Matris https://matris.sba-research.org Thu, 08 May 2025 08:20:55 +0000 en-US hourly 1 https://matris.sba-research.org/wp-content/uploads/2022/12/cropped-1-1-32x32.png Matris https://matris.sba-research.org 32 32 Combinatorial Security Testing for Bluetooth Low Energy accepted at USENIX ATC https://matris.sba-research.org/combinatorial-security-testing-for-bluetooth-low-energy-accepted-at-usenix-atc/ Thu, 08 May 2025 08:20:55 +0000 https://matris.sba-research.org/?p=4190 Bluetooth Low Energy is one of the most widely used protocols used in Internet of Things (IoT) and multimedia devices. Security issues in these applications are prone to affect a significant number of end users and companies alike.

In their latest work applying the Combinatorial Security Testing (CST) approach to Bluetooth Low Energy devices, Dominik Schreiber, Manuel Leithner, Jovan Zivanovic and Dimitris Simos of the MATRIS group of SBA Research, the researchers uncovered 19 distinct vulnerabilities in 10 Bluetooth LE devices. Most of these issues could be used to remotely freeze the devices indefinitely (also known as a Denial of Service), while others lead to incorrect behavior or core dumps being emitted over debugging connections, indicating potentially exploitable conditions. The work is originally based on a fuzzing approach called SweynTooth but extended towards combinatorial security testing, offering a mathematically guaranteed degree of coverage based on an attack grammar.

All affected vendors were contacted to facilitate a coordinated responsible disclosure process, minimizing the impact to end users by enabling device manufacturers to release updated firmware versions before vulnerabilities are published. Additionally, related CVEs are in the process of being assigned.

The work titled Bluetooth Low Energy Security Testing with Combinatorial Methods has been accepted to the 2025 USENIX Annual Technical Conference and will be presented in July 2025 in Boston, MA.

]]>
Combinatorial Security Testing @ Award Ceremony for 2025 Houska Prize https://matris.sba-research.org/combinatorial-security-testing-award-ceremony-for-2025-houska-prize/ Fri, 18 Apr 2025 09:57:54 +0000 https://matris.sba-research.org/?p=4174 The award ceremony for the 2025 Houska Prize was held on 9 April 2025 and MATRIS members participated in this prestigious event as a result of the project ‘Combinatorial Security Testing’ (CST) being nominated in the category ‘Non-University Research’.

Represented by Dimitris Simos (CST Project Lead), Bernhard Garn and Manuel Leithner, as well as by Markus Klemen (Managing Director of SBA Research), MATRIS research in combinatorial security testing was prominently presented to the attendees during the ceremony.

Combinatorial Security Testing offers an innovative combination of mathematical guarantees and effective identification of vulnerabilities. It allows testers, developers and scientists to rapidly find and fix flaws in security- and safety-relevant applications. For its practical relevance and achievements in transferring these results of innovative applications of discrete mathematics to real-world security testing benefitting Austrian companies, the CST project as finalist for the 2025 Houska Prize in the category ‘Non-University Research’ was awarded a prize of 10,000 Euro.

© Gregor Hofbauer

In 2025, the Houska Prize celebrated its 20th round, proudly sponsored by the B&C Private Foundation. The Houska Prize recognizes and promotes business-related research and innovation. B&C’s goal with the Houska Prize is to strengthen the business location Austria as well as to appreciate outstanding research work. The Houska Prize is unique in its kind and in 2025 a total endowment of EUR 760,000 was awarded between the winners as well as nominees in the categories University Research, Non-University Research and Research & Development in SMEs, as well as for the Mariella Schurz Prize.

]]>
MATRIS @ IWCT 2025 https://matris.sba-research.org/matris-iwct-2025/ Mon, 14 Apr 2025 09:32:58 +0000 https://matris.sba-research.org/?p=4162 Members of the MATRIS Research Group participated in the 14th International Workshop on Combinatorial Testing (IWCT 2025) in Naples, Italy. IWCT is among the premier venues for research dedicated to combinatorial testing and was held co-located with the 18th ICST on Monday, March 31, 2025.

Andrea Bombarda (University of Bergamo) and Bernhard Garn (MATRIS)  served as PC Co-Chairs together with General Chair Angelo Gargantini (University of Bergamo).

IWCT 2025 proudly featured a keynote given by Dr. Juraj Somorovsky, Professor at Paderborn University (Germany), titled “Lessons learned from systematic security testing of TLS”: Transport Layer Security (TLS) is one of the most important cryptographic protocols, securing a vast range of communications, including web traffic, email, chat, and VPNs. Given its widespread importance, TLS implementations have become prime targets for numerous famous attacks. To detect TLS attacks automatically, Juraj – together with his System Security Group at UPB – developed a flexible tool for TLS security evaluations called TLS-Attacker. He demonstrated how combinatorial testing integrated into TLS-Attacker leveraged a practical TLS test suite called TLS-Anvil that found new exploits, cryptographic problems, and interoperability issues.  

Manuel Leithner presented a paper on the practical integration of Combinatorial (Security) Testing workflows in Continuous Integration and Deployment environments (joint work with Jovan Zivanovic, Reinhard Kugler and Dimitris Simos), continuing to support a shift of combinatorial testing methods towards practical applicability.

Bernhard Garn presented the paper titled “Combinatorial Methods for Enhancing the Resilience of Production Facilities”; joint work with Konstantin Gerner and Wolfgang Czerni (both Infraprotect), Rick Kuhn and Raghu Kacker (both NIST) and Klaus Kieseberg and Dimitris Simos. In their paper, they applied combinatorial methods to generate crisis scenarios for production facilities with the goal of strengthening their resilience by identifying weaknesses in operational aspects or crisis response plans, extending previous work from the domain of disaster research. This paper highlights the wide range of topics covered at IWCT 2025.

More applications of combinatorial testing were presented in the papers:

  •  “A Search-Based Benchmark Generator for Constrained Combinatorial Testing Models” by Paolo Arcaini (National Institute of Informatics), Andrea Bombarda (University of Bergamo), Angelo Gargantini (University of Bergamo)
  • Combinatorial Test Design Model Creation using Large Language Models” by Deborah Furman (IBM), Eitan Farchi (IBM Haifa Research Lab), Michael Gildein (IBM), Andrew Hicks (IBM), Ryan Rawlins (IBM)
  • Evaluating Large Language Model Robustness Using Combinatorial Testing” by Jaganmohan Chandrasekaran (Virginia Tech), Ankita Ramjibhai Patel (The University of Texas at Arlington), Erin Lanus (Virginia Tech), Laura Freeman (Virginia Tech)
  • Utilizing Ontologies for Combinatorial Testing” by Franz Wotawa (Graz University of Technology)
  • Towards Accessibility of Covering Arrays for Practitioners of Combinatorial Testing” by Ulrike Grömping (BHT – Berliner Hochschule für Technik)
  • Testing Tool for Combinatorial Transition Testing in Dynamically Adaptive Software Systems” by Pierre Martou (UCLouvain / ICTEAM), Benoît Duhoux (Université catholique de Louvain), Kim Mens (Université catholique de Louvain, ICTEAM), Axel Legay (Nexova)
  • Extended Abstract of Poster: STARS: Tree-based Classification and Testing of Feature Combinations in the Automated Robotic Domain” by Till Schallau (TU Dortmund University), Dominik Schmid (TU Dortmund University), Nick Pawlinorz (TU Dortmund University), Stefan Naujokat (TU Dortmund University), Falk Howar (TU Dortmund University)
  • Data Frequency Coverage Impact on AI Performance” by Erin Lanus (Virginia Tech), Brian Lee (Virginia Tech), Jaganmohan Chandrasekaran (Virginia Tech), Laura Freeman (Virginia Tech), M S Raunak (NIST), Raghu Kacker (NIST), Rick Kuhn (NIST)
  • A Combinatorial Approach to Reduce Machine Learning Dataset Size” by Megan Olsen (Loyola University Maryland), M S Raunak (NIST), Rick Kuhn (NIST), Fenrir Badorf (Loyola University Maryland), Hans van Lierop (Loyola University Maryland), Francis Durso (Johns Hopkins University)
  • Fairness Testing of Machine Learning Models Using Combinatorial Testing in Latent Space” by Arjun Dahal (University of Texas at Arlington), Sunny Shree (University of Texas at Arlington), Jeff Lei (University of Texas at Arlington), Raghu Kacker (NIST), Rick Kuhn (NIST)

Dimitris Simos, in his capacity as IWCT Steering Committee Chair, formulated the strategic direction of the workshop in cooperation with members of the Steering Committee, bolstered by great suggestions provided by the IWCT community in attendance.

On behalf of the Organizers of IWCT 2025, we would like to thank all authors of accepted papers, all presenters and all participants! Furthermore, we would like to thank the Organizing Committee of ICST 2025 for their support; with special appreciation to the ICSTW Co-Chairs Matteo Biagiola, Mitchell Olsthoorn and Francesca Lonetti, the Finance Co-Chairs Domenico Amalfitano and Vincenzo Riccio, the Registration Chairs Aurora Ramírez and Baharin Aliashrafi Jodat as well as the Local Arrangement Chair Alessandra De Benedictis!

]]>
Visit to NCSR “DEMOKRITOS” https://matris.sba-research.org/visit-to-ncsr-demokritos/ Thu, 10 Apr 2025 17:23:33 +0000 https://matris.sba-research.org/?p=4159 In March 2025, Bernhard Garn and Dimitris Simos visited the NATIONAL CENTRE FOR SCIENTIFIC RESEARCH “DEMOKRITOS” (NCSR-D) in Athens, Greece. During their visit, they met with Georgios Xilouris, Head of the Network Operations Center (NOC) at the Institute of Informatics & Telecommunications (IIT) of NCSR-D. Both NCSR-D and SBA are partners in the INTACT project, which proposes an Integrated Software Toolbox that will offer predictive Cybersecurity sensing, optimization and management services for the distributed IoT-to-Cloud continuum. NOC leads one of the pilots of INTACT, which is about a safety-critical network environment that includes SDN/NFV and IoT-Edge technologies with radiation and environmental sensors. In their technical exchange, they discussed technical aspects of INTACT and in particular focused on the pilot let by NOC.

NCSR-D was founded in July 1961 as a research centre for nuclear research, Demokritos is today the largest multidisciplinary research centre of Greece with approximately 180 researchers in tenured and tenure-track positions and over 500 research personnel working in projects funded mainly by grants from state funds, the European Union and private industries.

]]>
Bernhard Garn participated in the 1st NERO Winter School on Fire Spread and Behavior Reconstruction https://matris.sba-research.org/bernhard-garn-participated-in-the-1st-nero-winter-school-on-fire-spread-and-behavior-reconstruction/ Tue, 04 Mar 2025 11:18:21 +0000 https://matris.sba-research.org/?p=4150

Bernhard Garn participated as trainee in the 1st NERO Winter School on Fire Spread and Behavior Reconstruction, which was held between February 18 – 21, 2025, at the Command Center of the Autoridade Nacional de Emergência e Proteção Civil (engl.,Portuguese National Authority for Emergency and Civil Protection; ANEPC) in Carnaxide, Portugal.

The Winter School focused on advancing knowledge and skills in reconstructing wildfire spread and estimating fire behavior descriptors such as the rate of spread via remote sensing. Theoretical aspects presented included remote sensing principles and data applications as well as different data sources such as satellite and airborne data together with their individual characteristics. Practical skills were improved when working in groups on case studies for wildfire reconstruction using Python and QGIS.

Experts in remote sensing, programming, and GIS, including professionals from EUMETSAT, conducted the trainings. Attendees were grateful for the insights provided by members of ANEPC. The Winter School was an overall success, much knowledge acquired by the trainees and perfectly organized by Akli Benali (Vice-Chair of NERO). Special thanks for this Winter School go to the fellow participating trainees, the excellent trainers and dedicated organizers – especially Akli Benali, and to the members of the Command Center of ANEPC for their openness and willingness to share knowledge as well as their great hospitality!

Bernhard Garn is Management Committee (MC) member for Austria in the COST Action european Network on Extreme fiRe behaviOr (COST Action CA22164 NERO). Learn more about the NERO network here: https://nero-network.eu/

COST (European Cooperation in Science and Technology) is a funding agency for research and innovation networks. Our Actions help connect research initiatives across Europe and enable scientists to grow their ideas by sharing them with their peers. This boosts their research, career and innovation.

Visit COST at www.cost.eu

]]>
KomMKonLLM @ SBA Security Meetup hosted by Dynatrace! https://matris.sba-research.org/kommkonllm-sba-security-meetup-hosted-by-dynatrace/ Mon, 03 Mar 2025 18:29:06 +0000 https://matris.sba-research.org/?p=4144 Large Language Models (LLMs) are powerful — but are they consistent? Can they reliably produce the same output when presented with inputs that have the same meaning? This is a key question for trustworthiness in AI systems that is being addressed within the KomMKonLLM project (Netidee: Förderjahr 2024 / Projekt Call #19 / ProjectID: 7409).

On Tuesday, February 25, 2025, Ludwig Kampel and Bernhard Garn joined the event “SBA Security Meetup hosted by Dynatrace!” to present a combinatorial approach to consistency testing of LLMs that is being implemented within KomMKonLLM. The presentation about KomMKonLLM – given jointly by Ludwig and Bernhard – generated much interest from the audience and the ensuing discussion covered several different aspects on the topic of consistency (testing) of LLMs.

You can find more information on the official project homepage of KomMKonLLM here: https://www.netidee.at/kommkonllm and you can get in contact about KomMKonLLM at (n o sp ac es): “K omMKon LLM@s ba-resear ch.o r g ”.

]]>
2025 Houska Prize Nomination https://matris.sba-research.org/2025-houska-prize-nomination/ Sat, 15 Feb 2025 17:42:26 +0000 https://matris.sba-research.org/?p=4130

The research project combinatorial security testing of the MATRIS Research Group has been nominated in the category Non-University Research for the 2025 Houska Prize!

Since its establishment in 2005, the Houska Prize is sponsored by the B&C Private Foundation to promote business-related research and innovation. The Houska Prize expresses the appreciation for outstanding research work that has been performed in Austria. The year 2025 marks the 20th round of the Houska Prize and the winners will be announced in an award ceremony on 9 April 2025.

]]>
Keynote by Dimitris Simos @ DX’24 https://matris.sba-research.org/keynote-by-dimitris-simos-dx24/ Wed, 20 Nov 2024 18:35:45 +0000 https://matris.sba-research.org/?p=4105 At the 35th International Conference on Principles of Diagnosis and Resilient Systems (DX’24), an event co-organized by TU Graz and Ben Gurion University, and sponsored by AIJ, Dimitris Simos gave a keynote titled “Combinatorial Methods beyond Testing: Optimizing Disaster Scenarios to Strengthen Disaster Preparedness and Resilience”. In his keynote, Dimitris presented the application of combinatorial methods beyond system testing, and in particular examined their adaptation for use-cases typically encountered as part of the disaster management cycle with the aim to advance disaster preparedness and enhance the resilience of (cyber-) physical systems. Any efforts in the ex-ante phase of a disaster require detailed understanding of potential disaster scenarios, which makes them an integral part of activities around advancing disaster preparedness, prevention, and resilience. For this reason, Dimitris also put emphasis on different discrete mathematical models and generation techniques for descriptive disaster scenario generation.

The keynote was followed by an intensive round of questions from the audience moderated by Ingo Pill. Topics put forward included the impact of multiple, simultaneously occurring disasters as well as thoughts on technical aspects on how to start designing for resilience right from the beginning.

https://conf.researchr.org/home/dx-2024

https://conf.researchr.org/info/dx-2024/invited-speakers

Copyright: MATRIS
Copyright: MATRIS
Copyright: MATRIS
]]>
Invited talk “COMBINATORIAL METHODS FOR TESTING AND ANALYSIS OF COMPLEX SYSTEMS” given by Dimitris Simos in the Lecture Series of the Research Institute for Supply Chain Management @ WU https://matris.sba-research.org/invited-talk-combinatorial-methods-for-testing-and-analysis-of-complex-systems-given-by-dimitris-simos-in-the-lecture-series-of-the-research-institute-for-supply-chain-management-w/ Mon, 21 Oct 2024 12:39:38 +0000 https://matris.sba-research.org/?p=4091 On October 18, 2024 Dimitris Simos gave an invited talk titled “COMBINATORIAL METHODS FOR TESTING AND ANALYSIS OF COMPLEX SYSTEMS” [DS] in the Lecture Series of the Research Institute for Supply Chain Management at the Vienna University of Economics and Business (WU) [LS-RI_SCM]. Dimitris started his talk with some background material on combinatorial testing for software and then presented selected R&D highlights achieved by the MATRIS Research Group together with collaborators. At the end, Dimitris presented a future outlook how combinatorial methods can be adapted for use cases typically encountered in research problems pertaining to operations research and disaster management.

The talk of Dimitris was well received and several questions were discussed during as well as after the talk. Professor Tina Wakolbinger, Head of the Research Institute for Supply Chain Management, moderated the event.

Klaus and Bernhard from the DEFSYS team also attended the event at WU.

The slides of the talk are available here:

Copyright: MATRIS
Copyright: MATRIS
Copyright: MATRIS

References:
[DS] https://www.wu.ac.at/fileadmin/wu/d/i/itl/MSc_SCM/Vortragsreihe_Lecture_Serie_Interdisciplinary/Ank%C3%BCndigung_Dimitris_Samos_WS2425.pdf

[LS-RI_SCM] https://www.wu.ac.at/en/scm/events/speaker-series/winter-semester-2024-2025

]]>
Reinhard Kugler @WeAreDevelopers 2024 https://matris.sba-research.org/reinhard-kugler-troopers-2024/ Sat, 31 Aug 2024 08:48:57 +0000 https://matris.sba-research.org/?p=4010

This year’s WeAreDevelopers Congress 2024, held in Berlin from July 17th to 19th with intriguing sessions covering the latest trends and advancements across the industry. Reinhard Kugler, lead of the MARC team, contributed to the congress with his standout presentations titled “A Hitchhiker’s Guide to Container Security in Embedded Systems – Make and Break an Automotive Container Platform.”

Exploring Container Security in Automotive Systems

Reinhard began his presentation by reflecting on the evolution of automotive software. What was once a tightly sealed black box has now transformed into what he aptly described as a “tablet on wheels.” In today’s vehicles, nearly every function—from the engine’s performance to door locking and lane assist—is managed by a complex web of software-driven control units. While these systems are engineering marvels, they also introduce significant challenges, particularly when it comes to software maintenance and updates.

Reinhard walked the audience through the complexities of these systems, explaining how the increasing sophistication has made maintaining and updating automotive software a daunting task. Unlike the straightforward updates on phones or computers, updating a car’s software is like orchestrating a symphony—every component needs to be in perfect harmony. As the number of these interconnected components grows, so does the complexity of managing them effectively.

Introducing Containers and Kubernetes in Vehicles

Reinhard then introduced the innovative concept of using containers and Kubernetes within vehicles as a solution to these challenges. This approach represents a significant shift towards a more unified, containerized platform, which could help the automotive industry address the difficulties of managing complex software systems. By adopting this technology, the industry can create a more flexible, secure, and maintainable environment within vehicles. However, as Reinhard pointed out, this transition also introduces new challenges, particularly concerning security.

Live Hacking: Building and Securing Embedded Containers

One of the highlights of Reinhard’s presentation was a live hacking demonstration where he built embedded containers from scratch. He showcased how these containers can be integrated with critical vehicle systems like CAN bus, temperature sensors, and door actuators. Reinhard emphasized the importance of securing these components as the industry moves toward a software-defined vehicle architecture, offering practical insights into mitigating security risks while implementing this technology.

Looking Forward: The Future of Automotive Security

Reinhard Kugler’s session at WeAreDevelopers Congress 2024 highlighted the ongoing evolution in the automotive industry, where the intersection of software and hardware is becoming increasingly significant. His exploration of container security within embedded systems is particularly relevant as the industry prepares for greater integration of software-driven solutions. As vehicles become more complex and interconnected, the insights shared in Reinhard’s session will be crucial in guiding the future of automotive security and innovation.


Related Links:
We Are Developers Official Website: https://www.wearedevelopers.com/world-congress

Take a look at Reinhard’s talk: A Hitchiker’s Guide to Container Security in Embedded Systems by Reinhard Kugler

]]>