SBA Research is a research center for Information Security funded partly by the national initiative for COMET Competence Centers for Excellent Technologies.
The paper “Coveringcerts: Combinatorial Methods for X.509 Certificate Testing” by Kristoffer Kleine and Dimitris Simos has been accepted for publication in the 10th IEEE International Conference on Software Testing, Verification and Validation (ICST 2017). ICST is one of the leading conferences for software testing and validation. The results of this… Read More
Last Saturday, students and faculty of SBA Research and the Vienna University of Technology participated as members of the team We_0wn_Y0u in the 2016 RuCTFe competition. The team scored 9th of 451 registered teams worldwide. Students are primarily recruited from our “(Advanced) Internet Security” lecture series which is taught together… Read More
SBA Research attended the IT-SeCX, the annual security exchange event of the FH St. Pölten, which took place on November 4th 2016. Researchers of SBA Research presented multiple talks at the IT-SeCX 2016, including Peter Kieseberg, Martin Schmiedecker, Damjan Buhov, and Adrian Dabrowski. You can find the subset of the… Read More
Today is the official start of the ACM Conference on Computer and Communications Security (CCS’16) in the Hofburg, Vienna, Austria. The first keynote was held by Dr. Hellman, recipient of the 2015 ACM A.M. Turing Award. Numerous members of SBA are around as well as staffing our info… Read More
The European Cybersecurity Talks – boosting the Cybersecurity Industry event took place during the ACM CCS Conference on October, 24 at Hofburg Vienna. The event was organized by SBA Research in cooperation with KSÖ and BM.I, supported by the City of Vienna (Vienna Business Agency)… Read More
Our paper titled “Block Me If You Can: A Large-Scale Study of Tracker-Blocking Tools” has been accepted for publication at IEEE EuroS&P 2017. The paper is a joint work of SBA Research (G. Merzdovnik, D. Buhov, S. Neuner, M. Schmiedecker, and E. Weippl), FH St. Pölten (M. Huber), and… Read More
Kristoffer Kleine and Bernhard Garn presented the paper „A Combinatorial Approach to Analyzing Cross-Site Scripting (XSS) Vulnerabilities in Web Application Security Testing” at ICTSS 2016 taking place October 17 – 19 2016, in Graz. This work is a joint contribution between SBA Research (Dimitris E. Simos,… Read More
Today is the first day of the 21th European Symposium on Research in Computer Security (ESORICS 2016). Two of our researchers, Stefan Brunthaler and Johanna Ullrich, are attending; Johanna is presenting her paper on attacks exploiting Xen rate limits tomorrow. ESORICS 2016… Read More
The second joint workshop between NIST and SBA Research on combinatorial security testing was held at SBA Research, Vienna on August 4th, 2016. The scope of the workshop was to strengthen the existing and already high successful cooperation between the Combinatorial Security Testing team of SBA Research and the ACTS… Read More
The 21th International Conference on Availability, Reliability, and Security (ARES 2026) took center stage in Linköping, Sweden, from August 24 - 27, 2026, offering a platform for experts and enthusiasts to explore the latest developments in the field. The conference was jointly organised by Linköpings universitet (LiU) and SBA Research. ∞
New paper “Send and Pretend: Exploiting Transcript Consistency Issues in End-to-End Encrypted Group Chats”, was recently accepted for the 35th USENIX Security Symposium. The paper is a collaboration between SBA, the University of Vienna, and the Interdisciplinary Transformation University Austria (IT:U). It was authored by Gabriel K. Gegenhuber, Moritz Grefner, Maximilian Günther, Matthäus Wininger, David Schmidt, and Aljosha Judmayer. ∞
The IRIS web application in version 2.4.26 and possibly others is vulnerable to stored cross-site scripting (XSS) in the assets (CVE-2026-16969), custom attributes (CVE-2026-18360) and datastore upload (CVE-2026-18361) functions. ∞