Stefan Kiltz

dblp:91/1808 · DBLP profile ↗
← Back
13ranked-venue papers
2as first author
6since 2021 · last 2025
0009-0001-1261-8081ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 13 · 2 first-author · 6 since 2021
YearPublicationVenuePosition
2025 Traces Left by the Originator: Forensic Fingerprinting Hidden Malware in Images to Enable Attribution on the Example of SteganoAmor
abstract
Information Hiding used in malware is a recent trend.Its detection as well as origin attribution is of interest to hold actors responsible and provide well tuned prevention and reaction.We propose a Forensic Fingerprint for images to individualize traces left from malicious actors.The idea is to define feature spaces to structure artefacts in the stego objects caused by embedding code into a cover image as StegoFingerprint to describe Parameter-based-Artefacts and artefacts included in embedded malicious payloads as PayloadFingerprint to collect Payload-based-Artefacts.The approach is exemplary applied on 11 live samples (AV-Test cases) from the SteganoAmor campaign (appending code into JPEG meta data) and compared with a simulation using the known steganographic algorithm StegHide with an embedding into media data.We investigate how a first feature space of 10 StegoFingerprint and 32 PayloadFingerprint features can answer the questions: (1) Enable-Detection (EDE): How many incidents can be detected?, (2) Enable-Attribution (EAT): How many different attackers are active in detected cases? and (3) Enable-Discrimination of Identity (EDI): Can traces be used to attribute digital or real identities by using found trace knowledge in context searches.In summary results for the live samples and our simulations show that the Fingerprint can differentiate between attacks and derive for one live sample an attacker identity, pseudonymized in this paper.
Jana Dittmann, Stefan Kiltz, Robert Altschaffel, Judith Antal
IH&MMSec2
2024 Forensic Image Trace Map for Image-Stego-Malware Analysis: Validation of the Effectiveness with Structured Image Sets
abstract
Cybersecurity incident become more and more hardened with obfuscation techniques such as steganography. Especially image data is often used for malicious action such as infiltration, exfiltration and Command&Control. To allow an easy forensic assessment of steganographic images traces in Stego-Malware, we propose a Forensic Image Trace Map motivated from Trace Map in [4] from general IT forensic incident handling. The trace map for images include properties of meta data and media data traces such as used in image forensics from European Network of Forensic Science Institutes (ENFSI) [5]. The approach is validated based on four validation metrics from [4] within an informed analysis of four simple known image techniques and a test set of 10 challenging heterogeneous JPEG image samples. In the validation we structure the traces in the Forensic Image Trace Map and from the map we can conclude that out of the 9 primary traces, some are more distinctive between stego tools and their parametrization, such as file size alteration, and their combination enhances the discriminatory power. Also, some image type characteristics influence the support of individualization, the synthetic bicolour image from our test set resulted in very distinctive cover images.
Stefan Kiltz, Jana Dittmann, Fabian Loewe, Christian Heidecke, Max John, Jonas Mädel, Fabian Preißler
IH&MMSec1
2022 Revisiting Online Privacy and Security Mechanisms Applied in the In-App Payment Realm from the Consumers' Perspective
abstract
This paper presents an in-depth network data stream analysis on data gathering to evaluate the current data protection situation of online payment in smartphone applications. To this end, we applied a digital forensic methodology from previous work in the field, analyzing network traffic generated by applications during a purchase process. We revisit previous work’s results on browser-based payments and compare them to the current security and privacy situation of in-app payments in 2022. We study an exemplary selection of ten mobile apps and four payment systems often used by young consumers (i.e., between 20 and 25 years old): Paypal, Google Pay, Klarna, and Visa/Mastercard credit cards. Furthermore, we examine the apps concerning their trackers and applications’ privacy policies. For this purpose, we use OSINT sources to perform a static tracker analysis and their purposes based on privacy policy descriptions. Subsequently, we perform a dynamic analysis applying a man-in-the middle attack vector, which allows us to bypass the TLS encryption of the smartphone’s HTTPS traffic, and analyze the data stream payload. We repeatedly identify significant security vulnerabilities and how applications handling sensitive data do not follow standard recommendations in security and data protection regulations during the result analysis. Moreover, some data sharing is noticed, with sensitive data passed on to third parties. The data obtained can also be used in application fields, such as by a forensic expert in a financial crime case in steps of a forensic investigation.
Salatiel Ezennaya-Gomez, Edgar Blumenthal, Marten Eckardt, Justus Krebs, Christopher Kuo, Julius Porbeck, Emirkan Toplu, Stefan Kiltz, Jana Dittmann
ARES8
2022 Hidden in Plain Sight - Persistent Alternative Mass Storage Data Streams as a Means for Data Hiding With the Help of UEFI NVRAM and Implications for IT Forensics
abstract
This article presents a first study on the possibility of hiding data using the UEFI NVRAM of today's computer systems as a storage channel. Embedding and extraction of executable data as well as media data are discussed and demonstrated as a proof of concept. This is successfully evaluated using 10 different systems. This paper further explores the implications of data hiding within UEFI NVRAM for computer forensic investigations and provides forensics measures to address this new challenge.
Stefan Kiltz, Robert Altschaffel, Jana Dittmann
IH&MMSec1
2021 A Semi-Automated HTTP Traffic Analysis for Online Payments for Empowering Security, Forensics and Privacy Analysis
abstract
The paper discusses means to identify potential impacts of data flows on customers’ security, and privacy during online payments. The main objectives of our research are looking into the evolution of cybercrime new trends of online payments and detection, more precisely the usage of mobile phones, and describing methodologies for digital trace identification in data flows for potential online payment fraud. The paper aims to identify potential actions for identity theft while conducting the Reconnaissance step of the kill chain, and documenting a forensic methodology for guidance and further data collection for law enforcement bodies. Moreover, a secondary objective of the paper is to identify, from a user’s perspective, transparency issues of data sharing among involved parties for online payments. We thus declare the transparency analysis as the incident triggering a forensic examination. Hence, we devise a semi-automated traffic analysis approach, based on previous work, to examine data flows, and data exchanged among parties in online payments. For this, the main steps are segmenting traffic generated by the process payment, and other sources, subsequently, identifying data streams in the process. We conduct three tests which include three different payment gateways: PayPal, Klarna-sofort, and Amazon Pay. The experiment setup requires circumventing TLS encryption for the correct identification of forensic data types in TCP/IP traffic, and potential data leaks. However, it requires no extensive expertise in mobile security for its installation. In the results, we identified some important security vulnerabilities from some payment APIs that pose financial and privacy risks to the marketplace’s customers.
Salatiel Ezennaya-Gomez, Stefan Kiltz, Christian Krätzer, Jana Dittmann
ARES2
2021 Meta and Media Data Stream Forensics in the Encrypted Domain of Video Conferences
abstract
Our paper presents a systematic approach to investigate whether and how events can be identified and extracted during the use of video conferencing software. Our approach is based on the encrypted meta and multimedia data exchanged during video conference sessions. It relies on the network data stream which contains data interpretable without decryption (plain data) and encrypted data (encrypted content) some of which is decrypted using our approach (decrypted content). This systematic approach uses a forensic process model and the fission of network data streams before applying methods on the specific individual data types. Our approach is applied exemplary to the Zoom Videoconferencing Service with Client Version 5.4.57862.0110 [4], the mobile Android App Client Version 5.5.2 (1328) [4], the webbased client and the servers (accessed between Jan 21st and Feb 4th). The investigation includes over 50 different configurations. For the heuristic speaker identification, two series of nine sets for eight different speakers are collected. The results show that various user data can be derived from characteristics of encrypted media streams, even if end-to-end encryption is used. The findings suggest user privacy risks. Our approach offers the identification of various events, which enable activity tracking (e.g. camera on/off, increased activity in front of camera) by evaluating heuristic features of the network streams. Further research into user identification within the encrypted audio stream based on pattern recognition using heuristic features of the corresponding network data stream is conducted and suggests the possibility to identify users within a specific set.
Robert Altschaffel, Jonas Hielscher, Stefan Kiltz, Jana Dittmann
IH&MMSec3
2019 Digital Forensics in Industrial Control Systems
Robert Altschaffel, Mario Hildebrandt, Stefan Kiltz, Jana Dittmann
SAFECOMP3
2015 ForeMan, a Versatile and Extensible Database System for Digitized Forensics Based on Benchmarking Properties
abstract
To benefit from new opportunities offered by the digitalization of forensic disciplines, the challenges especially w.r.t. comprehensibility and searchability have to be met. Important tools in this forensic process are databases containing digitized representations of physical crime scene traces. We present ForeMan, an extensible database system for digitized forensics handling separate databases and enabling intra and inter trace type searches. It now contains 762 fiber data sets and 27 fingerprint data sets (anonymized time series). Requirements of the digitized forensic process model are mapped to design aspects and conceptually modeled around benchmarking properties. A fiber categorization scheme is used to structure fiber data according to forensic use case identification. Our research extends the benchmarking properties by fiber fold shape derived from the application field of fibers (part of micro traces) and sequence number derived from the application field of time series analysis for fingerprint aging research. We identify matching data subsets from both digitized trace types and introduce the terms of entity-centered and spatial-centered information. We show how combining two types of digitized crime scene traces (fiber and fingerprint data) can give new insights for research and casework and discuss requirements for other trace types such as firearm and toolmarks.
Christian Arndt, Stefan Kiltz, Jana Dittmann, Robert Fischer 0001
IH&MMSec2
2012 IT-Forensic Automotive Investigations on the Example of Route Reconstruction on Automotive System and Communication Data
Tobias Hoppe, Sven Kuhlmann, Stefan Kiltz, Jana Dittmann
SAFECOMP3
2009 Automotive IT-Security as a Challenge: Basic Attacks from the Black Box Perspective on the Example of Privacy Threats
Tobias Hoppe, Stefan Kiltz, Jana Dittmann
SAFECOMP2
2008 Adaptive Dynamic Reaction to Automotive IT Security Incidents Using Multimedia Car Environment
abstract
Modern cars offer an increasingly powerful multimedia environment. While also the potential for an application as human computer interface (HCI) is growing, in this paper we concentrate on already existing possibilities for their use as computer-human-interface (CHI) to communicate system security related information to the driver. After identifying the intrusion detection approach from desktop IT as a promising supplemental measure for the IT security of future automotive systems and successfully testing it in practice, in this paper we investigate about how such an automotive intrusion detection system (IDS) could communicate security-related information to the driver. We propose an adaptive dynamic concept to address the frequently changing environmental conditions in the automotive domain and discuss it using three exemplarily selected scenarios.
Tobias Hoppe, Stefan Kiltz, Jana Dittmann
IAS2
2008 Security Threats to Automotive CAN Networks - Practical Examples and Selected Short-Term Countermeasures
Tobias Hoppe, Stefan Kiltz, Jana Dittmann
SAFECOMP2
2007 Future Perspectives: The Car and Its IP-Address - A Potential Safety and Security Risk Assessment
Andreas Lang 0001, Jana Dittmann, Stefan Kiltz, Tobias Hoppe
SAFECOMP3