Marius Musch is a PhD candidate since October 2017. His field of research is web application security with a focus on client-side attacks and large-scale analyses
R̶o̶o̶m̶ ̶2̶0̶9̶B̶
m.musch[at]tu-braunschweig.de
0̶5̶3̶1̶/̶3̶9̶1̶-̶2̶2̶9̶2̶
Server-Side Browsers: Exploring the Web’s Hidden Attack Surface
Marius Musch, Robin Kirchner, Max Boll, and Martin Johns
Proc. of the 17th ACM Asia Conference on Computer and Communications Security (ASIA CCS), 2022.
U Can’t Debug This: Detecting JavaScript Anti-Debugging Techniques in the Wild
Marius Musch and Martin Johns
Proc. of the 30th USENIX Security Symposium, 2021.
Who’s Hosting the Block Party? Studying Third-Party Blockage of CSP and SRI
Marius Steffens, Marius Musch, Martin Johns, and Ben Stock
Network and Distributed System Security Symposium (NDSS), 2021.
Thieves in the Browser: Web-based Cryptojacking in the Wild *Best Paper Award Runner-up*
Marius Musch, Christian Wressnegger, Martin Johns, and Konrad Rieck
Proc. of 14th Int. Conference on Availability, Reliability and Security (ARES), 2019.
ScriptProtect: Mitigating Unsafe Third-Party JavaScript Practices
Marius Musch, Marius Steffens, Sebastian Roth, Ben Stock, and Martin Johns
Proc. of 14th ACM Asia Conference on Computer and Communications Security (ASIACCS), 2019.
New Kid on the Web: A Study on the Prevalence of WebAssembly in the Wild *Best Paper Award Runner-up*
Marius Musch, Christian Wressnegger, Martin Johns, and Konrad Rieck
Proc. of 16th Conference on Detection of Intrusions and Malware & Vulnerability Assessment (DIMVA), 2019.
Towards an Automatic Generation of Low-Interaction Web Application Honeypots
Marius Musch, Martin Härterich, and Martin Johns
Proc. of 13th Int. Conference on Availability, Reliability and Security (ARES), 2018.
Web-based Cryptojacking in the Wild
Marius Musch, Christian Wressnegger, Martin Johns, and Konrad Rieck
Technical report, arXiv:1808.09474, 2018.
ScriptProtect: Mitigating Unsafe Third-Party JavaScript Practices [Video, Slides]
OWASP Global AppSec, 27.09.2019, Amsterdam, The Netherlands
The Now and the Future of Malicious WebAssembly [Video, Slides]
OWASP Global AppSec, 26.09.2019, Amsterdam, The Netherlands
Web-based Cryptojacking in the Wild [Video, Slides]
35C3, 29.12.2018, Leipzig, Germany
Chameleon: Automatic Generation of Low-Interaction Web Honeypots
German OWASP Day, 14.11.2017, Essen, Germany
Year | Degree | Title |
---|---|---|
2021 | Bachelor | On the Feasibility of In- and Out-of-Band JavaScript Anti-Debugging Detection and Prevention |
2021 | Bachelor | Capability Analysis of JavaScript Anti-Bot Implementations in the Wild |
2020 | Bachelor | Performant and Reliable Detection of JavaScript Libraries |
2020 | Bachelor | An Analysis of the State of Electron Security in the Wild |
2020 | Master | Detecting and Fingerprinting Server-Side Requests |
2020 | Bachelor | Towards Automatic Generation of Universal XSS Payloads |
Year | Conference |
---|---|
2021 | SecWeb |
Year | Conference |
---|---|
2022 | S&P, Euro S&P, CODASPY |
2021 | WWW, ACSAC, CODASPY, SAC, ARES |
2020 | WWW, Euro S&P, ACSAC, CODASPY, SAC, ARES |
2019 | ACSAC, CODASPY, SAC, ICWE |
2018 | Euro S&P, ACSAC, CODASPY, SAC |
Year | Semester | Name |
---|---|---|
2022 | Summer | Web Security, Seminar |
2021 | Winter | Hacklab, Seminar |
2021 | Summer | Web Security, SEP, Seminar |
2020 | Winter | Programming 1, Seminar |
2020 | Summer | Seminar |
2019 | Winter | Seminar |
2018 | Summer | Programming 1, SEP, Seminar |