middle attacks. This paper implements an attack detection and mitigation strategy called Router Advertisement Guard (RA-Guard) in P4 to defend IPv6 networks against router spoofing attacks directly on the data plane. In contrast to very few proprietary RA-Guard implementations with limited details, we consider different scenarios to exploit IPv6 packet structure and publish our implementation open-source. The experiments show that our P4-based implementation can detect and mitigate spoofing attacks leveraging RA-Guard together with its control plane extensions. Moritz Mönnich, Nurefsan Sertbas Bülbül, Doganalp Ergenç, Mathias Fischer 0001 |
ANCS | 4 |
| 2021 | Analysing Leakage during VPN Establishment in Public Wi-Fi NetworksabstractThe use of public Wi-Fi networks can reveal sensitive data to both operators and bystanders. A VPN can prevent this. However, a machine that initiates a connection to a VPN server might already leak sensitive data before the VPN tunnel is fully established. Furthermore, it might not be immediately possible to establish a VPN connection if the network requires authentication via a captive portal, thus increasing the leakage potential. In this paper we examine both issues. For that, we analyse the behaviour of native and third-party VPN clients on various platforms, and introduce a new method called selective VPN bypassing to avoid captive portal deadlocks. Christian Burkert, Johanna Ansohn McDougall, Hannes Federrath, Mathias Fischer 0001 |
ICC | 4 |
| 2021 | On the Reliability of IEEE 802.1CB FRERabstractThe introduction of IEEE Time-sensitive Networking (TSN) enables the design of real-time and mission-critical networks based on Ethernet technologies. Apart from providing necessary tools for near-deterministic scheduling, TSN comes with further functionalities for configurability, security, and reliability. IEEE 802.1CB Frame Replication and Elimination (FRER) is the only protocol in the TSN toolbox for adding fault-tolerance via sending the same packets via redundant paths. Although its core functions are defined by the standard, its effective use mainly depends on the actual deployment scenario and the path selection strategy. In this paper, we show that FRER can induce unintentional elimination of packets packets when the paths chosen for a particular packet flow are non-disjoint. We propose the new metric reassurance that can be used in FRER path selection. Besides, we propose an additional enhancement to FRER that can prevent unintended packet eliminations independent from the deployment scenario. Our simulation results indicate that the reassurance-based path selection performs better than random or maximum-disjoint path selection in random failure scenarios. Doganalp Ergenç, Mathias Fischer 0001 |
INFOCOM | 2 |
| 2021 | SDN-based Self-Configuration for Time-Sensitive IoT NetworksabstractThe convergence of Information Technology (IT) and Industrial Operations Technology (OT) results in efficient network management solutions for automotive and industrial automation environments. However, configuring real-time Ethernet networks while maintaining the desired QoS is challenging due to the dynamic nature of OT networks and the high number of configuration parameters. This paper introduces a Software-Defined Network (SDN)-based self-configuration framework for the time-sensitive networks (TSNs). Unlike standard TSN, we remove end-host-related dependencies and put streams initially on default paths to extract traffic characteristics by monitoring network traffic at edge switches. Communicated to a central SDN controller, these characteristics allow moving streams to optimal paths while maintaining hard real-time guarantees, for which we also formulate an optimization problem. According to the results, although the proposed approach increases the average delay of critical frames by less than 1%, a certain level of real-time guarantee can be provided without prior knowledge of the streams. Nurefsan Sertbas Bülbül, Doganalp Ergenç, Mathias Fischer 0001 |
LCN | 3 |
| 2021 | Service-Based Resilience via Shared Protection in Mission-Critical Embedded NetworksabstractMission-critical networks, which for example can be found in autonomous cars and avionics, are complex systems with a multitude of interconnected embedded nodes and various service demands. Their resilience against failures and attacks is a crucial property and has to be already considered in their design phase. In this paper, we introduce a novel approach for optimal joint service allocation and routing, leveraging virtualized embedded devices and shared backup capacity for the fault-tolerant design of mission-critical networks. This approach operates in phases utilizing multiple optimization models. Furthermore, we propose a new heuristic that ensures resource efficiency and fault-tolerance against single node and link failures as pre-requisite for resilience. Our experiments for different application scenarios indicate that our heuristic achieves results close to the optimum and provides 50% of capacity gain compared to a dedicated capacity protection scheme. Moreover, our heuristic ensures fault-tolerance against at least 90% of all potential single node failures. Doganalp Ergenç, Jacek Rak, Mathias Fischer 0001 |
IEEE Trans. Netw. Serv. Manag. | 3 |
| 2020 | Enhanced performance for the encrypted web through TLS resumption across hostnamesabstractTLS can resume previous connections via abbreviated resumption handshakes that decrease the delay and save expensive cryptographic operations by reusing cryptographic TLS state from previous connections. TLS version 1.3 recommends avoiding resumption handshakes, when connecting to a different hostname. In this work, we reassess this recommendation, as we find that sharing cryptographic TLS state across hostnames is a common practice on the web. We propose a TLS extension that allows the server to inform the client about TLS state sharing with other hostnames. This information enables the client to efficiently resume TLS sessions across hostnames. Our evaluation indicates that our TLS extension provides performance gains for the web. For example, about 58.7% of the 20.24 full TLS handshakes that are required to retrieve an average website on the web can be converted to resumed connection establishments which reduces the CPU time consumed for TLS connection establishments by 44%. Furthermore, our TLS extension accelerates the connection establishment with an average website by up to 30.7%. Thus, our proposal significantly reduces the (energy) costs and the delay overhead in the encrypted web. Erik Sy, Moritz Mönnich, Tobias Mueller, Hannes Federrath, Mathias Fischer 0001 |
ARES | 5 |
| 2020 | Service-Based Resilience for Embedded IoT NetworksabstractEmbedded IoT networks are the backbone of safety-critical systems like smart factories, autonomous vehicles, and airplanes. Therefore, resilience against failures and attacks should be a prior concern already in their design stage. In this study, we introduce a service-based network model as an MILP optimization problem for the efficient deployment of a service overlay to the embedded network by meeting QoS and resilience requirements. We show the complexity and boundaries of the problem and propose several heuristics to relax the service deployment phase and increase the fault-tolerance against node and link failures. Our results indicate that the heuristics achieve results close to the optimum for small sizes of the problem with up to 10^8 time faster solution time. We also show that the heuristics can solve larger problem sizes and can maintain the service availability for 85% of all potential single node failures. Doganalp Ergenç, Jacek Rak, Mathias Fischer 0001 |
DSN | 3 |
| 2020 | SDN/NFV-based DDoS Mitigation via PushbackabstractDistributed Denial of Service (DDoS) attacks aim at bringing down or decreasing the availability of services for their legitimate users, by exhausting network or server resources. It is difficult to differentiate attack traffic from legitimate traffic as the attack can come from distributed nodes that additionally might spoof their IP addresses. Traditional DoS mitigation solutions fail to defend all kinds of DoS attacks and huge DoS attacks might exceed the processing capacity of routers and firewalls easily. The advent of Software-defined Networking (SDN) and Network Function Virtualization (NFV) has brought a new perspective for network defense. Key features of such technologies like global network view and flexibly positionable security functionality can be used for mitigating DDoS attacks. In this paper, we propose a collaborative DDoS attack mitigation scheme that uses SDN and NFV. We adopt a machine learning algorithm from related work to derive accurate patterns describing DDoS attacks. Our experimental results indicate that our framework is able to differentiate attack and legitimate traffic with high accuracy and in near-realtime. Furthermore, the derived patterns can be used to create OpenFlow (OF) or Firewall rules that can be pushed back into the direction of the attack origin for more efficient and distributed filtering. Nurefsan Sertbas Bülbül, Mathias Fischer 0001 |
ICC | 2 |
| 2020 | Accountant: Protection of Data Integrity and Identification of Malicious Nodes in In-network Data Processing
David Jost, Mathias Fischer 0001 |
ICISSP | 2 |
| 2020 | Scan Correlation - Revealing distributed scan campaignsabstractPublic networks are exposed to port scans from the Internet. Attackers search for vulnerable services they can exploit. In large scan campaigns, attackers often utilize different machines to perform distributed scans, which impedes their detection and might also camouflage the actual goal of the scanning campaign. In this paper, we present a correlation algorithm to detect scans, identify potential relations among them, and reassemble them to larger campaigns. We evaluate our approach on real-world Internet traffic and our results indicate that it can summarize and characterize standalone and distributed scan campaigns based on their tools and intention. Steffen Haas, Florian Wilkens, Mathias Fischer 0001 |
NOMS | 3 |
| 2020 | Zeek-Osquery: Host-Network Correlation for Advanced Monitoring and Intrusion Detection
Steffen Haas, Robin Sommer, Mathias Fischer 0001 |
SEC | 3 |
| 2020 | Enhanced Performance and Privacy for TLS over TCP Fast OpenabstractAbstract Small TCP flows make up the majority of web flows. For them, the TCP three-way handshake induces significant delay overhead. The TCP Fast Open (TFO) protocol can significantly decrease this delay via zero round-trip time (0-RTT) handshakes for all TCP handshakes that follow a full initial handshake to the same host. However, this comes at the cost of privacy limitations and also has some performance limitations. In this paper, we investigate the TFP deployment on popular websites and browsers. We found that a client revisiting a web site for the first time fails to use an abbreviated TFO handshake in 40% of all cases due to web server load-balancing using multiple IP addresses. Our analysis further reveals significant privacy problems of the protocol design and implementation. Network-based attackers and online trackers can exploit TFO to track the online activities of users. As a countermeasure, we introduce a novel protocol called TCP Fast Open Privacy (FOP). TCP FOP prevents tracking by network attackers and impedes third-party tracking, while still allowing 0-RTT handshakes as in TFO. As a proof-of-concept, we have implemented the proposed protocol for the Linux kernel and a TLS library. Our measurements indicate that TCP FOP outperforms TLS over TFO when websites are served from multiple IP addresses. Erik Sy, Tobias Mueller, Christian Burkert, Hannes Federrath, Mathias Fischer 0001 |
Proc. Priv. Enhancing Technol. | 5 |
| 2019 | Towards Efficient Reconstruction of Attacker Lateral MovementabstractOrganization and government networks are a target of Advanced Persistent Threats (APTs), i.e., stealthy attackers that infiltrate networks slowly and usually stay undetected for long periods of time. After an attack has been discovered, security administrators have to manually determine which hosts were compromised to clean and restore them. For that, they have to analyze a large number of hosts. Florian Wilkens, Steffen Haas, Dominik Kaaser, Peter Kling, Mathias Fischer 0001 |
ARES | 5 |
| 2019 | Path-Based Optimization of NFV-Resource Allocation in SDN NetworksabstractNetwork Function Virtualization (NFV) and Software-defined Networking (SDN) enable flexible and scalable placement of Virtual Network Functions (VNFs). Existing approaches for optimal VNF selection, placement, and traffic routing use link-based approaches. In this paper, we introduce a path-based mathematical optimization model for the NFV Resource Allocation (NFV-RA-PB) problem. The output is an optimal routing based on paths in conjunction with selection and placement of Virtual Network Functions (VNFs). As the problem is known to be hard and not efficiently to solve, we further introduce a more efficient version of the problem (NFV-RA-KSP) that uses k-shortest paths as input. Our evaluation results indicate that our heuristic is able to reduce the solution space of the optimization problem significantly, and eliminates the exponential complexity of NFV-RA-PB. It allows the computation of near-optimal assignments in reasonable time. Malte Hamann, Mathias Fischer 0001 |
ICC | 2 |
| 2019 | Sandnet: Towards High Quality of Deception in Container-Based Microservice ArchitecturesabstractResponding to network security incidents requires interference with ongoing attacks to restore the security of services running on production systems. This approach prevents damage, but drastically impedes the collection of threat intelligence and the analysis of vulnerabilities, exploits, and attack strategies. We propose the live confinement of suspicious microservices into a sandbox network that allows to monitor and analyze ongoing attacks under quarantine and that retains an image of the vulnerable and open production network. A successful sandboxing requires that it happens completely transparent to and cannot be detected by an attacker. Therefore, we introduce a novel metric to measure the Quality of Deception (QoD) and use it to evaluate three proposed network deception mechanisms. Our evaluation results indicate that in our evaluation scenario in best case, an optimal QoD is achieved. In worst case, only a small downtime of approx. 3s per microservice (MS) occurs and thus a momentary drop in QoD to 70.26% before it converges back to optimum as the quarantined services are restored. Amr Osman, Pascal Bruckner, Hani Salah, Frank H. P. Fitzek, Thorsten Strufe, Mathias Fischer 0001 |
ICC | 6 |
| 2019 | Efficient Attack Correlation and Identification of Attack Scenarios based on Network-MotifsabstractAn Intrusion Detection System (IDS) to secure computer networks reports indicators for an attack as alerts. However, every attack can result in a multitude of IDS alerts that need to be correlated to see the full picture of the attack. In this paper, we present a correlation approach that transforms clusters of alerts into a graph structure on which we compute signatures of network motifs to characterize these clusters. A motif representation of attack characteristics is magnitudes smaller than the original alert data, but still allows to efficiently compare and correlate attacks with each other and with reference signatures. This allows not only to identify known attack scenarios, e.g., DDoS, scan, and worm attacks, but also to derive new reference signatures for unknown scenarios. Our results indicate a reliable identification of scenarios, even when attacks differ in size and at least slightly in their characteristics. Applied on real-world alert data, our approach can classify and assign attack scenarios of up to 96% of all attacks and can represent their characteristics using 1% of the size of the full alert data. Steffen Haas, Florian Wilkens, Mathias Fischer 0001 |
IPCCC | 3 |
| 2019 | QUICker Connection Establishment with Out-Of-Band Validation TokensabstractQUIC is a secure transport protocol that improves the performance of HTTPS. An initial QUIC handshake that enforces a strict validation of the client's source address requires two round-trips. In this work, we extend QUIC's address validation mechanism by an out-of-band validation token to save one round-trip time during the initial handshake. The proposed token allows sharing an address validation between the QUIC server and trusted entities issuing these tokens. This saves a round-trip time for the address validation. Furthermore, we propose distribution mechanisms for these tokens using DNS resolvers and QUIC connections to other hostnames. Our proposal can save up to 50% of the delay overhead of an initial QUIC handshake. Furthermore, our analytical results indicate that 363.6 ms in total can be saved for all connections required to retrieve an average website, if a round-trip time of 90 ms is assumed. Erik Sy, Christian Burkert, Tobias Mueller, Hannes Federrath, Mathias Fischer 0001 |
LCN | 5 |
| 2019 | A QUIC Look at Web TrackingabstractAbstract QUIC has been developed by Google to improve the transport performance of HTTPS traffic. It currently accounts for approx. 7% of the global Internet traffic. In this work, we investigate the feasibility of user tracking via QUIC from the perspective of an online service. Our analysis reveals that the protocol design contains violations of privacy best practices through which a tracker can passively and uniquely identify clients across several connections. This tracking mechanisms can achieve reduced delays and bandwidth requirements compared to conventional browser fingerprinting or HTTP cookies. This allows them to be applied in resource- or time-constrained scenarios such as real-time biddings in online advertising. To validate this finding, we investigated browsers which enable QUIC by default, e.g., Google Chrome. Our results suggest that the analyzed browsers do not provide protective measures against tracking via QUIC. However, the introduced mechanisms reset during a browser restart, which clears the cached connection data and thus limits achievable tracking periods. To mitigate the identified privacy issues, we propose changes to QUIC’s protocol design, the operation of QUIC-enabled web servers, and browser implementations. Erik Sy, Christian Burkert, Hannes Federrath, Mathias Fischer 0001 |
Proc. Priv. Enhancing Technol. | 4 |
| 2018 | Tracking Users across the Web via TLS Session ResumptionabstractUser tracking on the Internet can come in various forms, e.g., via cookies or by fingerprinting web browsers. A technique that got less attention so far is user tracking based on TLS and specifically based on the TLS session resumption mechanism. To the best of our knowledge, we are the first that investigate the applicability of TLS session resumption for user tracking. For that, we evaluated the configuration of 48 popular browsers and one million of the most popular websites. Moreover, we present a so-called prolongation attack, which allows extending the tracking period beyond the lifetime of the session resumption mechanism. To show that under the observed browser configurations tracking via TLS session resumptions is feasible, we also looked into DNS data to understand the longest consecutive tracking period for a user by a particular website. Our results indicate that with the standard setting of the session resumption lifetime in many current browsers, the average user can be tracked for up to eight days. With a session resumption lifetime of seven days, as recommended upper limit in the draft for TLS version 1.3, 65% of all users in our dataset can be tracked permanently. Erik Sy, Christian Burkert, Hannes Federrath, Mathias Fischer 0001 |
ACSAC | 4 |
| 2018 | Efficient Identification of Applications in Co-resident VMs via a Memory Side-Channel
Jens Lindemann 0001, Mathias Fischer 0001 |
SEC | 2 |
| 2017 | SensorBuster: On Identifying Sensor Nodes in P2P BotnetsabstractThe ever-growing number of cyber attacks originating from botnets has made them one of the biggest threat to the Internet ecosystem. Especially P2P-based botnets like ZeroAccess and Sality require special attention as they have been proven to be very resilient against takedown attempts. To identify weaknesses and to prepare takedowns more carefully it is thus a necessity to monitor them by crawling and deploying sensor nodes. This in turn provokes botmasters to come up with monitoring countermeasures to protect their assets. Most existing anti-monitoring countermeasures focus mainly on the detection of crawlers and not on the detection of sensors deployed in a botnet. In this paper, we propose two sensor detection mechanisms called SensorRanker and SensorBuster. We evaluate these mechanisms in two real world botnets, Sality and ZeroAccess. Our results indicate that SensorRanker and SensorBuster are able to detect up to 17 sensors deployed in Sality and four within ZeroAccess. Shankar Karuppayah, Leon Bock, Tim Grube, Selvakumar Manickam, Max Mühlhäuser, Mathias Fischer 0001 |
ARES | 6 |
| 2017 | Guest Editorial Emerging Technologies in Software- Driven Communication
Mathias Fischer 0001, Marcus Brunner, Ashutosh Dutta, Toktam Mahmoodi |
IEEE J. Sel. Areas Commun. | 1 |
| 2016 | On the anonymity of privacy-preserving many-to-many communication in the presence of node churn and attacksabstractAnonymity can protect from political repression in Online Social Networks (OSNs) as well as from undesired profiling, e.g., by advertisement companies, in todays' Internet. P2P-based anonymous publish-subscribe (pub-sub) is a highly-scalable approach to protect anonymity while enabling efficient many-to-many communication between services and users. However, churn and the resulting overlay degradation in P2P-based pub-sub systems require repairs and optimizations to maintain anonymity and efficiency. This paper analyzes attacks on such repair and optimization functions to disclose participants. For that, we apply a strong attacker model that combines large-scale traffic monitoring with malicious insiders. Furthermore, we propose and evaluate heuristic countermeasures. Our findings indicate that some attacks can be mitigated at reasonable costs. However, churn seems to remain a major threat to anonymity. Jörg Daubert, Tim Grube, Max Mühlhäuser, Mathias Fischer 0001 |
CCNC | 4 |
| 2016 | BoobyTrap: On autonomously detecting and characterizing crawlers in P2P botnetsabstractThe ever-growing number of cyber attacks from botnets has made them one of the biggest threats on the Internet. Thus, it is crucial to study and analyze botnets, to take them down. For this, an extensive monitoring is a pre-requisite for preparing a botnet takedown, e.g., via a sinkholing attack. However, every new monitoring mechanism developed for botnets is usually tackled by the botmasters by introducing novel antimonitoring countermeasures. In this paper, we anticipate these countermeasures by proposing a set of lightweight techniques for detecting the presence of crawlers in P2P botnets, called BoobyTrap. For that, we exploit botnet-specific protocol and design constraints. We evaluate the performance of our BoobyTrap mechanism on two real-world botnets: Sality and ZeroAccess. Our results indicate that we can distinguish many crawlers from benign bots. In fact, we discovered close to 10 crawler nodes within our observation period in the Sality botnet and around 120 in the ZeroAccess botnet. In addition, we also describe the observable characteristics of the detected crawlers and suggest crawler improvements for enabling monitoring in the presence of the BoobyTrap mechanism. Shankar Karuppayah, Emmanouil Vasilomanolakis, Steffen Haas, Max Mühlhäuser, Mathias Fischer 0001 |
ICC | 5 |
| 2016 | Analyzing flow-based anomaly intrusion detection using Replicator Neural NetworksabstractDefending key network infrastructure, such as Internet backbone links or the communication channels of critical infrastructure, is paramount, yet challenging. The inherently complex nature and quantity of network data impedes detecting attacks in real world settings. In this paper, we utilize features of network flows, characterized by their entropy, together with an extended version of the original Replicator Neural Network (RNN) and deep learning techniques to learn models of normality. This combination allows us to apply anomaly-based intrusion detection on arbitrarily large amounts of data and, consequently, large networks. Our approach is unsupervised and requires no labeled data. It also accurately detects network-wide anomalies without presuming that the training data is completely free of attacks. The evaluation of our intrusion detection method, on top of real network data, indicates that it can accurately detect resource exhaustion attacks and network profiling techniques of varying intensities. The developed method is efficient because a normality model can be learned by training an RNN within a few seconds only. Carlos Garcia Cordero, Sascha Hauke, Max Mühlhäuser, Mathias Fischer 0001 |
PST | 4 |
| 2016 | AnonPubSub: Anonymous publish-subscribe overlays
Jörg Daubert, Mathias Fischer 0001, Tim Grube, Stefan Schiffner, Panayotis Kikiras, Max Mühlhäuser |
Comput. Commun. | 2 |
| 2015 | Zeus Milker: Circumventing the P2P Zeus Neighbor List Restriction MechanismabstractThe emerging trend of highly-resilient P2P botnets poses a huge security threat to our modern society. Carefully designed countermeasures as applied in sophisticated P2P botnets such as P2P Zeus impede botnet monitoring and successive takedown. These countermeasures reduce the accuracy of the monitored data, such that an exact reconstruction of the botnet's topology is hard to obtain efficiently. However, an accurate topology snapshot, revealing particularly the identities of all bots, is crucial to execute effective botnet takedown operations. With the goal of obtaining the required snapshot in an efficient manner, we provide a detailed description and analysis of the P2P Zeus neighbor list restriction mechanism. As our main contribution, we propose ZeusMilker, a mechanism for circumventing the existing anti-monitoring countermeasures of P2P Zeus. In contrast to existing approaches, our mechanism deterministically reveals the complete neighbor lists of bots and hence can efficiently provide a reliable topology snapshot of P2P Zeus. We evaluated ZeusMilker on a real-world dataset and found that it outperforms state-of-the-art techniques for botnet monitoring with regard to the number of queries needed to retrieve a bot's complete neighbor list. Furthermore, ZeusMilker is provably optimal in retrieving the complete neighbor list, requiring at most 2n queries for an n-elemental list. Moreover, we also evaluated how the performance of ZeusMilker is impacted by various protocol changes designed to undermine its provable performance bounds. Shankar Karuppayah, Stefanie Roos, Christian Rossow, Max Mühlhäuser, Mathias Fischer 0001 |
ICDCS | 5 |
| 2015 | SkipMon: A locality-aware Collaborative Intrusion Detection SystemabstractDue to the increasing quantity and sophistication of cyber-attacks, Intrusion Detection Systems (IDSs) are nowadays considered mandatory security mechanisms for protecting critical networks. Research on cyber-security is moving from such isolated IDSs towards Collaborative IDSs (CIDSs) in order to protect large-scale networks. In CIDSs, a number of IDS sensors work together for creating a holistic picture of the monitored network. Our contribution in this paper is a novel distributed and scalable CIDS, called SkipMon. Our system supports, both, the idea of locality and privacy preserving communication by means of exchanging compact alert data. Furthermore, we propose a mechanism for interconnecting sensors that experience similar traffic patterns. The experimental results suggest that our CIDS, with our technique of connecting monitoring nodes that experience similar traffic, is scalable and offers a good accuracy rate compared to a centralized system with full knowledge of the participating sensors' data. Emmanouil Vasilomanolakis, Matthias Krugl, Carlos Garcia Cordero, Max Mühlhäuser, Mathias Fischer 0001 |
IPCCC | 5 |
| 2015 | RBCS: A resilient backbone construction scheme for hybrid Peer-To-Peer streamingabstractHybrid Peer-to-Peer streaming systems combine the advantages of an efficient push-based with a more resilient pull-based system to deliver video streams over the Internet. In this manner, hybrid systems offer low latency and an increased robustness to failures and node churn. However, current hybrid systems is vulnerable to misbehaving nodes and deliberate attacks. By taking central positions in the overlay, malicious nodes can perform extremely harmful Denial-of-Service (DoS) attacks. We propose RBCS, a novel backbone construction scheme, that is highly resilient against DoS attacks while maintaining fast content dissemination. RBCS incorporates stable peers into a manipulation-resistant multi-tree backbone overlay, which is resilient against both attacks and node churn. Additionally, RBCS securely identifies stable peers by using only local knowledge about the participation time of others. Extensive simulations indicate that RBCS outperforms the state-of-the-art in being more resilient against attacks at the price of a slightly increased overhead. Giang T. Nguyen 0002, Stefanie Roos, Thorsten Strufe, Mathias Fischer 0001 |
LCN | 4 |
| 2015 | Community-Based Collaborative Intrusion Detection
Carlos Garcia Cordero, Emmanouil Vasilomanolakis, Max Mühlhäuser, Mathias Fischer 0001 |
SecureComm | 4 |
| 2014 | Twitterize: Anonymous Micro-bloggingabstractPrivacy, in particular anonymity, is required to increase the acceptance of users for the Internet of Things (IoT). The IoT is built upon sensors that encompass us in each step we take. Hence, they can collect sensitive, privacy-invading data that can be used to establish complete user profiles. For this reason, sensing in the IoT needs to provide means of privacy-protection. In this paper, we discuss an approach for sharing smartphone sensor data and user-generated content in a privacy-protecting manner via the Micro-blogging platform (MbP) Twitter. For that, we discuss privacy needs of users in Micro-blogging platforms (MbPs) and that privacy should not only ensure confidentiality but also anonymity. We discuss related work and systems along these requirements and conclude that anonymity is hardly considered. We introduce our construction Twitterize that integrates well with the MbP Twitter and allows users and sensors to share information normally as well as privacy-preserving with a single application. Twitterize establishes overlay networks for hashtags over Twitters' social network and neither depends on additional infrastructure nor peer-to-peer communication. Jörg Daubert, Leon Bock, Panayotis Kikiras, Max Mühlhäuser, Mathias Fischer 0001 |
AICCSA | 5 |
| 2014 | On advanced monitoring in resilient and unstructured P2P botnetsabstractBotnets are a serious threat to Internet-based services and end users. The recent paradigm shift from centralized to more sophisticated Peer-to-Peer (P2P)-based botnets introduces new challenges for security researchers. Centralized botnets can be easily monitored, and once their command and control server is identified, easily be taken down. However, P2P-based botnets are much more resilient against such attempts. To make it worse, botnets like P2P Zeus include additional countermeasures to make monitoring and crawling more difficult for the defenders. In this paper, we discuss in detail the problems of P2P botnet monitoring. As our main contribution, we introduce the Less Invasive Crawling Algorithm (LICA) for efficiently crawling unstructured P2P botnets and utilize only local information. We compare the performance of LICA with other known crawling methods such as Depth-first and Breadth-first search. This is achieved by simulating these methods on not only a real-world botnet dataset, but also on an unstructured P2P file sharing network dataset. Our analysis results indicate that LICA significantly outperforms the other known crawling methods. Shankar Karuppayah, Mathias Fischer 0001, Christian Rossow, Max Mühlhäuser |
ICC | 2 |
| 2014 | HosTaGe: a Mobile Honeypot for Collaborative DefenseabstractThe continuous growth of the number of cyber attacks along with the massive increase of mobile devices creates a highly heterogeneous landscape in terms of security challenges. We argue that in order for security researchers to cope with both the massive amount and the complexity of attacks, a more pro-active approach has to be taken into account. In addition, distributed attacks that are carried out by interconnected attackers require a collaborative defense. Diverging from traditional security defenses, honeypots are systems whose value lies on in being attacked and compromised. In this paper, we extend the idea of HosTaGe, i.e., a low interaction honeypot for mobile devices. Our system is specifically designed in a user-centric manner and runs out-of-the-box in the Android operating system. We present the design rational and discuss the different attack surfaces that HosTaGe is able to handle. The main contribution of this paper is the introduction of the collaborative capabilities of HosTaGe. Emmanouil Vasilomanolakis, Shankar Karuppayah, Max Mühlhäuser, Mathias Fischer 0001 |
SIN | 4 |
| 2014 | On the Resilience of Pull-Based P2P Streaming Systems against DoS Attacks
Giang T. Nguyen 0002, Mathias Fischer 0001, Thorsten Strufe |
SSS | 2 |
| 2014 | Resilient and underlay-aware P2P live-streaming
Mathias Fischer 0001, Sascha Grau, Giang T. Nguyen 0002, Günter Schäfer |
Comput. Networks | 1 |
| 2013 | Distributed and Anonymous Publish-Subscribe
Jörg Daubert, Mathias Fischer 0001, Stefan Schiffner, Max Mühlhäuser |
NSS | 2 |
| 2011 | On the Dependencies between Source Neighbors in Optimally DoS-stable P2P Streaming TopologiesabstractWe study tree-based peer-to-peer streaming topologies that minimize the maximum damage that can be caused by the failure of any number of peers. These optimally stable topologies can be characterized by a distinctive damage sequence. Although checking whether a given topology is optimally stable is a co-NP-complete problem, a large subclass of these topologies can be constructed by applying a simple set of rules. One of these rules states that every optimally stable topology must have optimally stable inter-dependencies between the nodes directly adjacent to the streaming source (called heads). However, until now, only a single stable head topology was known. In this article, we first give a short outline to previous results about optimally stable topologies. Then, we identify necessary and sufficient requirements for the optimal stability of head topologies, thereby largely increasing the number of known representatives from this class. All requirements can be checked in polynomial time. Furthermore, we show how to efficiently decide stability for head topologies with at most four stripes and give a procedure that, given a stable topology, produces a stable topology with an arbitrary number of stripes. Reversing this procedure can also speed up stability testing. Finally, we describe strategies how stable head topologies can be constructed in real-world streaming systems. Sascha Grau, Mathias Fischer 0001, Günter Schäfer |
ICDCS | 2 |
| 2011 | Underlay-robust application layer multicastabstractIn recent years, ALM emerged as cost-efficient and scalable form of content distribution by overcoming the classical client-server bottleneck. The client bandwidth is incorporated to stream distribution, so that every client that receives the stream forwards it as well. ALM systems are usually classified in push, pull and hybrid approaches [1]. In the remainder of this article we are focusing on live-streaming, which imposes strict delay constraints on the content distribution and thus cannot be realized with pull-based approaches. Hence, we concentrate on push-based ALM that splits a stream in multiple substreams (so-called stripes) by using Multiple Description Coding (MDC) and assigns each of them a separate spanning tree. However, the results of this article apply to hybrid and partially to pull-based approaches as well. Mathias Fischer 0001, Sebastian Delling, Sascha Grau, Günter Schäfer |
IPCCC | 1 |
| 2011 | On Complexity and Approximability of Optimal DoS Attacks on Multiple-Tree P2P Streaming TopologiesabstractWe investigate the hardness of malicious attacks on multiple-tree topologies of push-based Peer-to-Peer streaming systems. In particular, we study the optimization problem of finding a minimum set of target nodes to achieve a certain damage objective. For this, we differentiate between three natural and increasingly complex damage types: global packet loss, service loss when using Multiple Description Coding, and service loss when using Forward Error Correction. We show that each of these attack problems is NP-hard, even for an idealized attacker with global knowledge about the topology. Despite tree-based topologies seem susceptible to such attacks, we can even prove that (under strong assumptions about NP) there is no polynomial time attacker, capable of guaranteeing a general solution quality within factors of c_1 \log (n) and c_2 2^{\log^{1-\delta } n} (with n topology nodes, \delta = 1 / \log \log^d n for d<1/2 and constants c_1, c_2), respectively. To our knowledge, these are the first lower bounds on the quality of polynomial time attacks on P2P streaming topologies. The results naturally apply to major real-world DoS attackers and show hard limits for their possibilities. In addition, they demonstrate superior stability of Forward Error Correction systems compared to Multiple Description Coding and give theoretical foundation to properties of stable topologies. Sascha Grau, Mathias Fischer 0001, Michael Brinkmeier, Günter Schäfer |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2008 | A Distributed IP Mobility Approach for 3G SAEabstractFuture generations of mobile operator networks, based on an all-IP-based flat architecture and a multitude of different access technologies, require a proper IP-based mobility management in place. In this article, a scalable and completely distributed mobility management is presented which is based on a Distributed Hash Table data structure. The Distributed IP Mobility Approach (DIMA) remains completely compatible towards Mobile IP and its variants Hierarchical Mobile IP and Proxy Mobile IP. We examine the average service time per packet and the load caused by lookups in the system, by applying a suitable mobility model and by using a traffic model consisting of a mix of representative traffic classes (HTTP, VoIP, Audio and Video streaming). Thereby, we show that the system remains scalable allowing to serve an arbitrary amount of participants, provides a network-based route optimization and a better resilience than Mobile IP at the cost of only slightly increased signalling effort. Mathias Fischer 0001, Frank-Uwe Andersen, Andreas Köpsel, Günter Schäfer, Morten Schläger |
PIMRC | 1 |
| 2008 | A Key Management Solution for Overlay-Live-StreamingabstractConfidential communication of live-generated multimedia data distributed via application level multicast (ALM) still remains a mostly unaddressed subject even though some important usage scenarios, e.g. paid subscription services or personal video-streaming, are anticipated to gain more widespread use as the Internet continues to evolve into the common transport platform for all kinds of services. In this article, we examine the specific requirements for key management schemes to be used in ALM-based distribution systems and analyze existing key management approaches with respect to these requirements [1, 2, 3]. Based on the results of this analysis, we design a new key management scheme that combines ideas of the Logical Key Hierarchy (LKH) protocol [4, 5] and the Iolus approach [6]. We compare the resulting scheme to a simple approach that is based on pairwise keys between neighboring nodes without further key-hierarchy based optimization and that serves as a benchmark. Our results of a comparative simulation study clearly indicate the suitability of our scheme for ALM-based livestreaming. Mathias Fischer 0001, Günter Schäfer, Robert Karl Schmidt, Thorsten Strufe |
SecureComm | 1 |