activity
20172020
most cited(Un)informed Consent: Studying GDPR Consent Notices in the Field

356 citations · 443 across the 15 of their papers we have counts for

collaborators

18 papers

cs.CR202016 cited

Unacceptable, where is my privacy? Exploring Accidental Triggers of Smart Speakers

Lea Schönherr, Maximilian Golla, Thorsten Eisenhofer +3

Voice assistants like Amazon's Alexa, Google's Assistant, or Apple's Siri, have become the primary (voice) interface in smart speakers that can be found in millions of households.…

cs.CR2020

VPS: Excavating High-Level C++ Constructs from Low-Level Binaries to Protect Dynamic Dispatching

Andre Pawlowski, Victor van der Veen, Dennis Andriesse +4

Polymorphism and inheritance make C++ suitable for writing complex software, but significantly increase the attack surface because the implementation relies on virtual function tab…

cs.CR2020

Automated Multi-Architectural Discovery of CFI-Resistant Code Gadgets

Patrick Wollgast, Robert Gawlik, Behrad Garmany +2

Memory corruption vulnerabilities are still a severe threat for software systems. To thwart the exploitation of such vulnerabilities, many different kinds of defenses have been pro…

cs.CR2020

Detile: Fine-Grained Information Leak Detection in Script Engines

Robert Gawlik, Philipp Koppe, Benjamin Kollenda +3

Memory disclosure attacks play an important role in the exploitation of memory corruption vulnerabilities. By analyzing recent research, we observe that bypasses of defensive solut…

cs.CR2020

An Exploratory Analysis of Microcode as a Building Block for System Defenses

Benjamin Kollenda, Philipp Koppe, Marc Fyrbiak +3

Microcode is an abstraction layer used by modern x86 processors that interprets user-visible CISC instructions to hardware-internal RISC instructions. The capability to update x86…

cs.CR2020

Breaking and Fixing Destructive Code Read Defenses

Jannik Pewny, Philipp Koppe, Lucas Davi +1

Just-in-time return-oriented programming (JIT-ROP) is a powerful memory corruption attack that bypasses various forms of code randomization. Execute-only memory (XOM) can potential…