VLDB 2026 Research / reviewers in the wild / expert
Stephan Seifermann
dblp:162/8631
· DBLP profile ↗
14ranked-venue papers
5as first author
7since 2021 · last 2023
0000-0002-9727-0407ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 11 · 4 first-author · 6 since 2021Applied, interdisciplinary, general and emerging computing · 4 · 2 since 2021Security and privacy · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2023 | Generating adaptation rule-specific neural networks
Tomás Bures, Petr Hnetynka, Martin Krulis, Frantisek Plásil, Danylo Khalyeyev, Sebastian Hahner, Stephan Seifermann, Maximilian Walter, Robert Heinrich |
Int. J. Softw. Tools Technol. Transf. | 7 |
| 2022 | Accurate Performance Predictions with Component-Based Models of Data Streaming Applications
Dominik Werle, Stephan Seifermann, Anne Koziolek |
ECSA | 2 |
| 2022 | Handling Environmental Uncertainty in Design Time Access Control AnalysisabstractThe high complexity, connectivity, and data exchange of modern software systems make it crucial to consider confidentiality early. An often used mechanism to ensure confidentiality is access control. When the system is modeled during design time, access control can already be analyzed. This enables early identification of confidentiality violations and the ability to analyze the impact of what-if scenarios. However, due to the abstract view of the design time model and the ambiguity in the early stages of development, uncertainties exist in the system environment. These uncertainties can have a direct effect on the validity of access control attributes in use, which might result in compromised confidentiality.To handle such known uncertainty, we present a notion of confidence in the context of design time access control. We define confidence as a composition of known uncertainties in the environment of the system, which influence the validity of access control attributes. We extend an existing modeling and analysis approach for design time access control with our notion of confidence. For evaluation, we apply the notion of confidence to multiple real-world case studies and discuss the resulting benefits for different stages of system development. We also analyze the expressiveness of the extended approach in defining confidentiality constraints and measure the accuracy in identifying confidentiality violations. Our results show that using the notion of confidence increases expressiveness while being able to accurately identify access control violations. Nicolas Boltz, Sebastian Hahner, Maximilian Walter, Stephan Seifermann, Robert Heinrich, Tomás Bures, Petr Hnetynka |
SEAA | 4 |
| 2022 | Attuning Adaptation Rules via a Rule-Specific Neural Network
Tomás Bures, Petr Hnetynka, Martin Krulis, Frantisek Plásil, Danylo Khalyeyev, Sebastian Hahner, Stephan Seifermann, Maximilian Walter, Robert Heinrich |
ISoLA (3) | 7 |
| 2022 | Detecting violations of access control and information flow policies in data flow diagramsabstractThe security of software-intensive systems is frequently attacked. High fines or loss in reputation are potential consequences of not maintaining confidentiality, which is an important security objective. Detecting confidentiality issues in early software designs enables cost-efficient fixes. A Data Flow Diagram (DFD) is a modeling notation, which focuses on essential, functional aspects of such early software designs. Existing confidentiality analyses on DFDs support either information flow control or access control, which are the most common confidentiality mechanisms. Combining both mechanisms can be beneficial but existing DFD analyses do not support this. This lack of expressiveness requires designers to switch modeling languages to consider both mechanisms, which can lead to inconsistencies. In this article, we present an extended DFD syntax that supports modeling both, information flow and access control, in the same language. This improves expressiveness compared to related work and avoids inconsistencies. We define the semantics of extended DFDs by clauses in first-order logic. A logic program made of these clauses enables the automated detection of confidentiality violations by querying it. We evaluate the expressiveness of the syntax in a case study. We attempt to model nine information flow cases and six access control cases. We successfully modeled fourteen out of these fifteen cases, which indicates good expressiveness. We evaluate the reusability of models when switching confidentiality mechanisms by comparing the cases that share the same system design, which are three pairs of cases. We successfully show improved reusability compared to the state of the art. We evaluated the accuracy of confidentiality analyses by executing them for the fourteen cases that we could model. We experienced good accuracy. Stephan Seifermann, Robert Heinrich, Dominik Werle, Ralf Reussner |
J. Syst. Softw. | 1 |
| 2021 | Aspect-Oriented Adaptation of Access Control RulesabstractCyber-physical systems (CPS) and IoT systems are nowadays commonly designed as self-adaptive, endowing them with the ability to dynamically reconFigure to reflect their changing environment. This adaptation concerns also the security, as one of the most important properties of these systems. Though the state of the art on adaptivity in terms of security related to these systems can often deal well with fully anticipated situations in the environment, it becomes a challenge to deal with situations that are not or only partially anticipated. This uncertainty is however omnipresent in these systems due to humans in the loop, open-endedness and only partial understanding of the processes happening in the environment. In this paper, we partially address this challenge by featuring an approach for tackling access control in face of partially unanticipated situations. We base our solution on special kind of aspects that build on existing access control system and create a second level of adaptation that addresses the partially unanticipated situations by modifying access control rules. The approach is based on our previous work where we have analyzed and classified uncertainty in security and trust in such systems and have outlined the idea of access-control related situational patterns. The aspects that we present in this paper serve as means for application-specific specialization of the situational patterns. We showcase our approach on a simplified but real-life example in the domain of Industry 4.0 that comes from one of our industrial projects. Tomás Bures, Ilias Gerostathopoulos, Petr Hnetynka, Stephan Seifermann, Maximilian Walter, Robert Heinrich |
SEAA | 4 |
| 2021 | A Unified Model to Detect Information Flow and Access Control Violations in Software Architectures
Stephan Seifermann, Robert Heinrich, Dominik Werle, Ralf Reussner |
SECRYPT | 1 |
| 2020 | Data Stream Operations as First-Class Entities in Component-Based Performance Models
Dominik Werle, Stephan Seifermann, Anne Koziolek |
ECSA | 2 |
| 2020 | Capturing Dynamicity and Uncertainty in Security and Trust via Situational Patterns
Tomás Bures, Petr Hnetynka, Robert Heinrich, Stephan Seifermann, Maximilian Walter |
ISoLA (2) | 4 |
| 2019 | Data-Driven Software Architecture for Analyzing ConfidentialityabstractPreservation of confidentiality has become a crucial quality property of software systems that software vendors have to consider in each development phase. Especially, neglecting confidentiality constraints in the software architecture leads to severe issues in later phases that often are hard to correct. In contrast to the implementation phase, there is no support for systematically considering confidentiality in architectural design phases by means of data processing descriptions. To fill this gap, we introduce data flows in an architectural description language to enable simple definition of confidentiality constraints. Afterwards, we transform the software architecture specification to a logic program to find violated confidentiality constraints. In a case study-based evaluation, we apply the analysis to sixteen scenarios to show the accuracy of the approach. Stephan Seifermann, Robert Heinrich, Ralf Reussner |
ICSA | 1 |
| 2018 | UML4ALL Syntax - A Textual Notation for UML Diagrams
Claudia Loitsch, Karin Müller 0001, Stephan Seifermann, Jörg Henß, Sebastian Dieter Krach, Gerhard Jaworek, Rainer Stiefelhagen |
ICCHP (1) | 3 |
| 2016 | Guidelines for Accessible Textual UML Modeling Notations
Vanessa Petrausch, Stephan Seifermann, Karin Müller 0001 |
ICCHP (1) | 2 |
| 2016 | Survey on Textual Notations for the Unified Modeling LanguageabstractThe Unified Modeling Language (UML) has become the lingua franca of software description languages. Textual notations of UML are also accessible for visually impaired people and allow a more developer-oriented and compact presentation. There are many textual notations that largely differ in their syntax, coverage of the UML, user editing experience, and applicability in teams due to the lack of a standardized textual notation. The available surveys do not cover the academic state of the art, the editing experience and applicability in teams. This implies heavy effort for evaluating and selecting notations. This survey identifies textual notations for UML that can be used instead of or in combination with graphical notations, e.g. by collaborating teams or in different contexts. We identified and rated the current state of 16 known notations plus 15 notations that were not covered in previous surveys. 20 categories cover the applicability in engineering teams. No single editable textual notation has full UML coverage. The mean coverage is 2.7 diagram types and editing support varies between none and 7 out of 9 categories. The survey facilitates the otherwise unclear notation selection and can reduce selection effort. Stephan Seifermann, Henning Groenda |
MODELSWARD | 1 |
| 2016 | Architectural Data Flow AnalysisabstractQuality properties including performance, security and compliance are crucial for a system's success but are hard to prove, especially for complex systems. Data flow analyses support this but often only consider source code and thereby introduce high costs of repair. Data flow analyses on the architectural design level use call-and-return semantics or event-based communication between components but do not define data flows as first class entities or consider important runtime or deployment configurations. We propose introducing data flows as first class entities on the architectural level. Analyses ensure that systems meet the quality requirements even after changes in e.g. runtime or deployment configurations. Having data flows modeled as first class entities allows analyzing compliance with privacy laws, requirements for external service providers, and throughput requirements in big data scenarios on architectural level. The results allow early, cost-efficient fixing of issues. Stephan Seifermann |
WICSA | 1 |