I'm an infosec researcher working as a postdoc in the Secure Systems group at the Graz University of Technology, Institute of Applied Information Processing and Communications (see my profile there), where I also obtained my PhD in June 2017. In summer 2016 I've been an intern at Microsoft Research Cambridge. In my research I explore software-based microarchitectural attacks and operating system features.
I teach undergraduate courses (Operating Systems, System-Level Programming) and graduate courses (Embedded Security, Security Aspects in Software Development).
Publications
Presentations
|
2018
June |
Software-based Microarchitectural Attacks
Invited Talk @ Austrian Computer Science Day, Salzburg, Austria, June 15, 2018 |
| May |
The Story of Meltdown and Spectre
Talk @ RuhrSec, Bochum, Germany, May 17-18, 2018 |
| April |
Software-based Microarchitectural Attacks
Invited Talk @ CRYPTACUS Training School, Azores, Portugal, April 16-20, 2018 |
|
Software-based Microarchitectural Attacks
Invited Talk @ Symposium and Bootcamp on the Science of Security (HotSoS), Raleigh, NC, USA, April 10-11, 2018 |
|
| March |
Software-based Microarchitectural Attacks
Invited Talk @ RISE Spring School, Cambridge, UK, March 28-29, 2018 |
|
Software-based Microarchitectural Attacks: What do we learn from Meltdown and Spectre?
Guest Talk @ Apple, Cupertino, California, USA, March 27, 2018 |
|
|
Microarchitectural Attacks and the Case of Meltdown and Spectre
Invited Talk @ Insomni'hack, Geneva, Switzerland, March 22-23, 2018 |
|
|
Software-based Microarchitectural Attacks
Talk @ Security and Privacy Group, University of Birmingham, UK, March 21, 2018 |
|
|
Microarchitectural Attacks: Meltdown, Spectre, Rowhammer
Talk @ King's College London, UK, March 20, 2018 |
|
|
Microarchitectural Attacks: From the Basics to Arbitrary Read and Write Primitives without any Software Bugs
Talk @ CISPA Saarland, Saarbrücken, Germany, March 16, 2018 |
|
|
Microarchitectural Attacks: Meltdown, Spectre, Rowhammer
Invited Talk @ Austrian Trust Circle der öffentlichen Verwaltung, Salzburg, Austria, March 1, 2018 |
|
| February |
Kurzüberblick zu Meltdown und Spectre
Invited Talk @ Digitaldialog, Graz, Austria, February 27, 2018 |
|
Software-based Microarchitectural Attacks
Invited Talk @ NeCS Cyber Security Winter School, Trento, Italy, February 12-16, 2018 |
|
|
Microarchitectural Attacks: From the Basics to Arbitrary Read and Write Primitives
Guest Talk @ Microsoft Research Cambridge, UK, February 05, 2018 |
|
| January |
Brief Overview on Meltdown and Spectre
Talk @ European Government CERT Meeting, Vienna, Austria, January 26, 2018 |
|
Microarchitectural Attacks and Defenses in JavaScript
Guest Talk (Joint presentation with Moritz Lipp and Michael Schwarz) @ Google, Munich, Germany, January 25, 2018 |
|
|
Beyond Belief: The Case of Spectre and Meltdown
Keynote (Joint presentation with Moritz Lipp and Michael Schwarz) @ BlueHat IL, Tel Aviv, Israel, January 24, 2018 |
|
|
Software-based Microarchitectural Attacks
Invited Talk @ CERT.at IT Security Stammtisch, Vienna, Austria, January 10, 2018 |
|
|
2017
November |
Why SGX design flaws hinder its application in cloud computing
Invited Talk @ Workshop on Cryptography for the Internet of Things and Cloud, Bochum, Germany, November 06-07, 2017 |
| October |
Oh my Cache! 2 - More fun with caches.
Guest Talk @ QSP Lab, University of Innsbruck, Innsbruck, Austria, October 13, 2017 |
| September |
Cash Attacks on SGX
Invited Talk (Joint presentation with Michael Schwarz) @ Breaking Bitcoin, Paris, France, September 09-10, 2017 |
| June |
Rowhammer Attacks: An Extended Walkthrough Guide
Guest Talk @ SBA Research, Vienna, Austria, June 27, 2017 |
| May |
How processor performance is tied to side-channel leakage: With great speed comes great leakage
Joint presentation with Moritz Lipp @ Qualcomm Mobile Security Summit, San Diego, CA, USA, May 18-19, 2017 |
|
Rowhammer Attacks: A Walkthrough Guide
Joint presentation with Clémentine Maurice @ RuhrSec, Bochum, Germany, May 4-5, 2017 |
|
|
2016
October |
Microarchitectural Incontinence - You would leak too if you were so fast!
Invited talk @ 13th Hacktivity conference, Budapest, Hungary, October 21-22, 2016 |
|
Oh my Cache! - Introduction to having fun with your Cache.
Guest Talk @ QSP Lab, University of Innsbruck, Innsbruck, Austria, October 21, 2016 |
|
| August |
Microarchitectural Attacks (and what we can do against them)
Guest Talk @ Constructive Security Group, Microsoft Research Cambridge, UK, August 25, 2016 |
|
Software-based Microarchitectural Attacks
Guest Talk @ Qualcomm, San Diego, California, USA, August 8, 2016 |
|
|
Using Undocumented CPU Behavior to See into Kernel Mode and Break KASLR in the Process
Joint presentation with Anders Fogh @ BlackHat USA 2016, Las Vegas, USA, July 30 - August 4, 2016 |
|
| April |
Cache Side-Channel Attacks and the case of Rowhammer
Invited talk @ RuhrSec, Bochum, Germany, April 28-29, 2016 |
|
2015
December |
Rowhammer.js: Root privileges for web apps?
Joint presentation with Clémentine Maurice @ 32nd Chaos Communication Congress, Hamburg, Germany, December 27-30, 2015 |
| November |
Software-based Side-Channel and Fault Attacks
Invited Talk @ MooseCon 2015, Palo Alto, California, USA, November 19-20, 2015 |
Service
- Technical Program Committee: CCS'18, WOOT '18, SPACE'18, WoSSCA'18
- Reviewer: AJSE, PLOS ONE, IET Information Security
- External Reviewer: PoPETS'18, DIMVA'17, EUROCRYPT'17, CHES'16, CT-RSA'16, DATE'16, CT-RSA'15, DATE'15, Indocrypt'15
- On-site organization: COSADE'16