EDBT 2026 Demo / reviewers in the wild / expert
Hartmut König
dblp:k/HartmutKonig
· DBLP profile ↗
44ranked-venue papers
1as first author
7since 2021 · last 2026
0000-0002-8785-6383ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 17 · 1 first-author · 3 since 2021Security and privacy · 11 · 4 since 2021Software engineering, systems software and programming languages · 9Systems, architecture and hardware · 4Human-computer interaction and ubiquitous computing · 3Graphics, computer vision, multimedia, augmented reality and games · 1Applied, interdisciplinary, general and emerging computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | POSTER: Improving WLAN Firmware Fuzzing for Advanced Analyses of Qualcomm Hexagon WLAN Chips
Daniel Bücheler, Daniel Fraunholz, Hartmut König |
WISEC | 3 |
| 2024 | Questioning the Myth: Investigating ICS Traffic Homogeneity from an Anomaly Detection Perspective
Franka Schuster, Hartmut König |
CRITIS | 2 |
| 2024 | No Need for Details: Effective Anomaly Detection for Process Control Traffic in Absence of Protocol and Attack KnowledgeabstractThe rapidly expanding landscape of attack vectors on cyber-physical systems (CPS) has led to the proposal of various attack detection methods for this area. Most approaches focus on analyzing time series of data from physical processes. However, the availability of such well-prepared data is not guaranteed in most infrastructures. In contrast, relatively few approaches address the direct analysis of network traffic, which is the natural basis for interaction between CPS devices. In this paper, we examine traffic-based methods using data flows, packets, and packet sequences as monitoring base. We include the packet payload in the analysis in a protocol-agnostic manner. This offers the possibility to apply the approach in different networks independently of the used CPS technologies or processes. We use one-class machine learning methods applied on only normal traffic in the training phase. This allows us to configure the detection capabilities independently of attack knowledge or given attack examples. Besides the evaluation regarding detection capability and efficiency, we further examine the potential of the protocol-agnostic models for a transfer on foreign detection scenarios. Franka Schuster, Hartmut König |
RAID | 2 |
| 2024 | Radio-in-the-Loop simulation and emulation modeling for energy-efficient and cognitive Internet of Things in smart cities: A cross-layer optimization case studyabstractWireless communication technologies and Internet of Things (IoT) applications are the main drivers of upcoming sustainable smart networks which require an effective resource management. The reduction of the transmission energy consumption and the efficient utilization of the available spectrum for wireless communication, for instance, have to be enabled by energy-efficient and cognitive IoT networks. These are implemented through optimized communication protocol stacks and algorithms that rely on actual physical layer and channel state information. The modeling and the prototype evaluation of protocol optimization approaches are mainly driven by pure simulation studies with abstracted physical layer and channel models. With the Radio-in-the-Loop (RIL) simulation (S. Böhm and H. König, 2023) and modeling (S. Böhm and H. König, 2021), we have created an evaluation approach that integrates real wireless hardware and radio environments into the simulation of protocol sequences and algorithms. In this paper, we summarize the fundamentals of our basic methodology and demonstrate a cross-layer optimization case study for energy efficient modeling using software-defined radios. We exemplary show the scenario of a receiver-sensitivity control to increase the energy efficiency of receiver-dominated IoT nodes in Smart City networks. Sebastian Boehm, Hartmut König |
Comput. Commun. | 2 |
| 2023 | Whitelisting for Characterizing and Monitoring Process Control Communication
Andreas Paul 0003, Franka Schuster, Hartmut König |
NSS | 3 |
| 2023 | Real-Time-Shift: Pseudo-Real-Time Event Scheduling for the Split-Protocol-Stack Radio-in-the-Loop EmulationabstractThe incorporation of real radio hardware and physical emulated radio links into higher layer network and protocol simulation studies has been a largely untouched area of research so far. The Split-Protocol-Stack Radio-in-the-Loop emulation combines pure discrete-event protocol simulation with a hardware-based radio link emulation. Since the basic techniques involve contrary time concepts, event communication between the two domains requires a rethink of scheduling and synchronization. With the Real-Time-Shift conservative synchronization and time compensation scheme, the simulator is decoupled from real-time constraints and limitations by introducing predetermined pause times for event execution. In this work, we present the core synchronization and event scheduling approach allowing for scalable pseudo-real-time simulations with radio hardware in the loop. This enables discrete-event simulations for wireless host systems and networks with link-level emulation accuracy, accompanied by an overall high modeling flexibility. Sebastian Boehm, Hartmut König |
Comput. Commun. | 2 |
| 2022 | Real-Time-Shift: Pseudo-Real-Time Event Scheduling for the Split-Protocol-Stack Radio-in-the-Loop EmulationabstractThe incorporation of real radio hardware and physical emulated radio links into higher layer network and protocol simulation studies has been a largely untouched area of research so far. The Split-Protocol-Stack Radio-in-the-Loop emulation combines pure discrete-event protocol simulation with a hardware-based radio link emulation. Since the basic techniques involve contrary time concepts, event communication between the two domains requires a rethink of scheduling and synchronization. With the Real-Time-Shift conservative synchronization and time compensation scheme, the simulator is decoupled from real-time constraints and limitations by introducing predetermined pause times for event execution. In this paper, we present the core synchronization and event scheduling approach allowing for scalable pseudo-real-time simulations with radio hardware in the loop. This enables discrete-event simulations for wireless host systems and networks with link-level emulation accuracy, accompanied by an overall high modeling flexibility. Sebastian Boehm, Hartmut König |
MSWiM | 2 |
| 2019 | No Need to Marry to Change Your Name! Attacking Profinet IO Automation Networks Using DCP
Stefan Mehner, Hartmut König |
DIMVA | 2 |
| 2019 | An SDN-based Approach to Protect Communication Between Virtual MachinesabstractAs a result of the increasing virtualization of computer systems, areas arise in corporate networks and cloud environments that are insufficiently supervised by established security mechanisms, such as firewalls or network monitoring. Conventional firewalls cannot protect Virtual Machines (VMs) because the communication between them runs only within the virtualization server/host. Thus, virtualized systems represent blind spots for network monitoring. They are particularly susceptible to attacks on the data link and network layers (L2/L3 attacks). Software-Defined Networking (SDN) provides the opportunity to better control communication relationships. In this paper, we present an SDN-based approach to protect the communication between VMs on a virtualization host which preserves the multi-gigabit throughput of interconnected VMs. Radoslaw Cwalinski, René Rietz, Michael Vogel, Hartmut König |
LCN | 4 |
| 2018 | Attack and Fault Detection in Process Control Communication Using Unsupervised Machine LearningabstractIn the course of industrial digitalization, the security of process control networks and especially critical infrastructures has become a major issue that requires novel methods to achieve a multi-level protection. An important feature of this protection is a protocol-specific monitoring within the process control networks that identifies faults and attacks which already have overcome the firewall protection. For a wide-spread application in various sites, this monitoring must be self-adaptive to the different traffic characteristics of the respective networks. Protocol knowledge combined with unsupervised machine learning algorithms can leverage this task. In this paper we present the latest results of applying two machine learning methods on real-world traffic datasets from two plant process control networks. The results for different mappings of the considered packet features are discussed in terms of f-score, precision, and recall. They demonstrate the high potential of using unsupervised learning for training anomaly detectors to identify intrusions in industrial networks. Franka Schuster, Fabian Malte Kopp, Andreas Paul 0003, Hartmut König |
INDIN | 4 |
| 2016 | Distributed Cluster-Topology Maintenance for Mobile Collaborative ApplicationsabstractNowadays, collaborative applications play an increasing role in mobile communications in order to enable cooperation among mobile and/or stationary participants - often using the peer-to-peer (P2P) group communication paradigm. The probability of communication failures increases in mobile environments. As a consequence, frequent leaving and joining of partners can be observed resulting in unstable group topologies. A widely used approach is to divide the group into peer clusters that are fully meshed among each other. In this paper, we propose an application-independent approach for a periodic maintenance of distributed cluster-based group topologies for mobile collaborative applications. The proposed approach also dynamically adapts the overlay structure to changing network conditions. The maintenance strategy can be parametrized by several metrics. It outperforms simple overlay maintenance strategies, such as round-robin, by respecting the resource and computation limitations of mobile devices. The run-time is increased by 10% in the best case compared to LEACH, and by 3 - 5% on average. We describe the approach and evaluate its performance w.r.t. different metrics. Jan Gäbler, Hartmut König |
LCN | 2 |
| 2016 | Firewalls for the Web 2.0abstractThe widespread use of Web 2.0 technologies yields an increasing threat potential for users and related systems. Modern web applications and online services are nowadays based on Web 2.0 technologies, such as JavaScript and AJAX, and thus on the execution of active content in the browsers of the users. Firewalls are a common practice to securely connecting to the internet. In this paper, we propose a novel perimeter firewall architecture for web applications that addresses the entire process chain starting from the data transfer with HTTP via the analysis of manipulated web documents to the extraction and analysis of active contents. The basic idea is to allow only a restricted set of web applications to pass the firewall based on a model of their HTML and JavaScript structure. We evaluate the capability of the resulting models for identifying the underlying web applications and their ability to ward off additional malicious inputs. René Rietz, Hartmut König, Steffen Ullrich, Benjamin Stritter |
QRS | 2 |
| 2015 | Distributed latency estimation using global knowledge for mobile collaborative applicationsabstractMobile collaborative applications are designed for close collaboration among mobile peers. The coordination of these applications is completely distributed using a global knowledge. There is no central controller or manager. In order to implement this coordination with a reasonable Quality of Service a sufficiently precise estimation of the transmission latency within the group is needed. Classical estimation approaches use a local clock to determine the latency for the next message to transfer. Due to the asynchronous nature of the applications, it is not possible to determine the timeout value in a distributed fashion based on latency estimation with classical approaches. In this paper, we propose a distributed latency estimation for mobile collaborative applications.We present five approaches to estimate the latency of group-communication-operations and compare their performance with that of Bertier. It shows that the Max-Estimator outperforms the other ones. Jan Gäbler, Hartmut König |
IWCMC | 2 |
| 2014 | Parallelization of Network Intrusion Detection Systems under Attack Conditions
René Rietz, Michael Vogel, Franka Schuster, Hartmut König |
DIMVA | 4 |
| 2014 | Puzzle - an efficient, compression independent video encryption algorithm
Fuwen Liu, Hartmut König |
Multim. Tools Appl. | 2 |
| 2013 | uBeeMe - A platform to enable mobile collaborative applicationsabstractThe vision of ubiquitous communication is driven by increasing user mobility and the need to collaborate. Mobile collaborative applications, such as mobile audio/video conferences, collaborative writing, social networks, and mobile gaming, are already important parts of human interaction. In this p Jan Gäbler, Ronny Klauck, Mario Pink, Hartmut König |
CollaborateCom | 4 |
| 2013 | Towards the Protection of Industrial Control Systems - Conclusions of a Vulnerability Analysis of Profinet IO
Andreas Paul 0003, Franka Schuster, Hartmut König |
DIMVA | 3 |
| 2012 | On the Formalization of UML Activities for Component-Based Protocol Design Specifications
Prabhu Shankar Kaliappan, Hartmut König |
SOFSEM | 2 |
| 2011 | An Approach to Synchronize UML-Based Design Components for Model-Driven Protocol DevelopmentabstractApplying UML diagrams for the design of dependable systems like communication protocols helps to visualize the protocol behavior in multiple representations. In principle, protocols are comprehensible by modeling its behaviors through sequence diagrams. However, the sequence diagrams encapsulate local protocol functions, such as protocol data unit coding/decoding, correctness checks, etc. To model the local actions of the protocol entities activity diagrams may be used as a balancing model. By using two different models, one should ensure that the described behaviors are consistent. To prove this we present an approach in this paper to synchronize the UML sequence and activity diagrams through mapping rules. The rules are predefined according to the UML specification by a stereotype. Later they are used for validating the two diagrams. We show the approach for an example protocol function. Prabhu Shankar Kaliappan, Hartmut König |
SEW | 2 |
| 2011 | A Simple Balanced Password-Authenticated Key Agreement ProtocolabstractPassword authentication protocols have been broadly deployed in client/server communication settings for its convenient usage and low costs of deployment. Nowadays peer-to-peer networks become increasingly popular, where the role of principals is symmetric (balanced), i.e. each principal acts not only as a client but also as a server. In this setting a robust and simple password authentication protocol is highly desired, since PKIs (Public Key Infrastructures) are not always available for authentication. In this paper, we present a simple password-authenticated key agreement protocol for the use in peer-to-peer communication paradigms. It fulfils the security requirements on password authentication protocols, and is resilient to passive and active attacks as well as dictionary attacks. The proposed scheme is more efficient than the well established protocols due to its simple design concept. Fuwen Liu, Hartmut König |
TrustCom | 2 |
| 2011 | Using model checking to identify errors in intrusion detection signatures
Sebastian Schmerl, Michael Vogel, Hartmut König |
Int. J. Softw. Tools Technol. Transf. | 3 |
| 2010 | Model-Driven Protocol Design Based on Component Oriented Modeling
Prabhu Shankar Kaliappan, Hartmut König, Sebastian Schmerl |
ICFEM | 2 |
| 2010 | A survey of video encryption algorithms
Fuwen Liu, Hartmut König |
Comput. Secur. | 2 |
| 2009 | Predicting Free Computing Capacities on Individual Machines
Alek Opitz, Hartmut König |
GPC | 2 |
| 2009 | Security Considerations on Pervasive Real-time CollaborationabstractA real-time pervasive collaboration system enables people to work together on a certain task at anytime and from anyplace. Security is one of the primary concerns for these systems, when running over public networks. In particular, end-to-end security represents a crucial issue in pervasive collaboration environments due to the heterogeneity of the networks and devices used. In this paper, we explore the feasibility of security measures at the diverse protocol layers to shielding pervasive real-time collaboration systems, and propose a security framework residing at the application layer to secure pervasive collaborations. Fuwen Liu, Hartmut König |
MASS | 2 |
| 2008 | Systematic Signature Engineering by Re-use of Snort SignaturesabstractMost intrusion detection systems deployed today apply the misuse detection approach. Misuse detection compares recorded audit data with predefined patterns denoted as signatures. A signature is usually empirically engineered based on experience and expert knowledge. This induces relatively long development times for novel signatures causing inappropriate long vulnerability windows. Methods for a systematic engineering have been scarcely reported so far. Approaches for an automated re-use of design and modeling decisions of available signatures also do not exist. In this paper we present an approach for systematic engineering of signatures which is based on the re-use of existing signatures. It exploits similarities with known attacks for the engineering process. The method applies an iterative abstraction of signatures. Based on a weighted assessment of the abstractions the signature engineer can select the most appropriate signatures or fragments of signatures for the development of the signature for a new attack. We demonstrate the usefulness of the method using Snort signatures as example. Sebastian Schmerl, Hartmut König, Ulrich Flegel, Michael Meier 0001, René Rietz |
ACSAC | 2 |
| 2008 | What Does Grid Computing Cost?
Alek Opitz, Hartmut König, Sebastian Szamlewska |
J. Grid Comput. | 2 |
| 2005 | Secure and efficient key distribution for collaborative applicationsabstractConfidentiality is a key demand for many collaborative applications in the Internet, e.g. business meetings. In a more and more mobile society there is an increasing need of spontaneous meetings in ad hoc environments, often with changing partners. To assure confidentiality of such meetings the partners have to agree upon a common secret key for encrypting their communication. While centralized collaborative systems provide practicable solutions for this, it still represents a challenging task in decentralized systems using the peer-to-peer paradigm. In this paper we present a simple key distribution protocol, called VTKD, which was especially designed for small dynamic peer groups. It consists of two parts: a mutual authentication of the partners and a secure key renewal. The protocol uses a virtual token to determine the partner responsible for the key generation and distribution procedure. VTKD fulfills the relevant demands concerning group key exchange and is more efficient related to key renewal delay than existing key exchange protocols. Fuwen Liu, Hartmut König |
CollaborateCom | 2 |
| 2005 | Optimizing the Access to Read-Only Data in Grid Computing
Alek Opitz, Hartmut König |
DAIS | 2 |
| 2005 | Improving the Efficiency of Misuse Detection
Michael Meier 0001, Sebastian Schmerl, Hartmut König |
DIMVA | 3 |
| 2005 | A novel encryption algorithm for high resolution videoabstractThe popularity of multimedia applications is rapidly growing nowadays. The confidentiality of video communication is of primary concern for their commercial use, e.g. in video on demand services or in multiparty video conferences. Specific video encryption algorithms are strongly required in real-time multimedia communication to fulfill the strict timing requi-rements. In this paper we present a novel video encryption algorithm, called Puzzle, to encrypt video data in software. It is fast enough to meet real-time demands and provides a sufficient security. The algorithm can readily be incorporated into existing multimedia systems. Fuwen Liu, Hartmut König |
NOSSDAV | 2 |
| 2005 | A Secure P2P Video Conference System for Enterprise Environments
Fuwen Liu, Hartmut König |
NPC | 2 |
| 2001 | Automated Derivation of ILP Implementations from SDL Specifications
Sven Twarok, Peter Langendörfer, Hartmut König |
FORTE | 3 |
| 2001 | Evaluation of Well-Known Protocol Implementation Techniques for Application in Wireless Networks
Peter Langendörfer, Rolf Kraemer, Hartmut König |
J. Supercomput. | 3 |
| 2000 | Improving the efficiency of automated protocol implementations using a configurable FDT compiler
Hartmut König, Peter Langendörfer, Heiko Krumm |
Comput. Commun. | 1 |
| 1999 | Deriving Activity Thread Implementations from Formal Descriptions Using Transition Reordering
Peter Langendörfer, Hartmut König |
FORTE | 2 |
| 1999 | OCTOPUS-a scalable global multiparty video conferencing systemabstractThis paper reports a joint work between the Hong Kong University of Science and Technology and the Brandenburg Technical University of Cottbus, Germany, in developing a global video conferencing framework called OCTOPUS that interconnects local conferencing systems over long distances. The system makes use of both high level information provided by the participants (to decide which videos are more important to them) as well as low level adaptive mechanisms to perform media scaling as the network and the processor intensities change. It is possible to provide a customized service to each conference participant according to his/her needs and the resources available at each site. OCTOPUS itself makes no assumption on the architecture of the local video conference systems. The paper presents the architecture and the design philosophy of the OCTOPUS framework. Samuel T. Chanson, Albert K. T. Hui, Eddy Siu, Ines Beier, Hartmut König, Mario Zühlke |
ICCCN | 5 |
| 1999 | Automated Protocol Implementations Based on Activity ThreadsabstractIn this paper we present a new approach for the automated mapping of formal descriptions into activity thread implementations. The approach resolves semantic conflicts by reordering of statements at compile time. This simplifies the mapping process and considerably improves the efficiency of the generated code. The approach is implemented in the SDL compiler COCOS. We describe the approach as well as its implementation and prove how semantic conflicts are resolved. Finally we present measurements which show the achieved performance gain. Peter Langendörfer, Hartmut König |
ICNP | 2 |
| 1998 | GCSVA - A Multiparty Videoconferencing System with Distributed Group and QoS ManagementabstractIn this paper, we introduce the multiparty videoconferencing system GCSVA (group communication and scalability in videoconferencing over ATM). It has been designed for the support of collaborative applications. The main features of GCSVA are: a strong floor control organization, dynamic scalability of video streams according to the number and the performance of the connected hosts, and a distributed group and QoS management. We describe these features as well as the design decisions made for their introduction. Finally, we give a short overview about the group communication protocol which constitutes the central element of the approach. Ines Beier, Hartmut König |
ICCCN | 2 |
| 1997 | Virtual Private ResourcesabstractCurrent approaches for service mediation, such as trading, do not provide means for a long-term binding of services. They do not ensure that certain services are provided and that the desired service properties are fulfilled. Moreover, a server may withdraw a service offer at any time. For the integration of external services into an enterprise internal service market, it is necessary to guarantee the permanent availability of the services with desired properties and to sustain these properties. This requires that the technical relationship between the service provider and the customer has to be extended by commercial and legal ones. In this paper, we introduce the concept of virtual private resources to enable long-term relationships between the customer and the provider of a service. Virtual private resources are services that can be bound by contract for a longer period of time. They can be considered as private ones, although the physical resources that provide the service may change or be shared with other customers. We introduce the basics of the approach and present a possible architecture for implementing virtual private resources. Finally, we give an example for the application of virtual private resources to implement a traffic information system. Thomas Preuß, Jens-Hagen Syrbe, Hartmut König |
EDOC | 3 |
| 1997 | On the Influence of Semantic Constraints on the Code Generation from Estelle Specifications
Ralf Henke, Andreas Mitschele-Thiel, Hartmut König |
FORTE | 3 |
| 1997 | Specification-based Testing of Concurrent Systems
Andreas Ulrich, Hartmut König |
FORTE | 2 |
| 1996 | Improving the efficiency of automated protocol implementation using Estelle
Reinhard Gotzhein, Jan Bredereke, Wolfgang Effelsberg, Stephan Fischer 0001, Thomas Held, Hartmut König |
Comput. Commun. | 6 |
| 1995 | SELEXPERT - A Knowledge-based Tool for Test Case Selection
Abdelaziz Guerrouat, Hartmut König, Andreas Ulrich |
FORTE | 2 |