EDBT 2026 Demo / reviewers in the wild / expert
Edgar R. Weippl
dblp:w/EdgarRWeippl
· DBLP profile ↗
143ranked-venue papers
16as first author
25since 2021 · last 2026
0000-0003-0665-6126ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 89 · 4 first-author · 17 since 2021Databases, data management, data science and information retrieval · 25 · 9 first-authorApplied, interdisciplinary, general and emerging computing · 22 · 7 first-author · 2 since 2021Artificial intelligence and machine learning · 9 · 2 first-author · 2 since 2021Human-computer interaction and ubiquitous computing · 8 · 3 since 2021Systems, architecture and hardware · 6 · 1 since 2021Software engineering, systems software and programming languages · 6Computer networks · 3 · 1 first-author · 2 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | StealthCup: Realistic, Multi-Stage, Evasion-Focused CTF for Benchmarking IDS
Manuel Kern, Dominik Steffan, Felix Schuster, Florian Skopik, Max Landauer, David Allison, Simon Freudenthaler, Edgar R. Weippl |
AsiaCCS | 8 |
| 2026 | Obfuscation detection using matrix complexity features of binary grayscale images
Sebastian Raubitzek, Sebastian Schrittwieser, Caroline König, Patrick Felbauer, Kevin Mallinger, Andreas Ekelhart, Edgar R. Weippl |
Comput. Secur. | 7 |
| 2026 | Collaborative anomaly detection in log data: Comparative analysis and evaluation frameworkabstractLog Anomaly Collaborative Intrusion Detection Systems (CIDS) are designed to detect suspicious activities and security breaches by analyzing log files using anomaly detection techniques while leveraging collaboration between multiple entities (e.g., different systems, organizations, or network nodes). Unlike traditional Intrusion Detection Systems (IDS) that require centralized algorithm updates and data aggregation, CIDS enable decentralized updates without extensive data exchange, improving efficacy, scalability, and compliance with regulatory constraints. Additionally, inter-detector communication helps to reduce the number of false positives. These systems are particularly useful in distributed environments, where individual system have limited visibility into potential threats. This paper reviews the current landscape of Log Anomaly CIDS and introduces an open-source framework designed to create benchmark datasets for evaluating system performance. We categorize log anomaly detectors into three categories: Sequential-wise, Embedding-wise, and Graph-wise. Furthermore, our open framework facilitates rigorous evaluation against different challenges identifying weaknesses in existing methods like Deeplog and enhancing model robustness. André García Gómez, Max Landauer, Markus Wurzenberger, Florian Skopik, Edgar R. Weippl |
Future Gener. Comput. Syst. | 5 |
| 2026 | Lightweight Techniques for Federated Anomaly Detection in Log DataabstractAccurately and efficiently identifying anomalies within log data is crucial for maintaining the reliability, availability, and security of modern computing systems. In interconnected environments, log data often come from distributed sources such as Internet of Things (IoT) devices, industrial networks, or smart grids. Centralizing these logs for anomaly detection can be challenging due to strict confidentiality requirements, regulatory constraints, and the limited bandwidth of edge networks. Federated learning (FL) offers an alternative by enabling local model training on site, while aggregating only models instead of sensitive data, thereby preserving data confidentiality and reducing data transfer. This paper develops and evaluates a federated log-anomaly detection pipeline and analyzes its components. We adapt lightweight anomaly detection techniques in a federated setting, comparing them with deep learning (DL) methods, assessing detection capabilities, computational efficiency, memory requirements, and inference time. We explore the residual privacy risks in FL within the proposed pipeline, develop a threat model and suggest mitigation strategies. Our findings indicate that lightweight anomaly detection methods can match the effectiveness of DL techniques in the FL framework, while often providing improved computational and communication efficiency. Furthermore, these techniques show better resilience to non-IID data distributions, a typical FL challenge that can severely hinder the effectiveness of traditional machine learning models. However, the memory footprint of lightweight models varies with dataset characteristics and, in some cases, may exceed that of DL models. Anastasia Pustozerova, André García Gómez, Max Landauer, Markus Wurzenberger, Florian Skopik, Edgar R. Weippl, Rudolf Mayer, Andreas Ekelhart |
IEEE Trans. Reliab. | 6 |
| 2025 | Leaky Apps: Large-scale Analysis of Secrets Distributed in Android and iOS AppsabstractMobile apps store various types of secrets to support their functionalities. These include API keys, and cryptographic material to authenticate users and access backend services. Once distributed, attackers can reverse-engineer the apps, and these secrets become accessible, posing risks such as data leaks, and service abuse. Sebastian Schrittwieser, Edgar R. Weippl |
CCS | 3 |
| 2024 | Message from General Chairs; EuroSP 2024abstractA warm welcome to Vienna! We're excited to host the IEEE EuroS&P 2024 at the University of Vienna's Faculty of Informatics from July 8th to 12th. It brings together researchers and enthusiasts in security&privacy from all over the world for in-person discussions and collaborations. Huge thanks to the organizers and everyone involved in making this event possible! Edgar R. Weippl, Matteo Maffei |
EuroS&P | 1 |
| 2024 | Why E.T. Can't Phone Home: A Global View on IP-based Geoblocking at VoWiFiabstractIn current cellular network generations (4G, 5G) the IMS (IP Multimedia Subsystem) plays an integral role in terminating voice calls and short messages. Many operators use VoWiFi (Voice over Wi-Fi, also Wi-Fi calling) as an alternative network access technology to complement their cellular coverage in areas where no radio signal is available (e.g., rural territories or shielded buildings). In a mobile world where customers regularly traverse national borders, this can be used to avoid expensive international roaming fees while journeying overseas, since VoWiFi calls are usually invoiced at domestic rates. To not lose this revenue stream, some operators block access to the IMS for customers staying abroad. Gabriel K. Gegenhuber, Philipp É. Frenzel, Edgar R. Weippl |
MobiSys | 3 |
| 2024 | Code Obfuscation Classification Using Singular Value Decomposition on Grayscale Image Representations
Sebastian Raubitzek, Sebastian Schrittwieser, Caroline Lawitschka, Kevin Mallinger, Andreas Ekelhart, Edgar R. Weippl |
SECRYPT | 6 |
| 2024 | Safe or Scam? An Empirical Simulation Study on Trust Indicators in Online Shopping
Sebastian Schrittwieser, Andreas Ekelhart, Esther Seidl, Edgar R. Weippl |
SECRYPT | 4 |
| 2024 | Diffie-Hellman Picture Show: Key Exchange Stories from Commercial VoWiFi Deployments
Gabriel K. Gegenhuber, Florian Holzbauer, Philipp É. Frenzel, Edgar R. Weippl, Adrian Dabrowski |
USENIX Security Symposium | 4 |
| 2024 | A logging maturity and decision model for the selection of intrusion detection cyber security solutionsabstractMany modern cyber attack techniques cannot be prevented. Logging and monitoring, however, offer a means to at least detect these techniques early, and therefore become increasingly important for defense. Many companies are unfortunately reluctant to invest more in cyber security logging and monitoring or hire additional security staff to operate detective solutions. There is a need for a methodology to pick appropriate cyber security solutions from the vast pool of available products. Our model takes requirements mandated by common standards from ISO, NIST, BSI and the like into account. While standards and guidelines remain at a high abstraction level and are applicable to different organizations over a long period of time, guidance on implementation becomes outdated comparatively quickly. We propose a novel logging maturity and decision model for the selection of the best fitting cyber security solutions for an organization. The novelty is that this model accounts for constraints in the selection process, such as cost, complexity, compliance, and relevance to the organization's assets. We validate the model with MITRE ATT&CK framework data and apply it to illustrative use cases based on our survey. Manuel Kern, Max Landauer, Florian Skopik, Edgar R. Weippl |
Comput. Secur. | 4 |
| 2023 | Controllable AI - An Alternative to Trustworthiness in Complex AI Systems?abstractAbstract The release of ChatGPT to the general public has sparked discussions about the dangers of artificial intelligence (AI) among the public. The European Commission’s draft of the AI Act has further fueled these discussions, particularly in relation to the definition of AI and the assignment of risk levels to different technologies. Security concerns in AI systems arise from the need to protect against potential adversaries and to safeguard individuals from AI decisions that may harm their well-being. However, ensuring secure and trustworthy AI systems is challenging, especially with deep learning models that lack explainability. This paper proposes the concept of Controllable AI as an alternative to Trustworthy AI and explores the major differences between the two. The aim is to initiate discussions on securing complex AI systems without sacrificing practical capabilities or transparency. The paper provides an overview of techniques that can be employed to achieve Controllable AI. It discusses the background definitions of explainability, Trustworthy AI, and the AI Act. The principles and techniques of Controllable AI are detailed, including detecting and managing control loss, implementing transparent AI decisions, and addressing intentional bias or backdoors. The paper concludes by discussing the potential applications of Controllable AI and its implications for real-world scenarios. Peter Kieseberg, Edgar R. Weippl, A Min Tjoa, Federico Cabitza, Andrea Campagner, Andreas Holzinger |
CD-MAKE | 2 |
| 2023 | Large Language Models for Code Obfuscation Evaluation of the Obfuscation Capabilities of OpenAI's GPT-3.5 on C Source Code
Patrick Kochberger, Maximilian Gramberger, Sebastian Schrittwieser, Caroline Lawitschka, Edgar R. Weippl |
SECRYPT | 5 |
| 2023 | MobileAtlas: Geographically Decoupled Measurements in Cellular Networks for Security and Privacy Research
Gabriel K. Gegenhuber, Wilfried Mayer, Edgar R. Weippl, Adrian Dabrowski |
USENIX Security Symposium | 3 |
| 2023 | An extended view on measuring tor AS-level adversariesabstractTor provides anonymity to millions of users around the globe which has made it a valuable target for malicious actors. As a low-latency anonymity system, it is vulnerable to traffic correlation attacks from strong passive adversaries such as large autonomous systems (ASes). In preliminary work Mayer et al.(2020), we have developed a measurement approach utilizing the RIPE Atlas framework – a network of more than 11,000 probes worldwide – to infer the risk of deanonymization for IPv4 clients in Germany and the US. In this paper, we apply our methodology to additional scenarios providing a broader picture of the potential for deanonymization in the Tor network. In particular, we (a) repeat our earlier (2020) measurements in 2022 to observe changes over time, (b) adopt our approach for IPv6 to analyze the risk of deanonymization when using this next-generation Internet protocol, and (c) investigate the current situation in Russia, where censorship has been intensified after the beginning of Russia’s full-scale invasion of Ukraine. According to our results, Tor provides user anonymity at consistent quality: While individual numbers vary in dependence of client and destination, we were able to identify ASes with the potential to conduct deanonymization attacks. For clients in Germany and the US, the overall picture, however, has not changed since 2020. In addition, the protocols (IPv4 vs. IPv6) do not significantly impact the risk of deanonymization. Russian users are able to securely evade censorship using Tor. Their general risk of deanonymization is, in fact, lower than in the other investigated countries. Beyond, the few ASes with the potential to successfully perform deanonymization are operated by Western companies, further reducing the risk for Russian users. Gabriel K. Gegenhuber, Florian Holzbauer, Wilfried Mayer, Georg Merzdovnik, Edgar R. Weippl, Johanna Ullrich |
Comput. Secur. | 6 |
| 2023 | QualSec: An Automated Quality-Driven Approach for Security Risk Identification in Cyber-Physical Production SystemsabstractAs the threat landscape in the industrial domain continually advances, security-by-design is an ever-growing concern in the engineering of cyber-physical production systems (CPPSs). Often, quality aspects are not considered when securing CPPSs, which creates attack vectors that could lead to malicious activity affecting the products' quality. Since quality control systems generally provide inadequate protection against intentionally introduced defects, and can be susceptible to attacks, quality considerations must be integrated into security-aware CPPS engineering. For this purpose, we propose the QualSec method that automatically identifies security risks pertaining to CPPSs, building on the quality characteristics associated with manufacturing operations to determine cascading effects. QualSec is based on a semantic representation of engineering knowledge, allowing to efficiently reuse engineering models from AutomationML artifacts. Moreover, QualSec utilizes Petri nets to facilitate the analysis of security risks and cascading effects. In this way, QualSec informs users about possible attack paths for compromising quality characteristics, how attackers may disguise their malicious actions, and the possible consequences of attacks with respect to product quality. We demonstrate the benefits of QualSec in a case study and analyze its scalability through a rigorous performance evaluation. Matthias Eckhart, Andreas Ekelhart, Stefan Biffl, Arndt Lüder, Edgar R. Weippl |
IEEE Trans. Ind. Informatics | 5 |
| 2022 | SoK: How private is Bitcoin? Classification and Evaluation of Bitcoin Privacy TechniquesabstractBlockchain is a disruptive technology that promises a multitude of benefits, such as transparency, traceability, and immutability. However, this unique bundle of key characteristics has proved to be a double-edged sword that can put users’ privacy at risk. Unlike in traditional systems, Bitcoin transactions are publicly and permanently recorded, and anyone can access the full history of the records. Despite using pseudonymous identities, an adversary can undermine users’ financial privacy and reveal their actual identities by using advanced heuristics and techniques to identify possible links between transactions, senders, receivers, and consumed services (e.g., online purchases). Hence, a multitude of approaches has been proposed to reduce financial transparency and enhance users’ anonymity. These techniques range from mixing services to off-chain transactions that address different privacy issues. In this paper, we particularly focus on comparing and evaluating privacy techniques in the Bitcoin blockchain (which can be applied in (Unspent Transaction Output (UTXO) based blockchains), present their limitations, and highlight new challenges. Simin Ghesmati, Walid Fdhila, Edgar R. Weippl |
ARES | 3 |
| 2022 | Opportunistic Algorithmic Double-Spending: - How I Learned to Stop Worrying and Love the Fork
Nicholas Stifter, Aljosha Judmayer, Philipp Schindler, Edgar R. Weippl |
ESORICS (1) | 4 |
| 2022 | Zero-Rating, One Big Mess: Analyzing Differential Pricing Practices of European MNOsabstractZero-rating, the practice of not billing data traffic that belongs to certain applications, has become popular within the mobile ecosystem around the globe. There is an ongoing debate whether mobile operators should be allowed to differentiate traffic or whether net neutrality regulations should prevent this. Despite the importance of this issue, we know little about the technical aspects of zero-rating offers since the implementation is kept secret by mobile operators and therefore is opaque to end-users and regulatory agencies. This work aims to independently audit classification practices used for zero-rating of four popular applications at seven different mobile operators in the EU. We execute and evaluate more than 300 controlled experiments within domestic and internationally roamed environments and identify potentially problematic behavior at almost all investigated operators. With this study, we hope to increase transparency around the current practices and inform future decisions and policies. Gabriel K. Gegenhuber, Wilfried Mayer, Edgar R. Weippl |
GLOBECOM | 3 |
| 2022 | Automated Security Risk Identification Using AutomationML-Based Engineering DataabstractSystems integrators and vendors of industrial components need to establish a security-by-design approach, which includes the assessment and subsequent treatment of security risks. However, conducting security risk assessments along the engineering process is a costly and labor-intensive endeavor due to the complexity of the system(s) under consideration and the lack of automated methods. This, in turn, hampers the ability of security analysts to assess risks pertaining to cyber-physical systems (CPSs) in an efficient manner. In this work, we propose a method that automatically identifies security risks based on the CPS's data representation, which exists within engineering artifacts. To lay the foundation for our method, we present security-focused semantics for the engineering data exchange format AutomationML (AML). These semantics enable the reuse of security-relevant know-how in AML artifacts by means of a formal knowledge representation, modeled with a security-enriched ontology. Our method is capable of automating the identification of security risk sources and potential consequences in order to construct cyber-physical attack graphs that capture the paths adversaries may take. We demonstrate the benefits of the proposed method through a case study and an open-source prototypical implementation. Finally, we prove that our solution is scalable by conducting a rigorous performance evaluation. Matthias Eckhart, Andreas Ekelhart, Edgar R. Weippl |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2021 | SoK: Automatic Deobfuscation of Virtualization-protected ApplicationsabstractMalware authors often rely on code obfuscation to hide the malicious functionality of their software, making detection and analysis more difficult. One of the most advanced techniques for binary obfuscation is virtualization-based obfuscation, which converts the functionality of a program into the bytecode of a randomly generated virtual machine which is embedded into the protected program. To enable the automatic detection and analysis of protected malware, new deobfuscation techniques against virtualization-based obfuscation are constantly being developed and proposed in the literature. Patrick Kochberger, Sebastian Schrittwieser, Stefan Schweighofer, Peter Kieseberg, Edgar R. Weippl |
ARES | 5 |
| 2021 | Digital Transformation for Sustainable Development Goals (SDGs) - A Security, Safety and Privacy Perspective on AI
Andreas Holzinger, Edgar R. Weippl, A Min Tjoa, Peter Kieseberg |
CD-MAKE | 2 |
| 2021 | RandRunner: Distributed Randomness from Trapdoor VDFs with Strong Uniqueness
Philipp Schindler, Aljosha Judmayer, Markus Hittmeir, Nicholas Stifter, Edgar R. Weippl |
NDSS | 5 |
| 2021 | On the Usability of Authenticity Checks for Hardware Security Tokens
Katharina Pfeffer, Alexandra Mai, Adrian Dabrowski, Matthias Gusenbauer, Philipp Schindler, Edgar R. Weippl, Michael Franz, Katharina Krombholz |
USENIX Security Symposium | 6 |
| 2021 | Editorial for Special Issue on Block Chain Technology and its Applications
Paolo Mori, Wolfgang Prinz, Laura Ricci, Edgar R. Weippl |
Pervasive Mob. Comput. | 4 |
| 2020 | Actively Probing Routes for Tor AS-Level Adversaries with RIPE Atlas
Wilfried Mayer, Georg Merzdovnik, Edgar R. Weippl |
SEC | 3 |
| 2020 | HydRand: Efficient Continuous Distributed RandomnessabstractA reliable source of randomness is not only an essential building block in various cryptographic, security, and distributed systems protocols, but also plays an integral part in the design of many new blockchain proposals. Consequently, the topic of publicly-verifiable, bias-resistant and unpredictable randomness has recently enjoyed increased attention. In particular random beacon protocols, aimed at continuous operation, can be a vital component for current Proof-of-Stake based distributed ledger proposals. We improve upon previous random beacon approaches with HydRand, a novel distributed protocol based on publicly-verifiable secret sharing (PVSS) to ensure unpredictability, bias-resistance, and public-verifiability of a continuous sequence of random beacon values. Furthermore, HydRand provides guaranteed output delivery of randomness at regular and predictable intervals in the presence of adversarial behavior and does not rely on a trusted dealer for the initial setup. Compared to existing PVSS based approaches that strive to achieve similar properties, our solution improves scalability by lowering the communication complexity from $\mathcal{O}\left( {{n^3}} \right)$ to $\mathcal{O}\left( {{n^2}} \right)$ . Furthermore, we are the first to present a detailed comparison of recently described schemes and protocols that can be used for implementing random beacons. Philipp Schindler, Aljosha Judmayer, Nicholas Stifter, Edgar R. Weippl |
SP | 4 |
| 2020 | Editorial: Special issue on security and privacy in smart cyber-physical systems
Lotfi Ben Othmane, Douglas W. Jacobson, Edgar R. Weippl |
Comput. Secur. | 3 |
| 2019 | Enhancing Cyber Situational Awareness for Cyber-Physical Systems through Digital TwinsabstractOperators of cyber-physical systems (CPSs) need to maintain awareness of the cyber situation in order to be able to adequately address potential issues in a timely manner. For instance, detecting early symptoms of cyber attacks may speed up the incident response process and mitigate consequences of attacks (e.g., business interruption, safety hazards). However, attaining a full understanding of the cyber situation may be challenging, given the complexity of CPSs and the ever-changing threat landscape. In particular, CPSs typically need to be continuously operational, may be sensitive to active scanning, and often provide only limited in-depth analysis capabilities. To address these challenges, we propose to utilize the concept of digital twins for enhancing cyber situational awareness. Digital twins, i.e., virtual replicas of systems, can run in parallel to their physical counterparts and allow deep inspection of their behavior without the risk of disrupting operational technology services. This paper reports our work in progress to develop a cyber situational awareness framework based on digital twins that provides a profound, holistic, and current view on the cyber situation that CPSs are in. More specifically, we present a prototype that provides real-time visualization features (i.e., system topology, program variables of devices) and enables a thorough, repeatable investigation process on a logic and network level. A brief explanation of technological use cases and outlook on future development efforts completes this work. Matthias Eckhart, Andreas Ekelhart, Edgar R. Weippl |
ETFA | 3 |
| 2019 | Avoiding Risky Designs When Using Blockchain Technologies in Cyber-Physical SystemsabstractBlockchain has been hailed as an emerging technology with the potential to cause significant impact in a variety of fields. One domain is an application in cyber-physical systems (CPSs), e.g., as a building block for the (Industrial) Internet of Things (IIoT) and Industry 4.0. In this regard, various use cases and designs have been proposed that seek to leverage the desirable properties blockchain technologies seem to offer. While many of the principles behind blockchain have actually been studied under the veil of Byzantine fault tolerance for decades, some approaches, such as relying on game-theoretic incentives and proof-of-work (PoW), are not yet fully understood. This knowledge gap can leave both practitioners and researchers in a difficult position regarding a possible application of such technologies, as it is often unclear what guarantees and characteristics a particular blockchain design actually achieves. This work-in-progress paper provides an overview of blockchain security research, outlines system designs that are likely to exhibit vulnerabilities, and provides examples of potentially insecure proposals in the field of CPSs that employ such designs. Nicholas Stifter, Matthias Eckhart, Bernhard Brenner, Edgar R. Weippl |
ETFA | 4 |
| 2019 | Security Related Technical Debt in the Cyber-Physical Production Systems Engineering ProcessabstractTechnical debt is an analogy introduced in 1992 by Cunningham to help explain how intentional decisions not to follow a gold standard or best practice in order to save time or effort during creation of software can later on lead to a product of lower quality in terms of product quality itself, reliability, maintainability or extensibility. Little work has been done so far that applies this analogy to cyber physical (production) systems (CP(P)S). Also there is only little work that uses this analogy for security related issues. This work aims to fill this gap: We want to find out which security related symptoms within the field of cyber physical production systems can be traced back to TD items during all phases, from requirements and design down to maintenance and operation. This work shall support experts from the field by being a first step in exploring the relationship between not following security best practices and concrete increase of costs due to TD as consequence. Bernhard Brenner, Edgar R. Weippl, Andreas Ekelhart |
IECON | 2 |
| 2019 | Security Development Lifecycle for Cyber-Physical Production SystemsabstractAs the connectivity within manufacturing processes increases in light of Industry 4.0, information security becomes a pressing issue for product suppliers, systems integrators, and asset owners. Reaching new heights in digitizing the manufacturing industry also provides more targets for cyber attacks, hence, cyber-physical production systems (CPPSs) must be adequately secured to prevent malicious acts. To achieve a sufficient level of security, proper defense mechanisms must be integrated already early on in the systems' lifecycle and not just eventually in the operation phase. Although standardization efforts exist with the objective of guiding involved stakeholders toward the establishment of a holistic industrial security concept (e.g., IEC 62443), a dedicated security development lifecycle for systems integrators is missing. This represents a major challenge for engineers who lack sufficient information security knowledge, as they may not be able to identify security-related activities that can be performed along the production systems engineering (PSE) process. In this paper, we propose a novel methodology named Security Development Lifecycle for Cyber-Physical Production Systems (SDL-CPPS) that aims to foster security by design for CPPSs, i.e., the engineering of smart production systems with security in mind. More specifically, we derive security-related activities based on (i) security standards and guidelines, and (ii) relevant literature, leading to a security-improved PSE process that can be implemented by systems integrators. Furthermore, this paper informs domain experts on how they can conduct these security-enhancing activities and provides pointers to relevant works that may fill the potential knowledge gap. Finally, we review the proposed approach by means of discussions in a workshop setting with technical managers of an Austrian-based systems integrator to identify barriers to adopting the SDL-CPPS. Matthias Eckhart, Andreas Ekelhart, Arndt Lüder, Stefan Biffl, Edgar R. Weippl |
IECON | 5 |
| 2019 | A Versatile Security Layer for AutomationMLabstractThe XML-based data format AutomationML enables vendor-independent exchange of design data between discipline-specific design tools. It is based on Computer Aided Engineering Exchange (CAEX) and hence, compatible with the W3C standards XMLEnc (XML encryption) and XMLDsig (XML signatures). However, despite the importance of protecting engineering data, so far no concept has been presented to ensure and control on a fine-grained level the confidentiality, authenticity and accessibility of information stored in AutomationML files. In this paper, we introduce a basic access control scheme for AutomationML that enables to define user read and write access for each component. Furthermore, the scheme supports nonrepudiation based on a change history and so-called “signature chains”. It is also capable of supporting views and restricted access to components. The scheme is based on cryptographic measures - i.e. cryptographic hashing, symmetric encryption, signatures, and asymmetric encryption - and enforces its access control mechanisms through encryption to protect against unauthorized reading, and through signature chains to protect against unauthorized manipulation and to ensure non-repudiation. This approach has the benefit to be independent of the underlying file and operating system, storage location, etc., and it keeps full CAEX-conformity by extending AutomationML. This concept can serve as basis for software tools that support AutomationML and want to integrate access control features directly into AutomationML. Bernhard Brenner, Edgar R. Weippl, Andreas Ekelhart |
INDIN | 2 |
| 2019 | Measuring Cookies and Web Privacy in a Post-GDPR World
Adrian Dabrowski, Georg Merzdovnik, Johanna Ullrich, Gerald Sendera, Edgar R. Weippl |
PAM | 5 |
| 2019 | Special Issue on Security and Privacy in Smart Cyber-physical Systems
Lotfi Ben Othmane, Douglas W. Jacobson, Edgar R. Weippl |
Comput. Secur. | 3 |
| 2018 | A Framework for Monitoring Net NeutralityabstractInternet service providers can discriminate traffic in certain ways, e.g., by the used protocol or application. This leads to advantages for providers, but also harms the freedom and innovation in the Internet. However, ISPs currently use a variety of technical measures. Some can be seen as questionable regarding net neutrality -- an important topic in legal and economic discussions. These methods are often neither technically identified nor continuously monitored, which prevents an informed discussion about the legitimacy of such methods. In this paper, we design and implement an open-source framework for monitoring such techniques within a country. Compared to other projects, we are able to fully control the client and server endpoint and therefore analyze network behavior in depth. We implement 17 different metrics that cover a wide range of the network spectrum. We test basic network features on transport layer as well as specific application layer protocols. We then use this framework to monitor five different Internet products in Austria over the time span of more than one year. We evaluate the results from our three measurement periods of three months each and find different questionable methods in place. This includes e.g., middleboxes used for various protocols, mon-etization of DNS results and different behavior for special DNS queries. However, many metrics show that currently no questionable techniques are used. Wilfried Mayer, Thomas Schreiber, Edgar R. Weippl |
ARES | 3 |
| 2018 | Current Advances, Trends and Challenges of Machine Learning and Knowledge Extraction: From Machine Learning to Explainable AI
Andreas Holzinger, Peter Kieseberg, Edgar R. Weippl, A Min Tjoa |
CD-MAKE | 3 |
| 2018 | USBlock: Blocking USB-Based Keypress Injection Attacks
Sebastian Neuner, Artemios G. Voyiatzis, Spiros Fotopoulos, Collin Mulliner, Edgar R. Weippl |
DBSec | 5 |
| 2018 | Proof-of-Blackouts? How Proof-of-Work Cryptocurrencies Could Affect Power Grids
Johanna Ullrich, Nicholas Stifter, Aljosha Judmayer, Adrian Dabrowski, Edgar R. Weippl |
RAID | 5 |
| 2017 | Lightweight Address Hopping for Defending the IPv6 IoTabstractThe rapid deployment of IoT systems on the public Internet is not without concerns for the security and privacy of consumers. Security in IoT systems is often poorly engineered and engineering for privacy does notseemtobea concern for vendors at all. Thecombination of poor security hygiene and access to valuable knowledge renders IoT systems a much-sought target for attacks. Aljosha Judmayer, Johanna Ullrich, Georg Merzdovnik, Artemios G. Voyiatzis, Edgar R. Weippl |
ARES | 5 |
| 2017 | Timestamp hiccups: Detecting manipulated filesystem timestamps on NTFSabstractRedundant capacity in filesystem timestamps is recently proposed in the literature as an effective means for information hiding and data leakage. Sebastian Neuner, Artemios G. Voyiatzis, Martin Schmiedecker, Edgar R. Weippl |
ARES | 4 |
| 2017 | Grid Shock: Coordinated Load-Changing Attacks on Power Grids: The Non-Smart Power Grid is Vulnerable to Cyber Attacks as WellabstractElectric power grids are among the largest human-made control structures and are considered as critical infrastructure due to their importance for daily life. When operating a power grid, providers have to continuously maintain a balance between supply (i.e., production in power plants) and demand (i.e., power consumption) to keep the power grid's nominal frequency of 50 Hz or alternatively 60 Hz. Power consumption is forecast by elaborated models including multiple parameters like weather, season, and time of the day; they are based on the premise of many small consumers averaging out their energy consumption spikes. Adrian Dabrowski, Johanna Ullrich, Edgar R. Weippl |
ACSAC | 3 |
| 2017 | Block Me If You Can: A Large-Scale Study of Tracker-Blocking ToolsabstractIn this paper, we quantify the effectiveness of third-party tracker blockers on a large scale. First, we analyze the architecture of various state-of-the-art blocking solutions and discuss the advantages and disadvantages of each method. Second, we perform a two-part measurement study on the effectiveness of popular tracker-blocking tools. Our analysis quantifies the protection offered against trackers present on more than 100,000 popular websites and 10,000 popular Android applications. We provide novel insights into the ongoing arms race between trackers and developers of blocking tools as well as which tools achieve the best results under what circumstances. Among others, we discover that rule-based browser extensions outperform learning-based ones, trackers with smaller footprints are more successful at avoiding being blocked, and CDNs pose a major threat towards the future of tracker-blocking tools. Overall, the contributions of this paper advance the field of web privacy by providing not only the largest study to date on the effectiveness of tracker-blocking tools, but also by highlighting the most pressing challenges and privacy issues of third-party tracking. Georg Merzdovnik, Markus Huber 0001, Damjan Buhov, Nick Nikiforakis, Sebastian Neuner, Martin Schmiedecker, Edgar R. Weippl |
EuroS&P | 7 |
| 2017 | Real-Time Forensics Through Endpoint Visibility
Peter Kieseberg, Sebastian Neuner, Sebastian Schrittwieser, Martin Schmiedecker, Edgar R. Weippl |
ICDF2C | 5 |
| 2017 | Research methods and examples of empirical research in information securityabstractSummary form only given. Over the last years, there is an increasing number of descriptive works observing and describing complex phenomena, e.g., the efficiency of different spam campaigns, the distribution of bots, or the likelihood of users to accept false identities as friends in social networks. These studies are characterized by large sets of samples. Future research will focus on networks and cloud systems; the research methodology will be empirical systems security: (1) passively observing large systems and (2) active probing that stimulates revealing behavior of the systems. The research contribution lies in observing, describing and inferring the behavior of complex systems that cannot be directly observed and have a large impact on users. In this presentation we will look at how we can measure whether ISPs implement peering, if they adhere to net neutrality and we will also look at aspects of privacy. Edgar R. Weippl |
RCIS | 1 |
| 2017 | Poster: Design of an Anomaly-based Threat Detection & Explication SystemabstractThe poster corresponding to this summary depicts a proposition of a system able to explain anomalous behavior within a user session by considering anomalies identified through their deviation from a set of baseline process graphs. We adapt star structures, a bipartite representation used to approximate the edit distance between two graphs. Relevant processes are selected from a dictionary of benign and malicious traces generated through a sentiment-like bigram extraction and scoring system based on the log likelihood ratio test. We prototypically implemented smart anomaly explication through a number of competency questions derived and evaluated by a decision tree. The determined key factors are ultimately mapped to a dedicated APT attack stage ontology that considers actions, actors, as well as target assets. Robert Luh, Sebastian Schrittwieser, Stefan Marschalek, Helge Janicke, Edgar R. Weippl |
SACMAT | 5 |
| 2017 | "I Have No Idea What I'm Doing" - On the Usability of Deploying HTTPS
Katharina Krombholz, Wilfried Mayer, Martin Schmiedecker, Edgar R. Weippl |
USENIX Security Symposium | 4 |
| 2017 | Security assurance assessment methodology for hybrid clouds
Aleksandar Hudic, Paul Smith 0001, Edgar R. Weippl |
Comput. Secur. | 3 |
| 2016 | Hand Dynamics for Behavioral User AuthenticationabstractWe propose and evaluate a method to authenticate individuals by their unique hand dynamics, based on measurements from wearable sensors. Our approach utilises individual characteristics of hand movement when opening a door. We implement a sensor-fusion machine learning algorithm to classify individuals based on their hand movement and conduct a lab study with 20 participants to test the feasibility of the concept in the context of accessing physical doors as found in office buildings. Our results show that our approach yields an accuracy of 92% in classifying an individual and thus highlights the potential for behavioral hand dynamics for authentication. Fuensanta Torres Garcia, Katharina Krombholz, Rudolf Mayer, Edgar R. Weippl |
ARES | 4 |
| 2016 | Notary-Assisted Certificate Pinning for Improved Security of Android AppsabstractThe security provided to Internet applications by the TLS protocol relies on the trust we put on Certificate Authorities (CAs) issuing valid identity certificates. TLS certificate pinning is a proposed approach to defend against man-in-the-middle (MitM) attacks that are realized using valid albeit fraudulent certificates. Yet, the implementation of certificate pinning for mobile applications, and especially for Google Android apps, is cumbersome and error-prone, resulting in inappropriate connection handling and privacy leaks of user information. We propose the use of TLS notary-assisted certificate pinning at the Android Runtime level. Our approach defends against a wide range of MitM attacks without needing to update the application using TLS. Furthermore, by relying on the collective knowledge of the trusted TLS notaries, we increase both the security and the usability, while at the same time we remove the burden for the user making trust decisions about system security issues. We describe a proof-of-concept implementation demonstrating its capabilities and discuss the next steps necessary towards general availability of our solution. Georg Merzdovnik, Damjan Buhov, Artemios G. Voyiatzis, Edgar R. Weippl |
ARES | 4 |
| 2016 | Condensed Cryptographic Currencies Crash Course (C5)abstract"Bitcoin is a rare case where practice seems to be ahead of theory." Joseph Bonneau et al. [3] This tutorial aims to further close the gap between IT security research and the area of cryptographic currencies and block chains. We will describe and refer to Bitcoin as an example throughout the tutorial, as it is the most prominent representative of such a system. It also is a good reference to discuss the underlying block chain mechanics which are the foundation of various altcoins and other derived systems. In this tutorial, the topic of cryptographic currencies is solely addressed from a technical IT security point-of-view. Therefore we do not cover any legal, sociological, financial or economical aspects. Aljosha Judmayer, Edgar R. Weippl |
CCS | 2 |
| 2016 | Whom You Gonna Trust? A Longitudinal Study on TLS Notary Services
Georg Merzdovnik, Klaus Falb, Martin Schmiedecker, Artemios G. Voyiatzis, Edgar R. Weippl |
DBSec | 5 |
| 2016 | The Beauty or The Beast? Attacking Rate Limits of the Xen Hypervisor
Johanna Ullrich, Edgar R. Weippl |
ESORICS (2) | 2 |
| 2016 | Ethics in Security Research
Edgar R. Weippl |
ICISSP | 1 |
| 2016 | The Messenger Shoots Back: Network Operator Based IMSI Catcher Detection
Adrian Dabrowski, Georg Petzl, Edgar R. Weippl |
RAID | 3 |
| 2016 | The role and security of firewalls in cyber-physical cloud computingabstractClouds are here to stay, and the same holds for cyber-physical systems—not to forget their combination. In light of these changing paradigms, it is of utter importance to reconsider security as both introduce new challenges. Overcoming the concept of zoned networks, clouds make former internal traffic traveling the Internet. Cyber-physical systems include physical parts into computing and make them potential targets for cyber attacks—a dare as a high number of physical parts have originally been developed to be stand-alone. Cyber-physical cloud computing reinforces the need for a thoughtful security concept. Firewalls are among the basic building blocks in network security and are offered by various cloud providers; however, the question on their quality of protection arises. In this paper, we assess firewall offers of five major cloud providers with respect to cyber-physical system integration. Therefore, we study their default configuration, configuration capabilities, documentation, and filtering behavior. We developed an extendible firewall monitoring tool that enables customers to probe their provider’s filtering behavior—an information of interest for risk management or further security consideration. Re-assessing filtering behavior, we found that all offered firewalls have evolved over a time period of more than a year: Configuration possibilities have been enhanced, more illegitimate packets are filtered now, and stateful behavior was discovered at a certain provider. Johanna Ullrich, Jordan Cropper, Peter Frühwirt, Edgar R. Weippl |
EURASIP J. Inf. Secur. | 4 |
| 2016 | Effectiveness of file-based deduplication in digital forensicsabstractAbstract Over the last decades, the increasing amount of storage became a pressing problem for forensic investigators. This is caused by the computerization of everyday life and the associated increasing number of different devices in typical households. Considering multi‐terabyte storage on the suspects' side, even more storage requirements emerge on the side of the investigator for secure backup and working copies. In this paper, we improve the standardized forensic process by proposing to rigorously use file deduplication across devices as well as file whitelisting in investigations in order to reduce the amount of data that needs to be stored for analysis as early as during data acquisition. These improvements happen in an automatic fashion and are completely transparent to the forensic investigator. They may furthermore be added without negative effects to the chain of custody or artifact validity in court and are evaluated in a realistic use case. Additionally, we illustrate the effectivity of our proposed approach on a real‐world corpus by showing a notable reduction in number of reduced files as well as storage. Copyright © 2016 John Wiley & Sons, Ltd. Sebastian Neuner, Martin Schmiedecker, Edgar R. Weippl |
Secur. Commun. Networks | 3 |
| 2015 | Network Security Challenges in Android ApplicationsabstractThe digital world is in constant battle for improvement - especially in the security field. Taking into consideration the revelations from Edward Snowden about the mass surveillance programs conducted by governmental authorities, the number of users that raised awareness towards security is constantly increasing. More and more users agree that additional steps must be taken to ensure the fact that communication will remain private as intended in the first place. Taking in consideration the ongoing transition in the digital world, there are already more mobile phones than people on this planet. According to recent statistics there are around 7 billion active cell phones by 2014 out of which nearly 2 billion are smartphones. The use of smartphones by itself could open a great security hole. The most common problem when it comes to Android applications is the common misuse of the HTTPS protocol. Having this in mind, this paper addresses the current issues when it comes to misuse of the HTTPS protocol and proposes possible solutions to overcome this common problem. In this paper we evaluate the SSL implementation in a recent set of Android applications and present some of the most common missuses. The goal of this paper is to raise awareness to current and new developers to actually consider security as one of their main goals during the development life cycle of applications. Damjan Buhov, Markus Huber 0001, Georg Merzdovnik, Edgar R. Weippl, Vesna Dimitrova |
ARES | 4 |
| 2015 | The Role and Security of Firewalls in IaaS Cloud ComputingabstractCloud computing is playing an ever larger role in the IT infrastructure. The migration into the cloud means that we must rethink and adapt our security measures. Ultimately, both the cloud provider and the customer have to accept responsibilities to ensure security best practices are followed. Firewalls are one of the most critical security features. Most IaaS providers make firewalls available to their customers. In most cases, the customer assumes a best-case working scenario which is often not assured. In this paper, we studied the filtering behavior of firewalls provided by five different cloud providers. We found that three providers have firewalls available within their infrastructure. Based on our findings, we developed an open-ended firewall monitoring tool which can be used by cloud customers to understand the firewall's filtering behavior. This information can then be efficiently used for risk management and further security considerations. Measuring today's firewalls has shown that they perform well for the basics, although may not be fully featured considering fragmentation or stateful behavior. Jordan Cropper, Johanna Ullrich, Peter Frühwirt, Edgar R. Weippl |
ARES | 4 |
| 2015 | QR Code Security - How Secure and Usable Apps Can Protect Users Against Malicious QR CodesabstractQR codes have emerged as a popular medium to make content instantly accessible. With their high information density and robust error correction, they have found their way to the mobile ecosystem. However, QR codes have also proven to be an efficient attack vector, e.g. To perform phishing attacks. Attackers distribute malicious codes under false pretenses in busy places or paste malicious QR codes over already existing ones on billboards. Ultimately, people depend on reader software to ascertain if a given QR code is benign or malicious. In this paper, we present a comprehensive analysis of QR code security. We determine why users are still susceptible to QR code based attacks and why currently deployed smartphone apps are unable to mitigate these attacks. Based on our findings, we present a set of design recommendations to build usable and secure mobile applications. To evaluate our guidelines, we implemented a prototype and found that secure and usable apps can effectively protect users from malicious QR codes. Katharina Krombholz, Peter Frühwirt, Thomas Rieder, Ioannis Kapsalis, Johanna Ullrich, Edgar R. Weippl |
ARES | 6 |
| 2015 | Gradually Improving the Forensic ProcessabstractAt the time of writing, one of the most pressing problems for forensic investigators is the huge amount of data to analyze per case. Not only the number of devices increases due to the advancing computerization of every days life, but also the storage capacity of each and every device raises into multi-terabyte storage requirements per case for forensic working images. In this paper we improve the standardized forensic process by proposing to use file deduplication across devices as well as file white listing rigorously in investigations, to reduce the amount of data that needs to be stored for analysis as early as during data acquisition. These improvements happen in an automatic fashion and completely transparent to the forensic investigator. They furthermore be added without negative effects to the chain of custody or artefact validity in court, and are evaluated in a realistic use case. Sebastian Neuner, Martin Mulazzani, Sebastian Schrittwieser, Edgar R. Weippl |
ARES | 4 |
| 2015 | On Reconnaissance with IPv6: A Pattern-Based Scanning ApproachabstractToday's capability of fast Internet-wide scanning allows insights into the Internet ecosystem, but the on-going transition to the new Internet Protocol version 6 (IPv6) makes the approach of probing all possible addresses infeasible, even at current speeds of more than a million probes per second. As a consequence, the exploitation of frequent patterns has been proposed to reduce the search space. Current patterns are manually crafted and based on educated guesses of administrators. At the time of writing, their adequacy has not yet been evaluated. In this paper, we assess the idea of pattern-based scanning for the first time, and use an experimental set-up in combination with three real-world data sets. In addition, we developed a pattern-based algorithm that automatically discovers patterns in a sample and generates addresses for scanning based on its findings. Our experimental results confirm that pattern-based scanning is a promising approach for IPv6 reconnaissance, but also that currently known patterns are of limited benefit and are outperformed by our new algorithm. Our algorithm not only discovers more addresses, but also finds implicit patterns. Furthermore, it is more adaptable to future changes in IPv6 addressing and harder to mitigate than approaches with manually crafted patterns. Johanna Ullrich, Peter Kieseberg, Katharina Krombholz, Edgar R. Weippl |
ARES | 4 |
| 2015 | Using Internal MySQL/InnoDB B-Tree Index Navigation for Data Hiding
Peter Frühwirt, Peter Kieseberg, Edgar R. Weippl |
IFIP Int. Conf. Digital Forensics | 3 |
| 2015 | WordPress security: an analysis based on publicly available exploitsabstractThe danger of SQL injections has been known for more than a decade but injection attacks have led the OWASP top 10 for years and still are one of the major reasons for devastating attacks on web sites. As about 24% percent of the top 10 million web sites are built upon the content management system WordPress, it's no surprise that content management systems in general and WordPress in particular are frequently targeted. To understand how the underlying security bugs can be discovered and exploited by attackers, 199 publicly disclosed SQL injection exploits for WordPress and its plugins have been analyzed. The steps an attacker would take to uncover and utilize these bugs are followed in order to gain access to the underlying database through automated, dynamic vulnerability scanning with well-known, freely available tools. Previous studies have shown that the majority of the security bugs are caused by the same programming errors as 10 years ago and state that the complexity of finding and exploiting them has not increased significantly. Furthermore, they claim that although the complexity has not increased, automated tools still do not detect the majority of bugs. The results of this paper show that tools for automated, dynamic vulnerability scanning only play a subordinate role for developing exploits. The reason for this is that only a small percentage of attack vectors can be found during the detection phase. So even if the complexity of exploiting an attack vector has not increased, this attack vector has to be found in the first place, which is the major challenge for this kind of tools. Therefore, from today's perspective, a combination with manual and/or static analysis is essential when testing for security vulnerabilities. Hannes Trunde, Edgar R. Weippl |
iiWAS | 2 |
| 2015 | Privacy is Not an Option: Attacking the IPv6 Privacy Extension
Johanna Ullrich, Edgar R. Weippl |
RAID | 2 |
| 2015 | Advanced social engineering attacks
Katharina Krombholz, Heidelinde Hobel, Markus Huber 0001, Edgar R. Weippl |
J. Inf. Secur. Appl. | 4 |
| 2014 | Towards a Hardware Trojan Detection CycleabstractIntentionally inserted malfunctions in integrated circuits, referred to as Hardware Trojans, have become an emerging threat. Recently, the scientific community started to propose technical approaches to mitigate the threat of unspecified and potentially malicious functionality. However, these detection and prevention mechanisms are still hardly integrated in the industry's Hardware development life cycles. We therefore propose in this work a secure hardware development life cycle that assembles methods from trustworthy software engineering. In addition to full traceability from specification to implementation, and down to each gate, we introduce a feedback detection cycle that systematically escorts every single step of the development process. To do so, we integrate different detection methods for each development phase that are derived from a common knowledge base. Adrian Dabrowski, Heidelinde Hobel, Johanna Ullrich, Katharina Krombholz, Edgar R. Weippl |
ARES | 5 |
| 2014 | AES-SEC: Improving Software Obfuscation through Hardware-AssistanceabstractWhile the resilience of software-only code obfuscation remains unclear and ultimately depends only on available resources and patience of the attacker, hardware-based software protection approaches can provide a much higher level of protection against program analysis. Almost no systematic research has been done on the interplay between hardware and software based protection mechanism. In this paper, we propose modifications to Intel's AES-NI instruction set in order to make it suitable for application in software protection scenarios and demonstrate its integration into a control flow obfuscation scheme. Our novel approach provides strong hardware-software binding and restricts the attack context to pure dynamic analysis - two major limiting factors of reverse engineering - to delay a successful attack against a program. Sebastian Schrittwieser, Stefan Katzenbeisser 0001, Georg Merzdovnik, Peter Kieseberg, Edgar R. Weippl |
ARES | 5 |
| 2014 | IMSI-catch me if you can: IMSI-catcher-catchersabstractIMSI Catchers are used in mobile networks to identify and eavesdrop on phones. When, the number of vendors increased and prices dropped, the device became available to much larger audiences. Self-made devices based on open source software are available for about US$ 1,500. Adrian Dabrowski, Nicola Pianta, Thomas Klepp, Martin Mulazzani, Edgar R. Weippl |
ACSAC | 5 |
| 2014 | A Multi-layer and MultiTenant Cloud Assurance Evaluation MethodologyabstractData with high security requirements is being processed and stored with increasing frequency in the Cloud. To guarantee that the data is being dealt in a secure manner we investigate the applicability of Assurance methodologies. In a typical Cloud environment the setup of multiple layers and different stakeholders determines security properties of individual components that are used to compose Cloud applications. We present a methodology adapted from Common Criteria for aggregating information reflecting the security properties of individual constituent components of Cloud applications. This aggregated information is used to categorise overall application security in terms of Assurance Levels and to provide a continuous assurance level evaluation. It gives the service owner an overview of the security of his service, without requiring detailed manual analyses of log files. Aleksandar Hudic, Markus Tauber, Thomas Lorünser, Maria Krotsiani, George Spanoudakis, Andreas Mauthe, Edgar R. Weippl |
CloudCom | 7 |
| 2014 | Towards Fully Automated Digital Alibis with Social Interaction
Stefanie Beyer, Martin Mulazzani, Sebastian Schrittwieser, Markus Huber 0001, Edgar R. Weippl |
IFIP Int. Conf. Digital Forensics | 5 |
| 2014 | Automated Analysis of Underground Marketplaces
Aleksandar Hudic, Katharina Krombholz, Thomas Otterbein, Christian Platzer, Edgar R. Weippl |
IFIP Int. Conf. Digital Forensics | 5 |
| 2014 | A Decision Framework Model for Migration into Cloud: Business, Application, Security and Privacy PerspectivesabstractCloud computing offers a different, affordable approach for supporting the IT needs of organisations. However, despite the unprecedented benefits cloud migration may bring, there are numerous difficulties involved in moving business critical applications, legacy systems or corporate data into the cloud. It is necessary to consider a broad view over all business areas, and taking into account the technical and business minutiae of a full scale cloud migration, as well as the wider concerns of security, privacy and other business and technical risks. A detailed understanding of all these areas is required in order to make the correct decisions concerning cloud migration. This paper aims to take a broad view of the issues relating to migration. We propose a process model to identify risks and requirements, as well as to provide control assurance during the migration decision. We also define an outline migration strategy by focusing on the context of the organisation. Shareeful Islam, Edgar R. Weippl, Katharina Krombholz |
iiWAS | 2 |
| 2014 | What's new with WhatsApp & Co.? Revisiting the Security of Smartphone Messaging ApplicationsabstractIn recent years mobile messaging and VoIP applications for smartphones have seen a massive surge in popularity, which has also sparked the interest in research related to the security of these applications. Various security researchers and institutions have performed in-depth analyses of specific applications or vulnerabilities. This paper gives an overview of the status quo in terms of security for a number of selected applications in comparison to a previous evaluation conducted two years ago, as well as performing an analysis on some new applications. The evaluation methods mostly focus on known vulnerabilities in connection with authentication and validation mechanisms but also describe some newly identified attack vectors. The results show a predominantly positive trend for new applications, which are mostly being developed with robust security and privacy features, while some of the older applications have shown little to no progress in this regard or have even introduced new vulnerabilities in recent versions. Robin Mueller, Sebastian Schrittwieser, Peter Frühwirt, Peter Kieseberg, Edgar R. Weippl |
iiWAS | 5 |
| 2014 | Empirical Research in Information SecurityabstractSocial Engineering has long been a very effective means of attacking information systems. The term knowledge worker has been coined by Peter Drucker more than 50 years ago and still describes very well the basic characteristics of many employees. Today, with current hypes such as BYOD (bring your own device) and public cloud services, young professionals expect to use the same technology both in their private life and while working. In global companies teams are no longer geographically co-located but staffed globally just-in-time. The decrease in personal interaction combined with the plethora of tools used (E-Mail, IM, Skype, Dropbox, Linked-In, Lync, etc.) create new opportunities for attackers. As recent attacks on companies such as the New York Times, RSA or Apple have shown, targeted spear-phishing attacks are an effective evolution of social engineering attacks. When combined with spear phishing to distribute zero-day-exploits they become a dangerous weapon, often used by advanced persistent threats. In this talk we will explore some attack vectors and possible steps to mitigate the risk. Edgar R. Weippl |
iiWAS | 1 |
| 2014 | Spoiled Onions: Exposing Malicious Tor Exit Relays
Philipp Winter, Richard Köwer, Martin Mulazzani, Markus Huber 0001, Sebastian Schrittwieser, Stefan Lindskog, Edgar R. Weippl |
Privacy Enhancing Technologies | 7 |
| 2014 | Advanced Persistent Threats & Social Engineering
Edgar R. Weippl |
SECRYPT | 1 |
| 2014 | Plugin in the Middle - Minimising Security Risks in Mobile Middleware ImplementationsabstractMobile computing platforms, like smartphones and tablet computers, are becoming a commodity nowadays. The diversity and fast changing nature of these systems often makes it hard for developers to adapt their applications to the user's context. To simplify development a number of approaches have been suggested, which offer a context-middleware solution such that common functionality can be pooled into plugins and provided to applications. These extensions are then automatically installed if needed, thus enabling easier and faster development of complex applications. Furthermore, if the device changes, it often suffices to exchange the plugins for the applications to function correctly. However, mobile platforms like Android never expected integration in the sense that one application would dynamically host pieces of code from different vendors and allow access to other applications, since doing so basically circumvents many built-in security measures of the operating system. In this paper we analyze Ambient Dynamix, an advanced context-middleware solution, in detail. Hereby, we propose and evaluate security mechanisms to increase the security of Ambient Dynamix. We outline a system to verify the permissions an application requests against the actual Ambient Dynamix plugins it uses. In the following, we evaluate the use of static code analysis to ensure requested and used permissions by a novel method for lightweight on-device analysis. Finally, we propose a secure infrastructure to host, download and install third-party plugins. Our proposed security extensions significantly improve the user's security regarding third-party applications and considerably advance the area of secure mobile middleware. Peter Aufner, Georg Merzdovnik, Markus Huber 0001, Edgar R. Weippl |
SIN | 4 |
| 2014 | Towards Practical Methods to Protect the Privacy of Location Information with Mobile DevicesabstractSmartphones and tablet computers continue to replace traditional mobile phones and are used by over one billion people worldwide. A number of novel security and privacy challenges result from the possibility to extend the functionality of smartphones with third-party applications. These third-party applications require that users provide personal information to third-party applications in exchange for additional features. This paper focuses on one specifically sensitive information requested by third-party applications, namely: location information. We discuss current methods to protect the privacy of location information and evaluate two approaches in depth. First, we introduce an extension to improve the usability of current interception methods on an operating system level. Second, we evaluate the applicability of proxy-level interception on basis of real-world Android applications. Our findings significantly extend the state-of-the-art regarding the protection of location information on mobile devices and further highlight open research challenges. Christoph Hochreiner, Markus Huber 0001, Georg Merzdovnik, Edgar R. Weippl |
SIN | 4 |
| 2014 | Securing Cloud and Mobility
Martin Kirchner, Edgar R. Weippl |
Comput. Secur. | 2 |
| 2014 | Covert Computation - Hiding code in code through compile-time obfuscation
Sebastian Schrittwieser, Stefan Katzenbeisser 0001, Peter Kieseberg, Markus Huber 0001, Manuel Leithner, Martin Mulazzani, Edgar R. Weippl |
Comput. Secur. | 7 |
| 2014 | An empirical study on the implementation and evaluation of a goal-driven software development risk management model
Shareeful Islam, Haralambos Mouratidis, Edgar R. Weippl |
Inf. Softw. Technol. | 3 |
| 2013 | SHPF: Enhancing HTTP(S) Session Security with Browser FingerprintingabstractSession hijacking has become a major problem in today's Web services, especially with the availability of free off-the-shelf tools. As major websites like Facebook, You tube and Yahoo still do not use HTTPS for all users by default, new methods are needed to protect the users' sessions if session tokens are transmitted in the clear. In this paper we propose the use of browser fingerprinting for enhancing current state-of-the-art HTTP(S) session management. Monitoring a wide set of features of the user's current browser makes session hijacking detectable at the server and raises the bar for attackers considerably. This paper furthermore identifies HTML5 and CSS features that can be used for browser fingerprinting and to identify or verify a browser without the need to rely on the User Agent string. We implemented our approach in a framework that is highly configurable and can be added to existing Web applications and server-side session management with ease. Thomas Unger, Martin Mulazzani, Dominik Fruhwirt, Markus Huber 0001, Sebastian Schrittwieser, Edgar R. Weippl |
ARES | 6 |
| 2013 | Covert computation: hiding code in code for obfuscation purposesabstractAs malicious software gets increasingly sophisticated and resilient to detection, new concepts for the identification of malicious behavior are developed by academia and industry alike. While today's malware detectors primarily focus on syntactical analysis (i.e., signatures of malware samples), the concept of semantic-aware malware detection has recently been proposed. Here, the classification is based on models that represent the underlying machine and map the effects of instructions on the hardware. In this paper, we demonstrate the incompleteness of these models and highlight the threat of malware, which exploits the gap between model and machine to stay undetectable. To this end, we introduce a novel concept we call covert computation, which implements functionality in side effects of microprocessors. For instance, the flags register can be used to calculate basic arithmetical and logical operations. Our paper shows how this technique could be used by malware authors to hide malicious code in a harmless-looking program. Furthermore, we demonstrate the resilience of covert computation against semantic-aware malware scanners. Sebastian Schrittwieser, Stefan Katzenbeisser 0001, Peter Kieseberg, Markus Huber 0001, Manuel Leithner, Martin Mulazzani, Edgar R. Weippl |
AsiaCCS | 7 |
| 2013 | Quantifying Windows File Slack Size and Stability
Martin Mulazzani, Sebastian Neuner, Peter Kieseberg, Markus Huber 0001, Sebastian Schrittwieser, Edgar R. Weippl |
IFIP Int. Conf. Digital Forensics | 6 |
| 2013 | Towards Security-Enhanced and Privacy-Preserving Mashup Compositions
Heidelinde Hobel, Johannes Heurix, Amin Andjomshoaa, Edgar R. Weippl |
SEC | 4 |
| 2013 | Social engineering attacks on the knowledge workerabstractSocial engineering has become an emerging threat in virtual communities and is an effective means to attack information systems. Today's knowledge workers make use of a number of services that leverage sophisticated social engineering attacks. Moreover, there is a trend towards BYOD (bring your own device) policies and the usage of online communication and collaboration tools in private and business environments. In globally acting companies, teams are no longer geographically co-located but staffed just-in-time. The decrease in personal interaction combined with the plethora of tools used (E-Mail, IM, Skype, Dropbox, LinkedIn, Lync, etc.) create new attack vectors for social engineering attacks. Recent attacks on companies such as the New York Times, RSA, or Apple have shown that targeted spear-phishing attacks are an effective evolution of social engineering attacks. When combined with zero-day-exploits they become a dangerous weapon, often used by advanced persistent threats. This paper provides a taxonomy of well-known social engineering attacks as well as a comprehensive overview of advanced social engineering attacks on the knowledge worker. Katharina Krombholz, Heidelinde Hobel, Markus Huber 0001, Edgar R. Weippl |
SIN | 4 |
| 2013 | Framework Based on Privacy Policy Hiding for Preventing Unauthorized Face Image ProcessingabstractWe put forward a framework to address a problem created by the rapidly spreading use of imaging devices and related to involuntarily or unintentionally photographed individuals: their pictures can accumulate additional meta information via face recognition systems and can be manually tagged via social networks and publishing platforms. With this framework a user can express his/her picture privacy policy in a machine readable format and (to some extent) automatically enforce it. An easily understandable flag system is used to define restrictions on picture usage and link ability. This policy is encoded in an unobtrusive way into wardrobe patterns and accessory designs with almost no impact on apparel appearance or social interaction. Adrian Dabrowski, Edgar R. Weippl, Isao Echizen |
SMC | 2 |
| 2013 | InnoDB database forensics: Enhanced reconstruction of data manipulation queries from redo logs
Peter Frühwirt, Peter Kieseberg, Sebastian Schrittwieser, Markus Huber 0001, Edgar R. Weippl |
Inf. Secur. Tech. Rep. | 5 |
| 2012 | InnoDB Database Forensics: Reconstructing Data Manipulation Queries from Redo LogsabstractInnoDB is a powerful open-source storage engine for MySQL that gained much popularity during the recent years. This paper proposes methods for forensic analysis of InnoDB databases by analyzing the redo logs, primarily used for crash recovery within the storage engine. This new method can be very useful in forensic investigations where the attacker got admin privileges, or was the admin himself. While such a powerful attacker could cover tracks by manipulating the log files intended for fraud detection, data cannot be changed easily in the redo logs. Based on a prototype implementation, we show methods for recovering Insert, Delete and Update statements issued against a database. Peter Frühwirt, Peter Kieseberg, Sebastian Schrittwieser, Markus Huber 0001, Edgar R. Weippl |
ARES | 5 |
| 2012 | Data Visualization for Social Network Forensics
Martin Mulazzani, Markus Huber 0001, Edgar R. Weippl |
IFIP Int. Conf. Digital Forensics | 3 |
| 2012 | Digital forensics for enterprise rights management systemsabstractDigital forensics is the application of techniques to recover, reconstruct and analyze data from a computer or a similar system in order to gather digital evidence (e.g. on a suspicious employee or for law enforcement). Guidelines and standards for forensic investigations exist (e.g. NIST SP800-86), but do not cover Enterprise Rights Management (ERM), where data is usually encrypted and therefore inaccessible without knowing the cryptographic key. This paper explores forensic techniques for ERM systems and develops application specific guidelines for forensic investigations targeting Microsoft Active Directory Rights Management Services (RMS) and Adobe LiveCycle Rights Management. Moreover, we illustrate the important role of database forensics for investigations in ERM systems and finally show that with Microsoft's ERM solution no secure, centrally-managed revocation of specific documents in order to prevent digital forensics is feasible. Sebastian Schrittwieser, Peter Kieseberg, Edgar R. Weippl |
iiWAS | 3 |
| 2012 | Is security an afterthought when designing apps?abstractMobile applications only become really useful if combined with cloud-based services. We have observed that the increasingly short time to market may cause serious design flaws in the security architecture. In this talk I will highlight some flaws discovered in the past. For example, we looked at nine popular mobile messaging and VoIP applications and evaluated their security models with a focus on authentication mechanisms. We find that a majority of the examined applications use the user's phone number as a unique token to identify accounts; they contain vulnerabilities allowing attackers to hijack accounts, spoof sender-IDs or enumerate subscribers. Other examples pertain to (already fixed) problems in cloud-based storage services such as Dropbox. Edgar R. Weippl |
iiWAS | 1 |
| 2012 | INMOTOS: extending the ROPE-methodologyabstractThe Interdependency Modeling Tool and Simulation (INMOTOS) project is aimed to develop a tool for modeling and assessment of interdependent business- and contingency plans and risks affecting them. In the scope of that project a methodology had to be created that enables the modeling of highly complex business processes, their structures and interdependencies, as well as threats and countermeasures. A time-based simulation of the impact of possible threats is required as well as a risk assessment by using multiple different impact calculations. The methodology shall be kept simple and flexible to enable modeling of a wide range of different business scenarios. For the fundamental basics the Risk-Oriented Process Evaluation (ROPE) methodology [7] was chosen due to its high flexibility. This paper describes the adaptations and enhancements that are applied on the ROPE methodology to refine it to the INMOTOS methodology. Lorenz Zechner, Peter Kieseberg, Edgar R. Weippl |
iiWAS | 3 |
| 2012 | Guess Who's Texting You? Evaluating the Security of Smartphone Messaging Applications
Sebastian Schrittwieser, Peter Frühwirt, Peter Kieseberg, Manuel Leithner, Martin Mulazzani, Markus Huber 0001, Edgar R. Weippl |
NDSS | 7 |
| 2012 | Private Cloud Computing: Consolidation, Virtualization, and Service-Oriented Infrastructure
Aleksandar Hudic, Edgar R. Weippl |
Comput. Secur. | 2 |
| 2012 | Android forensics
Manuel Leithner, Edgar R. Weippl |
Comput. Secur. | 2 |
| 2012 | Coding for Penetration Testers
Manuel Leithner, Edgar R. Weippl |
Comput. Secur. | 2 |
| 2012 | Thor's Microsoft Security Bible
Manuel Leithner, Edgar R. Weippl |
Comput. Secur. | 2 |
| 2012 | XBOX 360 Forensics: A Digital Forensics Guide to Examining Artifacts
Manuel Leithner, Edgar R. Weippl |
Comput. Secur. | 2 |
| 2012 | Low Tech Hacking
Manuel Leithner, Edgar R. Weippl |
Comput. Secur. | 2 |
| 2012 | Enterprise Security for the Executive
Edgar R. Weippl, Manuel Leithner |
Comput. Secur. | 1 |
| 2011 | Social snapshots: digital forensics for online social networksabstractRecently, academia and law enforcement alike have shown a strong demand for data that is collected from online social networks. In this work, we present a novel method for harvesting such data from social networking websites. Our approach uses a hybrid system that is based on a custom add-on for social networks in combination with a web crawling component. The datasets that our tool collects contain profile information (user data, private messages, photos, etc.) and associated meta-data (internal timestamps and unique identifiers). These social snapshots are significant for security research and in the field of digital forensics. We implemented a prototype for Facebook and evaluated our system on a number of human volunteers. We show the feasibility and efficiency of our approach and its advantages in contrast to traditional techniques that rely on application-specific web crawling and parsing. Furthermore, we investigate different use-cases of our tool that include consensual application and the use of sniffed authentication cookies. Finally, we contribute to the research community by publishing our implementation as an open-source project. Markus Huber 0001, Martin Mulazzani, Manuel Leithner, Sebastian Schrittwieser, Gilbert Wondracek, Edgar R. Weippl |
ACSAC | 6 |
| 2011 | Using the structure of B+-trees for enhancing logging mechanisms of databasesabstractToday's database management systems implement sophisticated access control mechanisms to prevent unauthorized access and modifications. This is, as an example, an important basic requirement for SOX (Sarbanes--Oxley Act) compliance, whereby every past transaction has to be traceable at any time. However, malicious database administrators may still be able to bypass the security mechanisms to make hidden modifications to the database. Peter Kieseberg, Sebastian Schrittwieser, Lorcan Morgan, Martin Mulazzani, Markus Huber 0001, Edgar R. Weippl |
iiWAS | 6 |
| 2011 | An Algorithm for k-Anonymity-Based Fingerprinting
Sebastian Schrittwieser, Peter Kieseberg, Isao Echizen, Sven Wohlgemuth, Noboru Sonehara, Edgar R. Weippl |
IWDW | 6 |
| 2011 | IT Governance, Risk & Compliance (GRC) Status Quo and Integration: An Explorative Industry Case StudyabstractThe integration of governance, risk, and compliance (GRC) activities has gained importance over the last years. This paper presents an analysis of the GRC integration efforts in information technology departments of three large enterprises. Action design research is used to organize the research in order to assess IT GRC activities based on a model with five dimensions. By means of semi-structured interviews key findings concerning the status quo of the three IT GRC disciplines, their integration and their relation to GRC on the corporate level are identified and rated. Five key findings explain the main commonalities and differences observed. Nicolas Racz, Edgar R. Weippl, Riccardo Bonazzi |
SERVICES | 2 |
| 2011 | Dark Clouds on the Horizon: Using Cloud Storage as Attack Vector and Online Slack Space
Martin Mulazzani, Sebastian Schrittwieser, Manuel Leithner, Markus Huber 0001, Edgar R. Weippl |
USENIX Security Symposium | 5 |
| 2010 | Context Oriented Analysis of Web 2.0 Social Network Contents - MindMeister Use-Case
Amin Andjomshoaa, Sao-Khue Vo, A Min Tjoa, Edgar R. Weippl, Michael Hollauf |
ACIIDS (1) | 4 |
| 2010 | InnoDB Database ForensicsabstractWhenever data is being processed, there are many places where parts of the data are temporarily stored; thus forensic analysis can reveal past activities, create a (partial) timeline and recover deleted data. While this fact is well known for computer forensics, multiple forensic tools exist to analyze data and the systematic analysis of database systems has only recently begun. This paper will describe the file format of the MySQL Database 5.1.32 with InnoDB Storage Engine. It will further explain with a practical example of how to reconstruct the data found in the file system of any SQL table. We will show how to reconstruct the table as it is, read data sets from the file and how to interpret the gained information. Peter Frühwirt, Markus Huber 0001, Martin Mulazzani, Edgar R. Weippl |
AINA | 4 |
| 2010 | Exploiting social networking sites for spamabstractIn the ongoing arms race between spammers and the multi-million dollar anti-spam industry, the number of unsolicited e-mail messages (better known as "spam") and phishing has increased heavily in the last decade. In this paper, we show that our novel friend-in-the-middle attack on social networking sites (SNSs) can be used to harvest social data in an automated fashion. This social data can then be exploited for large-scale attacks such as context-aware spam and social-phishing. We prove the feasibility of our attack exemplarily on Facebook and identify possible consequences based on a mathematical model and simulations. Alarmingly, all major SNSs are vulnerable to our attack as they fail to secure the network layer appropriately. Markus Huber 0001, Martin Mulazzani, Edgar R. Weippl, Gerhard Kitzler, Sigrun Roat |
CCS | 3 |
| 2010 | An event-based empirical process analysis frameworkabstractThe engineering of complex software-intensive systems, like industrial production plants, requires software engineering to coordinate and interact with other engineering disciplines. Project and quality managers need empirical study results to improve system quality, e.g., from process analysis of engineering process event sequences. In this paper, we propose a framework adapted from business process analysis to empirically analyzing engineering process event information. Initial results support the suitability of the approach for (software+) engineering environments. 2. RESEARCH APPROACH Based on the need for monitoring and improving crossdisciplinary engineering projects, we derive two research questions: 1. What adaptations are necessary to use the “process mining” methodology for analyzing (software+) engineering processes? 2. What kinds of events need to be integrated? We propose a framework for empirical event-based process analysis, as illustrated in Figure 1. The framework consists of three steps: (1) Heterogeneous event data is collected from a variety of tools used by multiple engineering disciplines. (2) Semantic integration integrates the collected heterogeneous event sequences and stores the data in an event log. (3) The integrated event data is used for process mining. Wikan Danar Sunindyo, Stefan Biffl, Richard Mordinyi, Thomas Moser, Alexander Schatten, Mohammed Tabatabai Irani, Dindin Wahyudin, Edgar R. Weippl, Dietmar Winkler 0001 |
ESEM | 8 |
| 2010 | Implementation of Affective States and Learning Styles Tactics in Web-Based Learning Management SystemsabstractLearning styles and affective states have a significant effect on student learning. The aim of this paper is to present a concept to identify and integrate learning styles and affective states of a learner into web-based learning management systems and therefore providing learners with adaptive courses and additional individualized pedagogical guidance that is tailored to their learning styles and affective states. Through considering affective states and learning styles, learners are provided with a learning environment that is more personalized and tailored to learners needs and current situation, leading to better learning outcomes and progress. Farman Ali Khan, Sabine Graf, Edgar R. Weippl, A Min Tjoa |
ICALT | 3 |
| 2010 | A SOM-Based Technique for a User-Centric Content Extraction and Classification of Web 2.0 with a Special Consideration of Security Aspects
Amirreza Tahamtan, Amin Andjomshoaa, Edgar R. Weippl, A Min Tjoa |
KSEM | 3 |
| 2010 | QR code securityabstractThis paper examines QR Codes and how they can be used to attack both human interaction and automated systems. As the encoded information is intended to be machine readable only, a human cannot distinguish between a valid and a maliciously manipulated QR code. While humans might fall for phishing attacks, automated readers are most likely vulnerable to SQL injections and command injections. Our contribution consists of an analysis of the QR Code as an attack vector, showing different attack strategies from the attackers point of view and exploring their possible consequences. Peter Kieseberg, Manuel Leithner, Martin Mulazzani, Lindsay Munroe, Sebastian Schrittwieser, Mayank Sinha, Edgar R. Weippl |
MoMM | 7 |
| 2010 | Who on Earth Is "Mr. Cypher": Automated Friend Injection Attacks on Social Networking Sites
Markus Huber 0001, Martin Mulazzani, Edgar R. Weippl |
SEC | 3 |
| 2010 | Anonymity and Monitoring: How to Monitor the Infrastructure of an Anonymity SystemabstractThe Tor network is a widely deployed anonymity system on the Internet used by thousands of users every day. A basic monitoring system has been designed and implemented to allow long-term statistics, provide feedback to the interested user, and detect certain attacks on the network. The implementation has been added to TorStatus, a project to display the current state of the Tor network. During a period of six months, this monitoring system collected data, where information and patterns have been extracted and analyzed. Interestingly, the Tor network is very stable with more than half of all the servers located in Germany and the United States. The data also shows a sinusoidal pattern every 24 h in the total number of servers. Martin Mulazzani, Markus Huber 0001, Edgar R. Weippl |
IEEE Trans. Syst. Man Cybern. Part C | 3 |
| 2010 | Guest Editorial Foreword to the Special Issue on Availability, Reliability, and SecurityabstractThe six papers in this special issue focus on availability, reliability, and security. Some of the topics covered include prevention of identity theft, biometric technology and authentication, and security considerations for RF identification. Rivi Sandhu, A Min Tjoa, Edgar R. Weippl |
IEEE Trans. Syst. Man Cybern. Part C | 3 |
| 2009 | Can end-to-end verifiable e-voting be explained easily?abstractE-Voting is a widely discussed topic---both in the public and in research. In the last couple of years new voting protocols have been proposed. The contribution of this paper is to explain the fundamental concepts of Ben Adida's Scratch & Vote, show an implementation we made and report on the "user" (i.e. voter) experience of a handful of technically knowledgeable voters. All voters were students and they were given an introduction to the concept and could vote which coffee the institute should buy. We explored whether they would be convinced that end-to-end auditable protocols were an improvement to "normal" voting machine typically used in the US. Peter Kalchgruber, Edgar R. Weippl |
iiWAS | 2 |
| 2009 | An approach for identifying affective states through behavioral patterns in web-based learning management systemsabstractIn a learning environment, the students experience different affective states. Learning environments that takes into account the students' affective state enhance the students' learning, gain and experience. Therefore, it is crucial to provide students with different learning material and activities according to different affective states. To provide learning that considers students' affective states, the primary step is the detection of affective states of a student. In this paper, we present an approach for the detection of affective states from the patterns of students' behavior observed during an online course. By calculating the affective states and then filling that affective state data into the student model of a learning management system a basis for adaptivity is provided. Farman Ali Khan, Sabine Graf, Edgar R. Weippl, A Min Tjoa |
iiWAS | 3 |
| 2009 | Blending the Sketched Use Case Scenario with License Agreements Using Semantics
Muhammad Asfand-e-yar, Amin Andjomshoaa, Edgar R. Weippl, A Min Tjoa |
KSEM | 3 |
| 2008 | Fortification of IT Security by Automatic Security Advisory ProcessingabstractThe past years have seen the rapid increase of security related incidents in the field of information technology. IT infrastructures in the commercial as well as in the governmental sector are becoming evermore heterogeneous which increases the complexity of handling and maintaining an adequate security level. Especially organizations which are hosting and processing highly sensitive data are obligated to establish a holistic company- wide security approach. We propose a novel security concept to reduce this complexity by automatic assessment of security advisories. A central entity collects vulnerability information from various sources, converts it into a standardized and machine-readable format and distributes it to its subscribers. The subscribers are then able to automatically map the vulnerability information to the ontological stored infrastructure data to visualize newly-discovered software vulnerabilities. The automatic analysis of vulnerabilities decreases response times and permits precise response to new threats and vulnerabilities, thus decreasing the administration complexity and increasing the IT security level. Stefan Fenz, Andreas Ekelhart, Edgar R. Weippl |
AINA | 3 |
| 2008 | XML security - A comparative literature review
Andreas Ekelhart, Stefan Fenz, Gernot Goluch, Markus Steinkellner, Edgar R. Weippl |
J. Syst. Softw. | 5 |
| 2007 | Security aspects in Semantic Web Services Filtering
Witold Abramowicz, Andreas Ekelhart, Stefan Fenz, Monika Kaczmarek-Heß, A Min Tjoa, Edgar R. Weippl, Dominik Zyskowski |
iiWAS | 6 |
| 2007 | A Comparative Literature Review on RFID Security and Privacy
Bernhard Riedl, Gernot Goluch, Stefan Pöchlinger, Edgar R. Weippl |
iiWAS | 4 |
| 2007 | Information Security Fortification by Ontological Mapping of the ISO/IEC 27001 StandardabstractThis paper introduces an ontology-based framework to improve the preparation of ISO/IEC 27001 audits, and to strengthen the security state of the company respectively. Building on extensive previous work on security ontologies, we elaborate on how ISO/IEC 27001 artifacts can be integrated into this ontology. A basic introduction to security ontologies is given first. Specific examples show how certain ISO/IEC 27001 requirements are to be integrated into the ontology; moreover, our rule-based engine is used to query the knowledge base to check whether specific security requirements are fulfilled. The aim of this paper is to explain how security ontologies can be used for a tool to support the ISO/IEC 27001 certification, providing pivotal information for the preparation of audits and the creation and maintenance of security guidelines and policies. Stefan Fenz, Gernot Goluch, Andreas Ekelhart, Bernhard Riedl, Edgar R. Weippl |
PRDC | 5 |
| 2007 | Ontological Mapping of Common Criteria's Security Assurance Requirements
Andreas Ekelhart, Stefan Fenz, Gernot Goluch, Edgar R. Weippl |
SEC | 4 |
| 2006 | Workshop-based Multiobjective Security Safeguard SelectionabstractCompanies spend considerable amounts of resources on minimizing security breaches but often neglect efficient security measures and/or are not aware whether their investments are effective. While security safeguards traditionally are evaluated through a single (aggregated) criterion such as the return on investment, this may not suffice any longer as economic and legal requirements force top management to pay more attention to security issues. Thus, there is a demand for decision support tools that assist decision makers in allocating security safeguards with respect to multiple objectives of the involved stakeholders. This paper proposes a tool called MOS/sup 3/T (multi-objective security safeguard selection tool), that integrates ideas from multiobjective decision making in a workshop environment The stepwise procedure for the assessment and interactive selection of sets of security safeguards improves security awareness of top management while minimizing the resources required for implementing a proper security environment that meets a corporate's needs. Thomas Neubauer, Christian Stummer, Edgar R. Weippl |
ARES | 3 |
| 2006 | Digital Signatures with Familiar Appearance for e-Government Documents: Authentic PDFabstractMost e-government applications have to find a solution for simple, reliable, secure and authentic signing of official documents. Citizens need a simple way to verify the authenticity and integrity of an official document. Currently XML documents allow representing such documents. However, the XML format does not guarantee a definite visual presentation of the document (presentation problem). In this paper we describe a solution approach -so-called authentic PDF - using PDF technology that fulfills the following key requirements: 1) A visual presentation that resembles the traditional style of an official document; 2) A visual representation of the signature value that does not change the document authenticity; 3) The option for the holder of an official document to restore the electronic version of the authentic official document from the visual representation of the document (e.g. printout); 4) The filtering of dynamic content. We implemented and evaluated different approaches in a feasibility study using a typical e-government document set. The results of the study indicate that PDF is suitable to meet specific legal requirements on a signature solution in combination with a smartcard; the method has proven to be reliable and support a sufficient level of security. Thomas Neubauer, Edgar R. Weippl, Stefan Biffl |
ARES | 2 |
| 2006 | Do we Really Need Access Control?
Edgar R. Weippl |
iiWAS | 1 |
| 2006 | Ontology based IT-security planningabstractIT-security has become a much diversified field and small and medium sized enterprises (SMEs), in particular, do not have the financial ability to implement a holistic IT-security approach. We thus propose a security ontology, to provide a solid base for an applicable and holistic IT-security approach for SMEs, enabling low-cost risk management and threat analysis Stefan Fenz, Edgar R. Weippl |
PRDC | 2 |
| 2005 | Privacy in E-learning: How to implement anonymity
Edgar R. Weippl, A Min Tjoa |
AICCSA | 1 |
| 2005 | Semantic Storage: A Report on Performance and Flexibility
Edgar R. Weippl, Markus D. Klemen, Manfred Linnert, Stefan Fenz, Gernot Goluch, A Min Tjoa |
DEXA | 1 |
| 2004 | From Maintenance to Evolutionary Development of Web Applications: A Pragmatic Approach
Rudolf Ramler, Klaus Wolfmaier, Edgar R. Weippl |
ICWE | 3 |
| 2004 | Security in E-Learning
Edgar R. Weippl |
iiWAS | 1 |
| 2003 | Can P2P Deliver What Web Repositories Promised: Global Sharing of E-Learning Content?
Reinhard Kronsteiner, Edgar R. Weippl, Ismail Khalil, Gabriele Kotsis |
iiWAS | 2 |
| 2003 | Security in E-Learning
Edgar R. Weippl |
iiWAS | 1 |
| 2003 | A New Approach To Secure Federated Information Bases Using Agent TechnologyabstractDatabase agents, in our context also called DBagents, can be utilized to establish a federated information base by integrating heterogeneous databases. Agents are especially well suited to also address the highly relevant issue of security. During the process of migration, DBagents are wrapped into Java agents that provide various mechanisms for security and migration. This special architecture can be used to perform schema updates on distributed databases as well as to extract information in order to create and refresh data warehouses. Moreover, queries that require data which is too detailed for data warehouses can be answered by propagating them from the data warehouse to the underlying operational databases wrapped in DBagents. Furthermore, a federation connected by DBagents is much more flexible; new databases may join or existing ones may leave the federation even while queries are executed. Edgar R. Weippl, Wolfgang Eßmayr, Ludwig Klug |
J. Database Manag. | 1 |
| 2003 | Personal Trusted Devices for Web Services: Revisiting Multilevel Security
Edgar R. Weippl, Wolfgang Eßmayr |
Mob. Networks Appl. | 1 |
| 2002 | Reusable Components for Developing Security-Aware ApplicationabstractToday, security is considered to be an important aspect of multi-tier application development. Thoroughly researched concepts for access control exist and have been proven in mainframe computing. However, they are often not used in today's development of multi-tier applications. One reason may be the lack of appropriate reusable components that support application developers that frequently have to re-invent the wheel when it comes to access controls. The goal of this paper is to promote awareness of security issues when developing applications and to illustrate a suitable approach for that. Our framework called GAMMA (Generic Authorization Mechanisms for Multi-Tier Applications) offers several authentication, access control, and auditing mechanisms. Access control models can be combined or used simultaneously in order to provide application-specific and highly customizable mechanisms. Moreover, due to its component-based structure, new security models and additional approaches for authentication or auditing can easily be added. Stefan Probst, Wolfgang Eßmayr, Edgar R. Weippl |
ACSAC | 3 |
| 2002 | CoSMo: An Approach Towards Conceptual Security Modeling
Christine Artelsmair, Wolfgang Eßmayr, Peter Lang, Roland R. Wagner, Edgar R. Weippl |
DEXA | 5 |
| 2000 | Fine Grained Replication in Distributed Databases: A Taxonomy and Practical Considerations
Edgar R. Weippl, Wolfgang Eßmayr |
DEXA | 1 |
| 2000 | Knowledge Landscapes: A VR Interface for Web-Based Training Knowledge Bases
Edgar R. Weippl, Hans Lohninger |
EJC | 1 |
| 2000 | Identity Mapping: An Approach to Unravel Enterprise Security Management Policies
Wolfgang Eßmayr, Edgar R. Weippl |
SEC | 2 |