Publications (9)
A Systematic Study of the Consistency of Two-Factor Authentication User Journeys on Top-Ranked Websites (Extended Version)
Sanam Ghorbani Lyastani, Michael Backes, Sven Bugiel
Heuristics for user experience state that users will transfer their expectations from one product to another. A lack of consistency between products can increase users' cognitive f…
Towards a Principled Approach for Dynamic Analysis of Android's Middleware
Oliver Schranz, Sebastian Weisgerber, Erik Derr +2
The Android middleware, in particular the so-called systemserver, is a crucial and central component to Android's security and robustness. To understand whether the systemserver pr…
simTPM: User-centric TPM for Mobile Devices (Technical Report)
Dhiman Chakraborty, Lucjan Hanzlik, Sven Bugiel
Trusted Platform Modules are valuable building blocks for security solutions and have also been recognized as beneficial for security on mobile platforms, like smartphones and tabl…
Studying the Impact of Managers on Password Strength and Reuse
Sanam Ghorbani Lyastani, Michael Schilling, Sascha Fahl +2
Despite their well-known security problems, passwords are still the incumbent authentication method for virtually all online services. To remedy the situation, end-users are very o…
Android Security Framework: Enabling Generic and Extensible Access Control on Android
Michael Backes, Sven Bugiel, Sebastian Gerling +1
We introduce the Android Security Framework (ASF), a generic, extensible security framework for Android that enables the development and integration of a wide spectrum of security…
Trust Nothing: RTOS Security without Run-Time Software TCB (Extended Version)
Eric Ackermann, Sven Bugiel
Embedded devices face an ever-expanding threat landscape: vulnerabilities in application software, operating system kernels, and peripherals threaten the embedded device integrity.…
Stack Overflow Meets Replication: Security Research Amid Evolving Code Snippets (Extended Version)
Alfusainey Jallow, Sven Bugiel
We study the impact of Stack Overflow code evolution on the stability of prior research findings derived from Stack Overflow data and provide recommendations for future studies. We…
TALUS: Reinforcing TEE Confidentiality with Cryptographic Coprocessors (Technical Report)
Dhiman Chakraborty, Michael Schwarz, Sven Bugiel
Platforms are nowadays typically equipped with tristed execution environments (TEES), such as Intel SGX and ARM TrustZone. However, recent microarchitectural attacks on TEEs repeat…
ARTist: The Android Runtime Instrumentation and Security Toolkit
Michael Backes, Sven Bugiel, Oliver Schranz +2
We present ARTist, a compiler-based application instrumentation solution for Android. ARTist is based on the new ART runtime and the on-device dex2oat compiler of Android, which re…