Manuel Leithner

dblp:86/9489 · DBLP profile ↗
← Back
25ranked-venue papers
9as first author
9since 2021 · last 2025
0000-0001-9433-1668ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 13 · 5 first-author · 2 since 2021Software engineering, systems software and programming languages · 7 · 3 first-author · 6 since 2021Artificial intelligence and machine learning · 2 · 1 first-authorSystems, architecture and hardware · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 first-authorGraphics, computer vision, multimedia, augmented reality and games · 1Theory of computation · 1
YearPublicationVenuePosition
2025 Reverse Engineering for Input Modeling: Input Parameter Model Inference from Network Traces
Manuel Leithner, Dimitris E. Simos
ICTSS1
2025 Bluetooth Low Energy Security Testing with Combinatorial Methods
Dominik-Philip Schreiber, Manuel Leithner, Jovan Zivanovic, Dimitris E. Simos
USENIX ATC2
2024 Combinatorial Testing Methods for Reverse Engineering Undocumented CAN Bus Functionality
abstract
Modern vehicles such as cars, ships, and planes are increasingly managed using Electronic Control Units (ECUs) that communicate over a Controller Area Network (CAN) bus. While this approach offers enhanced functionality, efficiency, and robustness, it may also be used for unforeseen or malicious purposes ranging from aftermarket modifications to full-fledged attacks threatening passengers’ safety. The ability to conduct in-depth tests is thus vital to protect against these issues. However, much of the functionality of ECUs is proprietary or undocumented. To alleviate this obstacle, this work presents a reverse engineering approach using high-coverage test sets produced using Combinatorial Testing (CT) methods. Our results indicate that this technique is promising for exciting unknown functionality, although challenges regarding the presence of hidden state and high-accuracy oracles are yet to be overcome.
Christoph Wech, Reinhard Kugler, Manuel Leithner, Dimitris E. Simos
ARES3
2024 Annotation-Based Input Modeling for Combinatorial Testing
Markus Fugger, Manuel Leithner, Dimitris E. Simos
ICTSS2
2024 State of the CArt: evaluating covering array generators at scale
Manuel Leithner, Andrea Bombarda, Michael Wagner 0026, Angelo Gargantini, Dimitris E. Simos
Int. J. Softw. Tools Technol. Transf.1
2023 Applying Pairwise Combinatorial Testing to Large Language Model Testing
Bernhard Garn, Ludwig Kampel, Manuel Leithner, Berina Celic, Ceren Çulha, Irene Hiess, Klaus Kieseberg, Marlene Koelbing, Dominik-Philip Schreiber, Michael Wagner 0026, Christoph Wech, Jovan Zivanovic, Dimitris E. Simos
ICTSS3
2022 A Two-Step TLS-Based Browser fingerprinting approach using combinatorial sequences
Bernhard Garn, Stefan Zauner, Dimitris E. Simos, Manuel Leithner, D. Richard Kuhn, Raghu Kacker
Comput. Secur.4
2022 Combinatorial methods for dynamic gray-box SQL injection testing
abstract
Summary This work presents an extended and enhanced gray‐box combinatorial security testing methodology for SQL injection vulnerabilities in web applications. We propose multiple new attack grammars modelling SQLi attacks against MySQL‐compatible databases, each one targeting a different injection context. Additionally, these grammars are also dynamically refined at the beginning of each attack against an endpoint of a web application, as a further optimization of the used attack model by taking into account the specifics of the generated query of that endpoint. Our goal is to enhance existing combinatorial approaches for detecting SQL injection vulnerabilities. The newly developed methodology is implemented in a prototype security testing tool called SQLInjector+, which is an extension of an earlier prototype developed by us in prior work. This improved tool can attack (i.e. test) any web application that uses a MySQL‐compatible database management system. We evaluate our revised approach and improved prototype tool in a case study comprising of different kinds of web applications to which SQLi is a potential security threat. The case study contains the well‐known verification framework WAVSEP among other five real‐world web applications and one web application firewall. Our generated attack vectors, constructed via combinatorial methods applied to our improved and dynamically optimized attack grammars, are capable of injecting every known vulnerable endpoint in WAVSEP and also of finding new vulnerable parameters in some of the real‐world applications investigated in this paper. Our approach performs equally well or better when compared with existing state‐of‐art of SQL injection security testing tools (sqlmap, w3af, wapiti and fuzzdb) across all tested web applications in the case study.
Bernhard Garn, Jovan Zivanovic, Manuel Leithner, Dimitris E. Simos
Softw. Test. Verification Reliab.3
2021 HYDRA: Feedback-driven black-box exploitation of injection vulnerabilities
Manuel Leithner, Bernhard Garn, Dimitris E. Simos
Inf. Softw. Technol.1
2019 A Fault-Driven Combinatorial Process for Model Evolution in XSS Vulnerability Detection
Bernhard Garn, Marco Radavelli, Angelo Gargantini, Manuel Leithner, Dimitris E. Simos
IEA/AIE4
2019 Testing TLS using planning-based combinatorial methods and execution framework
Dimitris E. Simos, Josip Bozic, Bernhard Garn, Manuel Leithner, Feng Duan 0002, Kristoffer Kleine, Yu Lei 0001, Franz Wotawa
Softw. Qual. J.4
2019 Problems and algorithms for covering arrays via set covers
Ludwig Kampel, Manuel Leithner, Bernhard Garn, Dimitris E. Simos
Theor. Comput. Sci.2
2018 DOMdiff: Identification and Classification of Inter-DOM Modifications
abstract
Current web crawlers, document databases and change monitoring systems for web sites are commonly limited to static content and analysis of code as retrieved from the server, an approach that is not suitable for modern dynamic web applications. The canonical representation of the contents of a single web page at any given time is an instance of the Document Object Model (DOM), a tree structure that forms the basis for rendering and processing of the page within the browser and is updated when content is modified. This work presents DOMdiff, an algorithm to identify changes between two different DOM instances, as well as a method to classify these changes in terms of a ranking that represents the distance between the two trees. We compare a manually derived classifier with the results of PRank, a ranked version of the Perceptron algorithm, a simple machine learning approach that generates a multiclass classifier based on formulae in a constrained predicate logic, and the established statistical classifier C5.0. Our results indicate that DOMdiff is suitable to large-scale change identification and that entropy-based statistical classifiers are more accurate than our simple predicate-based classifier for the problem at hand, but require a larger decision tree. We additionally identify a shortcoming of PRank when handling features with low information gain/high entropy.
Manuel Leithner, Dimitris E. Simos
WI1
2014 Covert Computation - Hiding code in code through compile-time obfuscation
Sebastian Schrittwieser, Stefan Katzenbeisser 0001, Peter Kieseberg, Markus Huber 0001, Manuel Leithner, Martin Mulazzani, Edgar R. Weippl
Comput. Secur.5
2013 Covert computation: hiding code in code for obfuscation purposes
abstract
As malicious software gets increasingly sophisticated and resilient to detection, new concepts for the identification of malicious behavior are developed by academia and industry alike. While today's malware detectors primarily focus on syntactical analysis (i.e., signatures of malware samples), the concept of semantic-aware malware detection has recently been proposed. Here, the classification is based on models that represent the underlying machine and map the effects of instructions on the hardware. In this paper, we demonstrate the incompleteness of these models and highlight the threat of malware, which exploits the gap between model and machine to stay undetectable. To this end, we introduce a novel concept we call covert computation, which implements functionality in side effects of microprocessors. For instance, the flags register can be used to calculate basic arithmetical and logical operations. Our paper shows how this technique could be used by malware authors to hide malicious code in a harmless-looking program. Furthermore, we demonstrate the resilience of covert computation against semantic-aware malware scanners.
Sebastian Schrittwieser, Stefan Katzenbeisser 0001, Peter Kieseberg, Markus Huber 0001, Manuel Leithner, Martin Mulazzani, Edgar R. Weippl
AsiaCCS5
2012 Guess Who's Texting You? Evaluating the Security of Smartphone Messaging Applications
Sebastian Schrittwieser, Peter Frühwirt, Peter Kieseberg, Manuel Leithner, Martin Mulazzani, Markus Huber 0001, Edgar R. Weippl
NDSS4
2012 Android forensics
Manuel Leithner, Edgar R. Weippl
Comput. Secur.1
2012 Coding for Penetration Testers
Manuel Leithner, Edgar R. Weippl
Comput. Secur.1
2012 Thor's Microsoft Security Bible
Manuel Leithner, Edgar R. Weippl
Comput. Secur.1
2012 XBOX 360 Forensics: A Digital Forensics Guide to Examining Artifacts
Manuel Leithner, Edgar R. Weippl
Comput. Secur.1
2012 Low Tech Hacking
Manuel Leithner, Edgar R. Weippl
Comput. Secur.1
2012 Enterprise Security for the Executive
Edgar R. Weippl, Manuel Leithner
Comput. Secur.2
2011 Social snapshots: digital forensics for online social networks
abstract
Recently, academia and law enforcement alike have shown a strong demand for data that is collected from online social networks. In this work, we present a novel method for harvesting such data from social networking websites. Our approach uses a hybrid system that is based on a custom add-on for social networks in combination with a web crawling component. The datasets that our tool collects contain profile information (user data, private messages, photos, etc.) and associated meta-data (internal timestamps and unique identifiers). These social snapshots are significant for security research and in the field of digital forensics. We implemented a prototype for Facebook and evaluated our system on a number of human volunteers. We show the feasibility and efficiency of our approach and its advantages in contrast to traditional techniques that rely on application-specific web crawling and parsing. Furthermore, we investigate different use-cases of our tool that include consensual application and the use of sniffed authentication cookies. Finally, we contribute to the research community by publishing our implementation as an open-source project.
Markus Huber 0001, Martin Mulazzani, Manuel Leithner, Sebastian Schrittwieser, Gilbert Wondracek, Edgar R. Weippl
ACSAC3
2011 Dark Clouds on the Horizon: Using Cloud Storage as Attack Vector and Online Slack Space
Martin Mulazzani, Sebastian Schrittwieser, Manuel Leithner, Markus Huber 0001, Edgar R. Weippl
USENIX Security Symposium3
2010 QR code security
abstract
This paper examines QR Codes and how they can be used to attack both human interaction and automated systems. As the encoded information is intended to be machine readable only, a human cannot distinguish between a valid and a maliciously manipulated QR code. While humans might fall for phishing attacks, automated readers are most likely vulnerable to SQL injections and command injections. Our contribution consists of an analysis of the QR Code as an attack vector, showing different attack strategies from the attackers point of view and exploring their possible consequences.
Peter Kieseberg, Manuel Leithner, Martin Mulazzani, Lindsay Munroe, Sebastian Schrittwieser, Mayank Sinha, Edgar R. Weippl
MoMM2