24 citations
8 papers
Padding Ain't Enough: Assessing the Privacy Guarantees of Encrypted DNS
Jonas Bushart, Christian Rossow
DNS over TLS (DoT) and DNS over HTTPS (DoH) encrypt DNS to guard user privacy by hiding DNS resolutions from passive adversaries. Yet, past attacks have shown that encrypted DNS is…
Better Code, Better Sharing:On the Need of Analyzing Jupyter Notebooks
Jiawei Wang, Li Li, Andreas Zeller
By bringing together code, text, and examples, Jupyter notebooks have become one of the most popular means to produce scientific results in a productive and reproducible way. As ma…
Verifying Security Policies in Multi-agent Workflows with Loops
Bernd Finkbeiner, Christian Müller, Helmut Seidl +1
We consider the automatic verification of information flow security policies of web-based workflows, such as conference submission systems like EasyChair. Our workflow description…
Deemon: Detecting CSRF with Dynamic Analysis and Property Graphs
Giancarlo Pellegrino, Martin Johns, Simon Koch +2
Cross-Site Request Forgery (CSRF) vulnerabilities are a severe class of web vulnerabilities that have received only marginal attention from the research and security testing commun…
PRIMA: Privacy-Preserving Identity and Access Management at Internet-Scale
Muhammad Rizwan Asghar, Michael Backes, Milivoj Simeonovski
The management of identities on the Internet has evolved from the traditional approach (where each service provider stores and manages identities) to a federated identity managemen…
A Survey on Routing in Anonymous Communication Protocols
Fatemeh Shirazi, Milivoj Simeonovski, Muhammad Rizwan Asghar +2
The Internet has undergone dramatic changes in the past 15 years, and now forms a global communication platform that billions of users rely on for their daily activities. While thi…