Research
Web Application Security:
The Web is one of the core technologies of our modern Society, it changed the way we communicate, collaborate, teach, and entertain us and our fellow human beings. We use it on a daily basis for social media, health care, bank transactions, and improving knowledge. This importance for our everyday life makes the Web one of the primary targets of malicious actors. Therefore one of the research areas of the chair is focusing on detecting and defending against existing and emerging threats for the security of Web applications. Here we are not only focusing on the security of the users (client-side Web security) but also the Server that is providing the application and storing the data (server-side Web Security).
Human Factors / Usable Security:
History has shown that although we have technical solutions that in theory work, those solutions are ailing in practice. Be it end-users encrypting their emails with PGP, or Web developer securing their Website with the Content Security Policy, without taking into account the human factor for those technical Solutions, they will fail. Therefore, one key Research area of the Chair is to identify problems and roadblocks for security solutions and work together with the affected stakeholders on solutions that are both, secure on paper, and usable in practice.
Mobile Application Security:
Nowadays, mobile devices are an integral part of our everyday life. They provide users with easy and all-time access to information and the services we know from the Web Domain. Securing these mobile services, especially the interaction and intersection between the mobile and web domain is one of the research areas of the Chair.
Embedded System Security:
Embedded Systems are becoming more and more important in Industry. At the same time, those Systems are built into private houses (Smart Homes). In either case, it is important that this technology is safe and secure, such that only authorized personnel, or the owner of the house, can Control what is happening. Especially in our homes data protection is a key factor as well. Therefore, one of the chair's focus areas is on the security and privacy of embedded systems as well as the API endpoints they are using.
Ethical & Legal Challenges:
Comprehensive and representative measurements are crucial to understanding security and privacy risks in real-world systems. However, those measurements of real-world systems could harm servers, disrupt service, and cause financial damage, which introduces ethical and legal challenges. At the Chair for Cybersecurity we try to investigate how we can achieve representative measurements of real-world systems in a way that causes minimal ethical and legal risks but at the same time does not hard the validity of the scientific results.