activity
20182021
collaborators

12 papers

cs.CR2021

Malware Sight-Seeing: Accelerating Reverse-Engineering via Point-of-Interest-Beacons

August See, Maximilian Gehring, Max Mühlhäuser +2

New types of malware are emerging at concerning rates. However, analyzing malware via reverse engineering is still a time-consuming and mostly manual task. For this reason, it is n…

cs.CR2021

Passive, Transparent, and Selective TLS Decryption for Network Security Monitoring

Florian Wilkens, Steffen Haas, Johanna Amann +1

Internet traffic is increasingly encrypted. While this protects the confidentiality and integrity of communication, it prevents network monitoring systems (NMS) and intrusion detec…

cs.CR2021

Multi-Stage Attack Detection via Kill Chain State Machines

Florian Wilkens, Felix Ortmann, Steffen Haas +2

Today, human security analysts collapse under the sheer volume of alerts they have to triage during investigations. The inability to cope with this load, coupled with a high false…

cs.NI2021

SDN-based Self-Configuration for Time-Sensitive IoT Networks

Nurefşan Sertbaş Bülbül, Doğanalp Ergenç, Mathias Fischer

The convergence of IT and OT technologies results in the need for efficient network management solutions for automotive and industrial automation environments. However, configuring…

cs.CR2020

Towards Flexible Security Testing of OT Devices

Florian Wilkens, Samuel Botzler, Julia Curts +6

In the factory of the future traditional and formerly isolated Operational Technology (OT) hardware will become connected with all kinds of networks. This leads to more complex sec…

cs.CR2020

Scan Correlation -- Revealing distributed scan campaigns

Steffen Haas, Florian Wilkens, Mathias Fischer

Public networks are exposed to port scans from the Internet. Attackers search for vulnerable services they can exploit. In large scan campaigns, attackers often utilize different m…