Forschung

Unsere Forschung verbindet große Mengen an Sicherheitsdaten mit den Systemen und Entscheidungen, die nötig sind, um daraus zu handeln. Die Schwerpunkte reichen von Security Analytics, Threat Intelligence und sicheren Identitäten über Sicherheitsbildung bis hin zum Einsatz und zur Sicherheit von KI-Systemen sowie zum Schutz von Daten in der Cloud.

AI and security

  • AI for SOC
  • Agentic systems
  • LLM security
  • Prompt injection
  • Secure AI

Language models and autonomous agents are arriving on both sides of security work at once: they promise to take load off analysts, and they open an attack surface that conventional controls only partly cover.

The first direction asks what AI can do for security operations. Analysts face more alerts than can be triaged by hand, spread across tools that share no common data model, and much of the effort goes into reconstructing context that already exists somewhere in the organisation. The group studies how language models and agents can support that work — enriching and correlating alerts, connecting threat intelligence to telemetry, turning intelligence into detection logic, and explaining a finding well enough for someone to act on it — while keeping the decisions that matter under human control and measuring the quality of the result rather than assuming it.

The second direction turns the question around and treats the AI system itself as the target. Prompts, retrieved documents, memory, tool descriptions and tool responses are all inputs that may carry untrusted content, and an agent able to call tools and reach other systems can be made to act on it. Work here covers the attack surface of model- and agent-based applications, injection attacks that cross from natural language into downstream systems such as databases, the telemetry needed to reconstruct what a model or an agent actually did, and systematic adversarial testing, so that defences are measured against attacks rather than against expectations.

Schwerpunkte

  • AI-assisted security operations
  • Advanced analytics for threat detection
  • Security of LLM applications
  • Prompt-injection defence
  • Agentic security

Personen

Security analytics

  • SIEM
  • Anomaly detection
  • Graph analytics
  • Stream processing

Complex attacks leave evidence across many systems. Looking at one host or one event in isolation can miss the relationships that distinguish routine activity from an attack.

The group builds and studies the whole analytics chain behind a SIEM: collecting security events from network, host and application sources, normalising them into a common representation, correlating them across sources, and running detection and analytics on top. Successive generations of an in-house analytics platform moved that pipeline onto distributed and edge-oriented infrastructure, using cluster storage, stream and batch processing and notebook-based analysis, so that methods can be tested against realistic event volumes rather than toy datasets.

On the detection side the work ranges from statistical and machine-learning anomaly detection to graph-based investigation, where hosts, users, processes and network endpoints are modelled as a graph so that multi-step attacks appear as paths rather than as isolated alerts. Recurring themes include high-throughput event normalisation, clustering and pattern mining over firewall, proxy, DNS and Windows event logs, ranking of malicious infrastructure, and the detection of periodic command-and-control communication. A further strand keeps detection knowledge independent of any one product, describing each approach in a structured, machine-readable form so that it can be implemented on whichever platform an organisation actually runs.

Schwerpunkte

  • Security data pipelines
  • Event-stream processing
  • Anomaly detection
  • Graph-based investigation
  • SIEM architectures
  • Detection engineering

Personen

Forschungsprototypen

Im HPI-Netzwerk verfügbar

Threat intelligence

  • Vulnerabilities
  • Attack graphs
  • Identity leaks

Security teams need structured, enriched and domain-specific threat information that can be collected and served efficiently.

Threat intelligence is only useful when it is structured, current, and connected to the systems that act on it. The group operates and studies a vulnerability database that collects, normalises and enriches publicly disclosed vulnerabilities, and pairs it with an open threat-intelligence platform so that indicators, malware families, campaigns and adversary techniques are stored as linked entities rather than as isolated feed entries.

Research on that base covers the extraction of structured intelligence from unstructured reports, the automated generation of intelligence reports, knowledge graphs that model security entities according to the task at hand, and contextualised observables that carry enough surrounding detail to support an investigation rather than just a match. Related work builds attack graphs that combine vulnerability, configuration and topology data to show how an attacker could traverse a network, applies fingerprinting to characterise exposed systems, and processes large volumes of leaked credential data so that affected users can be warned.

Schwerpunkte

  • Vulnerability information
  • Threat-intelligence platforms
  • Attack graphs
  • Identity-leak processing
  • Security knowledge graphs

Personen

Forschungsprototypen

Im HPI-Netzwerk verfügbar

Secure identities

  • Authentication
  • Self-sovereign identity
  • Credentials

Passwords and central identity providers leave usability, privacy and control problems. The group studied continuous authentication and user-controlled credentials.

Behavioural authentication asks whether the way a person moves, types or handles a device can help establish who they are. The group ran multi-year sensor studies to test that question: recording how participants carry and interact with a smartphone while walking, and instrumenting a touch-sensitive door handle across several hardware generations with pressure, motion and distance sensors to see whether the way someone presses a handle can identify them at room entry. Alongside the experiments, a domain model was developed so that behavioural authentication systems — and, just as importantly, their evaluations — can be described and compared consistently, instead of every study inventing its own metrics.

A second strand works with established identity standards rather than replacing them: using phones as roaming FIDO2 authenticators over Bluetooth, operating an OpenID Connect provider, and building a gateway that lets self-sovereign identities be consumed through conventional protocols such as OpenID Connect and SAML, so that decentralised credentials can be adopted without rewriting every relying application. Trust-level concepts and quantifiable trust models for claims and attestations link the two strands, turning a continuous behavioural signal into something an application can actually consume.

Schwerpunkte

  • Behaviour-based authentication
  • Self-sovereign identity
  • Digital credentials
  • FIDO2 and WebAuthn
  • Privacy in peer-to-peer networks

Security education

  • MOOCs
  • Awareness
  • CTF

Internet security affects people without specialist training. The group studied accessible online courses and practical learning formats.

Security education at scale runs through openHPI, where the group has contributed to open online courses on cybersecurity fundamentals, internet safety, cloud computing, blockchain and web technologies, reaching an audience well beyond enrolled students. A module on technical information security was also prepared for the eGov-Campus platform, aimed at professionals working in public administration.

The practical side is built on doing rather than watching. A capture-the-flag seminar sets attacking and defending teams against each other inside a persistent fictional company, complete with the kind of ageing, half-documented services found in real organisations, while lab courses run on automatically built virtual-machine images and custom network challenges so that students work on realistic infrastructure. Research accompanies the teaching, including studies of how effective online courses really are at changing behaviour towards phishing, and of how best to tell people that their credentials have appeared in a leak.

Schwerpunkte

  • Security MOOCs
  • Practical security teaching
  • Capture-the-flag formats
  • Security awareness
  • Identity-leak communication

Personen

Secure cloud and data protection

  • Cloud storage
  • Encryption
  • Access control

Storing data with a cloud provider means trusting that provider. The group studied how confidentiality and availability can be preserved even when individual providers are untrusted or unavailable.

One line of work distributed data across several independent cloud providers using erasure coding, so that no single provider ever holds a usable copy and the loss of one provider does not mean the loss of the data. The approach was implemented end to end, with web and mobile clients and with tooling to measure the trade-off between redundancy, storage cost and performance.

A second line applied attribute-based encryption, where access follows from the attributes a user holds rather than from a list of named individuals, and the data itself enforces the policy. The implementations added the properties such schemes need outside the laboratory — revoking users, and tracing the origin of leaked decryption keys — and were complemented by work on distributed data provenance and on access control that takes the physical location of a request into account.

Schwerpunkte

  • Multi-cloud redundancy
  • Attribute-based encryption
  • Data provenance
  • Location-based access control