Schiller, Katharina; Adamsky, Florian (2022)
11th International Workshop on Socio-Technical Aspects in Security affiliated with the 26th European Symposium on Research in Computer Security (ESORICS 2021), S. 182-193.
DOI: 10.1007/978-3-031-10183-0_9
E-mail is nearly 50 years old and is still one of the most used communication protocols nowadays. However, it has no support for End-to-end encryption (E2EE) by default, which makes it inappropriate for sending sensitive information. This is why two e-mail encryption standards have been developed—namely, Secure/Multipurpose Internet Mail Extensions (S/MIME) and OpenPGP. Previous studies found that bad usability of encryption software can lead to software that is incorrectly used or not at all. Both consequences have a fatal impact on users’ security and privacy. In recent years, the number of e-mails that are read and written on mobile devices has increased drastically. In this paper, we conduct to the best of our knowledge, the first usability study of e-mail encryption apps on smartphones. We tested two mobile apps, one uses OpenPGP on Android and one uses S/MIME on iOS. In our usability study, we tested both apps with eleven participants and evaluated the usability with the System Usability Scale (SUS) and the Short Version of User Experience Questionnaire (UEQ-S). Our study shows that both apps have several usability issues which partly led to unencrypted e-mails and participants sending their passphrase instead of their public key.
Ruscheweyh, Ruth; Klonowski, Theresa; Goßrau, Gudrun; Kraya, Torsten; Gaul, Charly; Straube, Andreas; Jürgens, Tim Patrick; Scheidt, Jörg; Förderreuther, Stefanie (2022)
Ruscheweyh, Ruth; Klonowski, Theresa; Goßrau, Gudrun; Kraya, Torsten; Gaul, Charly...
The Journal of Headache and Pain 2022 23 (74).
DOI: 10.1186/s10194-022-01447-3
Although good treatment options exist for many headache disorders, not all patients benefit and disability continues to be large. To design strategies for improving headache care, real-world data observing standard care is necessary. Therefore, the German Migraine and Headache Society (DMKG) has established the DMKG Headache Registry. Here we present methods and baseline data.
Schilling, Joschua; Müller, Tilo (2022)
19th Conference on Detection of Intrusions and Malware & Vulnerability Assessment (DIMVA 2022) 13358, S. 96–115.
DOI: 10.1007/978-3-031-09484-2_6
Abstract. While modern-day static analysis tools are capable of finding standard vulnerabilities as well as complex patterns, implementing those tools is expensive regarding both development time and runtime performance. During the last years, domain specific languages like Datalog have gained popularity as they simplify the development process of analyses and rule sets dramatically. Similarly, intermediate representations like LLVM-IR are used to facilitate static source code analysis. In this paper, we present VANDALIR, a vulnerability analyzer and detector based on Datalog and LLVM-IR. VANDALIR is a static source code analyzer that allows to define and customize detection rules in a high-level, declarative way. We implement VANDALIR as a comprehensive static analysis tool, aiming to simplify vulnerability detection by a new combination of modern technologies. Besides the novel design of VANDALIR, we present a predefined detection rule set covering stack-based memory corruption, double free and format string vulnerabilities. As we show, our rule set achieves a detection rate of over 90% on test cases from the Juliet Test Suite, outperforming well-established vulnerability scanners such as the Clang Static Analyzer. Furthermore, we evaluated VANDALIR on open source projects and could reproduce existing vulnerabilities as well as identify previously unknown vulnerabilities.
Wagener, Andreas (2022)
Nerdwärts.de, 29.06.2022, https://nerdwaerts.de/2022/06/churn-management-und-kundenrueckgewinnung-mit-ki/.
In vielen Branchen gilt immer noch das Paradigma, dass es deutlich kostengünstiger sei, bestehende Kunden zu binden, als neue zu gewinnen. In diesem Kontext kommt einem zielgerichteten, analytischen Churn Management eine besondere Bedeutung zu. KI und Methoden des maschinellen Lernens scheinen dafür wie geschaffen.
Schlingensiepen, Jörg; Boos, Franz-Xaver (2022)
Die neue Hochschule, 2022 (3), S. S. 18-21.
Wolff, Dietmar (2022)
Johnson, Catherine M.; Wengler, Stefan; Hildmann, Gabriele; Vossebein, Ulrich (2022)
Proceedings of the 15th Annual Conference of the Global Sales Science Institute, Jun8-11 2022, Frankfurt am Main, Germany.
Wolff, Dietmar (2022)
Wagener, Andreas (2022)
Conference Paper: The Royal Anthropological Institute, London: RAI2022: Anthropology, AI and the Future of Human Society. Panel: P28b: Blockchain Imaginaries: Techno-utopianism, dystopias, and the future-imagining of Web 3.0, 06.06.2022 (englisch), Conference Proceedings: https://therai.org.uk/conferences/anthropology-ai-and-the-future-of-human-society/programme#12019 , paper download: https://nomadit.co.uk/conference/rai2022/paper/64834/paper-download.pdf .
DOI: 10.57944/1051-129
Wagener, Andreas (2022)
Governance of Things: AI & DAOs in Politics - Utopia or Dystopia? Tagung „Anthropology, AI and the Future of Human Society”, 2022 des Royal Anthropological Institute, London, Panel des King’s College London „P28: Blockchain Imaginaries: Techno-utopianism, dystopias, and the future-imagining of Web 3.0”, 06.06.2022 .
Markus, Heike; Meuche, Thomas (2022)
Dieses Buch bietet ein ganzheitliches Konzept und konkrete Praxisempfehlungen, wie die öffentliche Verwaltung in Deutschland Digitalisierungsprojekte erfolgreich umsetzen kann. Dazu schauen die Autor:innen mit einem 360-Grad-Blick auf die Verwaltungsorganisation und geben konkrete Handlungsempfehlungen für Daten- und Prozessmanagement, den Einsatz neuer Technologien, Organisationsstrukturen, Führungskultur und die Qualifizierung von Mitarbeiter:innen. Der technologische Fortschritt schafft die Rahmenbedingungen für die Digitalisierung, doch damit alleine kann die Transformation nicht gelingen. Diese Erfahrung haben viele Organisationen in den letzten Jahren gemacht. Das in diesem Buch dargestellte Digitale Reifegradmodell m² ermöglicht die Ermittlung konkreter Ansatzpunkte für eine digitale Transformation. Es adressiert dabei alle Dimensionen, die auf dem Weg zur digitalen Verwaltung zu berücksichtigen sind, angefangen bei den strategischen Zielen, über die zu ihrer Umsetzung notwendigen Prozesse und Ressourcen, die Organisationsstruktur und -kultur bis hin zur Steuerung. Besonderes Gewicht haben in den Ausführungen die Themen Datenerfassung, -qualität, -schutz und -sicherheit als Kern der gesamten Entwicklung. Neben den Analysen enthält das Buch eine Reihe von Handlungsvorschlägen aus Best-Practice-Projekten aus der Praxis. Diese werden von unseren Gastautor:innen aus Bundes-, Landes- und Kommunaleinrichtungen sowie Universitäten und Unternehmen vorgestellt, die aus der Praxis berichten, wie Hürden bei der Digitalisierung überwunden werden können.
Roßner, Daniel; Atzenbeck, Claus; Gross, Tom (2022)
Proceedings of the 33rd ACM Conference on Hypertext and Social Media (HT'22), S. 132–142.
DOI: 10.1145/3511095.3531286
Hypertext systems support users in navigating structured data sets and to find relevant information. Various interaction and visualization concepts aim to give users better insight into the data set, by suggesting queries and visualizing elements of interest in a meaningful way. Ranked lists are very common to show some sort of priority, while spatial layouts often help users to trace relations in the data. Only little research has been done in user studies that systematically show and reason about the differences of such spatial layouts and ranked lists. In this paper we report on a systematic comparison of a spatial visualization versus a ranked list layout. For this purpose, we did an between-subject study with 43 participants. One group performed a task with a system providing semantic visualization in 2D, the other group performed the same task with a ranked list. Both interfaces are very similar and only differ in how suggestions are visualized. The results show that users of the spatial layout finished their task in shorter time and have a tendency towards higher satisfaction. At the same time, they had more interactions with the system. Furthermore we discuss some in-depth data of the test sessions, which show that the visualization influences the users’ behavior.
Roßner, Daniel; Cheong, Jaesook; Atzenbeck, Claus (2022)
Proceedings of the 5 th Workshop on Human Factors in Hypertext (HUMAN'22), 6, S. 1–6.
DOI: 10.1145/3538882.3542803
In this paper, we report on a software demonstrator that utilizes a spatial hypertext UI to support knowledge management in the context of maintenance in industry. To demonstrate the flexibility of that approach, we re-use the software to visualize bibliographic data of the Hypertext conference series.
Eidloth, Lisa; Roßner, Daniel; Atzenbeck, Claus (2022)
Proceedings of the 5 th Workshop on Human Factors in Hypertext (HUMAN'22), 4, S. 1–9.
DOI: 10.1145/3538882.3542802
Associating information by means of linking it is a universal concept of human thinking, and by constructivist means, a possible way of learning through exploring and constructing individual information spaces related to a topic or cross topics. An application, facilitating and externalizing this activity by enabling users to create individual hyperlinks inside the environment of the Web, is a promising way to satisfy this exploratory use of information. The focus on an augmentative approach by lining hypertext's linking paradigm, in conjunction with the Web's vast amount of information, opens up for a broad spectrum of potential use scenarios. The possibilities reflect potential complexities concerning usability and limitations of usage. Therefore, preliminary and iterative evaluations are indispensable for meeting these challenges. We discuss a preliminary evaluation of usability and user behavior of said application by a conducted study based on cross-sectional quasi experimental design, using a controlled test scenario and collected client side data that serves as basis for interpretation on user behavior. Results indicate a strong habituation to document-centric processing and storing of information, and the tendency for transferring this behavior onto the more versatile linking mechanism introduced by the application. We argue for applying additional supportive features, specific for facilitating the reduction of complexity on user-side, and a longer testing period, in order to gain better insight into the possible overcome of habitual patterns concerning the tested use scenario.
Atzenbeck, Claus; Bernstein, Mark; Diefenbach, Sarah (2022)
Proceedings of the 33rd ACM Conference on Hypertext and Social Media (HT'22), S. 232–235.
DOI: 10.1145/3511095.3536363
This blue sky paper envisions a novel system which promotes emotional closeness through storytelling. Family members, who may be separated, collaboratively build a spatial hypertext of images and text fragments to express and structure their thoughts and memories. The system observes their reactions as well as their media while they work. Live recommendations prompt users in their thinking and storytelling. Family stories are thus collaboratively adapted to more tightly connect the thoughts and emotions of their loved ones.
Groß, Tobias; Schleier, Tobias; Müller, Tilo (2022)
17th ACM ASIA Conference on Computer and Communications Security (ACM ASIACCS 2022), S. S. 589-601.
The Resilient File System (ReFS) from Microsoft promises new features such as increased performance and resilience compared to the New Technology File System (NTFS). On the downside, the ReFS drivers are growing more extensive and more complex, increasing the attack surface of the Windows kernel. Attackers can often use security-critical bugs in file system drivers to escalate privileges by mounting a file system. In this work, we present ReFuzz, a structure-aware fuzzer that uses hardware-assisted code coverage to identify bugs in the ReFS driver. The ReFS file system offers several challenges to fuzzing because first, while ReFS is not documented, it exhaustively uses checksums. Second, the minimal size of a ReFS partition is 2GB, notably decreasing the performance of naive fuzzing approaches. We demonstrate the effectiveness of our fuzzing approach by finding 27 unique payloads that panic the Windows kernel when mounting or accessing ReFS partitions. Furthermore, we find 162 unique payloads that lead to a system hang-up. Microsoft confirmed those bugs and acknowledged ten unique issues which are security-critical, eight of them allowing remote code execution attacks and got assigned with a CVE number.
Nadia, Cheikhrouhou; Islem, Megdiche; Mahmoud, Assad; Sonia, Selmi; Jamel, Slaimi; Radhouane, Aloui; Nour, Chebbi; Naoufel, Zitouni; Rabiaa, Gammoudi; Nejib, Hamrouni; Riadh Ben, Jeddou; Mnawer, Gassoumi; Mondher, Haggui; Alaä, Chabir; Souhaib, Amdouni; Aymen, Saadi; Nabil, Maghraoui; Malek, Aouachri; Malek, Khadhraoui; Lotfi, Mabrouki; Salah, Ghodhbani; Rzig, Ramzi; Alaä, Chabir; Ben Ammar, Imen; Sghaier, Narjess; Imen Ben, Omrane; Amen Allah, Massoudi; Sahbi, Marrouchil; Mansour, Baazouzi; Rihani, Rihab; Dhaoui, Samir; Elouni, Mohamed; Mourad, Saidi; Chaima, Bek; Siwar Ben, Salah; Plenk, Valentin; Troudi, Fathi (2022)
Nadia, Cheikhrouhou; Islem, Megdiche; Mahmoud, Assad; Sonia, Selmi; Jamel, Slaimi...
ARNT 2021 2021.
DOI: 10.57944/1051-123
The papers collected in this book represent the ideas exchanged during the 1st Conference of the Automation and Robotics Network Tunisia (ARNT2021) held from October 29 to October 31 in Sousse, Tunisia. The papers fall into four categories: 1. Models: These papers present new model constructions and the rehabilitation of old in-house installations for teaching purposes. The propositions were selected with a view to the limited financial resources of the ISETs. Consequently, the papers provide a multitude of interesting impulses for low-cost implementation of teaching high-tech subjects. 2. Didactics: In this category the papers expose a flurry of learning approaches applied on automation and robotic subjects. The presented didactic methods are deduced from real teaching experiences. 3. Visions: These contributions introduce futuristic student projects which will need more than one iteration to be realized. 4. Study plan: In this session, the authors demonstrate the efficiency of their innovative ideas and discuss their integration on study plans.
Ruscheweyh, Ruth; Förderreuther, Stefanie; Scheidt, Jörg (2022)
Nervenheilkunde 2022 41 (5).
DOI: 10.1055/s-0042-1745700
Fast jede/-r Migränepatient/-in verwendet eine Akutmedikation. Randomisiert-kontrollierte Studien haben die Wirksamkeit erwiesen. Es gibt aber wenig Real-life-Daten dazu, wie Patienten/-innen die Wirksamkeit und Verträglichkeit verschiedener Akutmedikationen beurteilen.
Klonowski, Theresa; Ruscheweyh, Ruth; Förderreuther, Stefanie; Scheidt, Jörg (2022)
Nervenheilkunde 2022 41 (5).
Real-world-Daten über die Versorgung von Kopfschmerzpatienten/-innen in Deutschland sind rar. Deswegen hat die DMKG ein deutschlandweites Kopfschmerzregister initiiert, an dem aktuell 20 Praxen und Kopfschmerzzentren teilnehmen. Das Register erfasst die Behandlung sowohl im Querschnitt als auch im Verlauf, und sowohl aus Sicht der Patienten/-innen (vor jeder Visite und über die DMKG-App als Kopfschmerzkalender) als auch aus Sicht der Ärzte und Ärztinnen (bei der Visite).
Wagener, Andreas (2022)
Willkommen in der Datengesellschaft: KI, Blockchain & das Metaverse. Wie disruptive Technologien verändern werden, wie wir leben und arbeiten. Penta-Hotels, Rostock, 03.05.2022.
Alfons-Goppel-Platz 1
95028 Hof
T +49 9281 409 - 4690
valentin.plenk[at]hof-university.de