EDBT 2026 Demo / reviewers in the wild / expert
Georg Lukas
dblp:96/706
· DBLP profile ↗
15ranked-venue papers
3as first author
4since 2021 · last 2024
—ORCID · none
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 9 · 1 first-author · 4 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 2 since 2021Security and privacy · 2 · 1 first-authorComputer networks · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | Evaluation of an Automated Security Risk Assessment Based on a Manual ReferenceabstractThe overall Industry 4.0 developments and the highly dynamic threat landscape enhance the need for continuous security engineering of industrial components, modules, and systems. Security risk assessments play a major role to ensure a secure operation of Industrial Automation and Control Systems (IACSs) but are often neglected due to missing resources and a lack of human experts for the sophisticated manual tasks. To relieve this situation and to increase the degree of automation of security risk assessments, a method for information and process modelling was developed in a previous work. The approach was also implemented prototypically as an expert system but has not been validated, yet. This work therefore presents the validation as an integral part of the overall evaluation of the automated security risk assessment concept. For a systematic validation, a reference security risk assessment is manually defined as a set of data for the comparison with the results of the automated expert system. In addition, the two main hypotheses with regard to the result quality and the process automation evaluated. Marco Ehrlich, Georg Lukas, Lisa Gebauer, Henning Trsek, Jürgen Jasperneite, Wolfgang Kastner, Christian Diedrich |
ETFA | 2 |
| 2024 | Requirements Analysis for the Evaluation of Automated Security Risk AssessmentsabstractThe overall Industry 4.0 developments and the highly dynamic threat landscape enhance the need for continuous security engineering of industrial components, modules, and systems. Security risk assessments play a major role to ensure a secure operation of Industrial Automation and Control Systems (IACSs) but are mostly neglected due to missing resources and a lack of human experts for the sophisticated manual tasks. Therefore, a method for information and process modelling regarding the automation of security risk assessments has been previously designed, but not yet evaluated. This work in progress begins the evaluation of the automated security risk assessment concept by investigating the related work and identifying the main deficits. The results include a requirements analysis for the verification and an outlook towards future evaluation aspects. Marco Ehrlich, Georg Lukas, Henning Trsek, Jürgen Jasperneite, Wolfgang Kastner, Christian Diedrich |
WFCS | 2 |
| 2022 | Evil SteVe: An Approach to Simplify Penetration Testing of OCPP Charge PointsabstractThe reduction of CO2 emissions caused by auto-mobile traffic relies on the development of electric mobility infrastructure which in turn relies on efficient communication between charge points, used to connect electric vehicles to the power network, and central systems, used to manage users and transactions. The Open Charge Point Protocol (OCPP) is an open communication protocol designed to connect charge points to a central system. An important aspect of the communication between these entities is the security of the connection. It is conceivable, for instance, that an adversary could compromise a central system to attack charge points.This work devises three different attack scenarios which could be executed by a malicious OCPP central system to attack an OCPP charge point. It also assesses the feasibility and potential consequences of such attacks. Additionally, it presents an approach of an "evil" OCPP server implementation, based on the SteVe server which was originally developed at the RWTH Aachen. The "evil" OCPP server implements various attack scenarios and is intended to be used for penetration testing of OCPP charge points that connect to the central system via WebSockets/JSON or SOAP/XML. Lisa Gebauer, Henning Trsek, Georg Lukas |
ETFA | 3 |
| 2022 | Investigation of Resource Constraints for the Automation of Industrial Security Risk AssessmentsabstractThe current static risk assessment processes and concepts do not match the increasing requirements with regard to flexibility within the industrial automation domain. The amount of manual tasks and needed efforts for risk assessments are too high in order to adequately cover the rising rate of system reconfigurations. Analysing the typical risk assessment processes from the IEC 62443 will show resource constraints with regard to time, bottlenecks, and the main cost drivers. If the most rewarding process steps can be identified and automated, the overall performance of risk assessments can be enhanced to keep up with the demanded flexibility. Marco Ehrlich, Georg Lukas, Henning Trsek, Jürgen Jasperneite, Christian Diedrich |
WFCS | 2 |
| 2020 | Towards Automated Security Evaluation within the Industrial Reference ArchitectureabstractThe current developments towards the visions of Industrie 4.0 will create open and dynamic architectures being supervised by Industrial Automation and Control Systems. Due to this new connectivity and flexibility, future industrial production systems need to be inspected during all phases of the whole lifecycle from a security point of view as well. Frequent reconfiguration and adaptation based on smart services impose advanced requirements on the audits and certification with regard to security. To facilitate that, this work presents an approach for the modeling of security requirements and capabilities within the Industrial Reference Architecture and evaluates it based on the concrete system architectures of a number of industrial use cases. The result is the Sec4ICS tooling-based concept for the automated assessment of security-related functionalities within industrial systems. Marco Ehrlich, Martin Gergeleit, Henning Trsek, Georg Lukas |
ETFA | 4 |
| 2013 | Wireless Mesh Network infrastructure for industrial applications - A case study of tele-operated mobile robotsabstractThe deployment of wireless communication networks in industrial facilities allows for increased flexibility and seamless integration of mobile participants. Time-critical control applications are generally realized with dedicated wireless sensor networks while common WLAN infrastructure networks allow high-throughput best-effort communication. To provide high-capacity communication as well as real-time service quality, we developed and implemented a Wireless Mesh Network (WMN) infrastructure for industrial applications. An example application that requires these properties is the video-based tele-operation of a mobile robot, which we present as case study in this work. It shows the applicability of our infrastructure as well as the necessity of its comprised components. Timo Lindhorst, Georg Lukas, Edgar Nett |
ETFA | 2 |
| 2011 | Modeling Medium Utilization for Admission Control in Industrial Wireless Mesh NetworksabstractWireless Mesh Networks (WMNs) are a promising technology for industrial environment communication because of their high flexibility and low cost. To fulfill the thereby arising reliability demands, admission control can be used to prevent congestion and to provide end-to-end guarantees to applications. However, this requires a very precise modeling of the medium utilization for existing and requested data flows, which is challenging due to the dynamics of such networks. In this paper we propose a medium utilization model for small-scale multi-rate WMNs considering the end-to-end throughput. The model is integrated into a feedback control loop to allow an admission control mechanism to ensure reliable end-to-end communication. Our approach increases the available performance without sacrificing reliability. A real test-bed evaluation shows that our admission control manager allows to fully utilize the network capacity while keeping packet losses under 0.5% and three-hop latency below 5.5ms. This is a significant improvement towards reliable multi-rate WMNs, leveraging their applicability in industrial applications with high throughput demands. Georg Lukas, Timo Lindhorst, Edgar Nett |
SRDS | 1 |
| 2010 | Modeling Fast Link Failure Detection for Dependable Wireless Mesh NetworksabstractWireless Mesh Networks (WMN) provide a flexible and inexpensive way to expand network applications to mobile entities. However, high communication reliability demands can not be met by regular WMNs due to mobility and inherent properties of wireless communication. Failing links are common events which impose a major challenge for providing a dependable communication service. By the use of suitable cross-layer models, we provide a timely detection of failed links without compromising the network stability. It is shown that the packet loss caused by a link failure can be reduced from a time-dependent value to at most four consecutive packets. For a typical control application this means an improvement by a factor of 100. In addition to an empirical evaluation we demonstrate the applicability of the mechanism by utilizing it in a real-world WMN to allow the tele-operation of a mobile robot. Timo Lindhorst, Georg Lukas, Edgar Nett |
NCA | 2 |
| 2010 | Data-Mining-Based Link Failure Detection for Wireless Mesh NetworksabstractMobile robot applications operating in wireless environments require fast detection of link failures in order to enable fast repair. In previous work, we have shown that cross-layer failure detection can reduce failure detection latency significantly. In particular, we monitor the behavior of the WLAN MAC layer to predict failures on the link layer. In this paper, we investigate data mining techniques to determine which parameters, i.e., the events, or combination and timing of events, occurring on the MAC layer most probably lead to link failures. Our results show, that the parameters revealed with the data mining approach produce similar or even more accurate failure predictions than achieved so far. Timo Lindhorst, Georg Lukas, Edgar Nett, Michael Mock |
SRDS | 2 |
| 2009 | MLCCA - Multi-Level Composability Check Architecture for Dependable Communication over Heterogeneous NetworksabstractDuring the design of complex networked systems, it is crucial to ensure the composability of the deployed applications and network protocols. Special care has to be taken to provide non-functional requirements like bandwidth and latency. Existing solutions only tackle this problem during the design phase; later refactoring or added components are not covered, potentially causing QoS violations. We propose MLCCA, a multi-level architecture which complements the design-time composability checks with additional automatic checks performed at compile-time and at run-time. The required infrastructure is embedded into our communication middleware FAMOUSO, making it transparent to application developers. The architecture has been evaluated in a tele-operated mobile robot case study. If the QoS attributes could not be fulfilled due to refactoring or changed conditions, no communication was allowed by the middleware, ensuring that the application could enter a fail-safe state. No data was sent over insufficient channels. Thus, our combination of FAMOUSO and MLCCA enables the sustainable deployment of complex networked systems. Michael Schulze, Georg Lukas |
ETFA | 2 |
| 2009 | WMNSec: security for wireless mesh networksabstractWireless Mesh Networks (WMNs) are gaining popularity as a flexible and inexpensive replacement for Ethernet-based infrastructure. However, WMN security has not been covered adequately by existing standards and implementations. We propose WMNSec, an adaptation of the IEEE 802.11i security standard, specifically targeted at Wireless Mesh Networks and accounting for limited CPU power, node mobility and interruption-free connectivity. WMNSec has been implemented on top of the MadWifi Linux driver and the hostapd suite. Experimental results from a real WMN show that even in a small eight-node network, WMNSec reduces the authentication time by up to a factor of 3 compared to 802.11i, while allowing mobile stations to move without performing additional authentications. The reduced overhead and the mobility feature confirm the practical usability of WMNSec, finally allowing to deploy WMNs in a secure way. Georg Lukas, Christian Fackroth |
IWCMC | 1 |
| 2008 | Preventing admission failures of bandwidth reservation in wireless mesh networksabstractQuality of Service for wireless mesh networks is an often requested feature for various kinds of applications. A common approach is the hop-by-hop reservation of bandwidth for individual routes. In this paper we address the problems of the reservation on a single hop. In previous works we used simulation studies to show that various existing approaches suffer from inconsistencies that lead to admission failures. In this paper, we discuss the reasons for these failures and present a protocol for preventing them. This allows to significantly increase the reliability of established communication links in WMNs. André Herms, Georg Lukas |
AICCSA | 2 |
| 2008 | An integrated approach for reliability and dependability of Wireless Mesh NetworksabstractWireless Mesh Networks (WMNs) are gaining popularity in many application areas because of their low cost and high flexibility. Technically, a WMN forms a distributed network-centric system which aims to provide communication services to the application layer, but has no built-in dependability provisions. To make the network dependable, many problems have to be solved on different layers. With this paper, we describe our ongoing work to provide an integrated solution to increase the dependability of WMNs. Our approach combines network coverage planning on the physical layer, bandwidth management on the link layer and live network monitoring to improve the reliability, availability and maintainability of a WMN. We provide fine-grained means to improve the predictability of the network components, thus making the WMN more dependable. In this paper, we present first results of our work, and describe how they are interleaved. Georg Lukas, André Herms, Svilen Ivanov, Edgar Nett |
IPDPS | 1 |
| 2007 | Precise Admission Control for Bandwidth Reservation in Wireless Mesh NetworksabstractQuality of service in wireless mesh networks is an often requested feature for various kinds of applications. A common approach is the establishment of routes based on hop-by-hop reservation of bandwidth. In this paper we address the problems of admission control in wireless mesh networks. We show that the existing solutions suffer from temporal inconsistencies during the distributed admission process, which lead to high admission failure rates of approximately 2% to 10% in typical topologies, even with the best approach. A solution for this problem is presented, based on the two phase commit protocol. It prevents inconsistencies and the corresponding admission failures. André Herms, Svilen Ivanov, Georg Lukas |
MASS | 3 |
| 2006 | Evaluating a clock synchronization for dependable sensor networksabstractA synchronized clock is an important prerequisite for many distributed algorithms. This clock is used to give an "occured before" relationship, as well as for synchronizing distributed actions. There are many clock synchronization algorithms with varying precisions and assumptions on the underlying network topology. In this paper, a synchronization protocol is presented which achieves a high precision in the order of 20 mus to 30 mus in a one-hop wireless environment, and a multiple of this value for multi-hop wireless networks, such as sensor networks. The protocol works reliably even if message losses occur, which is very likely in wireless networks. For this, it utilizes redundancy in the sent time information. This protocol is implemented and evaluated on standard PC hardware running RT-Linux/Free, and an outline of the extension for multi-hop scenarios is given Spiro Trikaliotis, Georg Lukas |
IPDPS | 2 |