Rafael Accorsi

dblp:02/3544 · DBLP profile ↗
← Back
11ranked-venue papers
7as first author
0since 2021 · last 2015
0000-0001-5620-561XORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 5 · 4 first-authorSoftware engineering, systems software and programming languages · 5 · 2 first-authorApplied, interdisciplinary, general and emerging computing · 3 · 1 first-authorDatabases, data management, data science and information retrieval · 1 · 1 first-author

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Software engineering, system software, and programming languages
1 paper
Services computing and microservices · 56% Empirical software engineering · 44%
Network and information security
1 paper
Systems and software security · 100%

Topics — the 4 heaviest of 4, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Systems and software security
vulnerability analysis
0.112011
Vulnerability Analysis in SOA-Based Business Processes · IEEE Trans. Serv. Comput. 2011
Services computing and microservices
service-oriented architecture
0.112011
Vulnerability Analysis in SOA-Based Business Processes · IEEE Trans. Serv. Comput. 2011
Empirical software engineering › mining software repositories
vulnerability analysis
0.112011
Vulnerability Analysis in SOA-Based Business Processes · IEEE Trans. Serv. Comput. 2011
Services computing and microservices
business process
0.012011
Vulnerability Analysis in SOA-Based Business Processes · IEEE Trans. Serv. Comput. 2011

Methods — techniques the papers use, named apart from their topics

attack trees · 0.2FMEA · 0.2
YearPublicationVenuePosition
2015 A Posteriori Process Security Control
Rafael Accorsi
ICISSP1
2015 Information leak detection in business process models: Theory, application, and tool support
Rafael Accorsi, Andreas Lehmann 0001, Niels Lohmann
Inf. Syst.1
2014 Privacy Dashboards: Reconciling Data-Driven Business Models and Privacy
abstract
We argue for the use of Privacy Dashboards as enablers for privacy-enabled data-driven business models. Specifically, while dashboards are succesful instruments in business intelligence tools, their use in privacy protection is far less well-understood. Addressing this problem at the technical level, this paper provides a classification scheme for Privacy Dashboards and elaborates on the current state of the art to draw a research agenda for designing Privacy Dashboards that cater to users' desire of control and businesses' need for data collection and usage.
Christian Zimmermann 0002, Rafael Accorsi, Günter Müller
ARES2
2012 Automatic Information Flow Analysis of Business Process Models
Rafael Accorsi, Andreas Lehmann 0001
BPM1
2011 SWAT: A Security Workflow Analysis Toolkit for Reliably Secure Process-aware Information Systems
abstract
This paper reports on ongoing work on SWAT, a new toolkit for security workflow analysis. SWAT provides a platform for the realization and testing of well-founded methods to detect information leaks in workflows, both for the workflow certification and for audit based upon the execution traces. Besides presenting the SWAT's functionality and high-level architecture, an example illustrates its operation.
Rafael Accorsi, Claus Wonnemann, Sebastian Dochow
ARES1
2011 Forensic Leak Detection for Business Process Models
Rafael Accorsi, Claus Wonnemann
IFIP Int. Conf. Digital Forensics1
2011 Vulnerability Analysis in SOA-Based Business Processes
abstract
Business processes and services can more flexibly be combined when based upon standards. However, such flexible compositions practically always contain vulnerabilities, which imperil the security and dependability of processes. Vulnerability management tools require patterns to find or monitor vulnerabilities. Such patterns have to be derived from vulnerability types. Existing analysis methods such as attack trees and FMEA result in such types, yet require much experience and provide little guidance during the analysis. Our main contribution is ATLIST, a new vulnerability analysis method with improved transferability. Especially in service-oriented architectures, which employ a mix of established web technologies and SOA-specific standards, previously observed vulnerability types and variations thereof can be found. Therefore, we focus on the detection of known vulnerability types by leveraging previous vulnerability research. A further contribution in this respect is the, to the best of our knowledge, most comprehensive compilation of vulnerability information sources to date. We present the method to search for vulnerability types in SOA-based business processes and services. Also, we show how patterns can be derived from these types, so that tools can be employed. An additional contribution is a case study, in which we apply the new method to an SOA-based business process scenario.
Lutz Lowis, Rafael Accorsi
IEEE Trans. Serv. Comput.2
2009 Log Data as Digital Evidence: What Secure Logging Protocols Have to Offer?
abstract
While log data are being increasingly used as digital evidence in judicial disputes, the extent to which existing secure logging protocols used to collect log data fulfill the legal requirements for admissible evidence remain largely unclear. We elucidate the necessary secure requirements for digital evidence and extensively survey the state of the art secure logging protocols,thereby demonstrating that none of the current proposals fulfills the necessary conditions for admissible evidence.
Rafael Accorsi
COMPSAC (2)1
2009 On a Classification Approach for SOA Vulnerabilities
abstract
Vulnerabilities in operating systems and Web applications have been and are being put into various classifications, leading to a better understanding of their causes and effects, and to improved vulnerability management tool support. In a service-oriented architecture (SOA), additional vulnerabilities exist in the implementations of new standards such as BPEL and SOAP. Attackers can exploit these vulnerabilities to interfere with the business processes, which are executed as orchestration of services. We describe our approach and ongoing work of creating a SOA vulnerability classification.
Lutz Lowis, Rafael Accorsi
COMPSAC (2)2
2009 On Information Flow Forensics in Business Application Scenarios
abstract
To-date, security analysis techniques focus on the explicit access to data, thereby neglecting information flows happening over covert channels. As a result, critical business software applications and their deployment may be labeled secure, whereas in fact they are not. We present ongoing research towards information flow forensics, a novel approach for the a-posteriori detection of information flow. We motivate our work by illustrating the implications of illicit information flow in different software application scenarios and demonstrate why current approaches fall short of effectively enforcing information flow policies in many cases. We show that information flow forensics can mitigate these drawbacks and outline some interesting research challenges involved in its realization.
Claus Wonnemann, Rafael Accorsi, Günter Müller
COMPSAC (2)2
2006 On the Relationship of Privacy and Secure Remote Logging in Dynamic Systems
abstract
We investigate a mechanism for secure remote logging to improve privacy guarantees in dynamic systems. Using an extended threat model for privacy, we first describe outer and inner privacy: outer privacy denotes the traditional attacker model for privacy where identity management systems control the collection of personal, observable information; inner privacy denotes the threat posed by an attacker who attempts to get hold of private log data by tampering with a device. While privacy-enhancing technologies should take outer and inner privacy into account, there is, to our knowledge, no approach for inner privacy, in particular for dynamic systems. To this end, we develop protocols to address inner privacy based on secure logging. Our approach accounts for the capacity limitations of resource-poor devices in dynamic systems, as it allows for the remote storage of log data, while fulfilling its security guarantees. Furthermore, our approach can be smoothly integrated into identity management systems to combine outer and inner privacy. These keywords were added by machine and not by the authors. This process is experimental and the keywords may be updated as the learning algorithm improves.
Rafael Accorsi
SEC1