|
|
|
Engin Kirda
|
Here is my
Eurecom home page
About me
I am faculty (i.e.,
Maitre de Conferences
) at
Eurecom
(Graduate School and Research Center) in the French
Riviera
and Adjunct Associate Professor (i.e.,
Priv. Doz.
) at the Technical University Vienna. My current research interest are software and network security (with focus on Web vulnerability detection and prevention, binary analysis, malware detection [e.g., spyware]). Before that, I was mainly interested in distributed systems, software engineering and software architectures.
I personally enjoy writing code in all sorts of languages (e.g., C, Perl, C#, Java, [recently] Python) and am convinced that computer science students need to be language-independent ;-) Nowadays, though, I find less time to code... ;-(
I am glad to be working with a bunch of master's and Ph.D. students (
InetSec 2 gurus
) who are good engineers.
|
General Information
|
Education:
|
Habilitation (Priv.Doz.), Dr. techn., Dipl.-Ing. in Computer Science,
Technical University of Vienna
|
|
Office Hours:
|
e-mail appointment
|
|
Email:
|
nspmekasdf@iseclab.org
(This is my one-time, spam-protected address. Contact me there and I'll get back to you)
|
|
Current Address:
|
Institut Eurecom
2229 Route des Cretes
F-06560 Sophia-Antipolis cedex
France
|
|
Telephone:
|
+33 4 9300 8247
|
|
Member of:
|
IEEE,
Shellphish
|
Research Labs
Current Funded Projects
VAMPIRE (Voice Over IP Security)
Sponsor: ANR (French National Research Agency)
Position: Principle Investigator
|
MECANOS (Smartcard Security)
Sponsor: POLE de Competitivite SCS, France
Position: Principle Investigator
|
SECoverer (Detection of Application Logic Errors in Web Applications)
Sponsor: FIT-IT Trust in IT-Systems 2. Call, Austria
Position: Principle Investigator (together with
Christopher Kruegel
)
|
TRADE (Trustworthy Adaptive Quality Balancing Through Temporal Decoupling)
Sponsor: FIT-IT Trust in IT-Systems 2. Call, Austria
Position: Investigator
|
FORWARD (Managing Emerging Threats in ICT Infrastructures)
Sponsor: The EU Commission
Position: Principle Investigator (together with
Christopher Kruegel
)
|
WOMBAT (Worldwide Observatory of Malicious Behaviors and Attack Threats)
Sponsor: The EU Commission
Position: Principle Investigator (together with
Christopher Kruegel
)
|
Pathfinder (Malicious Code Analysis and Detection) -- also selected best project of the call
Sponsor: FIT-IT Trust in IT-Systems 1. Call
Position: Principle Investigator (together with
Christopher Kruegel
)
|
Web-Defense: Defending Internet Users against web attacks
Sponsor: Fonds zur Foerderung der wissenschaftlichen Forschung (FWF) - No. P18764
Position: Principle Investigator (together with
Christopher Kruegel
)
|
Recently Completed Projects
Software Security through Binary Analysis
Sponsor: Fonds zur Foerderung der wissenschaftlichen Forschung (FWF) - No. P18157
Position: Principle Investigator (together with
Christopher Kruegel
)
|
Software Security Audit using Reverse Engineering
Sponsor: Austrian Central Bank (OeNB)
Position: Principle Investigator (together with
Christopher Kruegel
)
|
Omnis - Security, Components and Infrastructure for Pervasive Environments
Sponsor: Fonds zur Foerderung der wissenschaftlichen Forschung (FWF) - No. P18368
Position: Principle Investigator (together with
Christopher Kruegel
)
|
Software Security Analysis
Sponsor: BAWAG P.S.K. Bank
Position: Consultant
|
Solaris and Linux Baseline Security
Sponsor: Austrian Central Bank (OeNB)
Position: Principal Investigator (together with
Christopher Kruegel
)
|
Recent Awards
|
Wirtschaftskammerpreis 2005 (Award of the Austrian Federal Economic Chamber)
|
Publications
|
Workshops and Conferences (Security)
|
Julio Canto, Marc Dacier, Engin Kirda, and Corrado Leita, Large Scale Malware Collection: Lessons Learned, IEEE SRDS Workshop on Sharing Field Data and Experiment Measurements on Resilience of Distributed Computing Systems, Naples, Italy, October 2008
[
download
]
|
Guenther Starnberger, Christopher Kruegel, and Engin Kirda, Overbot - A botnet protocol based on Kademlia, 4th International Conference on Security and Privacy in Communication Networks (SecureComm), Istanbul, Turkey, September 2008
[
download
]
|
Eric Medved, Engin Kirda, Christopher Kruegel, Visual-Similarity-Based Phishing Detection, 4th International Conference on Security and Privacy in Communication Networks (SecureComm), Istanbul, Turkey, September 2008
[
download
]
|
Sean McAllister, Engin Kirda, and Christopher Kruegel, Expanding Human Interactions for In-Depth Testing of Web Applications, 11th Symposium on Recent Advances in Intrusion Detection (RAID), Boston, MA, September 2008
[
download
]
|
Marco Cova, Vika Felmetsger, Davide Balzarotti, Nenad Jovanovic, Christopher Kruegel, Engin Kirda, Giovanni Vigna, Saner: Composing Static and Dynamic Analysis to Validate Sanitization in Web Applications, Oakland, May 2008
[
download
]
|
Corrado Leita, V.H. Pham, Olivier Thonnard, E. Ramirez-Silva, Fabian Pouget, Engin Kirda , Marc Dacier, The Leurre.com Project: Collecting Internet Threats Information using a Worldwide Distributed Honeynet, In Proceedings of the 1st WOMBAT workshop, IEEE Computer Society, Amsterdam, April 2008
[
download
]
|
Gilbert Wondracek, Paulo Milani, Christopher Kruegel and Engin Kirda, Automatic Network Protocol Analysis, 15th Annual Network and Distributed System Security Symposium (NDSS 2008), San Diego, February 2008
[
download
]
|
Andreas Moser, Christopher Kruegel, and Engin Kirda, Limits of Static Analysis for Malware Detection, 23rd Annual Computer Security Applications Conference (ACSAC), Miami Beach, Florida, December 2007
[
download
]
|
Martin Syzdlowski, Christopher Kruegel, and Engin Kirda, Secure Input for Web Applications, 23rd Annual Computer Security Applications Conference (ACSAC), Miami Beach, Florida, December 2007
[
download
]
|
Heng Yin, Dawn Song, Manuel Egele, Christopher Kruegel, and Engin Kirda, Panorama: Capturing System-wide Information Flow for Malware Detection and Analysis, 14th ACM Conference on Computer and Communications Security, Alexandria, VA, November 2007
[
download
]
|
Christoph Karlberger, Guenter Bayler, Christopher Kruegel, and Engin Kirda, Exploiting Redundancy in Natural Language to Penetrate Bayesian Spam Filters, First USENIX Workshop on Offensive Technologies (WOOT '07), Boston, August 2007.
[
download
]
|
Christian Ludl, Sean McAllister, Engin Kirda, and Christopher Kruegel, On the Effectiveness of Techniques to Detect Phishing Sites, Detection of Intrusions and Malware and Vulnerability Assessment (DIMVA) 2007 Conference, Lucerne, Switzerland, July 2007.
[
download
]
|
Manuel Egele, Christopher Kruegel, Engin Kirda, Heng Yin, and Dawn Song, Dynamic Spyware Analysis, USENIX Annual Technical Conference, Santa Clara, CA, June 2007.
[
download
]
|
Thomas Raffetseder, Christopher Kruegel, and Engin Kirda, Detecting System Emulators, Information Security Conference (ISC 2007), Valparaiso, Chile, October 2007 (
Best Student Paper Award
)
[
download
]
|
Thomas Raffetseder, Engin Kirda, and Christopher Kruegel, Building Anti-Phishing Browser Plug-Ins: An Experience Report, The 3rd International Workshop on Software Engineering for Secure Systems (SESS07), 29th International Conference on Software Engineering (ICSE), Minneapolis, IEEE Computer Society Press, May 2007.
[
download
]
|
Andreas Moser, Christopher Kruegel, and Engin Kirda, Exploring Multiple Execution Paths for Malware Analysis, IEEE Security and Privacy, Oakland, May 2007.
[
download
]
|
Philipp Vogt, Florian Nentwich, Nenad Jovanovic, Christopher Kruegel, Engin Kirda and Giovanni Vigna, Cross Site Scripting Prevention with Dynamic Data Tainting and Static Analysis, 14th Annual Network and Distributed System Security Symposium (NDSS 2007), San Diego, CA, February 2007
[
download
]
|
Nenad Jovanovic, Engin Kirda and Christopher Kruegel, Preventing Cross Site Request Forgery Attacks, 2nd IEEE Communications Society International Conference on Security and Privacy in Communication Networks (SecureComm), Baltimore, MD, August 2006
[
download
] [
download technical report
]
|
Patrick Klinkoff, Christopher Kruegel, Engin Kirda and Giovanni Vigna, Extending .NET Security to Unmanaged Code, 9th Information Security Conference (ISC 2006), Samos, Greece, September 2006
[
download
]
|
Engin Kirda, Christopher Kruegel, Greg Banks, Giovanni Vigna, and Richard A. Kemmerer, Behavior-Based Spyware Detection, in USENIX Security '06, Vancouver, Canada, August 2006
[
download
]
|
Nenad Jovanovic, Christopher Kruegel, and Engin Kirda, Precise Alias Analysis for Syntactic Detection of Web Application Vulnerabilities, ACM SIGPLAN Workshop on Programming Languages and Analysis for Security, Ottowa, Canada, June 2006
[
download
]
|
Manuel Egele, Martin Szydlowski, Engin Kirda, and Christopher Kruegel, Using Static Program Analysis to Aid Intrusion Detection, Detection of Intrusions and Malware and Vulnerability Assessment (DIMVA) 2006 Conference, Berlin, Germany, July 2006
[
download
]
|
Stefan Kals, Engin Kirda, Christopher Kruegel, and Nenad Jovanovic, SecuBat: A Web Vulnerability Scanner, The 15th International World Wide Web Conference (WWW 2006), Edinburgh, Scotland, May 2006
[
download
]
|
Ulrich Bayer, Christopher Kruegel, and Engin Kirda, TTAnalyze: A Tool for Analyzing Malware, 15th European Institute for Computer Antivirus Research (EICAR 2006) Annual Conference, Hamburg, Germany, April 2006 (
Best Paper Award
)
[
download
]
|
Nenad Jovanovic, Christopher Kruegel, and Engin Kirda, Pixy: A
Static Analysis Tool for Detecting Web Application Vulnerabilities (Short
Paper), 2006 IEEE Symposium on Security and Privacy, Oakland, CA, May
2006
[
download
]
|
Engin Kirda, Christopher Kruegel, Giovanni Vigna, and Nenad Jovanovic, Noxes: A Client-Side Solution for Mitigating Cross Site Scripting Attacks, The 21st ACM Symposium on Applied Computing
(SAC 2006), Security Track, Dijon, France, April 2006
[
download
]
|
Fredrik Valeur, Giovanni Vigna, Christopher Kruegel, and Engin Kirda, An Anomaly-driven Reverse Proxy for Web Applications, The 21st ACM Symposium on Applied Computing
(SAC 2006), Security Track, Dijon, France, April 2006
[
download
]
|
Engin Kirda and Christopher Kruegel, Protecting Users against Phishing Attacks with AntiPhish, 29th Annual International Computer Software and Applications Conference (COMPSAC 2005), Edinburgh, Scotland, July 2005
[
download
]
|
Christopher Kruegel, Engin Kirda, Darren Mutz, William Robertson, and Giovanni Vigna, Polymorphic Worm Detection Using Structural Information of Executables, 8th Symposium on Recent Advances in Intrusion Detection (RAID), Lecture Notes in Computer Science, Springer Verlag. USA, September 2005.
[
download
]
|
Christopher Kruegel, Engin Kirda, Darren Mutz, William Robertson, Giovanni Vigna, Automating Mimicry Attacks Using Static Binary Analysis, in USENIX Security '05, Baltimore, US, August 2005
[
download
]
|
|
Workshops and Conferences (Software Engineering)
|
|
Clemens Kerer and Engin Kirda, XGuide - Concurrent Web Engineering with Contracts,
4th International Conference on Web Engineering (ICWE) 2004, Munich, Germany, Lecture Notes in Computer Science, July 2004.
|
|
Engin Kirda and Clemens Kerer, DIWE: A Framework for constructing Device-Independent Web Applications,
UMICS 2004 Workshop, CAISE 2004 Conference, Riga, Latvia, Lecture Notes in Computer Science, June 2004
|
|
Engin Kirda, Clemens Kerer, Christopher Kruegel and Roman Kurmanowytsch, Web Service
Engineering with DIWE, 29th EUROMICRO Conference, Antalya, Turkey, IEEE Computer Society Press,
September 2003
|
|
Sagar Chaki, Pascal Fenkam, Harald Gall, Somesh Jha, Engin Kirda and Helmuth Veith, Integrating
Publish/Subscribe into a Mobile Teamwork Support Platform, 15th International Software
Engineering and Knowledge Engineering Conference (SEKE 2003) (San Fransisco Bay,
USA). ACM Press, July 2003.
|
|
Roman Kurmanowytsch, Engin Kirda, Clemens Kerer
and Schahram Dustdar, OMNIX: A topology-independent P2P middleware,
Ubiquitous Mobile Information and Collaboration Systems (UMICS 2003) workshop,
CAISE 2003, Klagenfurt, Austria, June 2003
|
|
Zorlu Yalniz and Engin Kirda. Supporting Collaboration in the
Designing of Tools and Dies in Manufacturing Networks. IEEE 12th
International Workshops on Enabling Technologies:
Infrastructure for Collaborative Enterprises
(WETICE 2003), Linz, Austria. IEEE Computer Society Press, June 2003.
|
|
Schahram Dustdar, Harald Gall and Engin Kirda, Distributed Product
Development in Virtual Communities, 2nd Workshop on Cooperative
Supports for Distributed Software Engineering Processes, 7th European
Conference on Software Maintenance and Reengineering, Benevento,
Italy, in Cooperative Methods and Tools for Distributed
Software Processes, editors Aniello Cimitile, Andrea De Lucia and
Harald Gall, pages 25-43, FrancoAngeli ISBN-88-464-4774-3, March 2003
|
|
Engin Kirda, Pascal Fenkam, Gerald Reif, and Harald Gall. A Service
Architecture for Mobile Teamwork. 14th International Software
Engineering and Knowledge Engineering Conference (SEKE 2002) (Ischia,
Italy). ACM Press, July 2002.
|
|
Engin Kirda, Harald Gall, Pascal Fenkam, and Gerald Reif. MOTION: A
Peer-to-Peer Platform for Mobile Teamwork Support. In Cooperative
Support for Distributed Software Engineering Processes Workshop, 26th
COMPSAC Conference, Oxford, England. IEEE Computer Society Press,
August 2002.
|
|
Clemens Kerer, Engin Kirda, and Christopher Kruegel. XGuide - A
Practical Guide to XML-based Web Engineering. International Workshop
on Web Engineering, Networking 2002 (Pisa, Italy, May 2002), Eds: Lucy
Cherkasova and Fabio Panzieri, editors, Lecture Notes of Computer
Science, 2376, Springer, May 2002.
|
|
Roman Kurmanowytsch, Mehdi Jazayeri, and Engin Kirda. Towards a
hierarchical, semantic peer-to-peer topology. In Second IEEE
International Conference on Peer-to-Peer Computing, Use of Computers
at the Edge of Networks (P2P, Grid, Clusters), Linkoping, Sweden,
2002. IEEE Computer Society Press.
|
|
Pascal Fenkam, Schahram Dustdar, Engin Kirda, Harald Gall, and Gerald
Reif. Towards an Access Control System for Mobile Peer-to-Peer
Collaborative Environments. IEEE 11th International Workshops on
Enabling Technologies: Infrastructure for Collaborative Enterprises
(WETICE 2002) (Carnegie Mellon University, Pittsburgh, Pennsylvania,
USA). IEEE Computer Society Press, June 10-12 2002.
|
|
Pascal Fenkam, Engin Kirda, Schahram Dustdar, Harald Gall, and Gerald
Reif. Evaluation of a Publish/Subscribe System for Collaborative and
Mobile Working. IEEE 11th International Workshops on Enabling
Technologies: Infrastructure for Collaborative Enterprises (WETICE
2002) (Carnegie Mellon University, Pittsburgh, Pennsylvania,
USA). IEEE Computer Society Press, June 10-12 2002.
|
|
Engin Kirda, Gerald Reif, Harald Gall, and Pascal Fenkam. TWSAPI: A
Generic Teamwork Services Application Programming
Interface. International Workshop on Mobile Teamwork 2002, 22nd International
Conference on Distributed Computing Systems (ICDCS) (Vienna,
Austria). IEEE CS Press, June 2002.
|
|
Christopher Kruegel, Thomas Toth, and Engin Kirda. Service Specific
Anomaly Detection for Network Intrusion Detection. Symposium on
Applied Computing (SAC) (Madrid, Spain). ACM Press, March 2002.
|
|
Engin Kirda, Clemens Kerer, Mehdi Jazayeri, Harald Gall, and Roman
Kurmanowytsch. The Evolution of an Organizational Web Site: Migrating
to XML/XSL. 3rd International Workshop on Web Site Evolution, ICSM
2001 (Florence, Italy). IEEE Computer Society Press, 6-10 November,
2001.
|
|
Christopher Kruegel, Thomas Toth, and Engin Kirda. Sparta - A Mobile
Agent based Intrusion Detection System. IFIP Conference on Network
Security (I-NetSec) (Leuven, Belgium). Kluwer Academic Publishers,
November 2001.
|
|
Engin Kirda, Harald Gall, Gerald Reif, Pascal Fenkam, and Clemens
Kerer. Supporting Mobile Users and Distributed Teamwork. Proceedings
of ConTEL 2001 - 6th International Conference on Telecommunications
(Zagreb, Croatia, June 13-15 2001), edited by Maja Matijasevic
and Alen Bazant, Zagreb, ISBN 953-184-020-2, 2001
|
|
Clemens Kerer, Engin Kirda, Mehdi Jazayeri, and Roman Kurmanowytsch.
Building XML/XSL-Powered Web Sites: An Experience Report. 25th
International Computer Software and Applications Conference (COMPSAC)
(Chicago, IL, USA). IEEE Computer Society Press, October 2001.
|
|
Engin Kirda. Engineering of Web Services with XML and XSL, Tutorial
Abstract. 8th European Software Engineering Conference (ESEC)
(Vienna, Austria), pages 318-19, Volker Gruhn, editor. ACM Press,
September 10-14 2001.
|
|
Engin Kirda, Clemens Kerer, and Mehdi Jazayeri. Supporting
Multi-device Enabled Web Services: Challenges and Open Problems.10th
IEEE Workshops on Enabling Technologies: Infrastructure for
Collaborative Enterprises (WETICE) (Boston, MA, USA). IEEE Computer
Society, June 2001.
|
|
Gerald Reif, Engin Kirda, Harald Gall, Gian Pietro Picco, Gianpaola
Cugola, and Pascal Fenkam. A Web-based peer-to-peer architecture for
collaborative nomadic working. 10th IEEE Workshops on Enabling
Technologies: Infrastructures for Collaborative Enterprises (WETICE)
(Boston, MA, USA). IEEE Computer Society Press, June 2001.
|
|
Engin Kirda, Clemens Kerer, and Gerald Matzka. Using XML/XSL to build
adaptable database interfaces for Web site content management. XML in
Software Engineering Workshop (XSE 2001), 23rd International
Conference on Software Engineering (May 2001, Toronto, Ontario,
Canada), May 2001.
|
|
Engin Kirda. Web Engineering Device Independent Web Services. 23rd
International Conference on Software Engineering, Doctoral Symposium
(Toronto, Canada). IEEE Computer Society Press, May 2001.
|
|
Engin Kirda and Clemens Kerer. MyXML: An XML based template engine
for the generation of flexible web content. Proceedings of WEBNET 2000 (San Antonio,
Texas, USA), pages 317-322, November 2000.
|
|
Clemens Kerer and Engin Kirda. Layout, Content and Logic Separation
in Web Engineering. 9th International World Wide Web Conference, 3rd
Web Engineering Workshop (Amsterdam, 15-16 May 2000). Lecture Notes in
Computer Science Series, 2016, Springer Verlag, May 2000.
|
|
Journal (Security)
|
Patrick Klinkoff, Engin Kirda, Christopher Kruegel, and Giovanni Vigna, Extending .NET Security to Unmanaged Code (Special Issue on the Best of ISC 2007 papers, extended version), International Journal of Information Security, Springer Verlag, Volume 4176/2006
[
download
]
|
Ulrich Bayer, Andreas Moser, Christopher Kruegel, and Engin Kirda, Dynamic Analysis of Malicious Code, Journal in Computer Virology, Springer Computer Science
[
download
]
|
Engin Kirda and Christopher Kruegel, Protecting Users against Phishing Attacks (Best of COMPSAC 2005), The Computer Journal, Oxford University Press
[
download
]
|
|
Journal (Education)
|
|
Clemens Kerer, Gerald Reif, Thomas Gschwind, Engin Kirda, Roman
Kurmanowytsch and Marek Pralic, ShareMe: Running A Distributed Systems
Lab For 600 Students With 3 Faculty Members, IEEE Transactions on
Education, vol: 48, no: 3, pp. 430-437, August 2005
|
|
Journal (Software Engineering)
|
|
Engin Kirda and Harald Gall, A Service Architecture for Mobile
Teamwork, (Best of SEKE 2002), International Journal on Software
Engineering and Knowledge Engineering, World Scientific Publishing Company, August 2003.
|
|
Clemens Kerer, Engin Kirda and Roman
Kurmanowytsch, A Generic Content Management Tool for Web Databases,
IEEE Internet Computing, August 2002
|
|
Engin Kirda, Mehdi Jazayeri, Clemens Kerer, and Markus
Schranz. Experiences in Engineering Flexible Web Services. IEEE
Multimedia, Jannuary - March 2001.
|
|
Editorships
|
|
Richard Lippmann, Engin Kirda, Ari Trachtenberg, (eds), Proceedings of the 11th International Symposium on Recent Advances in Intrusion Detection, Volume 5230/2008, ISBN 978-3-540-87402-7, September 2008
|
|
Working seminar proceedings
|
|
Lothar Braun, Falko Dressler, Thorsten Holz, Engin Kirda, Jan Kohlrausch, Christopher Kruegel, Tobias Limmer, Konrad Rieck, James P. G. Sterbenz: 08102 Working Group -- Requirements for Network Monitoring from an IDS Perspective, Dagstuhlseminar Proceedings, Network Attack Detection and Defense 2008
|
|
Marc Dacier, Herve Debar, Thorsten Holz, Engin Kirda, Jan Kohlrausch, Christopher Kruegel, Konrad Rieck, James P. G. Sterbenz: 8102 Working Group -- Attack Taxonomy, Dagstuhlseminar Proceedings, Network Attack Detection and Defense 2008
|
Teaching
|
Internet Security (SS)
|
|
Advanced Topics in Security / Advanced Internet Security [also known as Internet Security 2] (WS)
|
|
Bakkalaureatsarbeiten
|
|
Praktika
|
|
Master's Theses
|
|
PhD Theses
|
|
Previous teaching:
|
|
Distributed Systems (WS)
|
|
Current Ph.D. students:
|
|
Ulrich Bayer
|
|
Leyla Bilge
|
|
Manuel Egele
|
|
Christoph Karlberger
|
|
Clemens Kolbitsch
|
|
Martin Szydlowski
|
|
Gilbert Wondracek
|
|
Peter Wurzinger
|
|
Former Ph.D. students:
|
|
Nenad Jovanovic
|
|
Current master's students:
|
|
Sylvester Keil, Topic: "Environment Emulation"
|
|
Stefan Mitterhofer, Topic: "Online Gaming Security"
|
|
Thomas Raffetseder, Topic: "Browser Security"
|
|
Former master's students:
|
|
Christian Ludl, "SWAP: A proxy-based solution for mitigating XSS attacks", 2008
|
|
Sean McAllister, "Increasing the coverage of Web Application Vulnerability Scanners", 2008
|
|
Clemens Kolbitsch, "Extending Mondrian Memory Protection", 2008
|
|
Andreas Stamminger, "Automated Spyware Collection and Analysis", 2007
|
|
Florian Nentwich, "Sicherheitsanalyse von Signatursoftware", 2007
|
|
Guenther Bayler, "Penetrating Bayesian Spam Filters Using
Redundancy in Natural Language", 2007
|
|
Martin Szydlowski, "Secure Input for Web Applications", 2007
|
|
Helmut Petritsch, "Understanding and Replaying Network Traffic in Windows XP for Malware Analysis", 2007
|
|
Manuel Egele, "Behavior-Based Spyware Detection Using Dynamic Taint Analysis", 2006
|
|
David Tischler, "WSFW: An Open Source Web Service Firewall", 2006
|
|
Philipp Vogt, "Cross Site Scripting (XSS) Attack Prevention with Dynamic Data Tainting on the Client Side", 2006
|
|
Stefan Kals, "Secubat: A Web Vulnerability Scanner", 2006
|
|
Viktor Moser, "Foxy: A proxy for mobile web access", 2006
|
|
Ullrich Bayer, "TTAnalyze: A Tool for Analyzing Malware", 2005
|
|
Patrick Klinkoff, "Extending .NET Security to Native Code", 2005
|
|
David Saez Palacios, "Survey on Techniques and Software for the Remote Security Analysis of Computer Systems", 2004.
|
|
Lorenz Froihofer, "A Survey of WLAN Security with Focus on HotSpot and Enterprise Environments", 2004 (Awarded the 2004 Best Computer Science Master's Thesis Award of the Vienna City).
|
Recent Professional Activities
|
Program Committee Memberships
|
|
PC Chair, Recent Advances in Intrusion Detection (RAID) 2009
|
|
Network and IT Security Conference (NDSS) 2009, San Diego, CA, February 2009
|
|
4th International CRIS Conference on Critical Infrastructures, Linkoeping, Sweden, April, 2009
|
|
European Workshop on System Security (EUROSEC) 2009
|
|
Network and IT Security Conference (NDSS) 2008, San Diego, CA, February 2008
|
|
4th International Conference on Information Systems Security (ICISS 2008), Hyderabad, India, December 2008.
|
|
4th European Conference on Computer Network Defense (EC2ND), Dublin, December 2008.
|
|
1st Workshop on Open Source Software for Computer and Network Forensics (OSSCoNF), Milan, September 2008
|
|
PC Co-Chair, Recent Advances in Intrusion Detection (RAID) 2008, Boston, September 2008
|
|
10th International Conference on Information and Communications Security (ICICS 2008), Prague, July 2008
|
|
The 5th International Conference on Autonomic and Trusted Computing, Oslo, June 2008
|
|
27th IEEE Symposium on Reliable Distributed Systems (SRDS-27), Napoli, October 2008
|
|
EUROSEC Workshop, Annual ACM SIGOPS EuroSys Conference, Glasgow, Marc 2008
|
|
The 4th International Workshop on Software Engineering for Secure Systems (SESS'08), 29th International Conference on Software Engineering (ICSE), Leipzig, May 2008
|
|
SecureComm 2008, Istanbul, Turkey, September 2008
|
|
Network and IT Security Conference (NDSS) 2007, San Diego, CA, February 2007
|
|
Ninth International Conference on Information and Communications Security (ICICS 2007)
|
|
5th Workshop on Recurring Malcode (WORM), 14th ACM Conference on Computer and Communications Security
(CCS), Alexandria, VA, October 2007
|
|
The 3rd International Workshop on Software Engineering for Secure Systems (SESS07), 29th International Conference on Software Engineering (ICSE), May 2007
|
|
Detection of Intrusions and Malware and Vulnerability Assessment Working Conference (DIMVA 2006), Berlin, Germany, June 2006
|
|
The 4th International Workshop on Ubiquitous Mobile Information and
Communication Systems (UMICS), Luxembourg, June 2006
|
|
International Conference on Communications and Networking in China, CHINACOM 2006, October 2006
|
|
Security and Privacy in Computing Systems Conference (SPCS2006), May 2006
|
|
4th International Workshop on Distributed and Mobile Collaboration (DMC 2006), WETICE-2006, Manchester, UK, June 2006
|
|
ICIW 2006 - IEEE International Conference on IP and Web Applications (ICIW'06), Guadeloupe, French Caribbean, February 2006
|
|
Detection of Intrusions and Malware and Vulnerability Assessment Working Conference (DIMVA 2005), Vienna, Austria, June 2005
|
|
Workshop on Distributed and Mobile Collaboration, IEEE 14th
International Workshops on Enabling Technologies Infrastructure for
Collaborative Enterprises (WETICE 2005), Linkoping, Sweden, June
2005
|
|
Workshop on Evaluation of Collaborative Information Systems and
Support for Virtual Enterprises, IEEE 14th International Workshops
on Enabling Technologies Infrastructure for Collaborative
Enterprises (WETICE 2005), Linkoping, Sweden, June 2005
|
|
Fault-Tolerant and Dependable Distributed Systems Minitrack of
the Software Technology Track 38th IEEE Hawaii International
Conference on System Sciences, Hawaii, USA, 2004
|
|
TECOS 2004 - Testing Component-based Systems Workshop, Net.ObjectDays 2004
|
|
3rd Workshop on Cooperative Support for Distributed Software Engineering Processes (CSSE), 19th Automated Software Engineering Conference (ASE), Linz, Austria, September 2004
|
|
Second International Workshop on Web Based Systems and
Applications, The 28th Annual International Computer Software and
Applications Conference (COMPSAC), Hong Kong, China, September
2004
|
|
Workshop on Evaluation of Collaborative Information Systems, IEEE
13th International Workshops on Enabling
Technologies Infrastructure for Collaborative Enterprises (WETICE
2003), Modena, Italy, June 2004
|
|
Workshop on Distributed Mobile Collaboration (DMC), IEEE
13th International Workshops on Enabling
Technologies Infrastructure for Collaborative Enterprises (WETICE
2003), Modena, Italy, June 2004
|
|
Workshop on Evaluation of Collaborative Information Systems and Support for Virtual Enterprises, IEEE 12th International Workshops on Enabling
Technologies Infrastructure for Collaborative Enterprises (WETICE
2003), Linz, Austria, June 2003
|
|
International Workshop on Distributed and Mobile Collaboration (DMC
2003), IEEE 12th International Workshops on Enabling Technologies
Infrastructure for Collaborative Enterprises (WETICE 2003) , Linz,
Austria, June 2003
|
|
2nd Workshop on Cooperative Supports for Distributed Software
Engineering Processes, 7th European Conference on Software
Maintenance and Reengineering, Benevento, Italy, March 2003
|
Mobile Teamwork Support (Mobile Teams 2002) Workshop, 22nd
International Conference on Distributed Computing Systems (ICDCS),
July 2002, Vienna, Austria
|
|
Conference organization
|
|
Detection of Intrusions and Malware and Vulnerability Assessment (DIMVA 2005) Working Conference
|
|
Reviewer (Journals)
|
|
Computer Networks
|
|
The Oxford Computer Journal
|
|
International Journal of Information Security
|
|
IEEE Transactions and Dependable and Secure Computing
|
|
IEEE Transactions on Knowledge and Data Engineering
|
|
Journal of Computer Security
|
|
IEEE Computer
|
|
IEEE Transactions on Education
|
|
IEEE Internet Computing
|
|
IEEE Transactions on Information Forensics and Security
|
|
IEEE Security and Privacy
|
|
IEEE Transactions on Systems, Man, and Cybernetics Part B
|
|
IEEE Software
|
|
International Journal of Internet Protocol Technology (IJIPT)
|
|
Multimedia Tools and Applications Journal, Kluwer Academic Publishers
|
|
Reviewer (Conferences)
|
|
17th Word Wide Web Conference, Beijing, China, May 2008
|
|
ACM Conference on Computer and Communications Security (CCS) 2007, Alexandria, VA, November 2007
|
|
ESORICS 2007, Dresden, Germany, September 2007
|
|
4th International Conference on Detection of Intrusions and Malware, and Vulnerability Assessment (DIMVA), Lucerne, Switzerland, July 2007
|
|
7th International Conference on Web Engineering (ICWE), Como, Italy, July 2007
|
|
Programming Language Design and Implementation (PLDI), San Diego, CA, June 2007
|
|
Annual Computer Security Applications Conference (ACSAC) 2006, Miami, Florida, USA
|
|
The 8th IEEE Conference on E-Commerce Technology (CEC' 06)
|
|
The 3rd IEEE Conference on Enterprise Computing, E-Commerce and E-Services (EEE' 06)
|
|
FASE (Fundamental Approaches to Software Engineering) 2006 Conference, Vienna, Austria
|
|
ICSE 2006 (International Conference on Software Engineering), Shanghai, China
|
|
ICDE 2006 (22nd International Conference on Data Engineering), Atlanta, Georgia
|
|
RAID 2005 (8th International Symposium on Recent Advances in Intrusion Detection), Seattle, Washington
|
|
FASE (Fundamental Approaches to Software Engineering) 2005 Conference, Edinburgh, Scotland
|
|
CONTEL 2005 Conference
|
|
Pervasive 2004 Conference
|
Experience (i.e., Code Hacks)
|
Languages used: Java, C#, C, C++, Pascal, Modula, Basic, Assembler, Perl, SQL, Prolog, XSLT, PHP, Python
|
|
Database technologies used: MySQL, Postgres, Oracle and Oracle Pro*C/C++, JDBC, ODBC
|
|
Operating Systems used: Windows (3.x, 95, 98, NT, XP, 2000, CE), OS/2, UNIX (Linux, Solaris, HP UNIX, Mac OS), DOS
|
|
Distributed programming done with: RMI, SUN RPC, CORBA, ISIS, Web Services
|
Last Modified:
29. 10. 2008, 22:57:38
|
|
|