Research Focus

  • AI-Driven Penetration Testing

    Penetration testing is still largely manual: labour-intensive, expensive, and hardly reproducible. The group investigates how AI-based agents and scanners can automate and scale security testing and make results comparable. Among other settings, the IT infrastructure of the Technische Hochschule Ingolstadt campus serves as a real-world laboratory, where AI-driven scanners are continuously deployed for protection and scientifically evaluated.

  • Quality Assessment of Program Analyses

    Tools such as fuzzing, symbolic execution, and static analysis discover vulnerabilities automatically. But how good are these analyses really, and where do they remain blind? The group develops metrics that go beyond classical coverage measures, systematically evaluates analysis tools, and derives concrete improvements for analysis pipelines in development practice.

  • Quality Assessment of Security Mechanisms

    For every threat there is a multitude of possible defence mechanisms, for example intrusion detection systems for connected vehicles. Selecting the right mechanism requires a fair, systematic comparison. Building on a purpose-built methodology for the quality assessment of intrusion detection systems, the group researches quality criteria, benchmark datasets, and automated effectiveness evidence for security mechanisms.

  • How We Work

    The group combines constructive and offensive security research: from binary analysis and reverse engineering of individual programs, through automated testing techniques such as fuzzing, to security testing of real, productive infrastructures. For this work, the group uses the laboratories and test vehicles of C-ECOS.

  • Teaching

    The group's research feeds directly into teaching, particularly in the bachelor's programme Cybersecurity, including the courses Advanced Cybersecurity, Security Architecture & Security Engineering, Security of Mobile and Web-Based Applications, and Reverse Engineering. In addition, Prof. Hutzelmann leads the THI student CTF team, which trains practical attack and defence techniques in capture-the-flag competitions.

  • Cooperation

The group works closely with the “Security in Mobility” research group (CARISSMA Institute of Electric, Connected and Secure Mobility) (Prof. Dr.-Ing. Hans-Joachim Hof): while that group focuses on attacks on vehicles and their defence, the Software and System Security group adds the methodological perspective of measurement and assessment.

 

Contact

Prof. Dr. Thomas Hutzelmann
Academic Advisor Cybersecurity
Prof. Dr. Thomas Hutzelmann
Phone: +49 841 9348-2291
E-Mail:

Info

Theses (Bachelor’s/Master’s) and student placements are available at any time. Please feel free to get in touch.

Publications: see www.thi.de/personen/prof-dr-thomas-hutzelmann/