Tino Jungebloud

dblp:180/7863 · DBLP profile ↗
← Back
6ranked-venue papers
2as first author
4since 2021 · last 2025
0000-0001-8319-9876ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 4 · 2 since 2021Security and privacy · 2 · 2 first-author · 2 since 2021
YearPublicationVenuePosition
2025 Model-based structural and behavioral cybersecurity risk assessment in system designs
abstract
Cybersecurity risk assessment has become a critical task in systems development and the operation of complex networked systems. However, current state-of-the-art approaches for detecting vulnerabilities, such as automated security testing or penetration testing, often result in late detection. Thus, there is a growing need for security by design, which involves conducting security-related analyses as early as possible in the system development life cycle. This paper proposes an integrated approach that combines static and dynamic hierarchical model-based security risk assessment. The approach enables early identification of security risks during system design, utilizing various models based on the Unified Modeling Language (UML), with lightweight extensions using profiles and stereotypes to capture security attributes like vulnerabilities and asset values. These security attributes are then used to compute relevant properties, including threat space, possible attack paths, and selected network-based security metrics. To facilitate dynamic security analysis, the UML model is subsequently translated into a deterministic and stochastic Petri net (DSPN). This translation allows for the dynamic analysis and simulation of the system’s state and behavior during an attack, capturing temporal aspects and probabilistic transitions. By representing system components and their interactions as modular Petri nets, the DSPN framework facilitates comprehensive simulation and analysis of possible attack scenarios. This also allows us to estimate time-based security metrics such as the duration required for an attacker to compromise system components. Consequently, this combined approach effectively addresses both static security analysis and dynamic state behavior, providing an integrated understanding of the system’s resilience against cyber threats. A real-world industrial case study illustrates the effectiveness of this approach. The underlying data originates from security assessments performed by Keen Security Labs, which were independently verified by BMW (Cai et al., 2019). Specifically, we present an infotainment system network model as implemented in multiple car models along with corresponding attack and defense models. We then demonstrate how the approach assesses the cybersecurity risk of such in-vehicle networks.
Tino Jungebloud, Nhung H. Nguyen, Dong Seong Kim 0001, Armin Zimmermann
Comput. Secur.1
2024 An Analysis and Simulation Framework for Systems with Classification Components
Francesco Bedini, Tino Jungebloud, Ralph Maschotta, Armin Zimmermann
MODELSWARD2
2023 Hierarchical Model-Based Cybersecurity Risk Assessment During System Design
Tino Jungebloud, Nhung H. Nguyen, Dong Seong Kim 0001, Armin Zimmermann
SEC1
2021 A Model-driven Implementation of PSCS Specification for C++
abstract
OMG's PSCS specification extends the execution model of fUML by precise runtime semantics for UML composite structures. With composite structures being a concept for describing structural properties of a model, the majority of execution semantics specified by PSCS concern analysis and processing of static information about the model's fine-grained structure at runtime. Using Model-To-Text-Transformation to generate source code, which serves as an input for PSCS's actual execution environment, the runtime level of model execution can be relieved by outsourcing analysis and processing of static information to the level of code generation. By inserting this step of preprocessing, the performance of the actual model execution at runtime can be improved. This paper introduces an implementation of the PSCS specification for C++ based on code generation using Model-to-Text-Transformation. Moreover, it presents a set of test models validating the correct functionality of the implementation a s well as a performance benchmark. The PSCS implementation presented by this paper was developed as a part of the MDE4CPP* project.
Maximilian Hammer, Ralph Maschotta, Alexander Wichmann, Tino Jungebloud, Francesco Bedini, Armin Zimmermann
MODELSWARD4
2016 An EMF-like UML Generator for C++
abstract
Model-driven architecture is a well-known approach for the development of complex software systems. The most famous tool chain is provided by Eclipse with the tools of the Eclipse modeling project. Like Eclipse itself, these tools are based on Java. However, there are numerous legacy software packages written in C++, which often use only an implicit meta-model. A real C++ implementation of this meta-model would be necessary instead to be used at run time. This paper presents a generator for C++ to create the classes, meta-model packages, and factories to realize modeling, transformation, validation, and comparison of UML models. It gives an overview of its workflow and major challenges. Moreover, a comparison between Java and C++ implementations is given, considering different benchmarks.
Sven Jäger 0002, Ralph Maschotta, Tino Jungebloud, Alexander Wichmann, Armin Zimmermann
MODELSWARD3
2016 Model-driven development of simulation-based system design tools
abstract
Analysis and validation using simulation is a helpful tool in systems engineering, but requires in-depth knowledge of various aspects of the system itself, used model classes, and an appropriate software tool. Usually, this expertise is spread over a number of team members, thus making it a non-trivial task. A domain-specific simulation-based system design tool (termed here simulation-based application, SBA) could fill this gap. It hides the complexity of the model from the system designer and allows to configure parameters and analyze results in one single application. The necessary extra effort in software development compared to a bare modeling tool can be reduced with techniques for model-driven development. This paper presents an approach to use such methods to improve the development of SBA as a case of domain-specific software product lines. The workflow is described as well as the existing meta-model and applied techniques from model-driven development. The paper also shows the necessary elements of a meta model to describe SBAs. An example shows the complete workflow using an example of a wireless sensor networks for avionic applications.
Sven Jäger 0002, Ralph Maschotta, Tino Jungebloud, Alexander Wichmann, Armin Zimmermann
SERA3