Security Engineering @ HPI

Research, teaching and systems for practical cybersecurity.

Practice-Oriented Cybersecurity Teaching and Research at HPI

The IT Security Engineering team at the Hasso Plattner Institute, University of Potsdam (Sec-Eng@HPI), conducts research and teaching at the forefront of cybersecurity, with a focus on emerging attack and defence techniques.

Our goal is to understand how modern cyberattacks operate in the real world, especially in large-scale networked environments, and to develop effective methods for detecting and responding to them. We design and implement innovative security solutions that address practical challenges and can be validated in real-world settings, either on operational data or directly within enterprise infrastructures.

Our work spans security analytics, cyber threat intelligence, attack modelling and penetration testing, and security automation, with a growing emphasis on both the application of AI to security operations and the security of AI systems themselves.

Our work is strongly practice-oriented and often carried out together with industry partners. The resulting insights are translated into prototypes, platforms and scientific publications that address real-world security challenges. These topics also shape our teaching, from lectures and seminars to research projects and thesis opportunities for bachelor's, master's and PhD students.

9
Current members
41
Alumni
15
Completed PhD dissertations
21
Master/Diplom theses supervised
61
Courses taught
116
Publications

Statistics: 2010 till now

Partners and collaborations

  • Commercialisation of the "Physical Separation Technology" Lock-Keeper, and ML-based security analytics on the HANA platform.

  • Graph modelling of security-relevant data, and advanced threat detection library.

  • Advanced analytics for enterprise security operations, AI-driven threat detection and automated incident response.

  • Big-data security analytics for enterprise data-management, intelligent lifecycle management for enterprise cloud, AI-driven threat data center operaations.

  • Secure distributed cloud storage, attribute-based access control, and secure identity management.

Research areas

AI and security

Language models and autonomous agents are arriving on both sides of security work at once: they promise to take load off analysts, and they open an attack surface that conventional controls only partly cover.

Learn more: AI and security

Security analytics

Complex attacks leave evidence across many systems. Looking at one host or one event in isolation can miss the relationships that distinguish routine activity from an attack.

Learn more: Security analytics

Threat intelligence

Security teams need structured, enriched and domain-specific threat information that can be collected and served efficiently.

Learn more: Threat intelligence

Secure identities

Passwords and central identity providers leave usability, privacy and control problems. The group studied continuous authentication and user-controlled credentials.

Learn more: Secure identities

Security education

Internet security affects people without specialist training. The group studied accessible online courses and practical learning formats.

Learn more: Security education

Secure cloud and data protection

Storing data with a cloud provider means trusting that provider. The group studied how confidentiality and availability can be preserved even when individual providers are untrusted or unavailable.

Learn more: Secure cloud and data protection

Theses, student jobs and PhD positions

We regularly offer topics for bachelor and master theses as well as research assistant positions.

Join us

Teaching

Show more: Teaching

Recent publications

Show more: Recent publications