10.9k citations
- Centre National de la Recherche ScientifiqueFR574 papers
- Heidelberg UniversityDE541 papers
- Johannes Gutenberg University MainzDE527 papers
- University of ManchesterGB518 papers
- Lawrence Berkeley National LaboratoryUS517 papers
- University of EdinburghGB517 papers
- University of LiverpoolGB516 papers
- University of MilanIT516 papers
- Rutherford Appleton LaboratoryGB512 papers
- Université Paris CitéFR509 papers
- Istituto Nazionale di Fisica Nucleare, Sezione di MilanoIT508 papers
- Queen Mary University of LondonGB504 papers
5 papers · 2 filters
A Call to Reconsider Certification Authority Authorization (CAA)
Pouyan Fotouhi Tehrani, Raphael Hiesgen, Thomas C. Schmidt +1
Certification Authority Authentication (CAA) is a safeguard against illegitimate certificate issuance. We show how shortcomings in CAA concepts and operational aspects undermine it…
The Age of DDoScovery: An Empirical Comparison of Industry and Academic DDoS Assessments
Raphael Hiesgen, Marcin Nawrocki, Marinho Barcellos +14
Motivated by the impressive but diffuse scope of DDoS research and reporting, we undertake a multistakeholder (joint industry-academic) analysis to seek convergence across the best…
CRISP: Confidentiality, Rollback, and Integrity Storage Protection for Confidential Cloud-Native Computing
Ardhi Putra Pratama Hartono, Andrey Brito, Christof Fetzer
Trusted execution environments (TEEs) protect the integrity and confidentiality of running code and its associated data. Nevertheless, TEEs' integrity protection does not extend to…
Do CAA, CT, and DANE Interlink in Certificate Deployments? A Web PKI Measurement Study
Pouyan Fotouhi Tehrani, Raphael Hiesgen, Teresa Lübeck +2
Integrity and trust on the web build on X.509 certificates. Misuse or misissuance of these certificates threaten the Web PKI security model, which led to the development of several…
Information Inference Diagrams: Complementing Privacy and Security Analyses Beyond Data Flows
Sebastian Rehms, Stefan Köpsell, Verena Klös +1
This work introduces Information Inference Diagrams (I2Ds), a modeling framework aiming to complement existing approaches for privacy and security analysis of distributed systems.…