Presentations at DIMVA 2026
The SIG SIDAR Conference on Detection of Intrusions and Malware & Vulnerability Assessment (DIMVA) is an established international forum for research on cybersecurity threats, intrusion detection, malware analysis, and vulnerability assessment. Bringing together leading researchers and security experts, the conference addresses emerging attack techniques, system vulnerabilities, and new methods for strengthening digital security. The 23rd DIMVA Conference took place in Chania, Greece, from 1–3 July 2026.
Two TU Wien contributions at DIMVA 2026 examined how everyday connected technologies can expose users to security and privacy risks in unexpected ways. While one study focused on vulnerabilities in web-enabled smart TVs, the other showed how encrypted smart-home traffic can still reveal sensitive information about device states and user activity.
Carlotta Tagliaro, Andrej Danis, and Martina Lindorfer, together with Kevin Borgolte from Ruhr University Bochum, presented “New Platform, Old Issues: How Web-based TV Broadcasts Threaten Users’ Security.” The study provides the first cross-vendor security analysis of Hybrid Broadcast Broadband TV (HbbTV) browsers on Smart TVs from Samsung, LG, and Toshiba. The researchers show that attackers can inject malicious HbbTV applications into broadcast streams and compromise Smart TVs without any user interaction. The demonstrated attacks include denial of service, phishing, spoofing of news banners to spread misinformation, and, on some devices, access to other systems on the local network. The researchers trace these risks to permissive HbbTV capabilities and outdated embedded browser engines. They recommend stronger security requirements for the HbbTV ecosystem, including mandatory HTTPS, permission-based access to sensitive APIs, independently updatable browser components, stronger browser isolation, and integrity verification for broadcast-delivered applications. The findings highlight a significant and largely overlooked attack surface affecting millions of HbbTV-enabled Smart TVs across Europe, Oceania, and parts of Asia.
Paul Mairinger presented the paper “Traces in WAN Traffic: Inferring Alarm States and User Activity from Encrypted Smart Home Traffic,” co-authored with Joachim Fabini and Tanja Zseby. The work investigates how much sensitive information can be inferred from encrypted smart-home communications by an attacker observing traffic solely at the Wide Area Network level. Using Philips Hue as a case study, they show that a passive observer at a WAN observation point, for example at an ISP or customer-premises uplink, can infer alarm arming and disarming, ON/OFF events for lights and smart plugs, motion activity, and other user-related events without decrypting traffic or accessing the local network. The method relies only on packet lengths, traffic direction, and timing patterns and requires no machine learning. The authors also evaluate countermeasures such as fixed-size padding, reply coalescing, synthetic jitter, and steady background traffic, highlighting the need for privacy-preserving traffic shaping in consumer IoT systems.
The research dataset is available via TU Wien Research Data. It contains 10,000 labeled Philips Hue on/off PCAP captures and labeled packet-burst features for arm/disarm security-state commands, supporting reproducible research on IoT traffic analysis, command inference, and device-behavior fingerprinting.