@book{Schuba1999, author = {Schuba, Marko}, title = {Skalierbare und zuverl{\"a}ssige Multicast-Kommunikation im Internet}, publisher = {Shaker}, address = {Aachen}, isbn = {3-8265-6289-5}, pages = {IV, 198 S. : graph. Darst.}, year = {1999}, language = {de} } @article{Schuba1997, author = {Schuba, Marko}, title = {A Performance Evaluation of Connectionless Overlay Networks for ATM}, series = {INFOCOM ´97. Sixteenth Annual Joint Conference of the IEEE Computer and Communications Societies. Proceedings Vol. 1}, journal = {INFOCOM ´97. Sixteenth Annual Joint Conference of the IEEE Computer and Communications Societies. Proceedings Vol. 1}, isbn = {0-8186-7780-5}, pages = {152 -- 158}, year = {1997}, language = {en} } @article{Schuba1998, author = {Schuba, Marko}, title = {SRMT-a scalable and reliable multicast transport protocol}, series = {IEEE International Conference on Communications, 1998. ICC 98. Vol. 1}, journal = {IEEE International Conference on Communications, 1998. ICC 98. Vol. 1}, isbn = {0-7803-4788-9}, pages = {612 -- 616}, year = {1998}, language = {en} } @article{Schuba1999, author = {Schuba, Marko}, title = {Analysis of Feedback Error Control Schemes for Block Based Video Communication / Meggers, Jens ; Schuba, Marko}, year = {1999}, language = {en} } @article{SchaeferHoefkenSchuba2011, author = {Schaefer, Thomas and H{\"o}fken, Hans-Wilhelm and Schuba, Marko}, title = {Windows Phone 7 from a Digital Forensics' Perspective}, publisher = {Springer}, address = {Berlin}, year = {2011}, language = {en} } @inproceedings{NethSchubaBrodkorbetal.2023, author = {Neth, Jannik and Schuba, Marko and Brodkorb, Karsten and Neugebauer, Georg and H{\"o}ner, Tim and Hack, Sacha}, title = {Digital forensics triage app for android}, series = {ARES '23: Proceedings of the 18th International Conference on Availability, Reliability and Security}, booktitle = {ARES '23: Proceedings of the 18th International Conference on Availability, Reliability and Security}, publisher = {ACM}, isbn = {9798400707728}, doi = {10.1145/3600160.3605017}, pages = {6 Seiten}, year = {2023}, abstract = {Digital forensics of smartphones is of utmost importance in many criminal cases. As modern smartphones store chats, photos, videos etc. that can be relevant for investigations and as they can have storage capacities of hundreds of gigabytes, they are a primary target for forensic investigators. However, it is exactly this large amount of data that is causing problems: extracting and examining the data from multiple phones seized in the context of a case is taking more and more time. This bears the risk of wasting a lot of time with irrelevant phones while there is not enough time left to analyze a phone which is worth examination. Forensic triage can help in this case: Such a triage is a preselection step based on a subset of data and is performed before fully extracting all the data from the smartphone. Triage can accelerate subsequent investigations and is especially useful in cases where time is essential. The aim of this paper is to determine which and how much data from an Android smartphone can be made directly accessible to the forensic investigator - without tedious investigations. For this purpose, an app has been developed that can be used with extremely limited storage of data in the handset and which outputs the extracted data immediately to the forensic workstation in a human- and machine-readable format.}, language = {en} } @article{MausHoefkenSchuba2011, author = {Maus, Stefan and H{\"o}fken, Hans-Wilhelm and Schuba, Marko}, title = {Forensic Analysis of Geodata in Android Smartphones}, pages = {1 -- 11}, year = {2011}, language = {en} } @inproceedings{LogenHoefkenSchuba2012, author = {Logen, Steffen and H{\"o}fken, Hans and Schuba, Marko}, title = {Simplifying RAM Forensics : A GUI and Extensions for the Volatility Framework}, series = {2012 Seventh International Conference on Availability, Reliability and Security (ARES), 20-24 August 2012, Prague, Czech Republic}, booktitle = {2012 Seventh International Conference on Availability, Reliability and Security (ARES), 20-24 August 2012, Prague, Czech Republic}, publisher = {IEEE}, address = {New York}, isbn = {978-1-4673-2244-7}, doi = {10.1109/ARES.2012.12}, pages = {620 -- 624}, year = {2012}, abstract = {The Volatility Framework is a collection of tools for the analysis of computer RAM. The framework offers a multitude of analysis options and is used by many investigators worldwide. Volatility currently comes with a command line interface only, which might be a hinderer for some investigators to use the tool. In this paper we present a GUI and extensions for the Volatility Framework, which on the one hand simplify the usage of the tool and on the other hand offer additional functionality like storage of results in a database, shortcuts for long Volatility Framework command sequences, and entirely new commands based on correlation of data stored in the database.}, language = {en} } @inproceedings{LindenlaufHoefkenSchuba2015, author = {Lindenlauf, Simon and H{\"o}fken, Hans-Wilhelm and Schuba, Marko}, title = {Cold Boot Attacks on DDR2 and DDR3 SDRAM}, series = {10th International Conference on Availability, Reliability and Security (ARES) 2015}, booktitle = {10th International Conference on Availability, Reliability and Security (ARES) 2015}, doi = {10.1109/ARES.2015.28}, pages = {287 -- 292}, year = {2015}, language = {en} } @inproceedings{KueppersSchubaNeugebaueretal.2023, author = {K{\"u}ppers, Malte and Schuba, Marko and Neugebauer, Georg and H{\"o}ner, Tim and Hack, Sacha}, title = {Security analysis of the KNX smart building protocol}, series = {ARES '23: Proceedings of the 18th International Conference on Availability, Reliability and Security}, booktitle = {ARES '23: Proceedings of the 18th International Conference on Availability, Reliability and Security}, publisher = {ACM}, doi = {10.1145/3600160.3605167}, pages = {1 -- 7}, year = {2023}, abstract = {KNX is a protocol for smart building automation, e.g., for automated heating, air conditioning, or lighting. This paper analyses and evaluates state-of-the-art KNX devices from manufacturers Merten, Gira and Siemens with respect to security. On the one hand, it is investigated if publicly known vulnerabilities like insecure storage of passwords in software, unencrypted communication, or denialof-service attacks, can be reproduced in new devices. On the other hand, the security is analyzed in general, leading to the discovery of a previously unknown and high risk vulnerability related to so-called BCU (authentication) keys.}, language = {en} }