[{"user_id":"63563","ddc":["006"],"main_file_link":[{"url":"https://www.petsymposium.org/foci/2026/foci-2026-0001.pdf","open_access":"1"}],"language":[{"iso":"eng"}],"_id":"64566","date_updated":"2026-02-21T10:20:16Z","has_accepted_license":"1","status":"public","year":"2026","title":"Towards Automated DNS Censorship Circumvention","author":[{"id":"67893","full_name":"Lange, Felix","first_name":"Felix","last_name":"Lange"},{"id":"63563","full_name":"Niere, Niklas","last_name":"Niere","first_name":"Niklas"},{"last_name":"Somorovsky","first_name":"Juraj","orcid":"0000-0002-3593-7720","full_name":"Somorovsky, Juraj","id":"83504"}],"conference":{"location":"Virtual","start_date":"2026-02-19","name":"Free and Open Communications on the Internet","end_date":"2026-02-19"},"type":"conference","oa":"1","file":[{"creator":"nniklas","date_created":"2026-02-20T14:34:05Z","file_name":"foci-2026-0001.pdf","file_size":775133,"access_level":"open_access","relation":"main_file","date_updated":"2026-02-21T10:20:16Z","file_id":"64568","content_type":"application/pdf"}],"date_created":"2026-02-20T14:35:34Z","abstract":[{"text":"Censorship is employed by many governments and ISPs worldwide, with an increasing trend in recent years. One of the most censored protocols is DNS: censors target unencrypted and encrypted DNS to prevent clients from resolving the domain name of unwanted websites. Despite much research on DNS censorship, only a few tools can circumvent it.To support users affected by DNS censorship, we present DPYProxy-DNS, a DNS resolver that automatically detects and employs a working DNS censorship circumvention. We demonstrate the effectiveness of DPYProxy-DNS by automatically circumventing DNS censorship in China and Iran and analyzing DNS censorship mechanisms in these countries. Our analyses re veal that DNS censorship in Iran is ineffective against encrypted DNS. In China, DPYProxy-DNS revealed two consistently working circumvention techniques for unencrypted DNS: TCP segmentation for DNS over TCP and ignoring DNS responses injected by the Great Firewall of China (GFW). Our findings reveal varying levels of DNS censorship across different countries, underscoring the importance of the automated circumvention approach we provide with DPYProxy-DNS.","lang":"eng"}],"file_date_updated":"2026-02-21T10:20:16Z","citation":{"ama":"Lange F, Niere N, Somorovsky J. Towards Automated DNS Censorship Circumvention. In: ; 2026.","short":"F. Lange, N. Niere, J. Somorovsky, in: 2026.","chicago":"Lange, Felix, Niklas Niere, and Juraj Somorovsky. “Towards Automated DNS Censorship Circumvention,” 2026.","bibtex":"@inproceedings{Lange_Niere_Somorovsky_2026, title={Towards Automated DNS Censorship Circumvention}, author={Lange, Felix and Niere, Niklas and Somorovsky, Juraj}, year={2026} }","apa":"Lange, F., Niere, N., &#38; Somorovsky, J. (2026). <i>Towards Automated DNS Censorship Circumvention</i>. Free and Open Communications on the Internet, Virtual.","mla":"Lange, Felix, et al. <i>Towards Automated DNS Censorship Circumvention</i>. 2026.","ieee":"F. Lange, N. Niere, and J. Somorovsky, “Towards Automated DNS Censorship Circumvention,” presented at the Free and Open Communications on the Internet, Virtual, 2026."}},{"has_accepted_license":"1","date_updated":"2026-07-05T20:11:03Z","author":[{"first_name":"Anonymous","last_name":"Anonymous","full_name":"Anonymous, Anonymous"},{"id":"63563","first_name":"Niklas","last_name":"Niere","full_name":"Niere, Niklas"},{"last_name":"Graf Lange","first_name":"Felix","full_name":"Graf Lange, Felix","id":"67893"},{"full_name":"Somorovsky, Juraj","first_name":"Juraj","last_name":"Somorovsky","orcid":"0000-0002-3593-7720","id":"83504"}],"conference":{"location":"Calgary","start_date":"2026-07-20","name":"Free and Open Communications on the Internet","end_date":"2026-07-24"},"status":"public","title":"Insights into an Iranian Internet Shutdown","year":"2026","user_id":"63563","ddc":["006"],"language":[{"iso":"eng"}],"_id":"66270","main_file_link":[{"open_access":"1","url":"https://www.petsymposium.org/foci/2026/foci-2026-0016.pdf"}],"abstract":[{"lang":"eng","text":"In June 2025, Iran enacted a nationwide Internet shutdown, culminating its already strict censorship apparatus. While Internet shutdowns happen regularly, insights into these shutdowns are notoriously difficult to obtain: their timing is hard to predict, and measurements are often impossible. In this paper, we present unique measurements surrounding Iran’s 2025 Internet shutdown in June, which we acquired during a regular analysis of Iran’s censorship apparatus. We contextualize our findings of Iranian DNS, HTTP, TLS, and QUIC censorship during the shutdown with measurements from platforms such as Cloudflare Radar and user reports. Our measurements show that Iranian censorship changed before and after the shutdown, marking preparation and recovery periods. For instance, QUIC censorship went into effect before and stayed in effect after the shutdown, while DNS over TCP censorship was only present briefly before the shutdown and resumed working afterwards. We also measured general network instabilities, especially for UDP, after the shutdown and the disabling of certain middleboxes. Our findings indicate that the Iranian censor enforced its shutdown using fine-grained techniques instead of relying on an all-or-nothing blackout. We advertise for continued measurements of the Iranian censor and hypothesize that future shutdowns in censoring countries could be detected during their preparation phase."}],"citation":{"ieee":"A. Anonymous, N. Niere, F. Graf Lange, and J. Somorovsky, “Insights into an Iranian Internet Shutdown,” presented at the Free and Open Communications on the Internet, Calgary, 2026.","apa":"Anonymous, A., Niere, N., Graf Lange, F., &#38; Somorovsky, J. (2026). <i>Insights into an Iranian Internet Shutdown</i>. Free and Open Communications on the Internet, Calgary.","short":"A. Anonymous, N. Niere, F. Graf Lange, J. Somorovsky, in: 2026.","chicago":"Anonymous, Anonymous, Niklas Niere, Felix Graf Lange, and Juraj Somorovsky. “Insights into an Iranian Internet Shutdown,” 2026.","mla":"Anonymous, Anonymous, et al. <i>Insights into an Iranian Internet Shutdown</i>. 2026.","bibtex":"@inproceedings{Anonymous_Niere_Graf Lange_Somorovsky_2026, title={Insights into an Iranian Internet Shutdown}, author={Anonymous, Anonymous and Niere, Niklas and Graf Lange, Felix and Somorovsky, Juraj}, year={2026} }","ama":"Anonymous A, Niere N, Graf Lange F, Somorovsky J. Insights into an Iranian Internet Shutdown. In: ; 2026."},"file_date_updated":"2026-07-05T20:08:45Z","oa":"1","type":"conference","date_created":"2026-07-05T20:10:58Z","file":[{"date_created":"2026-07-05T20:08:45Z","creator":"nniklas","content_type":"application/pdf","success":1,"file_id":"66271","access_level":"closed","file_size":539622,"file_name":"foci-2026-0016.pdf","date_updated":"2026-07-05T20:08:45Z","relation":"main_file"}]},{"abstract":[{"lang":"eng","text":"In September 2025, over 100K internal documents (including code, communications, etc.) from Geedge Networks, a Chinese DPI company with ties to the Great Firewall of China, were leaked to the public. In this paper, we analyze the source code from this leak, focusing on Geedge Networks’ flagship product, the Tiangou Secure Gateway (TSG) firewall. Working across multiple repositories, we successfully build and run a local copy of TSG—revealing key aspects of its architecture, including the protocols it is capable of parsing and the format of blocking rules used to censor sites, proxies, and other resources. Finally, we extract several fingerprints from TSG, including custom random number generators and parsing idiosyncrasies that allow us to identify its use and similar deployments in the Great Firewall of China. This is the first time that the source code of a commercial DPI has been leaked, and our work is the first code analysis of a core firewall component used in national censorship infrastructure. This unprecedented investigation offers insights that can assist circumvention developers and Internet security researchers in further understanding the capabilities and limitations of modern censorship technology."}],"file":[{"date_created":"2026-08-17T07:31:02Z","creator":"nniklas","file_id":"66727","content_type":"application/pdf","file_name":"usenixsecurity26-ablove.pdf","access_level":"local","file_size":1838094,"relation":"main_file","date_updated":"2026-08-17T07:39:32Z"}],"date_created":"2026-08-17T07:33:15Z","type":"conference","year":"2026","title":"Technical Analysis of the Geedge Networks Firewall Source Code Leak","author":[{"last_name":"Ablove","first_name":"Anna","full_name":"Ablove, Anna"},{"full_name":"Walker, Johnnie","last_name":"Walker","first_name":"Johnnie"},{"last_name":"Wolin","first_name":"Ben","full_name":"Wolin, Ben"},{"first_name":"Niklas","last_name":"Niere","full_name":"Niere, Niklas","id":"63563"},{"first_name":"Felix","last_name":"Graf Lange","full_name":"Graf Lange, Felix","id":"67893"},{"full_name":"Ortwein, Aaron","first_name":"Aaron","last_name":"Ortwein"},{"full_name":"Huremagic, Armin","last_name":"Huremagic","first_name":"Armin"},{"full_name":"Priyanka, Richa","first_name":"Richa","last_name":"Priyanka"},{"full_name":"Zohaib, Ali","last_name":"Zohaib","first_name":"Ali"},{"first_name":"Jade","last_name":"Sheffey","full_name":"Sheffey, Jade"},{"full_name":"Heitmann, Nico","last_name":"Heitmann","orcid":"0009-0003-7687-7044","first_name":"Nico","id":"74619"},{"last_name":"Halderman","first_name":"J. Alex","full_name":"Halderman, J. Alex"},{"full_name":"Somorovsky, Juraj","last_name":"Somorovsky","first_name":"Juraj","orcid":"0000-0002-3593-7720","id":"83504"},{"full_name":"Houmansadr, Amir","first_name":"Amir","last_name":"Houmansadr"},{"full_name":"Ensafi, Roya","first_name":"Roya","last_name":"Ensafi"},{"full_name":"Wu, Mingshi","first_name":"Mingshi","last_name":"Wu"},{"first_name":"Eric","last_name":"Wustrow","full_name":"Wustrow, Eric"}],"publication_identifier":{"isbn":["978-1-939133-58-8"]},"date_updated":"2026-08-17T07:39:32Z","publication_status":"published","main_file_link":[{"open_access":"1","url":"https://www.usenix.org/system/files/usenixsecurity26-ablove.pdf"}],"language":[{"iso":"eng"}],"file_date_updated":"2026-08-17T07:39:32Z","citation":{"chicago":"Ablove, Anna, Johnnie Walker, Ben Wolin, Niklas Niere, Felix Graf Lange, Aaron Ortwein, Armin Huremagic, et al. “Technical Analysis of the Geedge Networks Firewall Source Code Leak,” 2026.","short":"A. Ablove, J. Walker, B. Wolin, N. Niere, F. Graf Lange, A. Ortwein, A. Huremagic, R. Priyanka, A. Zohaib, J. Sheffey, N. Heitmann, J.A. Halderman, J. Somorovsky, A. Houmansadr, R. Ensafi, M. Wu, E. Wustrow, in: 2026.","ieee":"A. Ablove <i>et al.</i>, “Technical Analysis of the Geedge Networks Firewall Source Code Leak,” presented at the 35th USENIX Security Symposium, Baltimore, 2026.","apa":"Ablove, A., Walker, J., Wolin, B., Niere, N., Graf Lange, F., Ortwein, A., Huremagic, A., Priyanka, R., Zohaib, A., Sheffey, J., Heitmann, N., Halderman, J. A., Somorovsky, J., Houmansadr, A., Ensafi, R., Wu, M., &#38; Wustrow, E. (2026). <i>Technical Analysis of the Geedge Networks Firewall Source Code Leak</i>. 35th USENIX Security Symposium, Baltimore.","bibtex":"@inproceedings{Ablove_Walker_Wolin_Niere_Graf Lange_Ortwein_Huremagic_Priyanka_Zohaib_Sheffey_et al._2026, title={Technical Analysis of the Geedge Networks Firewall Source Code Leak}, author={Ablove, Anna and Walker, Johnnie and Wolin, Ben and Niere, Niklas and Graf Lange, Felix and Ortwein, Aaron and Huremagic, Armin and Priyanka, Richa and Zohaib, Ali and Sheffey, Jade and et al.}, year={2026} }","ama":"Ablove A, Walker J, Wolin B, et al. Technical Analysis of the Geedge Networks Firewall Source Code Leak. In: ; 2026.","mla":"Ablove, Anna, et al. <i>Technical Analysis of the Geedge Networks Firewall Source Code Leak</i>. 2026."},"oa":"1","status":"public","conference":{"start_date":"2026-08-12","name":"35th USENIX Security Symposium","location":"Baltimore","end_date":"2026-08-14"},"has_accepted_license":"1","_id":"66726","ddc":["006"],"user_id":"63563"},{"oa":"1","type":"conference","date_created":"2026-07-05T20:06:35Z","file":[{"creator":"nniklas","date_created":"2026-07-05T20:04:24Z","file_name":"foci-2026-0010.pdf","access_level":"local","file_size":559028,"relation":"main_file","date_updated":"2026-08-17T07:40:14Z","file_id":"66269","content_type":"application/pdf"}],"abstract":[{"text":"Governments around the world limit free access to information through Internet censorship. With the rising adoption of the QUIC protocol, these censors have been forced to evolve their systems. Russia introduced sweeping changes to its censorship after its full-scale invasion of Ukraine, including completely blocking international QUIC connections. However, after this broad filter was identified in 2022, Russian QUIC censorship received little attention: The current state of QUIC censorship by TSPU devices is largely unknown. In this paper, we provide a timeline of Russian QUIC censorship and detail its current state. We identify that Russian TSPU devices switched to SNI-dependent QUIC censorship on a large scale between May 2022 and July 2023, a fact that went largely unnoticed for three years. While the GFW was previously thought to be the first censor with broad SNI-dependent QUIC censorship, we highlight that Russian TSPU devices broadly adopted SNI-dependent QUIC censorship at least nine months before the GFW. We consider this an indicator of the TSPU devices’ flexibility and of Russia’s willingness to invest in strict and up-to-date censorship.","lang":"eng"}],"citation":{"mla":"Heitmann, Nico, et al. <i>On Russia’s Early Introduction of QUIC SNI Censorship</i>. 2026.","ama":"Heitmann N, Niere N, Graf Lange F, Somorovsky J. On Russia’s Early Introduction of QUIC SNI Censorship. In: ; 2026.","bibtex":"@inproceedings{Heitmann_Niere_Graf Lange_Somorovsky_2026, title={On Russia’s Early Introduction of QUIC SNI Censorship}, author={Heitmann, Nico and Niere, Niklas and Graf Lange, Felix and Somorovsky, Juraj}, year={2026} }","apa":"Heitmann, N., Niere, N., Graf Lange, F., &#38; Somorovsky, J. (2026). <i>On Russia’s Early Introduction of QUIC SNI Censorship</i>. Free and Open Communications on the Internet, Calgary.","ieee":"N. Heitmann, N. Niere, F. Graf Lange, and J. Somorovsky, “On Russia’s Early Introduction of QUIC SNI Censorship,” presented at the Free and Open Communications on the Internet, Calgary, 2026.","short":"N. Heitmann, N. Niere, F. Graf Lange, J. Somorovsky, in: 2026.","chicago":"Heitmann, Nico, Niklas Niere, Felix Graf Lange, and Juraj Somorovsky. “On Russia’s Early Introduction of QUIC SNI Censorship,” 2026."},"file_date_updated":"2026-08-17T07:40:14Z","user_id":"63563","ddc":["006"],"_id":"66268","language":[{"iso":"eng"}],"main_file_link":[{"open_access":"1","url":"https://www.petsymposium.org/foci/2026/foci-2026-0010.pdf"}],"has_accepted_license":"1","date_updated":"2026-08-17T07:40:14Z","author":[{"id":"74619","full_name":"Heitmann, Nico","first_name":"Nico","orcid":"0009-0003-7687-7044","last_name":"Heitmann"},{"first_name":"Niklas","last_name":"Niere","full_name":"Niere, Niklas","id":"63563"},{"id":"67893","full_name":"Graf Lange, Felix","last_name":"Graf Lange","first_name":"Felix"},{"full_name":"Somorovsky, Juraj","orcid":"0000-0002-3593-7720","first_name":"Juraj","last_name":"Somorovsky","id":"83504"}],"conference":{"end_date":"2026-07-20","start_date":"2026-07-20","name":"Free and Open Communications on the Internet","location":"Calgary"},"year":"2026","status":"public","title":"On Russia’s Early Introduction of QUIC SNI Censorship"},{"doi":"10.1109/SP61157.2025.00151","language":[{"iso":"eng"}],"date_updated":"2025-06-02T12:03:51Z","author":[{"full_name":"Niere, Niklas","last_name":"Niere","first_name":"Niklas","id":"63563"},{"full_name":"Lange, Felix","last_name":"Lange","first_name":"Felix","id":"67893"},{"last_name":"Merget","first_name":"Robert","full_name":"Merget, Robert"},{"full_name":"Somorovsky, Juraj","last_name":"Somorovsky","first_name":"Juraj","orcid":"0000-0002-3593-7720","id":"83504"}],"year":"2025","title":"Transport Layer Obscurity: Circumventing SNI Censorship on the TLS-Layer","department":[{"_id":"632"}],"type":"conference","date_created":"2025-05-06T13:40:50Z","file":[{"file_name":"TLS_Obscurity.pdf","file_size":463431,"access_level":"open_access","relation":"main_file","date_updated":"2025-05-06T13:51:45Z","file_id":"59826","content_type":"application/pdf","creator":"nniklas","date_created":"2025-05-06T13:49:35Z"}],"abstract":[{"text":"HTTPS composes large parts of today’s Internet traffic and has long been subject to censorship efforts in different countries. While censors analyze the Transport Layer Security (TLS) protocol to block encrypted HTTP traffic, censorship circumvention efforts have primarily focused on other protocols such as TCP. In this paper, we hypothesize that the TLS protocol offers previously unseen opportunities for censorship circumvention techniques. We tested our hypothesis by proposing possible censorship circumvention techniques that act on the TLS protocol. To validate the effectiveness of these techniques, we evaluate their acceptance by popular TLS servers and successfully demonstrate that these techniques can circumvent censors in China and Iran. In our evaluations, we discovered 38—partially standard-compliant—distinct censorship circumvention techniques, which we could group into 11 unique categories. Additionally, we provide novel insights into how China censors TLS traffic by presenting evidence of at least three distinct censorship appliances. We suspect that other parts of China’s censorship apparatus and other censors exhibit similar structures and advocate future censorship research to anticipate them. With this work, we hope to aid people affected by censorship and stimulate further\r\nresearch into censorship circumvention using cryptographic protocols.","lang":"eng"}],"publication":"2025 IEEE Symposium on Security and Privacy (SP)","ddc":["006"],"user_id":"63563","_id":"59824","has_accepted_license":"1","conference":{"location":"San Francisco","start_date":"2025-05-12","name":"46th IEEE Symposium on Security and Privacy","end_date":"2025-05-14"},"status":"public","oa":"1","citation":{"short":"N. Niere, F. Lange, R. Merget, J. Somorovsky, in: 2025 IEEE Symposium on Security and Privacy (SP), 2025.","chicago":"Niere, Niklas, Felix Lange, Robert Merget, and Juraj Somorovsky. “Transport Layer Obscurity: Circumventing SNI Censorship on the TLS-Layer.” In <i>2025 IEEE Symposium on Security and Privacy (SP)</i>, 2025. <a href=\"https://doi.org/10.1109/SP61157.2025.00151\">https://doi.org/10.1109/SP61157.2025.00151</a>.","ieee":"N. Niere, F. Lange, R. Merget, and J. Somorovsky, “Transport Layer Obscurity: Circumventing SNI Censorship on the TLS-Layer,” presented at the 46th IEEE Symposium on Security and Privacy, San Francisco, 2025, doi: <a href=\"https://doi.org/10.1109/SP61157.2025.00151\">10.1109/SP61157.2025.00151</a>.","apa":"Niere, N., Lange, F., Merget, R., &#38; Somorovsky, J. (2025). Transport Layer Obscurity: Circumventing SNI Censorship on the TLS-Layer. <i>2025 IEEE Symposium on Security and Privacy (SP)</i>. 46th IEEE Symposium on Security and Privacy, San Francisco. <a href=\"https://doi.org/10.1109/SP61157.2025.00151\">https://doi.org/10.1109/SP61157.2025.00151</a>","bibtex":"@inproceedings{Niere_Lange_Merget_Somorovsky_2025, title={Transport Layer Obscurity: Circumventing SNI Censorship on the TLS-Layer}, DOI={<a href=\"https://doi.org/10.1109/SP61157.2025.00151\">10.1109/SP61157.2025.00151</a>}, booktitle={2025 IEEE Symposium on Security and Privacy (SP)}, author={Niere, Niklas and Lange, Felix and Merget, Robert and Somorovsky, Juraj}, year={2025} }","ama":"Niere N, Lange F, Merget R, Somorovsky J. Transport Layer Obscurity: Circumventing SNI Censorship on the TLS-Layer. In: <i>2025 IEEE Symposium on Security and Privacy (SP)</i>. ; 2025. doi:<a href=\"https://doi.org/10.1109/SP61157.2025.00151\">10.1109/SP61157.2025.00151</a>","mla":"Niere, Niklas, et al. “Transport Layer Obscurity: Circumventing SNI Censorship on the TLS-Layer.” <i>2025 IEEE Symposium on Security and Privacy (SP)</i>, 2025, doi:<a href=\"https://doi.org/10.1109/SP61157.2025.00151\">10.1109/SP61157.2025.00151</a>."},"file_date_updated":"2025-05-06T13:51:45Z"},{"author":[{"full_name":"Hebrok, Sven Niclas","orcid":"0009-0006-1172-1665","first_name":"Sven Niclas","last_name":"Hebrok","id":"55616"},{"last_name":"Storm","orcid":"0009-0001-2681-1624","first_name":"Tim Leonhard","full_name":"Storm, Tim Leonhard","id":"74914"},{"first_name":"Felix Matthias","last_name":"Cramer","full_name":"Cramer, Felix Matthias"},{"full_name":"Radoy, Maximilian Manfred","orcid":"0009-0005-3059-6823","first_name":"Maximilian Manfred","last_name":"Radoy","id":"68826"},{"orcid":"0000-0002-3593-7720","first_name":"Juraj","last_name":"Somorovsky","full_name":"Somorovsky, Juraj","id":"83504"}],"status":"public","year":"2025","title":"STEK Sharing is Not Caring: Bypassing TLS Authentication in Web Servers using Session Tickets","has_accepted_license":"1","date_updated":"2025-09-29T13:46:49Z","_id":"60970","language":[{"iso":"eng"}],"main_file_link":[{"url":"https://www.usenix.org/conference/usenixsecurity25/presentation/hebrok","open_access":"1"}],"user_id":"55616","ddc":["000"],"citation":{"apa":"Hebrok, S. N., Storm, T. L., Cramer, F. M., Radoy, M. M., &#38; Somorovsky, J. (2025). STEK Sharing is Not Caring: Bypassing TLS Authentication in Web Servers using Session Tickets. <i>34th USENIX Security Symposium</i>.","ieee":"S. N. Hebrok, T. L. Storm, F. M. Cramer, M. M. Radoy, and J. Somorovsky, “STEK Sharing is Not Caring: Bypassing TLS Authentication in Web Servers using Session Tickets,” 2025.","short":"S.N. Hebrok, T.L. Storm, F.M. Cramer, M.M. Radoy, J. Somorovsky, in: 34th USENIX Security Symposium, 2025.","chicago":"Hebrok, Sven Niclas, Tim Leonhard Storm, Felix Matthias Cramer, Maximilian Manfred Radoy, and Juraj Somorovsky. “STEK Sharing Is Not Caring: Bypassing TLS Authentication in Web Servers Using Session Tickets.” In <i>34th USENIX Security Symposium</i>, 2025.","mla":"Hebrok, Sven Niclas, et al. “STEK Sharing Is Not Caring: Bypassing TLS Authentication in Web Servers Using Session Tickets.” <i>34th USENIX Security Symposium</i>, 2025.","ama":"Hebrok SN, Storm TL, Cramer FM, Radoy MM, Somorovsky J. STEK Sharing is Not Caring: Bypassing TLS Authentication in Web Servers using Session Tickets. In: <i>34th USENIX Security Symposium</i>. ; 2025.","bibtex":"@inproceedings{Hebrok_Storm_Cramer_Radoy_Somorovsky_2025, title={STEK Sharing is Not Caring: Bypassing TLS Authentication in Web Servers using Session Tickets}, booktitle={34th USENIX Security Symposium}, author={Hebrok, Sven Niclas and Storm, Tim Leonhard and Cramer, Felix Matthias and Radoy, Maximilian Manfred and Somorovsky, Juraj}, year={2025} }"},"file_date_updated":"2025-09-29T13:46:49Z","publication":"34th USENIX Security Symposium","date_created":"2025-08-21T13:43:47Z","file":[{"access_level":"open_access","file_size":333869,"file_name":"paper.pdf","date_updated":"2025-09-29T13:46:49Z","relation":"main_file","content_type":"application/pdf","file_id":"61465","creator":"snhebrok","date_created":"2025-09-29T13:41:18Z"},{"date_created":"2025-09-29T13:41:27Z","creator":"snhebrok","file_id":"61466","content_type":"application/pdf","relation":"supplementary_material","date_updated":"2025-09-29T13:46:49Z","file_name":"ae.pdf","file_size":162464,"access_level":"open_access"},{"relation":"poster","date_updated":"2025-09-29T13:46:49Z","file_name":"poster.pdf","access_level":"open_access","file_size":535577,"file_id":"61467","content_type":"application/pdf","creator":"snhebrok","date_created":"2025-09-29T13:41:41Z"},{"creator":"snhebrok","date_created":"2025-09-29T13:42:04Z","access_level":"open_access","file_size":3057223,"file_name":"slides.pdf","date_updated":"2025-09-29T13:46:49Z","relation":"slides","content_type":"application/pdf","file_id":"61468"}],"department":[{"_id":"632"}],"oa":"1","type":"conference"},{"date_created":"2025-12-02T08:48:00Z","oa":"1","keyword":["software vulnerabilities","vulnerability disclosure","security research"],"type":"conference","citation":{"chicago":"Sri Ramulu, Harshini, Anna Lena Rotthaler, Jost Rossel, Rachel Gonzalez Rodriguez, Dominik Wermke, Sascha Fahl, Tadayoshi Kohno, Juraj Somorovsky, and Yasemin Acar. “Poster: Computer Security Researchers’ Experiences with Vulnerability Disclosures.” In <i>Proceedings of the 2025 ACM SIGSAC Conference on Computer and Communications Security</i>. ACM, 2025. <a href=\"https://doi.org/10.1145/3719027.3760723\">https://doi.org/10.1145/3719027.3760723</a>.","short":"H. Sri Ramulu, A.L. Rotthaler, J. Rossel, R. Gonzalez Rodriguez, D. Wermke, S. Fahl, T. Kohno, J. Somorovsky, Y. Acar, in: Proceedings of the 2025 ACM SIGSAC Conference on Computer and Communications Security, ACM, 2025.","apa":"Sri Ramulu, H., Rotthaler, A. L., Rossel, J., Gonzalez Rodriguez, R., Wermke, D., Fahl, S., Kohno, T., Somorovsky, J., &#38; Acar, Y. (2025). Poster: Computer Security Researchers’ Experiences with Vulnerability Disclosures. <i>Proceedings of the 2025 ACM SIGSAC Conference on Computer and Communications Security</i>. <a href=\"https://doi.org/10.1145/3719027.3760723\">https://doi.org/10.1145/3719027.3760723</a>","ieee":"H. Sri Ramulu <i>et al.</i>, “Poster: Computer Security Researchers’ Experiences with Vulnerability Disclosures,” 2025, doi: <a href=\"https://doi.org/10.1145/3719027.3760723\">10.1145/3719027.3760723</a>.","ama":"Sri Ramulu H, Rotthaler AL, Rossel J, et al. Poster: Computer Security Researchers’ Experiences with Vulnerability Disclosures. In: <i>Proceedings of the 2025 ACM SIGSAC Conference on Computer and Communications Security</i>. ACM; 2025. doi:<a href=\"https://doi.org/10.1145/3719027.3760723\">10.1145/3719027.3760723</a>","bibtex":"@inproceedings{Sri Ramulu_Rotthaler_Rossel_Gonzalez Rodriguez_Wermke_Fahl_Kohno_Somorovsky_Acar_2025, title={Poster: Computer Security Researchers’ Experiences with Vulnerability Disclosures}, DOI={<a href=\"https://doi.org/10.1145/3719027.3760723\">10.1145/3719027.3760723</a>}, booktitle={Proceedings of the 2025 ACM SIGSAC Conference on Computer and Communications Security}, publisher={ACM}, author={Sri Ramulu, Harshini and Rotthaler, Anna Lena and Rossel, Jost and Gonzalez Rodriguez, Rachel and Wermke, Dominik and Fahl, Sascha and Kohno, Tadayoshi and Somorovsky, Juraj and Acar, Yasemin}, year={2025} }","mla":"Sri Ramulu, Harshini, et al. “Poster: Computer Security Researchers’ Experiences with Vulnerability Disclosures.” <i>Proceedings of the 2025 ACM SIGSAC Conference on Computer and Communications Security</i>, ACM, 2025, doi:<a href=\"https://doi.org/10.1145/3719027.3760723\">10.1145/3719027.3760723</a>."},"publication":"Proceedings of the 2025 ACM SIGSAC Conference on Computer and Communications Security","abstract":[{"text":"Vulnerability disclosures are necessary to improve the security of our digital ecosystem. However, they can also be challenging for researchers: it may be hard to find out who the affected parties even are, or how to contact them. Researchers may be ignored or face adversity when disclosing vulnerabilities. We investigate researchers' experiences with vulnerability disclosures, extract best practices, and make recommendations for researchers, institutions that employ them, industry, and regulators to enable effective vulnerability disclosures.","lang":"eng"}],"_id":"62738","language":[{"iso":"eng"}],"publisher":"ACM","main_file_link":[{"url":"https://dl.acm.org/doi/10.1145/3719027.3760723","open_access":"1"}],"user_id":"58331","doi":"10.1145/3719027.3760723","author":[{"full_name":"Sri Ramulu, Harshini","orcid":"0000-0002-0000-5843","last_name":"Sri Ramulu","first_name":"Harshini","id":"99000"},{"full_name":"Rotthaler, Anna Lena","last_name":"Rotthaler","first_name":"Anna Lena","id":"97843"},{"full_name":"Rossel, Jost","orcid":"0000-0002-3182-4059","first_name":"Jost","last_name":"Rossel","id":"58331"},{"first_name":"Rachel","last_name":"Gonzalez Rodriguez","full_name":"Gonzalez Rodriguez, Rachel"},{"full_name":"Wermke, Dominik","last_name":"Wermke","first_name":"Dominik"},{"first_name":"Sascha","last_name":"Fahl","full_name":"Fahl, Sascha"},{"full_name":"Kohno, Tadayoshi","last_name":"Kohno","first_name":"Tadayoshi"},{"id":"83504","orcid":"0000-0002-3593-7720","first_name":"Juraj","last_name":"Somorovsky","full_name":"Somorovsky, Juraj"},{"id":"94636","full_name":"Acar, Yasemin","last_name":"Acar","first_name":"Yasemin"}],"conference":{"start_date":"2025-10-13","end_date":"2025-10-17"},"status":"public","year":"2025","title":"Poster: Computer Security Researchers' Experiences with Vulnerability Disclosures","publication_status":"published","date_updated":"2025-12-02T08:54:18Z"},{"_id":"58657","page":"1867 - 1885","user_id":"58331","ddc":["000"],"conference":{"location":"Seattle, WA, USA","start_date":"2025-08-13","name":"34th USENIX Security Symposium","end_date":"2025-08-15"},"status":"public","has_accepted_license":"1","oa":"1","citation":{"apa":"Rossel, J., Mladenov, V., Wördenweber, N., &#38; Somorovsky, J. (2025). Security Implications of Malicious G-Codes in 3D Printing. <i>Proceedings of the 34th USENIX Security Symposium</i>, 1867–1885.","ieee":"J. Rossel, V. Mladenov, N. Wördenweber, and J. Somorovsky, “Security Implications of Malicious G-Codes in 3D Printing,” in <i>Proceedings of the 34th USENIX Security Symposium</i>, Seattle, WA, USA, 2025, pp. 1867–1885.","short":"J. Rossel, V. Mladenov, N. Wördenweber, J. Somorovsky, in: Proceedings of the 34th USENIX Security Symposium, 2025, pp. 1867–1885.","chicago":"Rossel, Jost, Vladislav Mladenov, Nico Wördenweber, and Juraj Somorovsky. “Security Implications of Malicious G-Codes in 3D Printing.” In <i>Proceedings of the 34th USENIX Security Symposium</i>, 1867–85, 2025.","mla":"Rossel, Jost, et al. “Security Implications of Malicious G-Codes in 3D Printing.” <i>Proceedings of the 34th USENIX Security Symposium</i>, 2025, pp. 1867–85.","ama":"Rossel J, Mladenov V, Wördenweber N, Somorovsky J. Security Implications of Malicious G-Codes in 3D Printing. In: <i>Proceedings of the 34th USENIX Security Symposium</i>. ; 2025:1867-1885.","bibtex":"@inproceedings{Rossel_Mladenov_Wördenweber_Somorovsky_2025, title={Security Implications of Malicious G-Codes in 3D Printing}, booktitle={Proceedings of the 34th USENIX Security Symposium}, author={Rossel, Jost and Mladenov, Vladislav and Wördenweber, Nico and Somorovsky, Juraj}, year={2025}, pages={1867–1885} }"},"file_date_updated":"2025-02-17T11:13:10Z","quality_controlled":"1","language":[{"iso":"eng"}],"main_file_link":[{"open_access":"1","url":"https://www.usenix.org/conference/usenixsecurity25/presentation/rossel"}],"author":[{"full_name":"Rossel, Jost","last_name":"Rossel","first_name":"Jost","orcid":"0000-0002-3182-4059","id":"58331"},{"first_name":"Vladislav","last_name":"Mladenov","full_name":"Mladenov, Vladislav"},{"first_name":"Nico","last_name":"Wördenweber","full_name":"Wördenweber, Nico"},{"id":"83504","full_name":"Somorovsky, Juraj","orcid":"0000-0002-3593-7720","last_name":"Somorovsky","first_name":"Juraj"}],"title":"Security Implications of Malicious G-Codes in 3D Printing","year":"2025","publication_status":"published","date_updated":"2025-08-22T10:34:24Z","date_created":"2025-02-17T11:12:17Z","file":[{"file_id":"58660","content_type":"application/pdf","relation":"main_file","date_updated":"2025-02-17T11:13:10Z","file_name":"Security_Analysis_of_G_Codes.pdf","access_level":"open_access","file_size":1562838,"date_created":"2025-02-17T11:10:31Z","creator":"jrossel"}],"department":[{"_id":"632"}],"type":"conference","publication":"Proceedings of the 34th USENIX Security Symposium","abstract":[{"text":"The rapid growth of 3D printing technology has transformed a wide range of industries, enabling the on-demand production of complex objects, from aerospace components to medical devices. However, this technology also introduces significant security challenges. Previous research highlighted the security implications of G-Codes—commands used to control the printing process. These studies assumed powerful attackers and focused on manipulations of the printed models, leaving gaps in understanding the full attack potential.\r\n\r\nIn this study, we systematically analyze security threats associated with 3D printing, focusing specifically on vulnerabilities caused by G-Code commands. We introduce attacks and attacker models that assume a less powerful adversary than traditionally considered, broadening the scope of potential security threats. Our findings show that even minimal access to the 3D printer can result in significant security breaches, such as unauthorized access to subsequent print jobs or persistent misconfiguration of the printer. We identify 278 potentially malicious G-Codes across the attack categories Information Disclosure, Denial of Service, and Model Manipulation. Our evaluation demonstrates the applicability of these attacks across various 3D printers and their firmware. Our findings underscore the need for a better standardization process of G-Codes and corresponding security best practices.\r\n","lang":"eng"}]},{"main_file_link":[{"url":"https://www.petsymposium.org/foci/2025/foci-2025-0002.pdf","open_access":"1"}],"language":[{"iso":"eng"}],"title":"I(ra)nconsistencies: Novel Insights into Iran’s Censorship","year":"2025","author":[{"id":"67893","first_name":"Felix","last_name":"Lange","full_name":"Lange, Felix"},{"id":"63563","first_name":"Niklas","last_name":"Niere","full_name":"Niere, Niklas"},{"last_name":"von Niessen","first_name":"Jonathan","full_name":"von Niessen, Jonathan"},{"full_name":"Suermann, Dennis","first_name":"Dennis","last_name":"Suermann"},{"full_name":"Heitmann, Nico","last_name":"Heitmann","first_name":"Nico","orcid":"0009-0003-7687-7044","id":"74619"},{"id":"83504","full_name":"Somorovsky, Juraj","last_name":"Somorovsky","orcid":"0000-0002-3593-7720","first_name":"Juraj"}],"date_updated":"2026-08-17T07:40:31Z","file":[{"date_created":"2025-02-24T08:07:59Z","creator":"flange","file_id":"58802","content_type":"application/pdf","file_name":"foci-2025-0002.pdf","file_size":535700,"access_level":"local","relation":"main_file","date_updated":"2026-08-17T07:40:31Z"}],"date_created":"2025-02-24T08:09:56Z","type":"conference","department":[{"_id":"632"}],"publication":"Proceedings on Privacy Enhancing Technologies","abstract":[{"lang":"eng","text":"Iran employs one of the most prominent Internet censors in the world. An important part of Iran’s censorship apparatus is its analysis of unencrypted protocols such as HTTP and DNS. During routine evaluations of Iran’s HTTP and DNS censorship, we noticed several properties we believe to be unknown today. For instance, we found injections of correct static IPs for some domains such as google.com on the DNS level, unclear HTTP version parsing, and correlations between DNS and HTTP censorship. In this paper, we present our findings to the community and discuss possible takeaways for affected people and the censorship circumvention community. As some of our findings left us bewildered, we hope to ignite a discussion about Iran’s censorship behavior. We aim to use the discussion of our work to execute a thorough analysis and explanation of Iran’s censorship behavior in the future."}],"_id":"58801","user_id":"63563","ddc":["006"],"status":"public","conference":{"end_date":"2025-02-20","start_date":"2025-02-20","name":"Free and Open Communications on the Internet","location":"Virtual"},"has_accepted_license":"1","oa":"1","file_date_updated":"2026-08-17T07:40:31Z","citation":{"ama":"Lange F, Niere N, von Niessen J, Suermann D, Heitmann N, Somorovsky J. I(ra)nconsistencies: Novel Insights into Iran’s Censorship. In: <i>Proceedings on Privacy Enhancing Technologies</i>. ; 2025.","bibtex":"@inproceedings{Lange_Niere_von Niessen_Suermann_Heitmann_Somorovsky_2025, title={I(ra)nconsistencies: Novel Insights into Iran’s Censorship}, booktitle={Proceedings on Privacy Enhancing Technologies}, author={Lange, Felix and Niere, Niklas and von Niessen, Jonathan and Suermann, Dennis and Heitmann, Nico and Somorovsky, Juraj}, year={2025} }","mla":"Lange, Felix, et al. “I(Ra)Nconsistencies: Novel Insights into Iran’s Censorship.” <i>Proceedings on Privacy Enhancing Technologies</i>, 2025.","chicago":"Lange, Felix, Niklas Niere, Jonathan von Niessen, Dennis Suermann, Nico Heitmann, and Juraj Somorovsky. “I(Ra)Nconsistencies: Novel Insights into Iran’s Censorship.” In <i>Proceedings on Privacy Enhancing Technologies</i>, 2025.","short":"F. Lange, N. Niere, J. von Niessen, D. Suermann, N. Heitmann, J. Somorovsky, in: Proceedings on Privacy Enhancing Technologies, 2025.","apa":"Lange, F., Niere, N., von Niessen, J., Suermann, D., Heitmann, N., &#38; Somorovsky, J. (2025). I(ra)nconsistencies: Novel Insights into Iran’s Censorship. <i>Proceedings on Privacy Enhancing Technologies</i>. Free and Open Communications on the Internet, Virtual.","ieee":"F. Lange, N. Niere, J. von Niessen, D. Suermann, N. Heitmann, and J. Somorovsky, “I(ra)nconsistencies: Novel Insights into Iran’s Censorship,” presented at the Free and Open Communications on the Internet, Virtual, 2025."},"quality_controlled":"1"},{"citation":{"ieee":"N. Niere, F. Lange, N. Heitmann, and J. Somorovsky, “Encrypted Client Hello (ECH) in Censorship Circumvention,” presented at the Free and Open Communications on the Internet, Washington, D.C., 2025.","apa":"Niere, N., Lange, F., Heitmann, N., &#38; Somorovsky, J. (2025). <i>Encrypted Client Hello (ECH) in Censorship Circumvention</i>. Free and Open Communications on the Internet, Washington, D.C.","short":"N. Niere, F. Lange, N. Heitmann, J. Somorovsky, in: 2025.","chicago":"Niere, Niklas, Felix Lange, Nico Heitmann, and Juraj Somorovsky. “Encrypted Client Hello (ECH) in Censorship Circumvention,” 2025.","mla":"Niere, Niklas, et al. <i>Encrypted Client Hello (ECH) in Censorship Circumvention</i>. 2025.","bibtex":"@inproceedings{Niere_Lange_Heitmann_Somorovsky_2025, title={Encrypted Client Hello (ECH) in Censorship Circumvention}, author={Niere, Niklas and Lange, Felix and Heitmann, Nico and Somorovsky, Juraj}, year={2025} }","ama":"Niere N, Lange F, Heitmann N, Somorovsky J. Encrypted Client Hello (ECH) in Censorship Circumvention. In: ; 2025."},"file_date_updated":"2026-08-17T07:40:46Z","oa":"1","has_accepted_license":"1","conference":{"location":"Washington, D.C.","start_date":"2025-07-14","name":"Free and Open Communications on the Internet","end_date":"2025-07-14"},"status":"public","ddc":["006"],"user_id":"63563","_id":"60503","abstract":[{"text":"Censors have long censored Transport Layer Security (TLS) traffic by inspecting the domain name in the unencrypted Server Name Indication (SNI) extension. By encrypting the SNI extension, the Encrypted ClientHello (ECH) prevents censors from blocking TLS traffic to certain domains. Despite this promising outlook, ECH’s current capability to contest TLS censorship is unclear; for instance, Russia has started censoring ECH connections successfully. This paper clarifies ECH’s current role for TLS censorship. To this end, we evaluate servers’ support for ECH and its analysis and subsequent blocking by censors. We determine Cloudflare as the only major provider supporting ECH. Additionally, we affirm previously known ECH censorship in Russia and uncover indirect censorship of ECH through encrypted DNS censorship in China and Iran. Our findings suggest that ECH’s contribution to censorship circumvention is currently limited: we consider ECH’s dependence on encrypted DNS especially challenging for ECH’s capability to circumvent censorship. We stress the importance of censorship-resistant ECH to solve the long-known problem of SNI-based TLS censorship.","lang":"eng"}],"keyword":["censorship","circumvention","ECH","TLS"],"type":"conference","date_created":"2025-07-03T07:14:00Z","file":[{"date_updated":"2026-08-17T07:40:46Z","relation":"main_file","file_size":755171,"access_level":"local","file_name":"foci-2025-0016.pdf","content_type":"application/pdf","file_id":"60505","creator":"nniklas","date_created":"2025-07-03T07:11:14Z"}],"date_updated":"2026-08-17T07:40:46Z","author":[{"full_name":"Niere, Niklas","last_name":"Niere","first_name":"Niklas","id":"63563"},{"full_name":"Lange, Felix","last_name":"Lange","first_name":"Felix","id":"67893"},{"last_name":"Heitmann","orcid":"0009-0003-7687-7044","first_name":"Nico","full_name":"Heitmann, Nico","id":"74619"},{"full_name":"Somorovsky, Juraj","first_name":"Juraj","last_name":"Somorovsky","orcid":"0000-0002-3593-7720","id":"83504"}],"year":"2025","title":"Encrypted Client Hello (ECH) in Censorship Circumvention","language":[{"iso":"eng"}],"main_file_link":[{"open_access":"1","url":"https://www.petsymposium.org/foci/2025/foci-2025-0016.pdf"}]},{"publication":"Applied Cryptography and Network Security","citation":{"bibtex":"@inproceedings{Heitmann_Siewert_Moog_Somorovsky_2024, place={Cham}, title={Security Analysis of BigBlueButton and eduMEET}, DOI={<a href=\"https://doi.org/10.1007/978-3-031-54776-8_8\">10.1007/978-3-031-54776-8_8</a>}, booktitle={Applied Cryptography and Network Security}, publisher={Springer Nature Switzerland}, author={Heitmann, Nico and Siewert, Hendrik and Moog, Sven and Somorovsky, Juraj}, year={2024} }","ama":"Heitmann N, Siewert H, Moog S, Somorovsky J. Security Analysis of BigBlueButton and eduMEET. In: <i>Applied Cryptography and Network Security</i>. Springer Nature Switzerland; 2024. doi:<a href=\"https://doi.org/10.1007/978-3-031-54776-8_8\">10.1007/978-3-031-54776-8_8</a>","mla":"Heitmann, Nico, et al. “Security Analysis of BigBlueButton and EduMEET.” <i>Applied Cryptography and Network Security</i>, Springer Nature Switzerland, 2024, doi:<a href=\"https://doi.org/10.1007/978-3-031-54776-8_8\">10.1007/978-3-031-54776-8_8</a>.","chicago":"Heitmann, Nico, Hendrik Siewert, Sven Moog, and Juraj Somorovsky. “Security Analysis of BigBlueButton and EduMEET.” In <i>Applied Cryptography and Network Security</i>. Cham: Springer Nature Switzerland, 2024. <a href=\"https://doi.org/10.1007/978-3-031-54776-8_8\">https://doi.org/10.1007/978-3-031-54776-8_8</a>.","short":"N. Heitmann, H. Siewert, S. Moog, J. Somorovsky, in: Applied Cryptography and Network Security, Springer Nature Switzerland, Cham, 2024.","ieee":"N. Heitmann, H. Siewert, S. Moog, and J. Somorovsky, “Security Analysis of BigBlueButton and eduMEET,” Abu Dhabi, 2024, doi: <a href=\"https://doi.org/10.1007/978-3-031-54776-8_8\">10.1007/978-3-031-54776-8_8</a>.","apa":"Heitmann, N., Siewert, H., Moog, S., &#38; Somorovsky, J. (2024). Security Analysis of BigBlueButton and eduMEET. <i>Applied Cryptography and Network Security</i>. <a href=\"https://doi.org/10.1007/978-3-031-54776-8_8\">https://doi.org/10.1007/978-3-031-54776-8_8</a>"},"abstract":[{"text":"Video conferencing systems have become an indispensable part of our world. Using video conferencing systems implies the expectation that online meetings run as smoothly as in-person meetings. Thus, online meetings need to be just as secure and private as in-person meetings, which are secured against disruptive factors and unauthorized persons by physical access control mechanisms.\r\n\r\nTo show the security dangers of conferencing systems and raise general awareness when using these technologies, we analyze the security of two widely used research and education open-source video conferencing systems: BigBlueButton and eduMEET. Because both systems are very different, we analyzed their architectures, considering the respective components with their main tasks, features, and user roles. In the following systematic security analyses, we found 50 vulnerabilities. These include broken access control, NoSQL injection, and denial of service (DoS). The vulnerabilities have root causes of different natures. While BigBlueButton has a lot of complexity due to many components, eduMEET, which is relatively young, focuses more on features than security. The sheer amount of results and the lack of prior work indicate a research gap that needs to be closed since video conferencing systems continue to play a significant role in research, education, and everyday life.","lang":"eng"}],"place":"Cham","date_created":"2024-05-23T11:15:39Z","type":"conference","department":[{"_id":"632"}],"year":"2024","status":"public","title":"Security Analysis of BigBlueButton and eduMEET","conference":{"location":"Abu Dhabi","start_date":"2024-03-05","end_date":"2024-03-08"},"author":[{"id":"74619","full_name":"Heitmann, Nico","first_name":"Nico","last_name":"Heitmann"},{"first_name":"Hendrik","last_name":"Siewert","full_name":"Siewert, Hendrik"},{"full_name":"Moog, Sven","last_name":"Moog","first_name":"Sven"},{"full_name":"Somorovsky, Juraj","first_name":"Juraj","orcid":"0000-0002-3593-7720","last_name":"Somorovsky","id":"83504"}],"date_updated":"2024-05-23T11:20:29Z","publication_status":"published","main_file_link":[{"url":"https://link.springer.com/content/pdf/10.1007/978-3-031-54776-8_8.pdf"}],"_id":"54437","publisher":"Springer Nature Switzerland","language":[{"iso":"eng"}],"doi":"10.1007/978-3-031-54776-8_8","user_id":"74619"},{"author":[{"full_name":"Radoy, Maximilian Manfred","last_name":"Radoy","first_name":"Maximilian Manfred","orcid":"0009-0005-3059-6823","id":"68826"},{"id":"55616","first_name":"Sven Niclas","last_name":"Hebrok","orcid":"0009-0006-1172-1665","full_name":"Hebrok, Sven Niclas"},{"orcid":"0000-0002-3593-7720","first_name":"Juraj","last_name":"Somorovsky","full_name":"Somorovsky, Juraj","id":"83504"}],"publication_identifier":{"issn":["0302-9743","1611-3349"],"isbn":["9783031708954","9783031708961"]},"title":"In Search of Partitioning Oracle Attacks Against TLS Session Tickets","status":"public","year":"2024","publication_status":"published","date_updated":"2024-10-07T13:38:28Z","_id":"56079","language":[{"iso":"eng"}],"publisher":"Springer Nature Switzerland","user_id":"68826","doi":"10.1007/978-3-031-70896-1_16","citation":{"apa":"Radoy, M. M., Hebrok, S. N., &#38; Somorovsky, J. (2024). In Search of Partitioning Oracle Attacks Against TLS Session Tickets. In <i>Lecture Notes in Computer Science</i>. Springer Nature Switzerland. <a href=\"https://doi.org/10.1007/978-3-031-70896-1_16\">https://doi.org/10.1007/978-3-031-70896-1_16</a>","mla":"Radoy, Maximilian Manfred, et al. “In Search of Partitioning Oracle Attacks Against TLS Session Tickets.” <i>Lecture Notes in Computer Science</i>, Springer Nature Switzerland, 2024, doi:<a href=\"https://doi.org/10.1007/978-3-031-70896-1_16\">10.1007/978-3-031-70896-1_16</a>.","ieee":"M. M. Radoy, S. N. Hebrok, and J. Somorovsky, “In Search of Partitioning Oracle Attacks Against TLS Session Tickets,” in <i>Lecture Notes in Computer Science</i>, Cham: Springer Nature Switzerland, 2024.","ama":"Radoy MM, Hebrok SN, Somorovsky J. In Search of Partitioning Oracle Attacks Against TLS Session Tickets. In: <i>Lecture Notes in Computer Science</i>. Springer Nature Switzerland; 2024. doi:<a href=\"https://doi.org/10.1007/978-3-031-70896-1_16\">10.1007/978-3-031-70896-1_16</a>","short":"M.M. Radoy, S.N. Hebrok, J. Somorovsky, in: Lecture Notes in Computer Science, Springer Nature Switzerland, Cham, 2024.","chicago":"Radoy, Maximilian Manfred, Sven Niclas Hebrok, and Juraj Somorovsky. “In Search of Partitioning Oracle Attacks Against TLS Session Tickets.” In <i>Lecture Notes in Computer Science</i>. Cham: Springer Nature Switzerland, 2024. <a href=\"https://doi.org/10.1007/978-3-031-70896-1_16\">https://doi.org/10.1007/978-3-031-70896-1_16</a>.","bibtex":"@inbook{Radoy_Hebrok_Somorovsky_2024, place={Cham}, title={In Search of Partitioning Oracle Attacks Against TLS Session Tickets}, DOI={<a href=\"https://doi.org/10.1007/978-3-031-70896-1_16\">10.1007/978-3-031-70896-1_16</a>}, booktitle={Lecture Notes in Computer Science}, publisher={Springer Nature Switzerland}, author={Radoy, Maximilian Manfred and Hebrok, Sven Niclas and Somorovsky, Juraj}, year={2024} }"},"publication":"Lecture Notes in Computer Science","date_created":"2024-09-06T07:06:14Z","place":"Cham","department":[{"_id":"632"}],"type":"book_chapter"},{"abstract":[{"lang":"eng","text":"TLS-Attacker is an open-source framework for analyzing Transport\r\nLayer Security (TLS) implementations. The framework allows users\r\nto specify custom protocol flows and provides modification hooks to\r\nmanipulate message contents. Since its initial publication in 2016 by\r\nJuraj Somorovsky, TLS-Attacker has been used in numerous studies\r\npublished at well-established conferences and helped to identify\r\nvulnerabilities in well-known open-source TLS libraries. To enable\r\nautomated analyses, TLS-Attacker has grown into a suite of projects,\r\neach designed as a building block that can be applied to facilitate\r\nvarious analysis methodologies. The framework still undergoes\r\ncontinuous improvements with feature extensions, such as DTLS\r\n1.3 or the addition of new dialects such as QUIC, to continue its\r\neffectiveness and relevancy as a security analysis framework."}],"publication":"Proceedings of Cybersecurity Artifacts Competition and Impact Award (ACSAC ’24)","department":[{"_id":"632"}],"keyword":["SSL","TLS","DTLS","Protocol State Fuzzing","Planning Based"],"type":"conference","date_created":"2024-12-17T11:25:14Z","file":[{"date_created":"2026-08-17T07:42:08Z","creator":"nniklas","file_id":"66728","content_type":"application/pdf","file_name":"comp-acsac24-final11.pdf","access_level":"local","file_size":530865,"relation":"main_file","date_updated":"2026-08-17T07:42:08Z"}],"date_updated":"2026-08-17T07:42:41Z","author":[{"first_name":"Fabian","last_name":"Bäumer","full_name":"Bäumer, Fabian"},{"last_name":"Brinkmann","first_name":"Marcus","full_name":"Brinkmann, Marcus"},{"full_name":"Erinola, Nurullah","last_name":"Erinola","first_name":"Nurullah"},{"id":"55616","full_name":"Hebrok, Sven Niclas","first_name":"Sven Niclas","orcid":"0009-0006-1172-1665","last_name":"Hebrok"},{"id":"74619","full_name":"Heitmann, Nico","last_name":"Heitmann","first_name":"Nico","orcid":"0009-0003-7687-7044"},{"id":"67893","full_name":"Lange, Felix","first_name":"Felix","last_name":"Lange"},{"last_name":"Maehren","first_name":"Marcel","full_name":"Maehren, Marcel"},{"last_name":"Merget","first_name":"Robert","full_name":"Merget, Robert"},{"id":"63563","full_name":"Niere, Niklas","last_name":"Niere","first_name":"Niklas"},{"full_name":"Radoy, Maximilian Manfred","orcid":"0009-0005-3059-6823","last_name":"Radoy","first_name":"Maximilian Manfred","id":"68826"},{"full_name":"Schmidt, Conrad","first_name":"Conrad","last_name":"Schmidt"},{"full_name":"Schwenk, Jörg","last_name":"Schwenk","first_name":"Jörg"},{"orcid":"0000-0002-3593-7720","first_name":"Juraj","last_name":"Somorovsky","full_name":"Somorovsky, Juraj","id":"83504"}],"year":"2024","title":"TLS-Attacker: A Dynamic Framework for Analyzing TLS Implementations","language":[{"iso":"eng"}],"main_file_link":[{"open_access":"1","url":"https://www.acsac.org/2024/program/artifacts_competition/comp-acsac24-final11.pdf"}],"quality_controlled":"1","citation":{"chicago":"Bäumer, Fabian, Marcus Brinkmann, Nurullah Erinola, Sven Niclas Hebrok, Nico Heitmann, Felix Lange, Marcel Maehren, et al. “TLS-Attacker: A Dynamic Framework for Analyzing TLS Implementations.” In <i>Proceedings of Cybersecurity Artifacts Competition and Impact Award (ACSAC ’24)</i>, 2024.","short":"F. Bäumer, M. Brinkmann, N. Erinola, S.N. Hebrok, N. Heitmann, F. Lange, M. Maehren, R. Merget, N. Niere, M.M. Radoy, C. Schmidt, J. Schwenk, J. Somorovsky, in: Proceedings of Cybersecurity Artifacts Competition and Impact Award (ACSAC ’24), 2024.","ieee":"F. Bäumer <i>et al.</i>, “TLS-Attacker: A Dynamic Framework for Analyzing TLS Implementations,” presented at the Annual Computer Security Applications Conference, Hawaii, 2024.","apa":"Bäumer, F., Brinkmann, M., Erinola, N., Hebrok, S. N., Heitmann, N., Lange, F., Maehren, M., Merget, R., Niere, N., Radoy, M. M., Schmidt, C., Schwenk, J., &#38; Somorovsky, J. (2024). TLS-Attacker: A Dynamic Framework for Analyzing TLS Implementations. <i>Proceedings of Cybersecurity Artifacts Competition and Impact Award (ACSAC ’24)</i>. Annual Computer Security Applications Conference, Hawaii.","bibtex":"@inproceedings{Bäumer_Brinkmann_Erinola_Hebrok_Heitmann_Lange_Maehren_Merget_Niere_Radoy_et al._2024, title={TLS-Attacker: A Dynamic Framework for Analyzing TLS Implementations}, booktitle={Proceedings of Cybersecurity Artifacts Competition and Impact Award (ACSAC ’24)}, author={Bäumer, Fabian and Brinkmann, Marcus and Erinola, Nurullah and Hebrok, Sven Niclas and Heitmann, Nico and Lange, Felix and Maehren, Marcel and Merget, Robert and Niere, Niklas and Radoy, Maximilian Manfred and et al.}, year={2024} }","ama":"Bäumer F, Brinkmann M, Erinola N, et al. TLS-Attacker: A Dynamic Framework for Analyzing TLS Implementations. In: <i>Proceedings of Cybersecurity Artifacts Competition and Impact Award (ACSAC ’24)</i>. ; 2024.","mla":"Bäumer, Fabian, et al. “TLS-Attacker: A Dynamic Framework for Analyzing TLS Implementations.” <i>Proceedings of Cybersecurity Artifacts Competition and Impact Award (ACSAC ’24)</i>, 2024."},"file_date_updated":"2026-08-17T07:42:08Z","oa":"1","has_accepted_license":"1","conference":{"location":"Hawaii","start_date":"2024-12-09","name":"Annual Computer Security Applications Conference","end_date":"2024-12-13"},"status":"public","ddc":["006"],"user_id":"63563","_id":"57816"},{"file_date_updated":"2026-08-17T07:40:56Z","citation":{"bibtex":"@inproceedings{Müller_Niere_Lange_Somorovsky_2024, place={Bristol}, title={Turning Attacks into Advantages: Evading HTTP Censorship with HTTP Request Smuggling}, booktitle={Proceedings on Privacy Enhancing Technologies}, author={Müller, Philipp and Niere, Niklas and Lange, Felix and Somorovsky, Juraj}, year={2024} }","ama":"Müller P, Niere N, Lange F, Somorovsky J. Turning Attacks into Advantages: Evading HTTP Censorship with HTTP Request Smuggling. In: <i>Proceedings on Privacy Enhancing Technologies</i>. ; 2024.","mla":"Müller, Philipp, et al. “Turning Attacks into Advantages: Evading HTTP Censorship with HTTP Request Smuggling.” <i>Proceedings on Privacy Enhancing Technologies</i>, 2024.","chicago":"Müller, Philipp, Niklas Niere, Felix Lange, and Juraj Somorovsky. “Turning Attacks into Advantages: Evading HTTP Censorship with HTTP Request Smuggling.” In <i>Proceedings on Privacy Enhancing Technologies</i>. Bristol, 2024.","short":"P. Müller, N. Niere, F. Lange, J. Somorovsky, in: Proceedings on Privacy Enhancing Technologies, Bristol, 2024.","ieee":"P. Müller, N. Niere, F. Lange, and J. Somorovsky, “Turning Attacks into Advantages: Evading HTTP Censorship with HTTP Request Smuggling,” presented at the Free and Open Communications on the Internet 2024 , Bristol, 2024.","apa":"Müller, P., Niere, N., Lange, F., &#38; Somorovsky, J. (2024). Turning Attacks into Advantages: Evading HTTP Censorship with HTTP Request Smuggling. <i>Proceedings on Privacy Enhancing Technologies</i>. Free and Open Communications on the Internet 2024 , Bristol."},"quality_controlled":"1","place":"Bristol","oa":"1","status":"public","conference":{"name":"Free and Open Communications on the Internet 2024 ","start_date":"2024-07-15","location":"Bristol","end_date":"2024-07-15"},"has_accepted_license":"1","_id":"55137","ddc":["006"],"user_id":"63563","publication":"Proceedings on Privacy Enhancing Technologies","abstract":[{"text":"Many countries limit their residents' access to various websites. As a substantial number of these websites do not support TLS encryption, censorship of unencrypted HTTP requests remains prevalent. Accordingly, circumvention techniques can and have been found for the HTTP protocol. In this paper, we infer novel circumvention techniques on the HTTP layer from a web security vulnerability by utilizing HTTP request smuggling (HRS). To demonstrate the viability of our techniques, we collected various test vectors from previous work about HRS and evaluated them on popular web servers and censors in China, Russia, and Iran. Our findings show that HRS can be successfully employed as a censorship circumvention technique against multiple censors and web servers. We also discover a standard-compliant circumvention technique in Russia, unusually inconsistent censorship in China, and an implementation bug in Iran. The results of this work imply that censorship circumvention techniques can successfully be constructed from existing vulnerabilities. We conjecture that this implication provides insights to the censorship circumvention community beyond the viability of specific techniques presented in this work.","lang":"eng"}],"file":[{"content_type":"application/pdf","file_id":"55139","access_level":"local","file_size":189676,"file_name":"Turning Attacks into Advantages_ Evading HTTP Censorship with HTTP Request Smuggling - foci-2024-0012.pdf","date_updated":"2026-08-17T07:40:56Z","relation":"main_file","date_created":"2024-07-09T07:42:54Z","creator":"flange"}],"date_created":"2024-07-09T07:49:37Z","keyword":["censorship","censorship circumvention","http","http request smuggling"],"type":"conference","department":[{"_id":"632"}],"title":"Turning Attacks into Advantages: Evading HTTP Censorship with HTTP Request Smuggling","year":"2024","author":[{"full_name":"Müller, Philipp","last_name":"Müller","first_name":"Philipp"},{"last_name":"Niere","first_name":"Niklas","full_name":"Niere, Niklas","id":"63563"},{"id":"67893","last_name":"Lange","first_name":"Felix","full_name":"Lange, Felix"},{"full_name":"Somorovsky, Juraj","last_name":"Somorovsky","orcid":"0000-0002-3593-7720","first_name":"Juraj","id":"83504"}],"date_updated":"2026-08-17T07:40:56Z","publication_status":"published","main_file_link":[{"url":"https://www.petsymposium.org/foci/2024/foci-2024-0012.pdf","open_access":"1"}],"language":[{"iso":"eng"}]},{"type":"conference","oa":"1","department":[{"_id":"632"}],"date_created":"2023-03-22T08:15:42Z","publication":"32nd USENIX Security Symposium","citation":{"ama":"Hebrok SN, Nachtigall S, Maehren M, et al. We Really Need to Talk About Session Tickets: A Large-Scale Analysis of Cryptographic Dangers with TLS Session Tickets. In: <i>32nd USENIX Security Symposium</i>. ; 2023.","bibtex":"@inproceedings{Hebrok_Nachtigall_Maehren_Erinola_Merget_Somorovsky_Schwenk_2023, title={We Really Need to Talk About Session Tickets: A Large-Scale Analysis of Cryptographic Dangers with TLS Session Tickets}, booktitle={32nd USENIX Security Symposium}, author={Hebrok, Sven Niclas and Nachtigall, Simon and Maehren, Marcel and Erinola, Nurullah and Merget, Robert and Somorovsky, Juraj and Schwenk, Jörg}, year={2023} }","mla":"Hebrok, Sven Niclas, et al. “We Really Need to Talk About Session Tickets: A Large-Scale Analysis of Cryptographic Dangers with TLS Session Tickets.” <i>32nd USENIX Security Symposium</i>, 2023.","chicago":"Hebrok, Sven Niclas, Simon Nachtigall, Marcel Maehren, Nurullah Erinola, Robert Merget, Juraj Somorovsky, and Jörg Schwenk. “We Really Need to Talk About Session Tickets: A Large-Scale Analysis of Cryptographic Dangers with TLS Session Tickets.” In <i>32nd USENIX Security Symposium</i>, 2023.","short":"S.N. Hebrok, S. Nachtigall, M. Maehren, N. Erinola, R. Merget, J. Somorovsky, J. Schwenk, in: 32nd USENIX Security Symposium, 2023.","apa":"Hebrok, S. N., Nachtigall, S., Maehren, M., Erinola, N., Merget, R., Somorovsky, J., &#38; Schwenk, J. (2023). We Really Need to Talk About Session Tickets: A Large-Scale Analysis of Cryptographic Dangers with TLS Session Tickets. <i>32nd USENIX Security Symposium</i>.","ieee":"S. N. Hebrok <i>et al.</i>, “We Really Need to Talk About Session Tickets: A Large-Scale Analysis of Cryptographic Dangers with TLS Session Tickets,” 2023."},"user_id":"83504","main_file_link":[{"url":"https://www.usenix.org/conference/usenixsecurity23/presentation/hebrok","open_access":"1"}],"_id":"43060","language":[{"iso":"eng"}],"date_updated":"2023-06-21T06:49:56Z","status":"public","title":"We Really Need to Talk About Session Tickets: A Large-Scale Analysis of Cryptographic Dangers with TLS Session Tickets","year":"2023","author":[{"id":"55616","full_name":"Hebrok, Sven Niclas","last_name":"Hebrok","first_name":"Sven Niclas"},{"first_name":"Simon","last_name":"Nachtigall","full_name":"Nachtigall, Simon"},{"last_name":"Maehren","first_name":"Marcel","full_name":"Maehren, Marcel"},{"full_name":"Erinola, Nurullah","last_name":"Erinola","first_name":"Nurullah"},{"full_name":"Merget, Robert","first_name":"Robert","last_name":"Merget"},{"last_name":"Somorovsky","first_name":"Juraj","orcid":"0000-0002-3593-7720","full_name":"Somorovsky, Juraj","id":"83504"},{"first_name":"Jörg","last_name":"Schwenk","full_name":"Schwenk, Jörg"}]},{"status":"public","conference":{"name":"2023 IEEE European Symposium on Security and Privacy Workshops (EuroS&PW)","start_date":"2023-07-03","location":"Delft, Netherlands","end_date":"2023-07-07"},"has_accepted_license":"1","page":"379-385","_id":"46500","publisher":"IEEE","ddc":["000"],"user_id":"58331","file_date_updated":"2024-09-05T13:00:09Z","citation":{"mla":"Pottebaum, Jens, et al. “Re-Envisioning Industrial Control Systems Security by Considering Human Factors as a Core Element of Defense-in-Depth.” <i>2023 IEEE European Symposium on Security and Privacy Workshops (EuroS&#38;PW)</i>, IEEE, 2023, pp. 379–85, doi:<a href=\"https://doi.org/10.1109/eurospw59978.2023.00048\">10.1109/eurospw59978.2023.00048</a>.","ama":"Pottebaum J, Rossel J, Somorovsky J, et al. Re-Envisioning Industrial Control Systems Security by Considering Human Factors as a Core Element of Defense-in-Depth. In: <i>2023 IEEE European Symposium on Security and Privacy Workshops (EuroS&#38;PW)</i>. IEEE; 2023:379-385. doi:<a href=\"https://doi.org/10.1109/eurospw59978.2023.00048\">10.1109/eurospw59978.2023.00048</a>","bibtex":"@inproceedings{Pottebaum_Rossel_Somorovsky_Acar_Fahr_Arias Cabarcos_Bodden_Gräßler_2023, title={Re-Envisioning Industrial Control Systems Security by Considering Human Factors as a Core Element of Defense-in-Depth}, DOI={<a href=\"https://doi.org/10.1109/eurospw59978.2023.00048\">10.1109/eurospw59978.2023.00048</a>}, booktitle={2023 IEEE European Symposium on Security and Privacy Workshops (EuroS&#38;PW)}, publisher={IEEE}, author={Pottebaum, Jens and Rossel, Jost and Somorovsky, Juraj and Acar, Yasemin and Fahr, René and Arias Cabarcos, Patricia and Bodden, Eric and Gräßler, Iris}, year={2023}, pages={379–385} }","apa":"Pottebaum, J., Rossel, J., Somorovsky, J., Acar, Y., Fahr, R., Arias Cabarcos, P., Bodden, E., &#38; Gräßler, I. (2023). Re-Envisioning Industrial Control Systems Security by Considering Human Factors as a Core Element of Defense-in-Depth. <i>2023 IEEE European Symposium on Security and Privacy Workshops (EuroS&#38;PW)</i>, 379–385. <a href=\"https://doi.org/10.1109/eurospw59978.2023.00048\">https://doi.org/10.1109/eurospw59978.2023.00048</a>","ieee":"J. Pottebaum <i>et al.</i>, “Re-Envisioning Industrial Control Systems Security by Considering Human Factors as a Core Element of Defense-in-Depth,” in <i>2023 IEEE European Symposium on Security and Privacy Workshops (EuroS&#38;PW)</i>, Delft, Netherlands, 2023, pp. 379–385, doi: <a href=\"https://doi.org/10.1109/eurospw59978.2023.00048\">10.1109/eurospw59978.2023.00048</a>.","short":"J. Pottebaum, J. Rossel, J. Somorovsky, Y. Acar, R. Fahr, P. Arias Cabarcos, E. Bodden, I. Gräßler, in: 2023 IEEE European Symposium on Security and Privacy Workshops (EuroS&#38;PW), IEEE, 2023, pp. 379–385.","chicago":"Pottebaum, Jens, Jost Rossel, Juraj Somorovsky, Yasemin Acar, René Fahr, Patricia Arias Cabarcos, Eric Bodden, and Iris Gräßler. “Re-Envisioning Industrial Control Systems Security by Considering Human Factors as a Core Element of Defense-in-Depth.” In <i>2023 IEEE European Symposium on Security and Privacy Workshops (EuroS&#38;PW)</i>, 379–85. IEEE, 2023. <a href=\"https://doi.org/10.1109/eurospw59978.2023.00048\">https://doi.org/10.1109/eurospw59978.2023.00048</a>."},"quality_controlled":"1","title":"Re-Envisioning Industrial Control Systems Security by Considering Human Factors as a Core Element of Defense-in-Depth","year":"2023","author":[{"full_name":"Pottebaum, Jens","orcid":"http://orcid.org/0000-0001-8778-2989","first_name":"Jens","last_name":"Pottebaum","id":"405"},{"full_name":"Rossel, Jost","first_name":"Jost","last_name":"Rossel","orcid":"0000-0002-3182-4059","id":"58331"},{"full_name":"Somorovsky, Juraj","orcid":"0000-0002-3593-7720","first_name":"Juraj","last_name":"Somorovsky","id":"83504"},{"first_name":"Yasemin","last_name":"Acar","full_name":"Acar, Yasemin","id":"94636"},{"id":"111","full_name":"Fahr, René","first_name":"René","last_name":"Fahr"},{"id":"92804","full_name":"Arias Cabarcos, Patricia","last_name":"Arias Cabarcos","first_name":"Patricia"},{"id":"59256","orcid":"0000-0003-3470-3647","first_name":"Eric","last_name":"Bodden","full_name":"Bodden, Eric"},{"id":"47565","full_name":"Gräßler, Iris","last_name":"Gräßler","first_name":"Iris","orcid":"0000-0001-5765-971X"}],"date_updated":"2025-07-16T11:06:47Z","publication_status":"published","main_file_link":[{"url":"https://ieeexplore.ieee.org/stamp/stamp.jsp?tp=&arnumber=10190647"}],"language":[{"iso":"eng"}],"doi":"10.1109/eurospw59978.2023.00048","publication":"2023 IEEE European Symposium on Security and Privacy Workshops (EuroS&PW)","abstract":[{"text":"The security of Industrial Control Systems is relevant both for reliable production system operations and for high-quality throughput in terms of manufactured products. Security measures are designed, operated and maintained by different roles along product and production system lifecycles. Defense-in-Depth as a paradigm builds upon the assumption that breaches are unavoidable. The paper at hand provides an analysis of roles, corresponding Human Factors and their relevance for data theft and sabotage attacks. The resulting taxonomy is reflected by an example related to Additive Manufacturing. The results assist in both designing and redesigning Industrial Control System as part of an entire production system so that Defense-in-Depth with regard to Human Factors is built in by design.","lang":"eng"}],"file":[{"date_created":"2024-09-05T13:00:09Z","creator":"jrossel","file_id":"56077","content_type":"application/pdf","relation":"main_file","date_updated":"2024-09-05T13:00:09Z","file_name":"Re_envisioning_Industrial_Control_Systems_security.pdf","file_size":197727,"access_level":"closed"}],"date_created":"2023-08-15T12:21:05Z","type":"conference","keyword":["Defense-in-Depth","Human Factors","Production Engineering","Product Design","Systems Engineering"],"department":[{"_id":"34"},{"_id":"152"},{"_id":"76"},{"_id":"632"},{"_id":"858"}]},{"_id":"48012","publisher":"ACM","ddc":["000"],"user_id":"58331","status":"public","conference":{"location":"Hongkong","name":"26th International Symposium on Research in Attacks, Intrusions and Defenses","start_date":"2023-10-16","end_date":"2023-10-18"},"has_accepted_license":"1","oa":"1","file_date_updated":"2024-09-05T11:14:40Z","citation":{"bibtex":"@inproceedings{Rossel_Mladenov_Somorovsky_2023, title={Security Analysis of the 3MF Data Format}, DOI={<a href=\"https://doi.org/10.1145/3607199.3607216\">10.1145/3607199.3607216</a>}, booktitle={Proceedings of the 26th International Symposium on Research in Attacks, Intrusions and Defenses}, publisher={ACM}, author={Rossel, Jost and Mladenov, Vladislav and Somorovsky, Juraj}, year={2023} }","ama":"Rossel J, Mladenov V, Somorovsky J. Security Analysis of the 3MF Data Format. In: <i>Proceedings of the 26th International Symposium on Research in Attacks, Intrusions and Defenses</i>. ACM; 2023. doi:<a href=\"https://doi.org/10.1145/3607199.3607216\">10.1145/3607199.3607216</a>","short":"J. Rossel, V. Mladenov, J. Somorovsky, in: Proceedings of the 26th International Symposium on Research in Attacks, Intrusions and Defenses, ACM, 2023.","chicago":"Rossel, Jost, Vladislav Mladenov, and Juraj Somorovsky. “Security Analysis of the 3MF Data Format.” In <i>Proceedings of the 26th International Symposium on Research in Attacks, Intrusions and Defenses</i>. ACM, 2023. <a href=\"https://doi.org/10.1145/3607199.3607216\">https://doi.org/10.1145/3607199.3607216</a>.","ieee":"J. Rossel, V. Mladenov, and J. Somorovsky, “Security Analysis of the 3MF Data Format,” presented at the 26th International Symposium on Research in Attacks, Intrusions and Defenses, Hongkong, 2023, doi: <a href=\"https://doi.org/10.1145/3607199.3607216\">10.1145/3607199.3607216</a>.","mla":"Rossel, Jost, et al. “Security Analysis of the 3MF Data Format.” <i>Proceedings of the 26th International Symposium on Research in Attacks, Intrusions and Defenses</i>, ACM, 2023, doi:<a href=\"https://doi.org/10.1145/3607199.3607216\">10.1145/3607199.3607216</a>.","apa":"Rossel, J., Mladenov, V., &#38; Somorovsky, J. (2023). Security Analysis of the 3MF Data Format. <i>Proceedings of the 26th International Symposium on Research in Attacks, Intrusions and Defenses</i>. 26th International Symposium on Research in Attacks, Intrusions and Defenses, Hongkong. <a href=\"https://doi.org/10.1145/3607199.3607216\">https://doi.org/10.1145/3607199.3607216</a>"},"quality_controlled":"1","main_file_link":[{"url":"https://dl.acm.org/doi/abs/10.1145/3607199.3607216"}],"language":[{"iso":"eng"}],"doi":"10.1145/3607199.3607216","title":"Security Analysis of the 3MF Data Format","year":"2023","author":[{"last_name":"Rossel","first_name":"Jost","orcid":"0000-0002-3182-4059","full_name":"Rossel, Jost","id":"58331"},{"last_name":"Mladenov","first_name":"Vladislav","full_name":"Mladenov, Vladislav"},{"id":"83504","first_name":"Juraj","orcid":"0000-0002-3593-7720","last_name":"Somorovsky","full_name":"Somorovsky, Juraj"}],"date_updated":"2025-07-16T11:06:49Z","publication_status":"published","file":[{"date_created":"2023-10-16T03:48:08Z","creator":"jrossel","content_type":"application/pdf","file_id":"48065","file_size":1054999,"access_level":"open_access","file_name":"Security_Analysis_of_the_3mf_Data_Format.pdf","date_updated":"2024-09-05T11:14:40Z","relation":"main_file"}],"date_created":"2023-10-11T13:42:09Z","type":"conference","keyword":["Data Format Security","3D Manufacturing Format","3D Printing","Additive Manufacturing"],"department":[{"_id":"632"}],"publication":"Proceedings of the 26th International Symposium on Research in Attacks, Intrusions and Defenses","abstract":[{"text":"3D printing is a well-established technology with rapidly increasing usage scenarios both in the industry and consumer context. The growing popularity of 3D printing has also attracted security researchers, who have analyzed possibilities for weakening 3D models or stealing intellectual property from 3D models. We extend these important aspects and provide the first comprehensive security analysis of 3D printing data formats. We performed our systematic study on the example of the 3D Manufacturing Format (3MF), which offers a large variety of features that could lead to critical attacks. Based on 3MF’s features, we systematized three attack goals: Data Exfiltration (dex), Denial of Service, and UI Spoofing (uis). We achieve these goals by exploiting the complexity of 3MF, which is based on the Open Packaging Conventions (OPC) format and uses XML to define 3D models. In total, our analysis led to 352 tests. To create and run these tests automatically, we implemented an open-source tool named 3MF Analyzer (tool), which helped us evaluate 20 applications.","lang":"eng"}]},{"date_created":"2023-12-15T07:34:24Z","file":[{"date_created":"2026-08-17T07:44:26Z","creator":"nniklas","content_type":"application/pdf","file_id":"66729","date_updated":"2026-08-17T07:44:26Z","relation":"main_file","access_level":"local","file_size":933515,"file_name":"3576915.3624372.pdf"}],"department":[{"_id":"632"}],"type":"conference","publication":"Proceedings of the 2023 ACM SIGSAC Conference on Computer and Communications Security","abstract":[{"text":"State actors around the world censor the HTTPS protocol to block access to certain websites. While many circumvention strategies utilize the TCP layer only little emphasis has been placed on the analysis of TLS-a complex protocol and integral building block of HTTPS. In contrast to the TCP layer, circumvention methods on the TLS layer do not require root privileges since TLS operates on the application layer. With this proposal, we want to motivate a deeper analysis of TLS in regard to censorship circumvention techniques. To prove the existence of such techniques, we present TLS record fragmentation as a novel circumvention technique and circumvent the Great Firewall of China (GFW) using this technique. We hope that our research fosters collaboration between censorship and TLS researchers.","lang":"eng"}],"language":[{"iso":"eng"}],"main_file_link":[{"url":"https://dl.acm.org/doi/pdf/10.1145/3576915.3624372","open_access":"1"}],"doi":"10.1145/3576915.3624372","author":[{"first_name":"Niklas","last_name":"Niere","full_name":"Niere, Niklas","id":"63563"},{"id":"55616","orcid":"0009-0006-1172-1665","last_name":"Hebrok","first_name":"Sven Niclas","full_name":"Hebrok, Sven Niclas"},{"id":"83504","orcid":"0000-0002-3593-7720","last_name":"Somorovsky","first_name":"Juraj","full_name":"Somorovsky, Juraj"},{"full_name":"Merget, Robert","last_name":"Merget","first_name":"Robert"}],"title":"Poster: Circumventing the GFW with TLS Record Fragmentation","year":"2023","date_updated":"2026-08-17T07:44:41Z","publication_status":"published","oa":"1","citation":{"mla":"Niere, Niklas, et al. “Poster: Circumventing the GFW with TLS Record Fragmentation.” <i>Proceedings of the 2023 ACM SIGSAC Conference on Computer and Communications Security</i>, ACM, 2023, doi:<a href=\"https://doi.org/10.1145/3576915.3624372\">10.1145/3576915.3624372</a>.","ama":"Niere N, Hebrok SN, Somorovsky J, Merget R. Poster: Circumventing the GFW with TLS Record Fragmentation. In: <i>Proceedings of the 2023 ACM SIGSAC Conference on Computer and Communications Security</i>. ACM; 2023. doi:<a href=\"https://doi.org/10.1145/3576915.3624372\">10.1145/3576915.3624372</a>","bibtex":"@inproceedings{Niere_Hebrok_Somorovsky_Merget_2023, title={Poster: Circumventing the GFW with TLS Record Fragmentation}, DOI={<a href=\"https://doi.org/10.1145/3576915.3624372\">10.1145/3576915.3624372</a>}, booktitle={Proceedings of the 2023 ACM SIGSAC Conference on Computer and Communications Security}, publisher={ACM}, author={Niere, Niklas and Hebrok, Sven Niclas and Somorovsky, Juraj and Merget, Robert}, year={2023} }","apa":"Niere, N., Hebrok, S. N., Somorovsky, J., &#38; Merget, R. (2023). Poster: Circumventing the GFW with TLS Record Fragmentation. <i>Proceedings of the 2023 ACM SIGSAC Conference on Computer and Communications Security</i>. <a href=\"https://doi.org/10.1145/3576915.3624372\">https://doi.org/10.1145/3576915.3624372</a>","ieee":"N. Niere, S. N. Hebrok, J. Somorovsky, and R. Merget, “Poster: Circumventing the GFW with TLS Record Fragmentation,” 2023, doi: <a href=\"https://doi.org/10.1145/3576915.3624372\">10.1145/3576915.3624372</a>.","chicago":"Niere, Niklas, Sven Niclas Hebrok, Juraj Somorovsky, and Robert Merget. “Poster: Circumventing the GFW with TLS Record Fragmentation.” In <i>Proceedings of the 2023 ACM SIGSAC Conference on Computer and Communications Security</i>. ACM, 2023. <a href=\"https://doi.org/10.1145/3576915.3624372\">https://doi.org/10.1145/3576915.3624372</a>.","short":"N. Niere, S.N. Hebrok, J. Somorovsky, R. Merget, in: Proceedings of the 2023 ACM SIGSAC Conference on Computer and Communications Security, ACM, 2023."},"file_date_updated":"2026-08-17T07:44:26Z","_id":"49654","publisher":"ACM","ddc":["006"],"user_id":"63563","status":"public","has_accepted_license":"1"},{"department":[{"_id":"632"}],"type":"conference","place":"Boston, MA","date_created":"2022-08-03T11:02:10Z","citation":{"chicago":"Mayer, Peter, Damian Poddebniak, Konstantin Fischer, Marcus Brinkmann, Juraj Somorovsky, Angela Sasse, Sebastian Schinzel, and Melanie Volkamer. “‘I Don’ Know Why I Check This...’ - Investigating Expert Users’ Strategies to Detect Email Signature Spoofing Attacks.” In <i>Eighteenth Symposium on Usable Privacy and Security (SOUPS 2022)</i>, 77–96. Boston, MA: USENIX Association, 2022.","short":"P. Mayer, D. Poddebniak, K. Fischer, M. Brinkmann, J. Somorovsky, A. Sasse, S. Schinzel, M. Volkamer, in: Eighteenth Symposium on Usable Privacy and Security (SOUPS 2022), USENIX Association, Boston, MA, 2022, pp. 77–96.","apa":"Mayer, P., Poddebniak, D., Fischer, K., Brinkmann, M., Somorovsky, J., Sasse, A., Schinzel, S., &#38; Volkamer, M. (2022). “I don’ know why I check this...” - Investigating Expert Users’ Strategies to Detect Email Signature Spoofing Attacks. <i>Eighteenth Symposium on Usable Privacy and Security (SOUPS 2022)</i>, 77–96.","ieee":"P. Mayer <i>et al.</i>, “‘I don’ know why I check this...’ - Investigating Expert Users’ Strategies to Detect Email Signature Spoofing Attacks,” in <i>Eighteenth Symposium on Usable Privacy and Security (SOUPS 2022)</i>, 2022, pp. 77–96.","ama":"Mayer P, Poddebniak D, Fischer K, et al. “I don’ know why I check this...” - Investigating Expert Users’ Strategies to Detect Email Signature Spoofing Attacks. In: <i>Eighteenth Symposium on Usable Privacy and Security (SOUPS 2022)</i>. USENIX Association; 2022:77–96.","bibtex":"@inproceedings{Mayer_Poddebniak_Fischer_Brinkmann_Somorovsky_Sasse_Schinzel_Volkamer_2022, place={Boston, MA}, title={“I don’ know why I check this...” - Investigating Expert Users’ Strategies to Detect Email Signature Spoofing Attacks}, booktitle={Eighteenth Symposium on Usable Privacy and Security (SOUPS 2022)}, publisher={USENIX Association}, author={Mayer, Peter and Poddebniak, Damian and Fischer, Konstantin and Brinkmann, Marcus and Somorovsky, Juraj and Sasse, Angela and Schinzel, Sebastian and Volkamer, Melanie}, year={2022}, pages={77–96} }","mla":"Mayer, Peter, et al. “‘I Don’ Know Why I Check This...’ - Investigating Expert Users’ Strategies to Detect Email Signature Spoofing Attacks.” <i>Eighteenth Symposium on Usable Privacy and Security (SOUPS 2022)</i>, USENIX Association, 2022, pp. 77–96."},"publication":"Eighteenth Symposium on Usable Privacy and Security (SOUPS 2022)","user_id":"83504","language":[{"iso":"eng"}],"_id":"32572","publisher":"USENIX Association","page":"77–96","date_updated":"2024-04-02T12:19:28Z","author":[{"last_name":"Mayer","first_name":"Peter","full_name":"Mayer, Peter"},{"last_name":"Poddebniak","first_name":"Damian","full_name":"Poddebniak, Damian"},{"last_name":"Fischer","first_name":"Konstantin","full_name":"Fischer, Konstantin"},{"first_name":"Marcus","last_name":"Brinkmann","full_name":"Brinkmann, Marcus"},{"full_name":"Somorovsky, Juraj","last_name":"Somorovsky","orcid":"0000-0002-3593-7720","first_name":"Juraj","id":"83504"},{"full_name":"Sasse, Angela","last_name":"Sasse","first_name":"Angela"},{"full_name":"Schinzel, Sebastian","first_name":"Sebastian","last_name":"Schinzel"},{"first_name":"Melanie","last_name":"Volkamer","full_name":"Volkamer, Melanie"}],"publication_identifier":{"isbn":["978-1-939133-30-4"]},"year":"2022","title":"\"I don' know why I check this...\" - Investigating Expert Users' Strategies to Detect Email Signature Spoofing Attacks","status":"public"},{"department":[{"_id":"632"}],"type":"conference","place":"Boston, MA","date_created":"2022-08-03T11:03:30Z","citation":{"mla":"Maehren, Marcel, et al. “TLS-Anvil: Adapting Combinatorial Testing for TLS Libraries.” <i>31st USENIX Security Symposium (USENIX Security 22)</i>, USENIX Association, 2022.","ama":"Maehren M, Nieting P, Hebrok SN, Merget R, Somorovsky J, Schwenk J. TLS-Anvil: Adapting Combinatorial Testing for TLS Libraries. In: <i>31st USENIX Security Symposium (USENIX Security 22)</i>. USENIX Association; 2022.","bibtex":"@inproceedings{Maehren_Nieting_Hebrok_Merget_Somorovsky_Schwenk_2022, place={Boston, MA}, title={TLS-Anvil: Adapting Combinatorial Testing for TLS Libraries}, booktitle={31st USENIX Security Symposium (USENIX Security 22)}, publisher={USENIX Association}, author={Maehren, Marcel and Nieting, Philipp and Hebrok, Sven Niclas and Merget, Robert and Somorovsky, Juraj and Schwenk, Jörg}, year={2022} }","apa":"Maehren, M., Nieting, P., Hebrok, S. N., Merget, R., Somorovsky, J., &#38; Schwenk, J. (2022). TLS-Anvil: Adapting Combinatorial Testing for TLS Libraries. <i>31st USENIX Security Symposium (USENIX Security 22)</i>.","ieee":"M. Maehren, P. Nieting, S. N. Hebrok, R. Merget, J. Somorovsky, and J. Schwenk, “TLS-Anvil: Adapting Combinatorial Testing for TLS Libraries,” 2022.","chicago":"Maehren, Marcel, Philipp Nieting, Sven Niclas Hebrok, Robert Merget, Juraj Somorovsky, and Jörg Schwenk. “TLS-Anvil: Adapting Combinatorial Testing for TLS Libraries.” In <i>31st USENIX Security Symposium (USENIX Security 22)</i>. Boston, MA: USENIX Association, 2022.","short":"M. Maehren, P. Nieting, S.N. Hebrok, R. Merget, J. Somorovsky, J. Schwenk, in: 31st USENIX Security Symposium (USENIX Security 22), USENIX Association, Boston, MA, 2022."},"publication":"31st USENIX Security Symposium (USENIX Security 22)","user_id":"83504","_id":"32573","language":[{"iso":"eng"}],"publisher":"USENIX Association","date_updated":"2024-04-02T12:19:45Z","author":[{"full_name":"Maehren, Marcel","first_name":"Marcel","last_name":"Maehren"},{"last_name":"Nieting","first_name":"Philipp","full_name":"Nieting, Philipp"},{"first_name":"Sven Niclas","orcid":"0009-0006-1172-1665","last_name":"Hebrok","full_name":"Hebrok, Sven Niclas","id":"55616"},{"first_name":"Robert","last_name":"Merget","full_name":"Merget, Robert"},{"last_name":"Somorovsky","orcid":"0000-0002-3593-7720","first_name":"Juraj","full_name":"Somorovsky, Juraj","id":"83504"},{"full_name":"Schwenk, Jörg","first_name":"Jörg","last_name":"Schwenk"}],"year":"2022","status":"public","title":"TLS-Anvil: Adapting Combinatorial Testing for TLS Libraries"}]
