SBA Research is a research center for Information Security funded partly by the national initiative for COMET Competence Centers for Excellent Technologies.
Sebastian Schrittwieser, Stefan Katzenbeisser, Johannes Kinder, Georg Merzdovnik and Edgar Weippl. Protecting software through obfuscation: Can it keep pace with progress in code analysis? ACM Computing Surveys (CSUR), accepted for publication, 2016.
Our Tutorial ‘Cryptographic Currencies Crash Course‘ (Aljosha Judmayer, Edgar Weippl) has been accepted at WWW2016. We also have a workshop on empirical research methods at the conference.
Yet another paper was accepted at the International Conference of Financial Cryptography and Data Security (FC’16): “CuriousDroid: Automated User Interface Interaction for Android Application Analysis Sandboxes” by Patrick Carter, Collin Mulliner, Martina Lindorfer, William Robertson, and Engin Kirda. CuriousDroid was developed in collaboration with Northeastern University in Boston and provides… Read More
Katharina Krombholz, Aljosha Judmayer, Matthias Gusenbauer and Edgar Weippl got their paper “The Other Side of the Coin: User Experiences with Bitcoin Security and Privacy” accepted at the International Conference of Financial Cryptography and Data Security (FC’16) which will be held in February 2016 in Christ… Read More
The 21th International Conference on Availability, Reliability, and Security (ARES 2026) took center stage in Linköping, Sweden, from August 24 - 27, 2026, offering a platform for experts and enthusiasts to explore the latest developments in the field. The conference was jointly organised by Linköpings universitet (LiU) and SBA Research. ∞
New paper “Send and Pretend: Exploiting Transcript Consistency Issues in End-to-End Encrypted Group Chats”, was recently accepted for the 35th USENIX Security Symposium. The paper is a collaboration between SBA, the University of Vienna, and the Interdisciplinary Transformation University Austria (IT:U). It was authored by Gabriel K. Gegenhuber, Moritz Grefner, Maximilian Günther, Matthäus Wininger, David Schmidt, and Aljosha Judmayer. ∞
The IRIS web application in version 2.4.26 and possibly others is vulnerable to stored cross-site scripting (XSS) in the assets (CVE-2026-16969), custom attributes (CVE-2026-18360) and datastore upload (CVE-2026-18361) functions. ∞