Publications (academic and professional)

2012

Seitenkanalangriffe im Web (pdf)
Sebastian Schinzel
19. DFN Workshop "Sicherheit in vernetzten Systemen"
Podiumsdiskussion: "2011, das Jahr der Datendiebstähle - Wann werden Entwicklungsprojekte endlich Softwareanwendungen erstellen, die wenigstens den offensichtlichen Angriffen widerstehen?"
Sebastian Schinzel
Softwareforen Leipzig: Jahrestreffen

2011

   Time is on my Side - Exploiting Timing Side Channel Vulnerabilities on the Web (pdf, YouTube)
Sebastian Schinzel
28th Chaos Communication Congress - Behind Enemy Lines
Quellcodescans von Webanwendungen in der Praxis - Friend or Foe
Sebastian Schinzel
Softwareforen Leipzig: User Group - IT-Sicherheit (pdf)
   Quellcodescans von Webanwendungen in der Praxis - gängige Fallstricke und Wege zum erfolgreichen Einsatz in Unternehmen (pdf)
Sebastian Schinzel
German OWASP Day 2011
  

SAP-Security - Sicherheitslöcher in eigenem ABAP-Code stopfen (pdf)
Sebastian Schinzel, Frederik Weidemann, Andreas Wiegenstein, Markus Schumacher
iX - Magazin für professionelle Informationstechnik, Ausgabe 07/2011

Detecting Hidden Storage Side Channel Vulnerabilities in Networked Applications (pdf)
Felix C. Freiling and Sebastian Schinzel
IFIP sec2011 - Future Challenges in Security and Privacy for Academia and Industry

An Efficient Mitigation Method for Timing Side Channels on the Web (pdf)
Sebastian Schinzel
2nd International Workshop on Constructive Side-Channel Analysis and Secure Design

   Side Channel Vulnerabilities on the Web - Detection and Prevention
Sebastian Schinzel
Hackerpraktikum - Ruhr-Universität-Bochum

2010

   Seitenkanalschwachstellen im Web erkennen und verhindern (Side Channel Vulnerabilities on the Web - Detection and Prevention)
Sebastian Schinzel
OWASP AppSec Germany 2010 Conference

2009

   Sichere Entwicklung und gängige Schwachstellen in eigenentwickelten SAP-Web-Anwendungen
Sebastian Schinzel
OWASP AppSec Germany 2009 Conference
   Software Supply Chain Integrity in SAP Applications
Sebastian Schinzel, Gunter Bitz, Andreas Wiegenstein, Markus Schumacher, Frederik Weidemann
Security Acts Journal

Security mechanisms of a legal peer-to-peer file sharing system
Sebastian Schinzel, Martin Schmucker, Peter Ebinger
IADIS International Journal on Computer Science and Information Systems

Sichere ABAP-Programmierung (Book in German Language)
Andreas Wiegenstein, Markus Schumacher, Sebastian Schinzel, Frederik Weidemann
SAP Press

2008

   Measuring the Security of Web Applications
Sebastian Schinzel
OWASP Germany 2008 Conference
Assessing and Measuring Security in Custom SAP Applications
Sebastian Schinzel
Conference: Mastering SAP Technologies, Goldcoast, Australia
The Missing Link: Compliance at the Code Level
Markus Schumacher, Sebastian Schinzel, Andreas Wiegenstein
SAP Experts - GRC Expert
   The Need for Measuring Software Security
Markus Schumacher, Sebastian Schinzel
Testing Experience - No. 01/08

Security mechanisms of a legal peer-to-peer file sharing system
Peter Ebinger, Sebastian Schinzel, Martin Schmucker
IADIS International Conference Applied Computing 2008

2007

Mastering Application Security - Threats and Countermeasures
Sebastian Schinzel
Conference: Mastering SAP Technologies, Melbourne, Australia

An Ad Hoc Writeable Rule Language for White-Box Security Scanners
Sebastian Schinzel
Master Thesis - Virtual Forge Research Department

2006

Writing Fast And Secure Code in C
Sebastian Schinzel
White Paper - Virtual Forge Research Department

2005

Security mechanisms of a legal peer-to-peer file sharing system
Sebastian Schinzel
Bachelor Thesis (Fraunhofer Institute for Computer Graphics Research)

Supervised Theses

Please find open thesis proposals on my personal page at FAU.

FinishedTypeTopicName of studentAffiliation
June 2011BachelorFingerprinting Rules of Web Applications Firewalls through Timing Side ChannelsIsabell SchmittUniversität Mannheim - Praktische Informatik I
June 2011BachelorFingerprinting of XML Programming Libraries through Storage Side ChannelsThilo MothesUniversität Mannheim - Praktische Informatik I
June 2011BachelorSide Channel Vulnerabilities in Web Application FirewallsStefan Kuch, Simon LehmannErgon AG in cooperation with Zurich University of Applied Sciences - InIT Institute of Applied Information Technology
September 2011DiplomQuantification of Information Flows in Business NetworksDennis MöbiusUniversität Mannheim - Praktische Informatik I
January 2012DiplomAdvanced Fingerprinting Techniques for the Recognition of Vulnerable Programming Libraries at the Example of Image Processing LibrariesSebastian MerkSecurity Research Group - Department of Computer Science Friedrich-Alexander-University Erlangen-Nuremberg
April 2012BachelorDas anonyme Netzwerk TOR und verdeckte KommunikationBenjamin KahlerSecurity Research Group - Department of Computer Science Friedrich-Alexander-University Erlangen-Nuremberg in cooperation with Augsburg University of Applied Sciences
ongoingDiplomFingerprinting-Techniken zur Erkennung anfälliger XML-BibliothekenAnders DickerSecurity Research Group - Department of Computer Science Friedrich-Alexander-University Erlangen-Nuremberg

Contact

Find me at