Zum Hauptinhalt springen / Jump to main Content

Publications

Read the peer-reviewed research papers, articles, and scientific contributions published by the SecLab group on IT security, privacy-enhancing technologies, federated identity and CTI.

2026

INPROCEEDINGS

Harder, Better, Faster, Stronger? A Longitudinal Analysis of an Institutional Passkey Deployment

Authors
Erwin Kupris, Florian Ritterhoff, Thomas Schreck
Year
2026
Booktitle
31st European Symposium on Research in Computer Security (ESORICS) 2026
INPROCEEDINGS

The Passkey Promise: A Comparative Usability Study of MFA Methods

Authors
Erwin Kupris, Thomas Schreck
Year
2026
Booktitle
2026 IEEE Symposium on Security and Privacy (SP)
Publisher
IEEE Computer Society
Pages
3647-3666
DOI
URL
Keywords
passkeys;usability;fido2
Abstract

Passkeys, the latest evolution of FIDO2 credentials, promise to combine enhanced security with improved usability. While passkeys are widely promoted as the long-awaited replacement for passwords, their real-world usability remains underexplored -- particularly as a passwordless and usernameless Multi-Factor Authentication (MFA) method in complex, heterogeneous environments like universities. Addressing this gap, we conducted a between-groups lab study with 92 university participants, comparing passkeys against security keys and one-time passwords across students, faculty, and staff. Our results show that passkeys are perceived as the most usable and accepted MFA method while enabling faster authentication. However, we also identified critical barriers including personal device requirements, exam scenario conflicts, privacy concerns, and recovery fears. These findings suggest that while passkeys outperform traditional MFA methods, successful deployment in academic settings requires addressing institutional constraints and providing role-specific implementation strategies.

INPROCEEDINGS

Always Authenticated, Never Exposed: Continuous Authentication via Zero-Knowledge Proofs

Authors
Dennis Hamm, Erwin Kupris, Thomas Schreck
Year
2026
Booktitle
Security and Trust Management
Publisher
Springer Nature Switzerland
Pages
23--42
ISBN
978-3-032-06155-3
Abstract

Continuous authentication enhances security by verifying users beyond their initial login. While it mitigates risks of one-time authentication, it often requires ongoing biometric data transmission, raising privacy concerns due to their sensitivity and non-revocability. To address this, we explore privacy-preserving continuous authentication using Zero-Knowledge Proofs (ZKP), which enable verification without revealing biometric data. We developed and evaluated two continuous authentication protocols: one using interactive ZKPs and another using Non-Interactive ZKPs (NIZKPs). Based on existing work, we selected and adapted a suitable one-time biometric authentication protocol, implemented a proof of concept, and tested different training sizes to optimize the trade-off between execution time and performance. With 30 training users, our system achieved a false acceptance rate of 0.0065, false rejection rate of 0.0048, and execution time of 0.1261 s. The NIZKP variant proved significantly faster due to reduced network overhead. Our approach demonstrates that continuous authentication can be made both secure and privacy-preserving, offering a scalable and highly adaptable alternative for existing systems.

INPROCEEDINGS

Evolution of Remote Attestation: A Systematic Literature Review of Post-2020 Approaches

Authors
Tobias Hilbig, Florian Wegscheider, Thomas Schreck
Year
2026
Booktitle
4th International Workshop on Trends in Digital Identity
Download PDF
INPROCEEDINGS

Jumping over Proprietary Gaps - Assessing security features in MCUs for Smart Inverters

Authors
Marius Biebel, Thomas Schreck
Year
2026
Booktitle
Proceedings of the 2026 ACM Sustainability Week
Series
ACM Sustainability Week '26
Publisher
Association for Computing Machinery
Pages
89–99
DOI
URL
ISBN
9798400721991
Keywords
Microcontroller Security Smart Inverters Distributed Energy Resources Firmware Security Secure Boot Cyber-Physical Systems Hardware Security CRA
Abstract

As Distributed Energy Resources (DERs), such as solar inverters, become integral to the power grid, their connectivity introduces significant security risks. While the physical and communication layers of these devices are well studied, the firmware layer often remains a black box due to its proprietary nature. This creates challenges for evaluating the security of these devices. In this work, we bridge this gap by first discussing the threat landscape these embedded devices face. In a second step, we assess the security capabilities of the most prominent Microcontroller Units (MCUs) specifically marketed for power control applications in smart inverters. We discuss security features such as cryptographic hardware acceleration, Secure Boot, secure storage, and physical protection mechanisms and set this in the context of the EU’s emerging Cyber Resilience Act (CRA). Our analysis highlights there is no uniform security solution provided by the MCUs recommended for smart inverters, outlining the differences between high-end connectivity-focused MCUs and pure real-time controllers. This review provides a foundation to understand the potential attack surface of smart inverters and the hardware-level mitigations available to manufacturers.

INPROCEEDINGS

SoK: The Engineer’s Guide to Post-Quantum Cryptography for Embedded Devices

Authors
Nikolai Puch, Maximilian Pursche, Sebastian N. Peters, Michael Heinl
Year
2026
Booktitle
11th IEEE European Symposium on Security and Privacy (EuroS&P 2026)
INPROCEEDINGS

All You Need is Trust: A Longitudinal Analysis of Italy's OpenID Federation Journey

Authors
Tobias Hilbig, Erwin Kupris, Thomas Schreck
Year
2026
Booktitle
11th IEEE European Symposium on Security and Privacy
Download PDF
Harder, Better, Faster, Stronger? A Longitudinal Analysis of an Institutional Passkey Deployment
Event:
31st European Symposium on Research in Computer Security (ESORICS) 2026
Authors:
Erwin Kupris, Florian Ritterhoff, Thomas Schreck
The Passkey Promise: A Comparative Usability Study of MFA Methods
Event:
2026 IEEE Symposium on Security and Privacy (SP)
Authors:
Erwin Kupris, Thomas Schreck
Always Authenticated, Never Exposed: Continuous Authentication via Zero-Knowledge Proofs
Event:
Security and Trust Management
Authors:
Dennis Hamm, Erwin Kupris, Thomas Schreck
Evolution of Remote Attestation: A Systematic Literature Review of Post-2020 Approaches
Event:
4th International Workshop on Trends in Digital Identity
Authors:
Tobias Hilbig, Florian Wegscheider, Thomas Schreck
Jumping over Proprietary Gaps - Assessing security features in MCUs for Smart Inverters
Event:
Proceedings of the 2026 ACM Sustainability Week
Authors:
Marius Biebel, Thomas Schreck
SoK: The Engineer’s Guide to Post-Quantum Cryptography for Embedded Devices
Event:
11th IEEE European Symposium on Security and Privacy (EuroS&P 2026)
Authors:
Nikolai Puch, Maximilian Pursche, Sebastian N. Peters, Michael Heinl
All You Need is Trust: A Longitudinal Analysis of Italy's OpenID Federation Journey
Event:
11th IEEE European Symposium on Security and Privacy
Authors:
Tobias Hilbig, Erwin Kupris, Thomas Schreck

2025

INPROCEEDINGS

Unlocking the Future of (edu)MFA: Integrating Passkeys for Research and Education

Authors
Erwin Kupris, Florian Ritterhoff, Steffen Hofmann, Thomas Schreck
Year
2025
Booktitle
32. DFN-Konferenz Sicherheit in vernetzten Systemen
INPROCEEDINGS

Identity Threats and Where to Find Them: Mapping ITDR and MITRE ATT&CK

Authors
Vitali Serzantov, Erwin Kupris, Thomas Schreck
Year
2025
Booktitle
2025 IEEE European Symposium on Security and Privacy Workshops (EuroS&PW)
Publisher
IEEE Computer Society
Pages
485-495
DOI
URL
Keywords
Industries;Prevention and mitigation;Standards organizations;Organizations;Threat assessment;Vectors;Security;Interoperability
Abstract

Modern cyber threats increasingly bypass traditional security controls, with attackers exploiting weakly secured identities instead of relying on sophisticated exploits. This shift has made identity-based threats a critical attack vector, necessitating specialized defense mechanisms. Identity Threat Detection and Response (ITDR) has emerged as a new security discipline designed to detect and mitigate these threats before they escalate. Despite its growing importance, ITDR lacks a structured, vendor-independent framework for understanding the threats it addresses. This paper aims to systematize knowledge on identity threats, examining how they impact different stages of the digital workforce identity lifecycle and identifying the methods available to detect and respond to them. To achieve this, we conducted a comprehensive analysis of identity threats within the MITRE ATT&CK framework. We identified 366 identity-related threats and developed a framework to categorize them based on their impact across the digital identity lifecycle, evaluating corresponding detection and response mechanisms. This research provides a foundational understanding of ITDR, contributing to its development as a formal security discipline and offering practical insights for organizations aiming to strengthen identity security in enterprise environments.

INPROCEEDINGS

Device Identity Bootstrapping in Constrained Environments: A BLE-Based BRSKI Extension

Authors
Julian Krieger, Tobias Hilbig, Thomas Schreck
Year
2025
Booktitle
2025 20th European Dependable Computing Conference (EDCC)
Pages
93-99
DOI
Keywords
Performance evaluation;Protocols;Power demand;Source coding;Scalability;Authentication;Software;Software reliability;Internet of Things;Microprogramming;IoT;Bluetooth;bootstrapping;BRSKI;ESP32
Abstract

In contrast to user authentication in the digital domain, device authentication entails distinct requirements and challenges. In the enterprise context, Internet-of-Things (IoT) devices must support strong identities to ensure secure and trusted operations. A critical first step in developing such systems is the secure bootstrapping of these devices. However, achieving trusted bootstrapping is challenging when Internet access is prohibited. In such environments, an identity must be provided to the device beforehand. The solution should also work with minimal human intervention in our scenario. To achieve this, we developed cBRSKI-PRM, a hybrid combination of BRSKI-PRM and cBRSKI. BRSKI-based communication between components is facilitated via Bluetooth Low Energy. We implemented the proposed solution on an ESP32 platform, ensuring reliable performance in both hardware and software while optimizing for low power consumption. Additionally, we identified and addressed several issues in the specifications of the employed protocols. We published all source code used in this project under the permissive MIT license. By combining and extending existing open protocols, we developed a highly assured bootstrapping process for IoT devices under minimal trust assumptions in constrained environments.

Download PDF
INPROCEEDINGS

Identifying key attacks on an IEEE 9-Bus System by leveraging the MITRE ATT&CK ICS Matrix

Authors
Marius Biebel, Zhao Song, Thomas Schreck, Christoph Hackl
Year
2025
Booktitle
Proceedings of the 16th ACM International Conference on Future and Sustainable Energy Systems
Series
E-Energy '25
Publisher
Association for Computing Machinery
Pages
791–798
DOI
URL
ISBN
9798400711251
Keywords
MITRE ATT&CK IEEE 9-Bus System Security Vulnerability Smart Grid Cyberphysicl Power System Modbus DNP3 IEC-60870 IEC-61850
Abstract

With the ongoing digitization of power grids, an increasing number of digital components are introduced into modern power grids. In this paper, we examine the IEEE 9-Bus system as a point of reference to highlight the process of moving from an electrical grid model to a cybersecurity model in order to identify relevant standards and protocols. We then leverage publicly accessible CVE data and a literature review to map discussed attack techniques for key protocols to the MITRE ATT&CK ICS Matrix and compare this information to identify similarities and differences between research findings and published vulnerabilities.The contributions of this study are twofold. First, we outline the way from an electro-technical grid model and derive potential standards and protocols for monitoring and control of such power networks. Second, we review and map related literature and CVEs to the MITRE ATT&CK ICS matrix to prototype this approach as a way of literature review to outline areas of high research activity and potential research gaps.Our analysis reveals that Denial of Service, Unauthorized Command Messages, and Adversary in the Middle techniques are among the most frequently discussed attack techniques in both published vulnerabilities and academic research concerning these protocols. Furthermore, we highlight a notable disparity: while academic research often emphasizes Adversary in the Middle techniques, the CVE data indicates a greater prevalence of initial access and lateral movement tactics.

INPROCEEDINGS

Leveraging BRSKI to Protect the Hardware Supply Chain of Operational Technology: Opportunities and Challenges

Authors
Michael P. Heinl, Adrian Reuter, Sebastian N. Peters, Markus Bever
Year
2025
Booktitle
Proceedings of the 40th ACM/SIGAPP Symposium on Applied Computing
Series
SAC '25
Publisher
Association for Computing Machinery
Pages
245–254
DOI
URL
ISBN
9798400706295
Keywords
hardware supply chain security industrial security PKI
Abstract

The increase of interconnected Operational Technology (OT) devices leads to a need for scalable, yet secure onboarding to establish a trust relationship between a new device and its operator domain. The protocol Bootstrapping Remote Secure Key Infrastructure (BRSKI) is a promising candidate to automatically establish such trust relationships and secure the OT hardware supply chain, especially when used in combination with hardware-based cryptographic device identities. Although there is a reference implementation, BRSKI has not seen many real-world applications yet. We develop a testbed to investigate possible causes by analyzing the capabilities of the BRSKI reference implementation, optimizing specific aspects, and extending its functionality to utilize trusted platform modules protecting the device's identity. Subsequently, we assess if BRSKI can be used in conformity with IEC 62443. Our findings suggest that BRSKI provides promising opportunities to secure the OT hardware supply chain but also potential for improvement.

ARTICLE

Leveraging LLMs for Memory Forensics: A Comparative Analysis of Malware Detection

Authors
Jan-Hendrik Lang, Thomas Schreck
Year
2025
Journal
Digital Threats
Publisher
Association for Computing Machinery
DOI
URL
Keywords
Malware Memory Forensics Volatility3 LLM Digital Forensics
Abstract

Memory forensics plays an important role in modern digital investigations in terms of detecting stealthy, fileless malware, and advanced persistent threats. Moreover, large language models (LLMs) have shown promise in different cybersecurity tasks. In this article, we integrate intelligence based on LLM into memory forensic workflows and evaluate multiple LLMs, including OpenAI GPT4o, OpenAI o1, Gemini 2.0 Flash, Gemini 2.0 Flash-Thinking, Grok 3, and Grok 3 with thinking mode enabled. We collect memory dumps encompassing a variety of attack scenarios such as process injection (using MSFVenom), a PowerShell Empire-based attack, and real-world malware such as Quasar RAT, MassLogger, DarkCloud, LockBit, and LockiBot. Our evaluation includes accuracy, precision, recall, and F1 score metrics and statistical analyses (ANOVA and correlation tests). The findings show that the reasoning-based (“thinking”) LLM models outperform standard models. OpenAI o1 and Gemini Flash-Thinking excel at decoding base64 obfuscated payloads, while Grok3 leads in detecting network anomalies. All LLM-based approaches suffer from high false-positive (FP) rates, reflected in low precision (often < 20\%). This tendency appears to stem from the precautionary principle in AI safety orientation, leading to models erring on the side of caution and occasionally hallucinating plausible threats when faced with ambiguous or incomplete evidence. The LockBit indicator of compromise (IoC) could not be detected with the LLM because the IoCs lie beyond the Volatility3 modules used. Due to this reason and the limited size of the context window from the LLM, it is essential to select appropriate data. Despite limitations, the study demonstrates the practical viability of integrating LLM-driven intelligence into a forensic system. The study lays the foundation for hybrid forensic systems combining symbolic analysis, domain-specific heuristics, and LLM-driven intelligence.

Unlocking the Future of (edu)MFA: Integrating Passkeys for Research and Education
Event:
32. DFN-Konferenz Sicherheit in vernetzten Systemen
Authors:
Erwin Kupris, Florian Ritterhoff, Steffen Hofmann, Thomas Schreck
Identity Threats and Where to Find Them: Mapping ITDR and MITRE ATT&CK
Event:
2025 IEEE European Symposium on Security and Privacy Workshops (EuroS&PW)
Authors:
Vitali Serzantov, Erwin Kupris, Thomas Schreck
Device Identity Bootstrapping in Constrained Environments: A BLE-Based BRSKI Extension
Event:
2025 20th European Dependable Computing Conference (EDCC)
Authors:
Julian Krieger, Tobias Hilbig, Thomas Schreck
Identifying key attacks on an IEEE 9-Bus System by leveraging the MITRE ATT&CK ICS Matrix
Event:
Proceedings of the 16th ACM International Conference on Future and Sustainable Energy Systems
Authors:
Marius Biebel, Zhao Song, Thomas Schreck, Christoph Hackl
Leveraging BRSKI to Protect the Hardware Supply Chain of Operational Technology: Opportunities and Challenges
Event:
Proceedings of the 40th ACM/SIGAPP Symposium on Applied Computing
Authors:
Michael P. Heinl, Adrian Reuter, Sebastian N. Peters, Markus Bever
Leveraging LLMs for Memory Forensics: A Comparative Analysis of Malware Detection
Event:
Digital Threats
Authors:
Jan-Hendrik Lang, Thomas Schreck

2024

INPROCEEDINGS

A-WAYF: Automated Where Are You From in Multilateral Federations

Authors
Erwin Kupris, Tobias Hilbig, David Pierre Sugar, Thomas Schreck
Year
2024
Booktitle
Proceedings of the 2nd International Workshop on Trends in Digital Identity (TDI 2024), Rome, Italy, April 9, 2024
Series
CEUR Workshop Proceedings
Publisher
CEUR-WS.org
Pages
6--17
URL
Download PDF
INPROCEEDINGS

Poster: FedCM for Research and Education

Authors
Erwin Kupris, Tobias Hilbig, Thomas Schreck
Year
2024
Booktitle
9th IEEE European Symposium on Security and Privacy
DOI
Download PDF
INPROCEEDINGS

BT2X: Multi-Leveled Binary Transparency to Protect the Software Supply Chain of Operational Technology

Authors
Michael P. Heinl, Victor Embacher
Year
2024
Booktitle
Proceedings of the Sixth Workshop on CPS&IoT Security and Privacy
Series
CPSIoTSec'24
Publisher
Association for Computing Machinery
Pages
41–54
DOI
URL
ISBN
9798400712449
Keywords
code signing constrained devices defense-in-depth iec 62443 software supply chain security software transparency
Abstract

An increasing number of attacks targeting software supply chains poses a significant threat to software-reliant systems such as Operational Technology (OT). One noteworthy variant of software supply chain attacks is the circumvention of code signing by utilizing stolen signing keys. Binary Transparency (BT) serves as a mechanism to detect and deter such attacks by mandating that every signed binary is stored in a trusted append-only log. We introduce BT-To-The-X (BT2X) which brings BT to OT. To support retrofitting of computationally less capable devices, BT2X introduces well-defined audit levels and assisting infrastructure. Furthermore, it includes a federated gossiping protocol to detect misbehaving logs presenting inconsistent views to different observers. We implemented BT2X on low-power microcontrollers using Rust and evaluated it with regard to size and performance to demonstrate its practical feasibility.

INPROCEEDINGS

The "Big Beast to Tackle": Practices in Quality Assurance for Cyber Threat Intelligence

Authors
Thomas Geras, Thomas Schreck
Year
2024
Booktitle
Proceedings of the 27th International Symposium on Research in Attacks, Intrusions and Defenses
Series
RAID '24
Publisher
Association for Computing Machinery
Pages
337–352
DOI
URL
ISBN
9798400709593
Keywords
cyber threat intelligence information sharing quality assurance sharing communities
Abstract

The quality of Cyber Threat Intelligence (CTI) has a profound impact on the efficacy of an organization’s defense against cyber threats, directly influencing its ability to safeguard critical assets and sensitive data. Despite its critical importance, the domain of CTI quality remains a multifaceted and evolving field, often operating at the intersection of theory and practice. Many organizations recognize the need for high-quality intelligence but may struggle to establish systematic processes for assessing and enhancing its quality. To investigate these issues, our research, encompassing 25 interviews with experts in the field, enriches the understanding of CTI quality in the real world, contributing valuable insights for practitioners and organizations striving to fortify their cybersecurity defenses and information-sharing practices. By bridging the gap between theory and practice, this work aims to inform and inspire advancements in CTI quality measurement.

INPROCEEDINGS

Machines Have Identities Too! Extending NIST's SP 800-63 for Device Identity

Authors
Tobias Hilbig, Erwin Kupris, Thomas Schreck
Year
2024
Booktitle
Security and Trust Management
Publisher
Springer Nature Switzerland
Pages
36--46
ISBN
978-3-031-76371-7
Abstract

User authentication has evolved from simple password-based procedures to phishing-resistant biometric methods. NIST, in special publication 800-63, provides definitions and requirements for digital identities. However, there is a growing need to also identify and authenticate the device in use. Such information can be included in fine-grained policy decisions to further enhance an enterprise's security posture. In addition, device authentication has been described in the literature as a significant factor in zero trust architectures. Despite the adoption of this security architecture by major stakeholders, device authentication remains lacking. Therefore, we propose extensions to SP 800-63 that cover device identity aspects. In addition, we present a best-of-breed solution using FIDO2 and an extension for OpenID Connect. Our results demonstrate that the integration of device identity aspects is feasible and aligns well with the existing guidelines. The proposed scheme can pave the way for a future where device authentication will become the norm in enterprise networks.

Download PDF
INPROCEEDINGS

Do You Play It by the Books? A Study on Incident Response Playbooks and Influencing Factors

Authors
Daniel Schlette, Philip Empl, Marco Caselli, Thomas Schreck, Günther Pernul
Year
2024
Booktitle
2024 IEEE Symposium on Security and Privacy (SP)
Pages
3625-3643
DOI
Keywords
Privacy;Systematics;Shape;Generative AI;Data integrity;Merging;Organizations;Incident Response;Playbook;Security Operations;Threat Intelligence
Abstract

Incident response "playbooks" are structured sets of operational procedures organizations use to instruct humans or machines on performing countermeasures against cybersecurity threats. These playbooks generally combine information about a given threat and organizational aspects relevant within the context of an organization. Both types of information are crucial for using, maintaining, and sharing playbooks across organizations as they ensure effectiveness and confidentiality. While practitioners show great interest in playbooks, their characteristics have not yet been thoroughly investigated from a research perspective. For this reason, we explore the topic by analyzing what is inside a playbook. Our approach consists of a comprehensive empirical assessment of available data (1217 playbooks), an online study with 147 participants, and final in-depth interviews with nine security professionals to consolidate and validate our findings. We notably find intrinsic ambiguities in the way practitioners and organizations define their playbooks. Furthermore, we notice that available playbooks cannot be used outright which might currently impair their wide use across different cybersecurity actors. As a result, we can conclude that organizations do "play it by the books" but individually define what is inside their playbooks and which areas of incident response they might address.

A-WAYF: Automated Where Are You From in Multilateral Federations
Event:
Proceedings of the 2nd International Workshop on Trends in Digital Identity (TDI 2024), Rome, Italy, April 9, 2024
Authors:
Erwin Kupris, Tobias Hilbig, David Pierre Sugar, Thomas Schreck
Poster: FedCM for Research and Education
Event:
9th IEEE European Symposium on Security and Privacy
Authors:
Erwin Kupris, Tobias Hilbig, Thomas Schreck
BT2X: Multi-Leveled Binary Transparency to Protect the Software Supply Chain of Operational Technology
Event:
Proceedings of the Sixth Workshop on CPS&IoT Security and Privacy
Authors:
Michael P. Heinl, Victor Embacher
The "Big Beast to Tackle": Practices in Quality Assurance for Cyber Threat Intelligence
Event:
Proceedings of the 27th International Symposium on Research in Attacks, Intrusions and Defenses
Authors:
Thomas Geras, Thomas Schreck
Machines Have Identities Too! Extending NIST's SP 800-63 for Device Identity
Event:
Security and Trust Management
Authors:
Tobias Hilbig, Erwin Kupris, Thomas Schreck
Do You Play It by the Books? A Study on Incident Response Playbooks and Influencing Factors
Event:
2024 IEEE Symposium on Security and Privacy (SP)
Authors:
Daniel Schlette, Philip Empl, Marco Caselli, Thomas Schreck, Günther Pernul

2023

INPROCEEDINGS

Sharing Communities: The Good, the Bad, and the Ugly

Authors
Thomas Geras, Thomas Schreck
Year
2023
Booktitle
Proceedings of the 2023 ACM SIGSAC Conference on Computer and Communications Security
Series
CCS '23
Publisher
Association for Computing Machinery
Pages
2755–2769
DOI
URL
ISBN
9798400700507
Keywords
csirt cyber threat intelligence information sharing sharing communities social and technical aspects socio-technical systems theory
Abstract

There are many mysteries surrounding sharing communities, mainly due to their hidden workings and the complexity of joining. Nevertheless, these communities are critical to the security ecosystem, so a more profound understanding is necessary. In addition, they face challenges such as building trust, communicating effectively, and addressing social problems.This work aims to understand better the working methods, organizational structures, goals, benefits, and challenges of sharing communities to help improve their effectiveness and efficiency. To achieve this goal, we conducted video interviews with 25 experts from different countries worldwide who participate in various types of sharing communities. In addition, we applied socio-technical systems (STS) theory in our analysis process to elaborate on our findings from the interviews, identify correlations between them, and explore the interrelationships between social and technical elements of sharing communities.Our findings underscore the need for a holistic view of how sharing communities work. Instead of looking at individual aspects in isolation, considering the interrelationships between the different elements, especially the social, is crucial. This holistic perspective allows us to understand better the complexity and dynamics of sharing communities and how they can function effectively and efficiently. The findings of this study provide valuable impetus for the further development of sharing communities and can serve as a basis for future research.

INPROCEEDINGS

Protect the Gate – Not Only Once: Continuous Access Evaluation in Practice

Authors
Tobias Hilbig, Vitali Serzantov, Thomas Schreck
Year
2023
Booktitle
2023 7th Cyber Security in Networking Conference (CSNet)
Pages
137-142
DOI
Keywords
Authorization;Privacy;Focusing;Logic gates;Internet;Security;Stakeholders;continuous access evaluation;authorization;zero trust architecture
Abstract

In increasingly dynamic enterprise systems, accessing resources such as data and APIs from a static context is no longer a given. It is also common for users to access multiple services simultaneously within a session over an extended period. For example, the security posture of the accessing device may change during a session. Is the device still authorized to access specific resources in such a case? Continuous Access Evaluation addresses these and other problems related to changing context within a session. The basic principle of this technology is as follows: After each event that affects the context of access authorization, all participants in a session are informed. They then can decide on the continued authorization of access within a session for a user, an application, or a device. In this paper, we discuss the current state of this concept, ongoing standardization efforts and initial usage in large enterprise systems. Our findings indicate that the concept is well-defined and understood, resulting in rising academic interest in the topic. We assess ongoing progress in current standardization efforts, and also see notable adoption by major stakeholders.

Download PDF
INPROCEEDINGS

`State of the Union': Evaluating Open Source Zero Trust Components

Authors
Tobias Hilbig, Thomas Schreck, Tobias Limmer
Year
2023
Booktitle
Security and Trust Management
Publisher
Springer Nature Switzerland
Pages
42--61
ISBN
978-3-031-47198-8
Abstract

Zero Trust Architecture (ZTA) is a security model based on the principle ``never trust, always verify''. In such a system, trust must be established for both the user and the device for access to be granted. While industry adoption of commercial ZTA solutions is accelerating, the state of open-source implementations has yet to be explored. To that end, we survey open-source implementations of zero trust components and put forward a set of ZTA specific requirements to evaluate against. We also identify seven major challenges that hinder the adoption and deployment of open-source zero trust solutions. Our results show that implementations for individual components are much more mature compared to ``all-in-one'' ZTA solutions. The interoperability between solutions and the development of inter-component protocols are the main areas in which improvements can be made. Despite encouraging developments, we conclude that building ZTAs on top of open-source components is difficult.

Download PDF
ARTICLE

security.txt Revisited: Analysis of Prevalence and Conformity in 2022

Authors
Tobias Hilbig, Thomas Geras, Erwin Kupris, Thomas Schreck
Year
2023
Journal
Digital Threats
Publisher
Association for Computing Machinery
DOI
URL
Keywords
Security.txt internet scanning vulnerability disclosure Incident Response
Abstract

Determining the correct contact person for a particular system or organization is challenging in today’s Internet architecture. However, there are various stakeholders who will need to have such information, such as national security teams, security researchers, or Internet service providers, among others. To address this problem, RFC 9116, or better known as “security.txt,” was developed. If implemented correctly, then it can help these stakeholders in finding contact information to be used to notify an organization of any security issues. Further, there is another proposal called “dnssecuritytxt,” which uses DNS records for this purpose.In this research article, we evaluated the prevalence of websites that have implemented security.txt and their conformity with the standard. Through a longitudinal analysis of the top one million websites, we investigated the adoption and usage of this standard among organizations. Our results show that the overall adoption of security.txt remains low, especially among less popular websites. To drive its acceptance among organizations, security researchers, and developers, we derived several recommendations, including partnerships with vendors of browsers and content management systems.

Download PDF
INPROCEEDINGS

Moderne PKI-Architektur an einer Hochschule

Authors
Thomas Schreck, Florian Ritterhoff
Year
2023
Booktitle
30. DFN-Konferenz „Sicherheit in vernetzten Systemen“
ISBN
978-3-7568-8139-0
INPROCEEDINGS

Enterprise Cyber Threat Modeling and Simulation of Loss Events for Cyber Risk Quantification

Authors
Christian Ellerhold, Johann Schnagl, Thomas Schreck
Year
2023
Booktitle
Proceedings of the 2023 on Cloud Computing Security Workshop
Series
CCSW '23
Publisher
Association for Computing Machinery
Pages
17–29
DOI
URL
ISBN
9798400702594
Keywords
cloud computing cyber risk quantification enterprise threat model factor analysis of information risk (fair) mitre att&ck quantitative risk assessment unified kill chain
Abstract

In today's enterprise landscape, effective risk management has emerged as a vital cornerstone. This importance has escalated significantly due to the widespread transition from traditional on-premise infrastructures to dynamic cloud environments. Many organizations rely on qualitative approaches for internal IT and cyber risk management; however, these approaches have notable drawbacks, such as a lack of accuracy and comparability. In this paper, we propose a novel approach to address these limitations by using the Factor Analysis of Information Risk (FAIR) methodology in conjunction with MITRE ATT&CK to model realistic cyberattacks on organizations and measure quantitative risk. We describe how this approach can be used to create an enterprise cyber threat model, providing a case study for a cloud scenario to demonstrate its usage and to illustrate its potential benefits. Our model has demonstrated its practical applicability in enterprise settings as we thoroughly evaluated its effectiveness within two prominent German companies. This allowed us to gain valuable insight into how our proposed approach can enhance an organization's risk management strategies. Our research demonstrates the value of using a quantitative approach like FAIR over qualitative risk assessment methods. Overall, our approach provides a more comprehensive understanding of the risks organizations are facing and offers guidance on implementing effective risk management strategies. This research can help organizations improve their risk management practices and reduce the potential negative impact of cyberattacks.

Sharing Communities: The Good, the Bad, and the Ugly
Event:
Proceedings of the 2023 ACM SIGSAC Conference on Computer and Communications Security
Authors:
Thomas Geras, Thomas Schreck
Protect the Gate – Not Only Once: Continuous Access Evaluation in Practice
Event:
2023 7th Cyber Security in Networking Conference (CSNet)
Authors:
Tobias Hilbig, Vitali Serzantov, Thomas Schreck
`State of the Union': Evaluating Open Source Zero Trust Components
Event:
Security and Trust Management
Authors:
Tobias Hilbig, Thomas Schreck, Tobias Limmer
security.txt Revisited: Analysis of Prevalence and Conformity in 2022
Event:
Digital Threats
Authors:
Tobias Hilbig, Thomas Geras, Erwin Kupris, Thomas Schreck
Moderne PKI-Architektur an einer Hochschule
Event:
30. DFN-Konferenz „Sicherheit in vernetzten Systemen“
Authors:
Thomas Schreck, Florian Ritterhoff
Enterprise Cyber Threat Modeling and Simulation of Loss Events for Cyber Risk Quantification
Event:
Proceedings of the 2023 on Cloud Computing Security Workshop
Authors:
Christian Ellerhold, Johann Schnagl, Thomas Schreck

2022

INPROCEEDINGS

Understanding the Usage of IT-Security Games in the Industry and Its Mapping to Job Profiles

Authors
Tilman Dewes, Tiago Gasiba, Thomas Schreck
Year
2022
Booktitle
Third International Computer Programming Education Conference (ICPEC 2022)
Series
Open Access Series in Informatics (OASIcs)
Publisher
Schloss Dagstuhl -- Leibniz-Zentrum f\"ur Informatik
Pages
3:1--3:12
DOI
URL
ISBN
978-3-95977-229-7
URN
urn:nbn:de:0030-drops-166077
Download PDF
Understanding the Usage of IT-Security Games in the Industry and Its Mapping to Job Profiles
Event:
Third International Computer Programming Education Conference (ICPEC 2022)
Authors:
Tilman Dewes, Tiago Gasiba, Thomas Schreck