3 papers
cs.CR2025
QUIC-Exfil: Exploiting QUIC's Server Preferred Address Feature to Perform Data Exfiltration Attacks
Thomas Grübl, Weijie Niu, Jan von der Assen +1
The QUIC protocol is now widely adopted by major tech companies and accounts for a significant fraction of today's Internet traffic. QUIC's multiplexing capabilities, encrypted hea…
cs.CR2024
The Danger Within: Insider Threat Modeling Using Business Process Models
Jan von der Assen, Jasmin Hochuli, Thomas Grübl +1
Threat modeling has been successfully applied to model technical threats within information systems. However, a lack of methods focusing on non-technical assets and their represent…
cs.CR2024
PACCOR4ESP: Embedded Device Security Attestation using Platform Attribute Certificates
Thomas Grübl, Jan von der Assen, Markus Knecht +1
Verifying the integrity of embedded device characteristics is required to ensure secure operation of a device. One central challenge is to securely extract and store device-specifi…