papers

Publications (9)

cs.CR2022

A Systematic Study of the Consistency of Two-Factor Authentication User Journeys on Top-Ranked Websites (Extended Version)

Sanam Ghorbani Lyastani, Michael Backes, Sven Bugiel

Heuristics for user experience state that users will transfer their expectations from one product to another. A lack of consistency between products can increase users' cognitive f…

cs.CR2021

Towards a Principled Approach for Dynamic Analysis of Android's Middleware

Oliver Schranz, Sebastian Weisgerber, Erik Derr +2

The Android middleware, in particular the so-called systemserver, is a crucial and central component to Android's security and robustness. To understand whether the systemserver pr…

cs.CR2019

simTPM: User-centric TPM for Mobile Devices (Technical Report)

Dhiman Chakraborty, Lucjan Hanzlik, Sven Bugiel

Trusted Platform Modules are valuable building blocks for security solutions and have also been recognized as beneficial for security on mobile platforms, like smartphones and tabl…

cs.CR2017

Studying the Impact of Managers on Password Strength and Reuse

Sanam Ghorbani Lyastani, Michael Schilling, Sascha Fahl +2

Despite their well-known security problems, passwords are still the incumbent authentication method for virtually all online services. To remedy the situation, end-users are very o…

cs.CR2014

Android Security Framework: Enabling Generic and Extensible Access Control on Android

Michael Backes, Sven Bugiel, Sebastian Gerling +1

We introduce the Android Security Framework (ASF), a generic, extensible security framework for Android that enables the development and integration of a wide spectrum of security…

cs.CR2026

Trust Nothing: RTOS Security without Run-Time Software TCB (Extended Version)

Eric Ackermann, Sven Bugiel

Embedded devices face an ever-expanding threat landscape: vulnerabilities in application software, operating system kernels, and peripherals threaten the embedded device integrity.…

cs.CR2025

Stack Overflow Meets Replication: Security Research Amid Evolving Code Snippets (Extended Version)

Alfusainey Jallow, Sven Bugiel

We study the impact of Stack Overflow code evolution on the stability of prior research findings derived from Stack Overflow data and provide recommendations for future studies. We…

cs.CR2023

TALUS: Reinforcing TEE Confidentiality with Cryptographic Coprocessors (Technical Report)

Dhiman Chakraborty, Michael Schwarz, Sven Bugiel

Platforms are nowadays typically equipped with tristed execution environments (TEES), such as Intel SGX and ARM TrustZone. However, recent microarchitectural attacks on TEEs repeat…

cs.CR2016

ARTist: The Android Runtime Instrumentation and Security Toolkit

Michael Backes, Sven Bugiel, Oliver Schranz +2

We present ARTist, a compiler-based application instrumentation solution for Android. ARTist is based on the new ART runtime and the on-device dex2oat compiler of Android, which re…