TY - CHAP A1 - Dresen, Christian A1 - Ising, Fabian A1 - Poddebniak, Damian A1 - Kappert, Tobias A1 - Holz, Thorsten A1 - Schinzel, Sebastian ED - Zhou, Jianying T1 - CORSICA: Cross-Origin Web Service Identification T2 - The 15th ACM ASIA Conference on Computer and Communications Security N2 - Vulnerabilities in private networks are difficult to detect for attackers outside of the network. While there are known methods for port scanning internal hosts that work by luring unwitting internal users to an external web page that hosts malicious JavaScript code, no such method for detailed and precise service identification is known. The reason is that the Same Origin Policy (SOP) prevents access to HTTP responses of other origins by default. We perform a structured analysis of loopholes in the SOP that can be used to identify web applications across network boundaries. For this, we analyze HTML5, CSS, and JavaScript features of standard-compliant web browsers that may leak sensitive information about cross-origin content. The results reveal several novel techniques, including leaking JavaScript function names or styles of cross-origin requests that are available in all common browsers. We implement and test these techniques in a tool called CORSICA. It can successfully identify 31 of 42 (74%) of web services running on different IoT devices as well as the version numbers of the four most widely used content management systems WordPress, Drupal, Joomla, and TYPO3. CORSICA can also determine the patch level on average down to three versions (WordPress), six versions (Drupal), two versions (Joomla), and four versions (TYPO3) with only ten requests on average. Furthermore, CORSICA is able to identify 48 WordPress plugins containing 65 vulnerabilities. Finally, we analyze mitigation strategies and show that the proposed but not yet implemented strategies Cross-Origin Resource Policy (CORP)} and Sec-Metadata would prevent our identification techniques. Y1 - 2020 UR - https://asiaccs2020.cs.nthu.edu.tw/program/ ER - TY - BOOK A1 - Mertens, Konrad T1 - Photovoltaik - Lehrbuch zu Grundlagen, Technologie und Praxis N2 - Das Standardlehrbuch zu Photovoltaik! Dieses Lehrbuch liefert Antworten auf die wichtigsten Fragen zur Photovoltaik-Technik. Es werden grundlegende physikalische und elektrotechnische Fragestellungen behandelt. Im Mittelpunkt stehen die Systemtechnik mit Informationen zur Zellen- und Modulverschaltung sowie die Netzintegration von Photovoltaikanlagen. Das Buch beschreibt die aktuellsten Messmethoden für Solarmodule und erläutert die technischen und wirtschaftlichen Entwicklungsperspektiven der photovoltaischen Stromerzeugung. Zahlreiche anschauliche Beispiele verdeutlichen die Konzepte zum Aufbau von Photovoltaikanlagen und machen das Buch zu einer unentbehrlichen Lektüre für Studierende der Ingenieurwissenschaften sowie in der Praxis tätige Techniker/innen und Elektroniker/innen. Durch den didaktischen Aufbau eignet sich das Buch zum Selbststudium aber auch zum Nachschlagen und Wissen auffrischen, zahlreiche Übungsaufgaben vertiefen das Verständnis in die Technik weiter. Schwerpunkte: - Sonnenstrahlung - Grundlagen der Halbleiterphysik - Aufbau und Wirkungsweise der Solarzelle - Zellentechnologien - Solarmodule und Solargeneratoren - Systemtechnik netzgekoppelter Anlagen - Solarstrom und seine Speicherung - Photovoltaische Messtechnik - Planung und Betrieb von Photovoltaikanlagen Parallel zum Buch finden Sie unter www.lehrbuch-photovoltaik.de zusätzliche Informationen, Software sowie die Lösungen der Übungsaufgaben. KW - Solarstrom KW - Solarzelle KW - Photovoltaik KW - Elektrolumineszenz KW - Outdoor-EL Y1 - 2020 SN - 978-3-446-46404-9 PB - Hanser CY - München ER - TY - CHAP A1 - Saatjohann, Christoph A1 - Ising, Fabian A1 - Krings, Luise A1 - Schinzel, Sebastian T1 - STALK: security analysis of smartwatches for kids T2 - ARES 2020: The 15th International Conference on Availability, Reliability and Security / Editors: Melanie Volkamer, Christian Wressnegger N2 - Smart wearable devices become more and more prevalent in the age of the Internet of Things. While people wear them as fitness trackers or full-fledged smartphones, they also come in unique versions as smartwatches for children. These watches allow parents to track the location of their children in real-time and offer a communication channel between parent and child. In this paper, we analyzed six smartwatches for children and the corresponding backend platforms and applications for security and privacy concerns. We structure our analysis in distinct attacker scenarios and collect and describe related literature outside academic publications. Using a cellular network Man-in-the-Middle setup, reverse engineering, and dynamic analysis, we found several severe security issues, allowing for sensitive data disclosure, complete watch takeover, and illegal remote monitoring functionality. KW - Security KW - Privacy Y1 - 2020 U6 - http://nbn-resolving.de/urn/resolver.pl?urn:nbn:de:hbz:836-opus-123548 SN - 978-1-4503-8833-7 SP - 1 EP - 10 ER - TY - JOUR A1 - Gierling, Markus A1 - Saatjohann, Christoph A1 - Dresen, Christian A1 - Köbe, Julia A1 - Rath, Benjamin A1 - Eckardt, Lars A1 - Schinzel, Sebastian T1 - Reviewing Cyber Security Research of Implantable Medical Rhythm Devices regarding Patients’ Risk JF - 86. Jahrestagung und Herztage 2020 der DGK N2 - Introduction: The recent publication of several critical cyber security issues in cardiac implantable devices and the resulting press coverage upsets affected users and their trust in medical device producers. Reviewing the published security vulnerabilities regarding networked medical devices, it raises the question, if the reporting media, the responsible security researchers, and the producers handle security vulnerabilities appropriately. Are the media reports of security vulnerabilities in medical devices meaningful in a way that patients can assess their respective risk for an attack via the security vulnerability? The collaboration between IT-security experts and clinicians aims at reviewing published security vulnerabilities of rhythm devices, and evaluate overall patients risks. Methodology: We performed a literature review on security vulnerabilities in implantable medical devices with a focus on cardiac devices. We analyzed (Fig. 1) the (1) requirements for an attacker and the (2) technical feasibility and clustered them in three different scenarios: The first scenario requires that the attacker physically approaches a victim with a programming device. The second scenario requires proximity to the victim, e.g., within a few meters. The third and strongest attacker scenario is a remote attack that doesn’t require any physical proximity to the victim. We then compare the attacker scenarios and (3) the overall patients’ risks with the press coverage (overhyped, adequate, underhyped). (4) The resulting overall patients’ risk was rated by clinicians (security vulnerability of patients’ data, dangerous programming possible). Results: Out of the three analyzed incidents, we found one to be underhyped, one to be overhyped, and one was appropriate compared to the medial coverage (Fig. 2). The most occurring technical issues were based on the absence of basic security primitives. The patient damage for all of the analyzed incidents was fatal in the worst-case scenario. Further, the patient damage and the overall patient risks are disjunct due to the missing capability of performing large scale attacks. Conclusion: The resulting overall patients’ risks may not adequately reflect the patient damage in the considered cases. Often, the overall patient risk is not as severe as the necessary attacker capabilities are high and it would require strongly motivated attackers to perform the attack. Therefore, most of the reviewed cases are considered with a smaller overall patient risk than implied by press reports. Reviewing the ongoing IT-Security trends regarding implantable medical devices shows an increasing focus on researching in the field of medical device security. Therefore, further findings in the near future are to be expected. To deal with this fact in a responsible way, proper proactive knowledge management is mandatory. We recommend medical staff to critically reflect reports in mass media due to possible sensationalism. Therefore, we propose a joint approach in combining the technical expertise of cyber security experts with clinical aspects of medical experts, to ensure a solid understanding of a newly published vulnerability. The combination of both communities promises to result in better predictions for patients’ risks from security vulnerabilities in implanted cardiac devices. KW - Cyber Security KW - Cardiac Implantable Devices Y1 - 2020 U6 - http://dx.doi.org/10.1007/s00392-020-01621-0 VL - Band 109, Supplement 1, April 2020 SP - 1 EP - 2 ER - TY - CHAP A1 - Müller, Jens A1 - Brinkmann, Marcus A1 - Poddebniak, Damian A1 - Schinzel, Sebastian A1 - Schwenk, Jörg T1 - Mailto: Me Your Secrets. On Bugs and Features in Email End-to-End Encryption T2 - 2020 IEEE Conference on Communications and Network Security (CNS) N2 - OpenPGP and S/MIME are the two major standards for email end-to-end encryption. We show practical attacks against both encryption schemes in the context of email. First, we present a design flaw in the key update mechanism, allowing a third party to deploy a new key to the communication partners. Second, we show how email clients can be tricked into acting as an oracle for decryption or signing by exploiting their functionality to auto-save drafts. Third, we demonstrate how to exfiltrate the private key, based on proprietary mailto parameters implemented by various email clients. An evaluation shows that 8 out of 20 tested email clients are vulnerable to at least one attack. While our attacks do not target the underlying cryptographic primitives, they raise concerns about the practical security of OpenPGP and S/MIME email applications. Finally, we propose countermeasures and discuss their advantages and disadvantages. KW - Cyber Security KW - PGP KW - S/MIME Y1 - 2020 U6 - http://dx.doi.org/10.1109/CNS48642.2020.9162218 SP - 1 EP - 9 ER - TY - CHAP A1 - Müller, Jens A1 - Ising, Fabian A1 - Mla­de­nov, Vla­dis­lav A1 - Mainka, Chris­ti­an A1 - Schinzel, Sebastian A1 - Schwenk, Jörg T1 - Of­fice Do­cu­ment Se­cu­ri­ty and Pri­va­cy T2 - 14th USE­NIX Work­shop on Of­fen­si­ve Tech­no­lo­gies (WOOT 2020) N2 - OOXML and ODF are the de facto standard data formats for word processing, spreadsheets, and presentations. Both are XML-based, feature-rich container formats dating back to the early 2000s. In this work, we present a systematic analysis of the capabilities of malicious office documents. Instead of focusing on implementation bugs, we abuse legitimate features of the OOXML and ODF specifications. We categorize our attacks into five classes: (1) Denial-of-Service attacks affecting the host on which the document is processed. (2) Invasion of privacy attacks that track the usage of the document. (3) Information disclosure attacks exfiltrating personal data out of the victim's computer. (4) Data manipulation on the victim's system. (5) Code execution on the victim's machine. We evaluated the reference implementations – Microsoft Office and LibreOffice – and found both of them to be vulnerable to each tested class of attacks. Finally, we propose mitigation strategies to counter these attacks. KW - Cyber Security KW - Open Document Format KW - docx Y1 - 2020 UR - https://www.usenix.org/conference/woot20/presentation/muller PB - USENIX ER - TY - JOUR A1 - Staacke, Robert A1 - John, Roger A1 - Wunderlich, Ralf A1 - Horsthemke, Ludwig A1 - Knolle, Wolfgang A1 - Laube, Christian A1 - Glösekötter, Peter A1 - Burchard, Bernd A1 - Abel, Bernd A1 - Meijer, Jan T1 - Isotropic Scalar Quantum Sensing of Magnetic Fields for Industrial Application JF - Advanced Quantum Technologies N2 - Magnetic field sensors based on quantum mechanic effects are often susceptible to misalignments of the magnetic field or need advanced procedures to compensate for these. Also, the record breaking sensitivities reported for superconducting quantum interference devices and alkali vapor magnetometers come along with large and complex experimental setups. The nitrogen vacancy center in diamond can be used to design a simple, small, and robust sensor without employing microwave radiation. By using compressed nanodiamond particles, it is possible to eliminate the need of an alignment of the magnetic field and still obtain the absolute magnetic flux density in a single measurement. In order to demonstrate the capabilities of this approach, a centimeter-sized modified automotive demo board is employed as a complete sensor with a sensitivity of 78 µT/Wurzel Hz. KW - Isotropic Scalar Y1 - 2020 U6 - http://dx.doi.org/10.1002/qute.202000037 SP - 1 EP - 8 PB - Wiley-Vch Verlag CY - Weinheim ER - TY - CHAP A1 - Horsthemke, Ludwig A1 - Staake, Robert A1 - Burchard, Bernd A1 - Meijer, Jan A1 - Bischoff, Christian A1 - Glösekötter, Peter T1 - Highly Sensitive Compact Room Temperature Quantum Scalar Magnetormeter T2 - SMSI 2020 N2 - Magnetometry with nitrogen–vacancy (NV) defects in diamond has been extensively stud-ied in the past [1]. While most approaches in-clude the use of microwaves (MW) for the de-tection of electron spin resonance, only few investigate the sensitivity of the photolumines-cence (PL) from NV centers to an external magnetic field without MW [2, 3, 4]. This work aims to utilize this effect to build a highly sensi-tive and compact room temperature magne-tometer. The avoidance of MW serves the re-duction of production costs and allows a com-mercialization at the current patent situation. KW - Highly Sensitive Y1 - 2020 U6 - http://dx.doi.org/10.5162/SMSI2020/A1.4 SP - 47 EP - 48 ER - TY - JOUR A1 - Löchte, Andre A1 - Thranow, Jan-Ole A1 - Gebing, Marcel A1 - Horsthemke, Ludwig A1 - Glösekötter, Peter T1 - Forschungsprojekt Zink-Luft-Akkumulator an der FH Münster JF - VDI Ingenieur forum N2 - Die wachsenden Anteile fluktuierender rege­nerativer Energien in der Energieversorgung (bis 2020 sollen 30 % und 2050 sogar So % des Stroms aus regenerativen Energiequellen stammen) sowie die Steigerung der Elektro­mobilität machen deutlich: Das Thema der Zwischenspeicherung elektrischer Energie ist von höchster gesellschaftlicher Relevanz und verlangt zwingend nach einer Lösung. Neue Technologien, die umweltfreundlich, sicher, leistungsfähig und bezahlbar zugleich sind, müssen deshalb entwickelt werden. KW - Zink-Luft-Akkumulator Y1 - 2020 VL - H 45620 IS - 2/2020 SP - 50 EP - 51 ER - TY - BOOK A1 - Job, Reinhart T1 - Electrochemical Energy Storage N2 - Due to a nonuniform and sometimes unsteady energy yield, a large scale renewable energy supply requires a broadening of centralized and decentralized energy storage systems. On this background, there are high expectations on batteries with regard to various energy storage systems in the near future. In engineering studies, batteries are usually regarded as a black box. However, this point of view is not sufficient and reasonable for the energy storage demands of the near future. Therefore, it is necessary to intensify the knowledge about the advantages and limitations of batteries in engineering lectures – but also in lectures for students of physics or chemistry. The book is written for graduate students from the engineering disciplines, in particular for graduate students of electrical engineering. It should be also of interest for graduate students of physics, chemistry and even industrial engineering. It is not intended to provide a specialized book for distinguished researchers or experts in electrochemistry and/or highly sophisticated battery technology. In particular, the book provides a presentation of the physical basics and principles of electrochemical energy storage. It gives an overview and explanation of the functionality of historical batteries. The electrochemical reaction mechanisms in important primary and secondary batteries are discussed in detail. Moreover, the availability of the relevant raw materials for a growing battery market is emphasized. The book is destined for background reading in corresponding university lectures and useful for self-study, too. KW - Energy Storage KW - Batteries KW - Physics of Batteries KW - Chemistry of Batteries KW - Electrochemistry Y1 - 2020 SN - 978-3-11-048437-3 U6 - http://dx.doi.org/https://doi.org/10.1515/9783110484427 PB - Walter De Gryuter GmbH CY - Berlin, Boston ER - TY - CHAP A1 - Willing, Markus A1 - Dresen, Christian A1 - Haverkamp, Uwe A1 - Schinzel, Sebastian T1 - Analyzing medical device connectivity and its effect on cyber security in german hospitals N2 - Background: Modern healthcare devices can be connected to computer networks and many western healthcareinstitutions run those devices in networks. At the same time, cyber attacks are on the rise and there is evidence thatcybercriminals do not spare critical infrastructure such as major hospitals, even if they endanger patients. Intuitively,the more and closer connected healthcare devices are to public networks, the higher the risk of getting attacked. Methods: To asses the current connectivity status of healthcare devices, we surveyed the field of German hospitalsand especially University Medical Center UMCs. Results: The results show a strong correlation between the networking degree and the number of medical devices.The average number of medical devices is 25.150, with a median of networked medical devices of 3.600. Actual keyusers of networked medical devices are the departments Radiology, Intensive Care, Radio-Oncology RO, NuclearMedicine NUC, and Anaesthesiology in the group of UMCs. In the next five years, the usage of networked medicaldevices will increase significantly in the departments of Surgery, Intensive Care, and Radiology. We detected a strongcorrelation between the degree of connectivity and the likelihood of being attacked.The survey answers regarding the cyber security status reveal a lack of security basics in some of the inquiredhospitals. We did discover successful attacks in hospitals with separated or subsidiary departments. A fusion ofcompetencies on an organizational level facilitates the right behavior here. Most hospitals rated themselvespredominantly positively in the self-assessment but also stated the usefulness of IT security insurance.Conclusions:Concluding our results, hospitals are already facing the consequences of omitted measures within theirgrowing pool of medical devices. Continuously relying on historically grown structures without adaption and trustingmanufactures to solve vectors is a critical behavior that could seriously endanger patients. Y1 - 2020 U6 - http://dx.doi.org/10.1186/s12911-020-01259-y PB - BMC Medical Informatics and Decision Making volume ER - TY - CHAP A1 - Horsthemke, Ludwig A1 - Bischoff, Christian A1 - Glösekötter, Peter A1 - Burchard, Bernd A1 - Staacke, Robert A1 - Meijer, Jan T1 - All optical readout scheme for photoluminescence based magnetic field sensors T2 - 2020 IEEE Sensors, Rotterdam, Netherlands N2 - An improvement on a concept for all optical mag- netometry using nitrogen vacancies in diamond is presented. The concept is based on the fluorescence attenuation of optically pumped nitrogen vacancies by magnetic fields up to ≈ 50 mT. The attenuation is registered by modulating the pumping power to generate a constant signal at a photodetector. A sensitivity of 2.6μT/√Hz at a sampling frequency of 500 Hz is achieved. KW - photoluminescence based magnetic field sensors Y1 - 2020 U6 - http://dx.doi.org/10.1109/SENSORS47125.2020.9278923 SP - 1 EP - 3 ER - TY - BOOK A1 - Poppe, Martin T1 - Grundkurs Theoretische Elektrotechnik N2 - Dieses Buch erklärt, warum es verschiedene Varianten der Maxwell’schen Gleichungen gibt und was genau die physikalische Bedeutung der in ihnen vorkommenden Größen ist. Gezeigt wird ferner, wie sich die Bestimmungsgleichungen für statische elektrische und magnetische Potenziale aus den Maxwell’schen Gleichungen ergeben. Dabei ist die Rolle der dem Feld ausgesetzter Materie immer von Anfang an integraler Bestandteil der Diskussion. Multipolentwicklungen werden begründet und hergeleitet. Ferner wird dargelegt, welches Vereinfachungspotenzial in der Formulierung der dynamischen Theorie als Eichfeldtheorie liegt. Die Gesetze der Optik werden aus denen der Elektrodynamik hergeleitet. Für quasi-stationäre Rechnungen werden Begründungen geliefert, Grenzen formuliert und technische Gegenbeispiele gezeigt. Am Schluss wird auf weiterführende Literatur hingewiesen. KW - Theoretische Elektrotechnik Y1 - 2020 SN - 978-3-662-61913-1 U6 - http://dx.doi.org/10.1007/978-3-662-61914-8 PB - Springer CY - Heidelberg ER - TY - CHAP A1 - Völker, Timo A1 - Volodina, Ekaterina A1 - Tüxen, Michael A1 - Rathgeb, Erwin Paul T1 - A QUIC Simulation Model for INET and its Application to the Acknowledgment Ratio Issue T2 - 2020 IFIP Networking Conference N2 - Quick UDP Internet Connections (QUIC) is a novel transport protocol introducing known features in a new protocol design. To investigate these features and the design, we developed a QUIC implementation in the INET simulation model suite. In this paper, we describe that implementation, its validation and a result achieved using the simulation model. The result shows the negative impact on throughput, when raising the acknowledgment ratio. We propose a solution and describe how it solves the issue. KW - QUIC KW - INET OMNeT++ KW - Protocol Simulation KW - Transport Protocol KW - Ack Ratio Y1 - 2020 U6 - http://nbn-resolving.de/urn/resolver.pl?urn:nbn:de:hbz:836-opus-149662 UR - https://ieeexplore.ieee.org/document/9142723 SN - 978-3-903176-28-7 SP - 737 EP - 742 PB - IEEE CY - New York, NY, USA ER - TY - GEN A1 - Fairhurst, Gorry A1 - Jones, Tom A1 - Tüxen, Michael A1 - Rüngeler, Irene A1 - Völker, Timo T1 - Packetization Layer Path MTU Discovery for Datagram Transports Y1 - 2020 UR - https://www.rfc-editor.org/info/rfc8899 U6 - http://dx.doi.org/10.17487/RFC8899 PB - IETF ER -