Image

Dr.-Ing. Florian Hantke

Researcher

© 2026 Florian Hantke

Built with Jekyll - Design based on HTML Codex

Thesis Proposal

Great, you want to write a thesis with me! This is awesome, and I'm looking forward to working with you. This page provides a template and guidelines for writing a thesis proposal for your BSc/MSc thesis with me. It is inspired by Christian Rossow's thesis proposal template. The proposal should be around 3-5 pages long, and it should be written in English.

Motivation

When writing a thesis with me, I want to make sure that we both have a clear and shared understanding of what you want to achieve with your thesis, and that we have a clear plan on how to achieve it. This is why I ask you to write a thesis proposal before you start working on your thesis. The proposal should outline your research questions, the related work in the field, the problem statement, and the planned methodology.

The great thing about writing a thesis proposal is that it gives you the opportunity to think about your research questions and the related work in the field before you start working on your thesis. Also, you can use parts of your proposal later on in your thesis, so it's not a waste of time.

Of course, you are not expected to have a fully fleshed-out proposal at the beginning. In fact, I expect that your proposal will evolve over a few iterations. But, you are not alone in this process. I will be happy to discuss your ideas with you, and to give you feedback on your proposal. Also, I will be happy to provide you with some initial literature that you can use as a starting point for your research. So, let's go!

Motivation (1 pg)

This is the most important part to convince the reader why they should read your work. Here, you should explain why your research is important and why it is relevant to the field of computer security. We probably have talked about potential research ideas,x or you have some of your own. Now, I want to see that you understood why this topic is important. Introduce the topic and the problem or research gap that you want to solve.

Do not present your proposed solution yet, and only briefly touch on related work - both will be addressed in the sections that follow.

Related Work (1 pg)

After motivating your research, you should show that you are aware of the related work in the field. This is important to show that you know what has been done already, and also what has not been done yet. This is important to show that your research is novel and that it contributes to the field.

I do not expect a list of 50 papers only to show that you have read a lot. Rather, I want to see that you have read the 3-5 most relevant papers in the field, and that you understand them. You should be able to explain (in one paragraph) what each paper is about and how it relates to your research. You should also be able to explain the limitations of each paper and show that there is room for improvement that you can address with your research.

How to find related works? Likely, you already have some papers in mind that you want to build upon, or I have mentioned some papers in our discussions. This is a good starting point. From these papers, you can find more related work by looking at the references and the related work section of these papers, as well as looking for papers that have cited the ones you are reading. I would recommend using search engines like Google Scholar ("Cited by", "Similar Articles"). Be aware that there are many papers out there, and not all of them are of good quality. Focus on well-known security conferences (e.g., IEEE S&P, USENIX Security, NDSS, ACM CCS, RAID, ACSAC, DIMVA, AsiaCCS, EuroS&P) and journals (e.g., ACM Transactions on Privacy and Security). If you are unsure about the quality of a paper, just ask me.

Problem Statement (1 pg)

Based on the motivation and the related work, you should now be able to precisely state the problem that you want to solve with your research. This is important to show that you have a clear understanding of what you want to achieve with your research. State the 2-4 research questions you aim to answer. What is your hypothesis? What is your contribution to the field?

Planned Methodology (1-2 pg)

Now that you have stated your problem, you should explain how you plan to solve it. This is important to show that you have a clear plan on how to achieve your research goals. You should explain the tools and methodologies you plan to use (e.g., Web measurements, browser modifications, interviews, surveys), and why you think they are promising. You should also discuss potential alternatives, and brainstorm on risks on your way to success, and how you may mitigate them. Maybe you already have preliminary results from some tests that you can present to make your case stronger.

While thinking about your methodology, you should also think and discuss about how you will evaluate your results. It is great to have interesting results, but can we trust them? We all make mistakes while programming, and we all have biases when interpreting data. This is why it is important to explain how to evaluate your results and how to validate them.

Of course, you are not expected to already know every detail of your methodology at the beginning. This is something that will evolve over time, and you will learn more about it as you work on your thesis. But you should already have a starting point and a good idea of how to achieve your research goals, and you should be able to explain it in your proposal.

Lastly, part of your considerations should include ethics. For example, if you perform offensive research or study humans, you should also discuss ethics here. But also in general, it makes sense to think about the ethical implications of your research, and to show that you are aware of them. Read more about this in ourRed Lines paper or Kohno's paper on ethics in security research.

Timeline (Optional)

Experience has shown that some students benefit from having a clear schedule with verifiable milestones to be reached on specific dates. This is not a requirement, but if you think this would help you, feel free to add a timeline here. You can use a simple table with milestones and dates, or you can use a Gantt chart, or whatever you think is best. If you are unsure about your timeline, just ask. I will be happy to help you to create a realistic timeline.

Bibliography

List all references that you cited in the text here. Please use LaTeX's bibliography tools to format your bibliography.

Further Hints

Finally, here are some general hints that may help you to write a good thesis (proposal).

  • Use LaTeX and its bibliography tools (see here).
  • Use a tool like Zotero to manage your references.
  • Assume you are writing for an audience with general knowledge of Computer Scientists and standard security knowledge. There is no need to explain XXS or the Web, yet any technical details beyond standard knowledge should be briefly explained to also shown that you know what you are talking about, and we are on the same page.
  • To make the text more engaging, use active tense ("We plan to..."), not passive ("It is planned to...").
  • Use "we", not "I". An academic publication is in most cases a collective effort.
  • AI... Yes, of course, it makes writing easier, but at the same time, you won't learn as much, and the result may be less insightful. Only by engaging deeply with your text while writing will you gain a deeper understanding of your experiments and data. While writing, you'll get new ideas that you would not have if you rely solely on AI tools. Use an LLM only to find typos and suggest grammatical improvements.

© 2026 Florian Hantke

Built with Jekyll - Design based on HTML Codex