Information Security
We Advance IT Security
The Information Security Research Group of the InIT is the first address for education and applied research and development in the field of information security in the Zurich area and beyond. Our vision is to combine science and practice to develop innovative security solutions for companies and the public to ensure the cyber security of tomorrow.
The knowledge gained from applied research and development also flows into our educational programs in the Bachelor's, Master's, PhD and Continuous Education program.
The Information Security research group is part of the ZHAW Cybersecurity Community.
Security by Design
In the area of security by design, we develop systems and methods that integrate security into the design process from the outset. This includes systems with security functions, such as cybersecurity management systems for organizations or systems to support analysts in a Security Operation Center (SOC), as well as systems in which security is only a means to an end, such as the development of secure communication networks or the secure processing of sensitive data.
A current project in this research area:
Security Analysis
In the field of security analysis, we examine systems for potential vulnerabilities. We are interested in a wide range of systems, from hardware-based communication systems to applications and firmware on mobile devices to web applications. We use our specialist knowledge for the analysis and develop systems that search for vulnerabilities as automatically as possible. Through our work, we can warn those affected of potential threats while advancing the state of the art of analysis tools.
A current project in this research area:
In the FirmewareDroid project, we identify the current difficulties and limitations that hinder security researchers in performing a dynamic analysis of pre-installed Android software components, such as pre-installed apps or native libraries. Based on the results of a literature review, we derive potential solution ideas and develop a concept for a security testing framework that enables researchers to dynamically test pre-installed Android software. We test the concept with proof-of-concept prototypes that demonstrate the feasibility of our basic solution ideas. We then use these prototypes to analyze a large data collection of Android firmware for potential vulnerabilities.
Continuing Education
CAS Applied Network & System Security: This page is not available in English. Please refer to the German page.
CAS Secure Software Design & Development: This page is not available in English. Please refer to the German page.
-
Beljulji, Edin; Gür, Gürkan,
2026.
[SOK] Large language models in security code review and testing.
Journal of Systems Research.
5(1).
Available from: https://doi.org/10.5070/sr3.62177
-
Cantali, Gökcan; Gür, Gürkan; Stiller, Burkhard,
2025.
FedSynthesis : a flower-based framework for carbon-reduced federated learning[paper].
In:
Proceedings of the 18th IEEE/ACM International Conference on Utility and Cloud Computing.
18th IEEE/ACM International Conference on Utility and Cloud Computing (UCC), Nantes, France, 1-4 December 2025.
Association for Computing Machinery.
Available from: https://doi.org/10.1145/3773274.3774265
-
Meier Azhari, Michael; Soussi, Wissem; Gür, Gürkan,
2025.
CubeMig : MTD live migration in Kubernetes with LLM-augmented post-incident analysis[paper].
In:
2025 IEEE Conference on Network Function Virtualization and Software-Defined Networking (NFV-SDN).
11th IEEE Conference on Network Functions Virtualization and Software-Defined Networking (NFV-SDN), Athens, Greece, 10-12 November 2025.
IEEE.
Available from: https://doi.org/10.1109/nfv-sdn66355.2025.11349649
-
Trammell, Ariane; Rennhard, Marc; Amon, Maurice; Wolf, Louie,
2025.
Towards an AI-based security consultant for SMEs[poster].
In:
Swiss Cyber Storm - AI Village, Bern, Switzerland, 28 October 2025.
ZHAW Zurich University of Applied Sciences.
Available from: https://doi.org/10.21256/zhaw-34519
-
Gaber, Chrystel; Dejon, Nicolas; Ndiaye, Ndeye G.; Waedt, Karl; Lefebvre, Vincent; Gür, Gürkan; Rennhard, Marc; Marinakis, Achilleas; Gizelis, Christos A.; Wary, Jean-Philippe; Loiseaux, Claire,
2025.
A continuous certification readiness framework for cloudification of IT/OT platforms[paper].
In:
2025 IEEE International Conference on Cloud Engineering (IC2E).
13th IEEE International Conference on Cloud Engineering (IC2E), Rennes, France, 23-26 September 2025.
IEEE.
pp. 42-46.
Available from: https://doi.org/10.1109/ic2e65552.2025.00011