Publications

Peer-Reviewed

Onelogon: Taking over Active Directory Accounts via Netlogon

Alexander Neff, ,

Proceedings of the 20th USENIX WOOT Conference on Offensive Technologies (WOOT), August 2026

New Platform, Old Issues: How Web-based TV Broadcasts threaten Users' Security

Carlotta Tagliaro, Andrej Danis, , Martina Lindorfer

Proceedings of the 23rd Conference on Detection of Intrusions and Malware & Vulnerability Assessment (DIMVA), July 2026

StorFuzz: Using Data Diversity to Overcome Fuzzing Plateaus

, ,

Proceedings of the 48th IEEE/ACM International Conference on Software Engineering (ICSE), April 2026

Hallucinating Certificates: Differential Testing of TLS Certificate Validation Using Generative Language Models

, Kyle Posluns, , Martina Lindorfer, David Choffnes

Proceedings of the 48th IEEE/ACM International Conference on Software Engineering (ICSE), April 2026

The Things That Count: Coverage Evaluation Under the Microscope (Registered Report)

, ,

Proceedings of the 5th International Fuzzing Workshop (FUZZING), February 2026

Pogofuzz: Profile-Guided Optimization for Fuzzing (Registered Report)

, ,

Proceedings of the 5th International Fuzzing Workshop (FUZZING), February 2026

Does Representation Matter? Evaluating IRs for LLM-based Binary Decompilation

Tomás Pelayo-Benedet, , Ricardo J. Rodríguez

Proceedings of the 9th Workshop on Binary Analysis Research (BAR), February 2026

Large-Scale Security Analysis of Real-World Backend Deployments Speaking IoT-Focused Protocols

Carlotta Tagliaro, Martina Komsic, Andrea Continella, , Martina Lindorfer

Proceedings of the 27th International Symposium on Recent Advances in Intrusion Detection (RAID), September 2024

Are You Sure You Want To Do Coordinated Vulnerability Disclosure?

Ting-Han Chen, Carlotta Tagliaro, Martina Lindorfer, , Jeroen van der Ham-de Vos

Proceedings of the 9th International Workshop on Traffic Measurements for Cybersecurity (WTMC), July 2024

IoTFlow: Inferring IoT Device Behavior at Scale through Static Mobile Companion App Analysis

David Schmidt, Carlotta Tagliaro, , Martina Lindorfer

Proceedings of the 30th ACM SIGSAC Conference on Computer and Communications Security (CCS), November 2023

Pushing Boundaries: An Empirical View on the Digital Sovereignty of Six Governments in the Midst of Geopolitical Tensions

Bernardus Jansen, Natalia Kadenko, Dennis Broeders, Michel van Eeten, , Tobias Fiebig

Government Information Quarterly (GIQ) (Volume 40, Issue 4), August 2023

Whiteboxgrind – Automated Analysis of Whitebox Cryptography

, Katharina Bogad, Michael Gruber

Proceedings of the 12th International Workshop on Constructive Side-Channel Analysis and Secure Design (COSADE), April 2023

Out of Sight, Out of Mind: Detecting Orphaned Web Pages at Internet-Scale

Stijn Pletinckx, , Tobias Fiebig

Proceedings of the 28th ACM SIGSAC Conference on Computer and Communications Security (CCS), November 2021

Designing for Tussle in Encrypted DNS

Austin Hounsel, Paul Schmitt, , Nick Feamster

Proceedings of the 20th Workshop on Hot Topics in Networking (HotNets), November 2021

Cyber Grand Shellphish

Antonio Bianchi, , Jacopo Corbetta, Francesco Disperati, Andrew Dutcher, John Grosen, Paul Grosen, Aravind Machiry, Christopher Salls, Yan Shoshitaishvili, Nick Stephens, Giovanni Vigna, Ruoyu Wang

Phrack (Volume 15, Issue 70), October 2021

Authors listed alphabetically.

Encryption without Centralization: Distributing DNS Queries Across Recursive Resolvers

Austin Hounsel, Paul Schmitt, , Nick Feamster

Proceedings of the 2021 Applied Networking Research Workshop (ANRW), July 2021

Extended abstract. Co-located with IETF 105.

Can Encrypted DNS Be Fast?

Austin Hounsel, Paul Schmitt, , Nick Feamster

Proceedings of the 22nd Passive and Active Measurement (PAM), March 2021

Those Who Know Don't, Those Who Don't Know Deploy: Understanding Security Awareness in the Adoption of Industrial IoT

Verena Schrama, Carlos H. Gañán, Doris Aschenbrenner, Mark de Reuver, , Tobias Fiebig

Proceedings of the 20th Workshop on the Economics of Information Security (WEIS), December 2020

Identifying Disinformation Websites Using Infrastructure Features

Austin Hounsel, Jordan Holland, Ben Kaiser, , Nick Feamster, Jonathan Mayer

Proceedings of the 10th USENIX Workshop on Free and Open Communications on the Internet, August 2020

Understanding The Performance Costs and Benefits of Privacy-focused Browser Extensions

, Nick Feamster

Proceedings of the 29th The Web Conference (TheWebConf, formerly known as WWW), April 2020

Comparing the Effects of DNS, DoT, and DoH on Web Performance

Austin Hounsel, , Paul Schmitt, Jordan Holland, Nick Feamster

Proceedings of the 29th The Web Conference (TheWebConf, formerly known as WWW), April 2020

How DNS over HTTPS is Reshaping Privacy, Performance, and Policy in the Internet Ecosystem

, Tithi Chattopadhyay, Nick Feamster, Mihir Kshirsagar, Jordan Holland, Austin Hounsel, Paul Schmitt

Proceedings of the 47th Research Conference on Communications, Information and Internet Policy (TPRC), September 2019

Authors listed alphabetically.

Analyzing the Costs (and Benefits) of DNS, DoT, and DoH for the Modern Web

Austin Hounsel, , Paul Schmitt, Jordan Holland, Nick Feamster

Proceedings of the 2019 Applied Networking Research Workshop (ANRW), July 2019

Extended abstract. Co-located with IETF 105.

Investigating Operators' Perspective on Security Misconfigurations

Constanze Dietrich, Katharina Krombholz, , Tobias Fiebig

Proceedings of the 25th ACM SIGSAC Conference on Computer and Communications Security (CCS), October 2018

Rampart: Protecting Web Applications from CPU-Exhaustion Denial-of-Service Attacks

Wei Meng, Chenxiong Qian, Shuang Hao, , Giovanni Vigna, Christopher Kruegel, Wenke Lee

Proceedings of the 27th USENIX Security Symposium (USENIX Security), August 2018

Cloud Strife: Mitigating the Security Risks of Domain-Validated Certificates

, Tobias Fiebig, Shuang Hao, Christopher Kruegel, Giovanni Vigna

Proceedings of the 2018 Applied Networking Research Workshop (ANRW), July 2018

Extended abstract. Co-located with IETF 102.

Enumerating Active IPv6 Hosts for Large-scale Security Scans via DNSSEC-signed Reverse Zones

, Shuang Hao, Tobias Fiebig, Giovanni Vigna

Proceedings of the 39th IEEE Symposium on Security & Privacy (S&P), May 2018

Mechanical Phish: Resilient Autonomous Hacking

Yan Shoshitaishvili, Antonio Bianchi, , Amat Cama, Jacopo Corbetta, Francesco Disperati, Andrew Dutcher, John Grosen, Paul Grosen, Aravind Machiry, Christopher Salls, Nick Stephens, Ruoyu Wang, Giovanni Vigna

IEEE Security & Privacy, March 2018

In rDNS We Trust: Revisiting a Common Data-Source's Reliability

Tobias Fiebig, , Shuang Hao, Christopher Kruegel, Giovanni Vigna, Anja Feldmann

Proceedings of the 19th Passive and Active Measurement (PAM), March 2018

Cloud Strife: Mitigating the Security Risks of Domain-Validated Certificates

, Tobias Fiebig, Shuang Hao, Christopher Kruegel, Giovanni Vigna

Proceedings of the 25th Network and Distributed System Security Symposium (NDSS), February 2018

Something From Nothing (There): Collecting Global IPv6 Datasets From DNS

Tobias Fiebig, , Shuang Hao, Christopher Kruegel, Giovanni Vigna

Proceedings of the 18th Passive and Active Measurement (PAM), March 2017

Drops for Stuff: An Analysis of Reshipping Mule Scams

Shuang Hao, , Nick Nikiforakis, Gianluca Stringhini, Manuel Egele, Michael Eubanks, Brian Krebs, Giovanni Vigna

Proceedings of the 22nd ACM SIGSAC Conference on Computer and Communications Security (CCS), October 2015

Meerkat: Detecting Website Defacements through Image-based Object Recognition

, Christopher Kruegel, Giovanni Vigna

Proceedings of the 24th USENIX Security Symposium (USENIX Security), August 2015

Internet Defense Prize Finalist.

What You Submit is Who You Are: A Multi-Modal Approach for Deanonymizing Scientific Publications

Mathias Payer, Ling Huang, Neil Zhenqiang Gong, , Mario Frank

IEEE Transactions on Information Forensics and Security (TIFS) (Volume 10, Issue 1), January 2015

Protecting Web Single Sign-on against Relying Party Impersonation Attacks through a Bi-directional Secure Channel with Authentication

Yinzhi Cao, Yan Shoshitaishvili, , Christopher Kruegel, Giovanni Vigna, Yan Chen

Proceedings of the 17th International Symposium on Recent Advances in Intrusion Detection (RAID), September 2014

Ten Years of iCTF: The Good, The Bad, and The Ugly

Giovanni Vigna, , Jacopo Corbetta, Adam Doupé, Yanick Fratantonio, Luca Invernizzi, Dhilung Kirat, Yan Shoshitaishvili

Proceedings of the 1st USENIX Summit on Gaming, Games and Gamification in Security Education (3GSE), August 2014

Relevant Change Detection: Framework for the Precise Extraction of Modified and Novel Web-based Content as a Filtering Technique for Analysis Engines

, Christopher Kruegel, Giovanni Vigna

Proceedings of the 23rd World Wide Web Conference (WWW), April 2014

Developers' Track.

Delta: Automatic Identification of Unknown Web-based Infection Campaigns

, Christopher Kruegel, Giovanni Vigna

Proceedings of the 20th ACM SIGSAC Conference on Computer and Communications Security (CCS), November 2013

Preprints

Human Factors in Security Research: Lessons Learned from 2008-2018

Mannat Kaur, Michel van Eeten, Marijn Janssen, , Tobias Fiebig

March 2021

Classifying Network Vendors at Internet Scale

Jordan Holland, Ross Teixera, Paul Schmitt, , Jennifer Rexford, Nick Feamster, Jonathan Mayer

June 2020