Tiago Heinrich

PhD Tiago Heinrich

Address
Max-Planck-Institut für Informatik
Saarland Informatics Campus
Campus E1 4
66123 Saarbrücken
Location
E1 4 - 505
Phone
+49 681 9325 3544
Fax
+49 681 9325 3599

Personal Information

I am mainly interested in security and network measurements. I believe that through systems such as honeypots or network telescopes, we can achieve a better understanding of the intentions of malicious users. My past research involves the design and implementation of honeypots such as MP-H, which was crucial for the study of carpet bombing attacks, and the development of detection strategies for virtualized environments through system calls and bytecode executed in a sandbox like WebAssembly. 

Publications

2026
Bitzki, L., Kreutz, D., Heinrich, T., Fideles, D., Bertholdo, L., Quincozes, S., & Diniz, A. (2026). NetSecBed: A Container-Native Testbed for Reproducible Cybersecurity Experimentation. Retrieved from https://arxiv.org/abs/2604.04121
(arXiv: 2604.04121)
Abstract
Cybersecurity research increasingly depends on reproducible evidence, such as traffic traces, logs, and labeled datasets, yet most public datasets remain static and offer limited support for controlled re-execution and traceability, especially in heterogeneous multi-protocol environments. This paper presents NetSecBed, a container-native, scenario-oriented testbed for reproducible generation of network traffic evidence and execution artifacts under controlled conditions, particularly suitable for IoT, IIoT, and pervasive multi-protocol environments. The framework integrates 60 attack scenarios, 9 target services, and benign traffic generators as single-purpose containers, enabling plug-and-play extensibility and traceability through declarative specifications. Its pipeline automates parametrized execution, packet capture, log collection, service probing, feature extraction, and dataset consolidation. The main contribution is a repeatable, auditable, and extensible framework for cybersecurity experimentation that reduces operational bias and supports continuous dataset generation.
Export
BibTeX
@online{Bitzki2604.04121, TITLE = {{NetSecBed}: A Container-Native Testbed for Reproducible Cybersecurity Experimentation}, AUTHOR = {Bitzki, Leonardo and Kreutz, Diego and Heinrich, Tiago and Fideles, Douglas and Bertholdo, Leandro and Quincozes, Silvio and Diniz, Angelo}, LANGUAGE = {eng}, URL = {https://arxiv.org/abs/2604.04121}, EPRINT = {2604.04121}, EPRINTTYPE = {arXiv}, YEAR = {2026}, ABSTRACT = {Cybersecurity research increasingly depends on reproducible evidence, such as traffic traces, logs, and labeled datasets, yet most public datasets remain static and offer limited support for controlled re-execution and traceability, especially in heterogeneous multi-protocol environments. This paper presents NetSecBed, a container-native, scenario-oriented testbed for reproducible generation of network traffic evidence and execution artifacts under controlled conditions, particularly suitable for IoT, IIoT, and pervasive multi-protocol environments. The framework integrates 60 attack scenarios, 9 target services, and benign traffic generators as single-purpose containers, enabling plug-and-play extensibility and traceability through declarative specifications. Its pipeline automates parametrized execution, packet capture, log collection, service probing, feature extraction, and dataset consolidation. The main contribution is a repeatable, auditable, and extensible framework for cybersecurity experimentation that reduces operational bias and supports continuous dataset generation.}, }
Endnote
%0 Report %A Bitzki, Leonardo %A Kreutz, Diego %A Heinrich, Tiago %A Fideles, Douglas %A Bertholdo, Leandro %A Quincozes, Silvio %A Diniz, Angelo %+ External Organizations External Organizations Internet Architecture, MPI for Informatics, Max Planck Society External Organizations External Organizations External Organizations External Organizations %T NetSecBed: A Container-Native Testbed for Reproducible Cybersecurity Experimentation : %G eng %U http://hdl.handle.net/21.11116/0000-0013-479B-D %U https://arxiv.org/abs/2604.04121 %D 2026 %X Cybersecurity research increasingly depends on reproducible evidence, such as traffic traces, logs, and labeled datasets, yet most public datasets remain static and offer limited support for controlled re-execution and traceability, especially in heterogeneous multi-protocol environments. This paper presents NetSecBed, a container-native, scenario-oriented testbed for reproducible generation of network traffic evidence and execution artifacts under controlled conditions, particularly suitable for IoT, IIoT, and pervasive multi-protocol environments. The framework integrates 60 attack scenarios, 9 target services, and benign traffic generators as single-purpose containers, enabling plug-and-play extensibility and traceability through declarative specifications. Its pipeline automates parametrized execution, packet capture, log collection, service probing, feature extraction, and dataset consolidation. The main contribution is a repeatable, auditable, and extensible framework for cybersecurity experimentation that reduces operational bias and supports continuous dataset generation. %K Computer Science, Cryptography and Security, cs.CR,Computer Science, Artificial Intelligence, cs.AI,Computer Science, Networking and Internet Architecture, cs.NI,Computer Science, Performance, cs.PF,
Frasao, A., Heinrich, T., & Fulber-Garcia, V. (2026). On the Design and Implementation of a Multiplatform Framework for Social Media Data Collection. In Advanced Information Networking and Applications (AINA 2026). Wellington, New Zealand: Springer. doi:10.1007/978-3-032-23335-6_32
Export
BibTeX
@inproceedings{Frasao_AINA26, TITLE = {On the Design and Implementation of a Multiplatform Framework for Social Media Data Collection}, AUTHOR = {Frasao, Anderson and Heinrich, Tiago and Fulber-Garcia, Vinicius}, LANGUAGE = {eng}, ISBN = {978-3-032-23334-9}, DOI = {10.1007/978-3-032-23335-6_32}, PUBLISHER = {Springer}, YEAR = {2026}, DATE = {2026}, BOOKTITLE = {Advanced Information Networking and Applications (AINA 2026)}, EDITOR = {Barolli, Leonard and Seah, Winston K. G. and Woungang, Isaac}, PAGES = {353--365}, SERIES = {Lecture Notes on Data Engineering and Communications Technologies}, VOLUME = {299}, ADDRESS = {Wellington, New Zealand}, }
Endnote
%0 Conference Proceedings %A Frasao, Anderson %A Heinrich, Tiago %A Fulber-Garcia, Vinicius %+ External Organizations Internet Architecture, MPI for Informatics, Max Planck Society External Organizations %T On the Design and Implementation of a Multiplatform Framework for Social Media Data Collection : %G eng %U http://hdl.handle.net/21.11116/0000-0013-4EA1-E %R 10.1007/978-3-032-23335-6_32 %D 2026 %B 40th International Conference on Advanced Information Networking and Applications %Z date of event: 2026-04-08 - 2026-04-10 %C Wellington, New Zealand %B Advanced Information Networking and Applications %E Barolli, Leonard; Seah, Winston K. G.; Woungang, Isaac %P 353 - 365 %I Springer %@ 978-3-032-23334-9 %B Lecture Notes on Data Engineering and Communications Technologies %N 299
Heinrich, T., & Obelheiro, R. R. (n.d.). An Experience Report: Honeypots for DRDoS Attacks. In Advanced Information Networking and Applications (AINA 2026). Wellington, New Zealand: Springer.
(Accepted/in press)
Export
BibTeX
@inproceedings{, TITLE = {An Experience Report: {H}oneypots for {DRDoS} Attacks}, AUTHOR = {Heinrich, Tiago and Obelheiro, Rafael R.}, PUBLISHER = {Springer}, YEAR = {2026}, PUBLREMARK = {Accepted}, BOOKTITLE = {Advanced Information Networking and Applications (AINA 2026)}, SERIES = {Lecture Notes on Data Engineering and Communications Technologies}, VOLUME = {294}, ADDRESS = {Wellington, New Zealand}, }
Endnote
%0 Conference Proceedings %A Heinrich, Tiago %A Obelheiro, Rafael R. %+ Internet Architecture, MPI for Informatics, Max Planck Society External Organizations %T An Experience Report: Honeypots for DRDoS Attacks : %U http://hdl.handle.net/21.11116/0000-0013-211D-6 %D 2026 %B 40th International Conference on Advanced Information Networking and Applications %Z date of event: 2026-04-08 - 2026-04-10 %C Wellington, New Zealand %B Advanced Information Networking and Applications %I Springer %B Lecture Notes on Data Engineering and Communications Technologies %N 294
Heinrich, T., Kreutz, D., Lunardi, R., Mansilha, R., Fulber-Garcia, V., Pereira, L. A., & Obelheiro, R. R. (2026). An Experience Report on Artifact Evaluation in Brazilian Conferences. ACM SIGCOMM Computer Communication Review, 56(1). doi:10.1145/3806097.3806100
Export
BibTeX
@article{Heinrich26, TITLE = {An Experience Report on Artifact Evaluation in {B}razilian Conferences}, AUTHOR = {Heinrich, Tiago and Kreutz, Diego and Lunardi, Roben and Mansilha, Rodrigo and Fulber-Garcia, Vinicius and Pereira, Lourenco Alves and Obelheiro, Rafael R.}, LANGUAGE = {eng}, ISSN = {0146-4833}, DOI = {10.1145/3806097.3806100}, PUBLISHER = {ACM}, ADDRESS = {New York, NY}, YEAR = {2026}, DATE = {2026}, JOURNAL = {ACM SIGCOMM Computer Communication Review}, VOLUME = {56}, NUMBER = {1}, PAGES = {11--17}, }
Endnote
%0 Journal Article %A Heinrich, Tiago %A Kreutz, Diego %A Lunardi, Roben %A Mansilha, Rodrigo %A Fulber-Garcia, Vinicius %A Pereira, Lourenco Alves %A Obelheiro, Rafael R. %+ Internet Architecture, MPI for Informatics, Max Planck Society External Organizations External Organizations External Organizations External Organizations External Organizations External Organizations %T An Experience Report on Artifact Evaluation in Brazilian Conferences : %G eng %U http://hdl.handle.net/21.11116/0000-0013-2113-0 %R 10.1145/3806097.3806100 %7 2026-05-01 %D 2026 %J ACM SIGCOMM Computer Communication Review %V 56 %N 1 %& 11 %P 11 - 17 %I ACM %C New York, NY %@ false
Heinrich, T., Will, N. C., Obelheiro, R., & Maziero, C. (2026). A Method for Detecting Anomalies in WebAssembly Using Categorical Data. SN Computer Science, 7. doi:10.1007/s42979-025-04599-6
Export
BibTeX
@article{HeinrichSN26, TITLE = {A Method for Detecting Anomalies in {WebAssembly} Using Categorical Data}, AUTHOR = {Heinrich, Tiago and Will, Newton Carlos and Obelheiro, Rafael and Maziero, Carlos}, LANGUAGE = {eng}, DOI = {10.1007/s42979-025-04599-6}, PUBLISHER = {Springer}, ADDRESS = {New York, NY}, YEAR = {2026}, DATE = {2026}, JOURNAL = {SN Computer Science}, VOLUME = {7}, EID = {68}, }
Endnote
%0 Journal Article %A Heinrich, Tiago %A Will, Newton Carlos %A Obelheiro, Rafael %A Maziero, Carlos %+ Internet Architecture, MPI for Informatics, Max Planck Society External Organizations External Organizations External Organizations %T A Method for Detecting Anomalies in WebAssembly Using Categorical Data : %G eng %U http://hdl.handle.net/21.11116/0000-0013-2DF2-8 %R 10.1007/s42979-025-04599-6 %7 2026-01-07 %D 2026 %J SN Computer Science %V 7 %Z sequence number: 68 %I Springer %C New York, NY
Heinrich, T., Giessler, S., Klein, D., & Dirksen, A. (2026). FAIR Enough? Assessing Open Science Practices on a Top-Tier Security & Privacy Conference. In 1st Workshop on Metascience and Critical Reflections in Security & Privacy (MetaCRiSP 2026). San Francisco, CA, USA.
Export
BibTeX
@inproceedings{Heinrich_MetaCRiSP26, TITLE = {{FAIR} Enough? {A}ssessing Open Science Practices on a Top-Tier Security & Privacy Conference}, AUTHOR = {Heinrich, Tiago and Giessler, Sebastian and Klein, David and Dirksen, Alexandra}, LANGUAGE = {eng}, YEAR = {2026}, BOOKTITLE = {1st Workshop on Metascience and Critical Reflections in Security \& Privacy (MetaCRiSP 2026)}, ADDRESS = {San Francisco, CA, USA}, }
Endnote
%0 Conference Proceedings %A Heinrich, Tiago %A Giessler, Sebastian %A Klein, David %A Dirksen, Alexandra %+ Internet Architecture, MPI for Informatics, Max Planck Society External Organizations External Organizations External Organizations %T FAIR Enough? Assessing Open Science Practices on a Top-Tier Security & Privacy Conference : %G eng %U http://hdl.handle.net/21.11116/0000-0013-2DE5-7 %D 2026 %B 1st Workshop on Metascience and Critical Reflections in Security & Privacy %Z date of event: 2026-05-21 - 2026-05-21 %C San Francisco, CA, USA %B 1st Workshop on Metascience and Critical Reflections in Security & Privacy
Kappes, S., Steger, L., Le Pochat, V., Gasser, O., Zirngibl, J., & Heinrich, T. (2026). How Did You Find That Address? An In-Depth Investigation of Domain-Based IPv6 Scanners. Proceedings of the ACM on Networking (Proc. CoNEXT 2026), 4(CoNEXT3). doi:10.1145/3749221
Export
BibTeX
@article{Tanveer_CoNEXT25, TITLE = {How Did You Find That Address? {A}n In-Depth Investigation of Domain-Based {IPv6} Scanners}, AUTHOR = {Kappes, Sebastian and Steger, Lion and Le Pochat, Victor and Gasser, Oliver and Zirngibl, Johannes and Heinrich, Tiago}, LANGUAGE = {eng}, ISSN = {2834-5509}, DOI = {10.1145/3749221}, PUBLISHER = {ACM}, ADDRESS = {New York, NY}, YEAR = {2026}, JOURNAL = {Proceedings of the ACM on Networking (Proc. CoNEXT)}, VOLUME = {4}, NUMBER = {CoNEXT3}, PAGES = {1--25}, EID = {35}, BOOKTITLE = {The 22nd International Conference on emerging Networking EXperiments and Technologies (CoNEXT 2026)}, }
Endnote
%0 Journal Article %A Kappes, Sebastian %A Steger, Lion %A Le Pochat, Victor %A Gasser, Oliver %A Zirngibl, Johannes %A Heinrich, Tiago %+ Internet Architecture, MPI for Informatics, Max Planck Society External Organizations External Organizations External Organizations Internet Architecture, MPI for Informatics, Max Planck Society Internet Architecture, MPI for Informatics, Max Planck Society %T How Did You Find That Address? An In-Depth Investigation of Domain-Based IPv6 Scanners : %G eng %U http://hdl.handle.net/21.11116/0000-0013-6AEA-D %R 10.1145/3749221 %7 2026 %D 2026 %J Proceedings of the ACM on Networking %O PACMNET %V 4 %N CoNEXT3 %& 1 %P 1 - 25 %Z sequence number: 35 %I ACM %C New York, NY %@ false %B The 22nd International Conference on emerging Networking EXperiments and Technologies %O CoNEXT 2026 Utrecht, The Netherlands, December 7-10, 2026
2025
Almeida, G., Pohlmann, M., Severo, A., Kreutz, D., Heinrich, T., & Pereira, L. (2025). On-Premise SLMs vs. Commercial LLMs: Prompt Engineering and Incident Classification in SOCs and CSIRTs. Retrieved from https://arxiv.org/abs/2511.14908
(arXiv: 2511.14908)
Abstract
In this study, we evaluate open-source models for security incident classification, comparing them with proprietary models. We utilize a dataset of anonymized real incidents, categorized according to the NIST SP 800-61r3 taxonomy and processed using five prompt-engineering techniques (PHP, SHP, HTP, PRP, and ZSL). The results indicate that, although proprietary models still exhibit higher accuracy, locally deployed open-source models provide advantages in privacy, cost-effectiveness, and data sovereignty.
Export
BibTeX
@online{Almeida2511.14908, TITLE = {On-Premise {SLMs} vs. Commercial {LLMs}: Prompt Engineering and Incident Classification in {SOCs} and {CSIRTs}}, AUTHOR = {Almeida, Geft{\'e} and Pohlmann, Marcio and Severo, Alex and Kreutz, Diego and Heinrich, Tiago and Pereira, Louren{\c c}o}, LANGUAGE = {eng}, URL = {https://arxiv.org/abs/2511.14908}, EPRINT = {2511.14908}, EPRINTTYPE = {arXiv}, YEAR = {2025}, MARGINALMARK = {$\bullet$}, ABSTRACT = {In this study, we evaluate open-source models for security incident classification, comparing them with proprietary models. We utilize a dataset of anonymized real incidents, categorized according to the NIST SP 800-61r3 taxonomy and processed using five prompt-engineering techniques (PHP, SHP, HTP, PRP, and ZSL). The results indicate that, although proprietary models still exhibit higher accuracy, locally deployed open-source models provide advantages in privacy, cost-effectiveness, and data sovereignty.}, }
Endnote
%0 Report %A Almeida, Gefté %A Pohlmann, Marcio %A Severo, Alex %A Kreutz, Diego %A Heinrich, Tiago %A Pereira, Lourenço %+ External Organizations External Organizations External Organizations External Organizations Internet Architecture, MPI for Informatics, Max Planck Society External Organizations %T On-Premise SLMs vs. Commercial LLMs: Prompt Engineering and Incident Classification in SOCs and CSIRTs : %G eng %U http://hdl.handle.net/21.11116/0000-0013-47A5-1 %U https://arxiv.org/abs/2511.14908 %D 2025 %X In this study, we evaluate open-source models for security incident classification, comparing them with proprietary models. We utilize a dataset of anonymized real incidents, categorized according to the NIST SP 800-61r3 taxonomy and processed using five prompt-engineering techniques (PHP, SHP, HTP, PRP, and ZSL). The results indicate that, although proprietary models still exhibit higher accuracy, locally deployed open-source models provide advantages in privacy, cost-effectiveness, and data sovereignty. %K Computer Science, Cryptography and Security, cs.CR,Computer Science, Artificial Intelligence, cs.AI,Computer Science, Learning, cs.LG,
Hennen, P., Heinrich, T., & Zirngibl, J. (2025). Measuring Increasing Heterogeneity in BGP. In IEEE Symposium on Network Operations and Management (NOMS 2025). Honolulu, HI, USA: IEEE. doi:10.1109/NOMS57970.2025.11073585
Export
BibTeX
@inproceedings{Hennen_NOMS25, TITLE = {Measuring Increasing Heterogeneity in {BGP}}, AUTHOR = {Hennen, Pascal and Heinrich, Tiago and Zirngibl, Johannes}, LANGUAGE = {eng}, ISBN = {979-8-3315-3163-8}, DOI = {10.1109/NOMS57970.2025.11073585}, PUBLISHER = {IEEE}, YEAR = {2025}, MARGINALMARK = {$\bullet$}, DATE = {2025}, BOOKTITLE = {IEEE Symposium on Network Operations and Management (NOMS 2025)}, PAGES = {1--4}, ADDRESS = {Honolulu, HI, USA}, }
Endnote
%0 Conference Proceedings %A Hennen, Pascal %A Heinrich, Tiago %A Zirngibl, Johannes %+ Internet Architecture, MPI for Informatics, Max Planck Society Internet Architecture, MPI for Informatics, Max Planck Society Internet Architecture, MPI for Informatics, Max Planck Society %T Measuring Increasing Heterogeneity in BGP : %G eng %U http://hdl.handle.net/21.11116/0000-0012-48E5-9 %R 10.1109/NOMS57970.2025.11073585 %D 2025 %B IEEE Symposium on Network Operations and Management %Z date of event: 2025-05-12 - 2025-05-16 %C Honolulu, HI, USA %B IEEE Symposium on Network Operations and Management %P 1 - 4 %I IEEE %@ 979-8-3315-3163-8
Pohlmann, M., Severo, A., Almeida, G., Kreutz, D., Heinrich, T., & Pereira, L. (2025). Temperature in SLMs: Impact on Incident Categorization in On-Premises Environments. Retrieved from https://arxiv.org/abs/2511.19464
(arXiv: 2511.19464)
Abstract
SOCs and CSIRTs face increasing pressure to automate incident categorization, yet the use of cloud-based LLMs introduces costs, latency, and confidentiality risks. We investigate whether locally executed SLMs can meet this challenge. We evaluated 21 models ranging from 1B to 20B parameters, varying the temperature hyperparameter and measuring execution time and precision across two distinct architectures. The results indicate that temperature has little influence on performance, whereas the number of parameters and GPU capacity are decisive factors.
Export
BibTeX
@online{Pohlmann2511.19464, TITLE = {Temperature in {SLMs}: Impact on Incident Categorization in On-Premises Environments}, AUTHOR = {Pohlmann, Marcio and Severo, Alex and Almeida, Geft{\'e} and Kreutz, Diego and Heinrich, Tiago and Pereira, Louren{\c c}o}, LANGUAGE = {eng}, URL = {https://arxiv.org/abs/2511.19464}, EPRINT = {2511.19464}, EPRINTTYPE = {arXiv}, YEAR = {2025}, MARGINALMARK = {$\bullet$}, ABSTRACT = {SOCs and CSIRTs face increasing pressure to automate incident categorization, yet the use of cloud-based LLMs introduces costs, latency, and confidentiality risks. We investigate whether locally executed SLMs can meet this challenge. We evaluated 21 models ranging from 1B to 20B parameters, varying the temperature hyperparameter and measuring execution time and precision across two distinct architectures. The results indicate that temperature has little influence on performance, whereas the number of parameters and GPU capacity are decisive factors.}, }
Endnote
%0 Report %A Pohlmann, Marcio %A Severo, Alex %A Almeida, Gefté %A Kreutz, Diego %A Heinrich, Tiago %A Pereira, Lourenço %+ External Organizations External Organizations External Organizations External Organizations Internet Architecture, MPI for Informatics, Max Planck Society External Organizations %T Temperature in SLMs: Impact on Incident Categorization in On-Premises Environments : %G eng %U http://hdl.handle.net/21.11116/0000-0013-47A8-E %U https://arxiv.org/abs/2511.19464 %D 2025 %X SOCs and CSIRTs face increasing pressure to automate incident categorization, yet the use of cloud-based LLMs introduces costs, latency, and confidentiality risks. We investigate whether locally executed SLMs can meet this challenge. We evaluated 21 models ranging from 1B to 20B parameters, varying the temperature hyperparameter and measuring execution time and precision across two distinct architectures. The results indicate that temperature has little influence on performance, whereas the number of parameters and GPU capacity are decisive factors. %K Computer Science, Distributed, Parallel, and Cluster Computing, cs.DC,Computer Science, Artificial Intelligence, cs.AI,Computer Science, Cryptography and Security, cs.CR,Computer Science, Learning, cs.LG,Computer Science, Performance, cs.PF,
Rostami, S., Albakour, T., & Heinrich, T. (2025). State of UDP Scanners on the Internet. In Proceedings of the 9th Network Traffic Measurement and Analysis Conference (TMA 2025). Copenhagen, Denmark: IEEE. doi:10.23919/TMA66427.2025.11097012
Export
BibTeX
@inproceedings{Rostami_TMA25, TITLE = {State of {UDP} Scanners on the Internet}, AUTHOR = {Rostami, Sina and Albakour, Taha and Heinrich, Tiago}, LANGUAGE = {eng}, ISBN = {978-3-903176-74-4}, DOI = {10.23919/TMA66427.2025.11097012}, PUBLISHER = {IEEE}, YEAR = {2025}, MARGINALMARK = {$\bullet$}, DATE = {2025}, BOOKTITLE = {Proceedings of the 9th Network Traffic Measurement and Analysis Conference (TMA 2025)}, PAGES = {1--11}, ADDRESS = {Copenhagen, Denmark}, }
Endnote
%0 Conference Proceedings %A Rostami, Sina %A Albakour, Taha %A Heinrich, Tiago %+ Internet Architecture, MPI for Informatics, Max Planck Society Internet Architecture, MPI for Informatics, Max Planck Society Internet Architecture, MPI for Informatics, Max Planck Society %T State of UDP Scanners on the Internet : %G eng %U http://hdl.handle.net/21.11116/0000-0013-478B-F %R 10.23919/TMA66427.2025.11097012 %D 2025 %B 9th Network Traffic Measurement and Analysis Conference %Z date of event: 2025-06-10 - 2025-06-13 %C Copenhagen, Denmark %B Proceedings of the 9th Network Traffic Measurement and Analysis Conference %P 1 - 11 %I IEEE %@ 978-3-903176-74-4
Viescinski, A., Heinrich, T., Fulber-Garcia, V., & Maziero, C. (2025). How Risky Is It? A Closer Look at Game Anti-Cheat Software. In 30th IEEE Symposium on Computers and Communications (ISCC 2025). Bologna, Italy: IEEE. doi:10.1109/ISCC65549.2025.11325807
Export
BibTeX
@inproceedings{Viescinski_ISCC25, TITLE = {How Risky Is It? {A} Closer Look at Game Anti-Cheat Software}, AUTHOR = {Viescinski, Amanda and Heinrich, Tiago and Fulber-Garcia, Vinicius and Maziero, Carlos}, LANGUAGE = {eng}, ISBN = {979-8-3315-2420-3}, DOI = {10.1109/ISCC65549.2025.11325807}, PUBLISHER = {IEEE}, YEAR = {2025}, MARGINALMARK = {$\bullet$}, DATE = {2025}, BOOKTITLE = {30th IEEE Symposium on Computers and Communications (ISCC 2025)}, PAGES = {1--6}, ADDRESS = {Bologna, Italy}, }
Endnote
%0 Conference Proceedings %A Viescinski, Amanda %A Heinrich, Tiago %A Fulber-Garcia, Vinicius %A Maziero, Carlos %+ External Organizations Internet Architecture, MPI for Informatics, Max Planck Society External Organizations External Organizations %T How Risky Is It? A Closer Look at Game Anti-Cheat Software : %G eng %U http://hdl.handle.net/21.11116/0000-0013-47A3-3 %R 10.1109/ISCC65549.2025.11325807 %D 2025 %B 30th IEEE Symposium on Computers and Communications %Z date of event: 2025-07-02 - 2025-07-05 %C Bologna, Italy %B 30th IEEE Symposium on Computers and Communications %P 1 - 6 %I IEEE %@ 979-8-3315-2420-3
Yazdani, Z., Hilal, F., Testart, C., Dainotti, A., Vermeulen, K., Heinrich, T., & Albakour, T. (2025). Poster: Investigating the Survivability of the Experimental TCP Option. In IMC ’25, ACM on Internet Measurement Conference. Madison, WI, USA: ACM. doi:10.1145/3730567.3768588
Export
BibTeX
@inproceedings{Yazdani_IMC25, TITLE = {Poster: {I}nvestigating the Survivability of the Experimental {TCP} Option}, AUTHOR = {Yazdani, Zahra and Hilal, Fahad and Testart, Cecilia and Dainotti, Alberto and Vermeulen, Kevin and Heinrich, Tiago and Albakour, Taha}, LANGUAGE = {eng}, ISBN = {979-8-4007-1860-1}, DOI = {10.1145/3730567.3768588}, PUBLISHER = {ACM}, YEAR = {2025}, MARGINALMARK = {$\bullet$}, DATE = {2025}, BOOKTITLE = {IMC '25, ACM on Internet Measurement Conference}, EDITOR = {Barford, Paul and Balasubramanian, Aruna and Dainotti, Alberto}, PAGES = {1080--1081}, ADDRESS = {Madison, WI, USA}, }
Endnote
%0 Conference Proceedings %A Yazdani, Zahra %A Hilal, Fahad %A Testart, Cecilia %A Dainotti, Alberto %A Vermeulen, Kevin %A Heinrich, Tiago %A Albakour, Taha %+ External Organizations Internet Architecture, MPI for Informatics, Max Planck Society External Organizations External Organizations External Organizations Internet Architecture, MPI for Informatics, Max Planck Society Internet Architecture, MPI for Informatics, Max Planck Society %T Poster: Investigating the Survivability of the Experimental TCP Option : %G eng %U http://hdl.handle.net/21.11116/0000-0013-6AF0-5 %R 10.1145/3730567.3768588 %D 2025 %B ACM on Internet Measurement Conference %Z date of event: 2025-10-28 - 2025-10-31 %C Madison, WI, USA %B IMC '25 %E Barford, Paul; Balasubramanian, Aruna; Dainotti, Alberto %P 1080 - 1081 %I ACM %@ 979-8-4007-1860-1
2024
Frasão, A., Heinrich, T., Fulber-Garcia, V., Will, N. C., Obelheiro, R. R., & Maziero, C. A. (2024). I See Syscalls by the Seashore: An Anomaly-based IDS for Containers Leveraging Sysdig Data. In 29th IEEE Symposium on Computers and Communications (ISCC 2024). Paris, France: IEEE. doi:10.1109/ISCC61673.2024.10733595
Export
BibTeX
@inproceedings{Frasao_ISCC24, TITLE = {I See Syscalls by the Seashore: {A}n Anomaly-based {IDS} for Containers Leveraging Sysdig Data}, AUTHOR = {Fras{\~a}o, Anderson and Heinrich, Tiago and Fulber-Garcia, Vinicius and Will, Newton C. and Obelheiro, Rafael R. and Maziero, Carlos A.}, LANGUAGE = {eng}, ISBN = {979-8-3503-5423-2}, DOI = {10.1109/ISCC61673.2024.10733595}, PUBLISHER = {IEEE}, YEAR = {2024}, MARGINALMARK = {$\bullet$}, DATE = {2024}, BOOKTITLE = {29th IEEE Symposium on Computers and Communications (ISCC 2024)}, PAGES = {1--6}, ADDRESS = {Paris, France}, }
Endnote
%0 Conference Proceedings %A Frasão, Anderson %A Heinrich, Tiago %A Fulber-Garcia, Vinicius %A Will, Newton C. %A Obelheiro, Rafael R. %A Maziero, Carlos A. %+ External Organizations Internet Architecture, MPI for Informatics, Max Planck Society External Organizations External Organizations External Organizations External Organizations %T I See Syscalls by the Seashore: An Anomaly-based IDS for Containers Leveraging Sysdig Data : %G eng %U http://hdl.handle.net/21.11116/0000-0010-4428-5 %R 10.1109/ISCC61673.2024.10733595 %D 2024 %B 29th IEEE Symposium on Computers and Communications %Z date of event: 2024-06-26 - 2024-06-29 %C Paris, France %B 29th IEEE Symposium on Computers and Communications %P 1 - 6 %I IEEE %@ 979-8-3503-5423-2
Helpa, C., Heinrich, T., Botacin, M., Will, N., Obelheiro, R., & Maziero, C. (2024). The Use of the DWARF Debugging Format for the Identification of Potentially Unwanted Applications (PUAs) in WebAssembly Binaries. In Proceedings of the 21st International Conference on Security and Cryptography. - Vol.1 (SECRYPT 2024). Dijon, France: SciTePress. doi:10.5220/0012754500003767
Export
BibTeX
@inproceedings{Helpa_SECRYPT24, TITLE = {The Use of the {DWARF} Debugging Format for the Identification of Potentially Unwanted Applications ({PUAs}) in {WebAssembly} Binaries}, AUTHOR = {Helpa, Calebe and Heinrich, Tiago and Botacin, Marcus and Will, Newton and Obelheiro, Rafael and Maziero, Carlos}, LANGUAGE = {eng}, ISBN = {978-989-758-709-2}, DOI = {10.5220/0012754500003767}, PUBLISHER = {SciTePress}, YEAR = {2024}, MARGINALMARK = {$\bullet$}, DATE = {2024}, BOOKTITLE = {Proceedings of the 21st International Conference on Security and Cryptography. -- Vol.1 (SECRYPT 2024)}, EDITOR = {De Capitani Di Vimercati, Sabrina and Samarati, Pierangela}, PAGES = {442--449}, ADDRESS = {Dijon, France}, }
Endnote
%0 Conference Proceedings %A Helpa, Calebe %A Heinrich, Tiago %A Botacin, Marcus %A Will, Newton %A Obelheiro, Rafael %A Maziero, Carlos %+ External Organizations Internet Architecture, MPI for Informatics, Max Planck Society External Organizations External Organizations External Organizations External Organizations %T The Use of the DWARF Debugging Format for the Identification of Potentially Unwanted Applications (PUAs) in WebAssembly Binaries : %G eng %U http://hdl.handle.net/21.11116/0000-0010-442C-1 %R 10.5220/0012754500003767 %D 2024 %B 21st International Conference on Security and Cryptography %Z date of event: 2024-07-08 - 2024-07-10 %C Dijon, France %B Proceedings of the 21st International Conference on Security and Cryptography. - Vol.1 %E De Capitani Di Vimercati, Sabrina; Samarati, Pierangela %P 442 - 449 %I SciTePress %@ 978-989-758-709-2
Rostami, S., Heinrich, T., & Albakour, T. (2024). Poster: An Investigation into Internet-facing Router Services. In IMC ’24, ACM on Internet Measurement Conference. Madrid, Spain: ACM. doi:10.1145/3646547.3689674
Export
BibTeX
@inproceedings{Rostami_IMC24, TITLE = {Poster: {A}n Investigation into Internet-facing Router Services}, AUTHOR = {Rostami, Sina and Heinrich, Tiago and Albakour, Taha}, LANGUAGE = {eng}, ISBN = {979-8-4007-0592-2}, DOI = {10.1145/3646547.3689674}, PUBLISHER = {ACM}, YEAR = {2024}, MARGINALMARK = {$\bullet$}, DATE = {2024}, BOOKTITLE = {IMC '24, ACM on Internet Measurement Conference}, EDITOR = {Vallina-Rodr{\'i}guez, Narseo and Suarez-T{\'a}ngil, Guillermo and Levin, Dave and Pelsser, Cristal and Pastrana, Sergio and Sun, Yixin}, PAGES = {775--776}, ADDRESS = {Madrid, Spain}, }
Endnote
%0 Conference Proceedings %A Rostami, Sina %A Heinrich, Tiago %A Albakour, Taha %+ Internet Architecture, MPI for Informatics, Max Planck Society Internet Architecture, MPI for Informatics, Max Planck Society Internet Architecture, MPI for Informatics, Max Planck Society %T Poster: An Investigation into Internet-facing Router Services : %G eng %U http://hdl.handle.net/21.11116/0000-0010-4416-9 %R 10.1145/3646547.3689674 %D 2024 %B ACM on Internet Measurement Conference %Z date of event: 2024-11-04 - 2024-11-06 %C Madrid, Spain %B IMC '24 %E Vallina-Rodríguez, Narseo; Suarez-Tángil, Guillermo; Levin, Dave; Pelsser, Cristal; Pastrana, Sergio; Sun, Yixin %P 775 - 776 %I ACM %@ 979-8-4007-0592-2

Research Interests

  • Computer Networks
  • Network Monitoring and Measurements
  • Intrusion Detection
  • Computer and Network Security

Honours & Awards

  • Best Paper Award New Kids on the DRDoS Block: Characterizing Multiprotocol and Carpet Bombing Attacks Passive and Active Measurement Conference (PAM’21)
  • One of the best among all the submissions (top 5) Latin American Student Workshop on Data Communication Networks (LANCOMM)
     

Reviewing Activity & Workshop / Conference positions

  • AEC Publication Chair, USENIX Security ’25’26
  • TPC Member, WWW’26
  • TPC Member, IEEE S&P’26’27
  • TPC Member, DIMVA’25’26
  • TPC Member, IEEE SysCon’23’24’25
  • TPC Member, SECRYPT’24’25’26
  • Editor Special Issue, JBCS’24
  • AEC Mentor, ACSAC’24
  • AEC Member, SIGCOMM’24
  • AEC Member, USENIX Security’23’24
  • Reviewer Computers & Security Journal

Teachings

Recent Positions

2024 - today
Postdoc researcher, INET group, Max Planck Institute for Informatics, Germany

Education

2019 - 2023
PhD in Informatics at Federal University of Paraná (UFPR), Brazil

2017 - 2019
MSc in Applied Computing at Santa Catarina State University (UDESC), Brazil

2013 - 2017
BS in Computer Science at Santa Catarina State University (UDESC), Brazil