Simon Koch

Postdoc at the Security and Privacy Lab.

profile_pic.jpg

Office:

ICT 2W02

Technikerstraße 21A

6020, Innsbruck

Austria

I am a postdoctoral fellow at the Security and Privacy Lab at the University of Innsbruck with Rainer Böhme. My research interests cover questions surrounding privacy and security focussing on mobile and web technologies. For mobile privacy I primarily conduct dynamic traffic measurements to assess the data leaked by applications. Whereas for web security I am doing both dynamic and static program analysis research, trying to understand live deployments as well as discovering new vulnerabilities of web applications. If some of my work peaked your interest I am always interested in new collaborations.

I did my PhD with Martin Johns at the Institute for Application Security, TU Braunschweig and defended in April of 2025.

news

Jun 20, 2025 The two papers “Extract: A PHP Foot-Gun Case Study” and “Confusing Value with Enumeration: Studying the Use of CVEs in Academia” I contributed to were accepted at WOOT and USENIX 2025.
Jun 02, 2025 I started my new postdoc position at the Security and Privacy Lab of Rainer Böhme at the University of Innsbruck.
Apr 14, 2025 I successfully defended my PhD and got a summa cum laude. Very greatful to have finally passed this milestone.

selected publications

  1. Confusing Value with Enumeration: Studying the Use of CVEs in Academia
    Moritz Schloegel , Daniel Klischies , Simon Koch, David Klein , Lukas Gerlach , Malte Wessels , Leon Trampert , Martin Johns , Mathy Vanhoef , Michael Schwarz , Thorsten Holz , and Jo Van Bulck
    In USENIX Security Symposium , 2025
  2. HyTrack: Resurrectable and Persistent Tracking Across Android Apps and the Web
    Malte Wessels , Simon Koch, Jan Niklas Dreschner , Louis Bettels , David Klein , and Martin Johns
    In USENIX Security Symposium , 2025
  3. The Impact of Default Mobile SDK Usage on Privacy and Data Protection
    Simon Koch, Manuel Karl , Robin Kirchner , Malte Wessels , Anne Paschke , and Martin Johns
    In Privacy Enhancing Technologies Symposium (PETS) , 2025
  4. The OK is Not Enough: Large Scale Study of Consent Dialogs in Smartphone Applications
    Simon Koch, Benjamin Altpeter , and Martin Johns
    In USENIX Security Symposium , 2023
  5. FUZZILLI: Fuzzing for JavaScript JIT Compiler Vulnerabilities
    Samuel Groß , Simon Koch, Lukas Bernhardt , Thorsten Holz , and Martin Johns
    In Network and Distributed System Security (NDSS) Symposium , 2023