Ana Petrovska

dblp:183/8461 · DBLP profile ↗
← Back
7ranked-venue papers
1as first author
7since 2021 · last 2025
0000-0001-6280-2461ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 3 · 1 first-author · 3 since 2021Security and privacy · 2 · 2 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021Theory of computation · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
YearPublicationVenuePosition
2025 An Optimized Framework for DSPG Synthesis and Trust Network Analysis with Subjective Logic
Koffi Ismael Ouattara, Ana Petrovska, Ioannis Krontiris, Theodosis Dimitrakos, Frank Kargl
RuleML+RR2
2024 On Subjective Logic Trust Discount for Referral Paths
abstract
Subjective Logic (SL) enriches probabilistic logic by incorporating uncertainty and subjective belief ownership, enabling the expression of uncertainty about subjective beliefs. Unlike traditional probabilistic logics, SL 1) accommodates situations where different agents express beliefs about the same proposition, integrating the subjective nature and ownership of beliefs; and 2) addresses existing limitations in Dempster-Shafer Theory of evidence (DST), particularly in modelling trust transitivity. In modern computer systems, trust assessment extends beyond direct relationships to complex networks, necessitating the consideration of referral and direct trust relationships. This paper introduces a novel trust discount operator for referral edges in complex networks, addressing challenges in discounting trust across two and multiple referral edges. Through our empirical analysis, we demonstrate the effectiveness of the proposed operator and establish a relationship between path length and trustworthiness.
Koffi Ismael Ouattara, Ana Petrovska, Artur Hermann, Natasa Trkulja, Theodosis Dimitrakos, Frank Kargl
FUSION2
2024 Obligation Management Framework for Usage Control
abstract
Obligations were introduced in access and usage control as a mechanism to specify mandatory actions to be fulfilled as part of authorization. In this paper, we address challenges related to obligation management in access and usage control, focusing on the Abbreviated Language For Authorization (ALFA) and eXtensible Access Control Markup Language (XACML) standards. Firstly, we provide a comprehensive analysis of Combining Algorithms (CAs) to determine their influence on the selection and ordering of obligations and identify nondeterminism. We then propose solutions to eliminate such nondeterminism enabling policy authors to explicitly specify the intended behavior. Secondly, we discuss the recurrence of obligations in usage control that occurs due to policy re-evaluations, highlighting the need to execute some obligations only once. We address this problem by introducing a parameter that enables policy authors to explicitly specify whether they intend an obligation to recur or not. Thirdly, we highlight an ambiguity in obligation applicability to lifecycle phases (e.g., ongoing) in usage control, arising from the lack of explicit associations between obligations and phases in particular cases. To address this issue, we introduce a parameter that explicitly specifies the scope of an obligation, allowing policy authors to restrict obligations to a single phase or apply them to the entire authorization. Finally, we extend the functionality of the Obligation Manager (OM) component to combine all three solutions, providing deterministic obligation management.
Hussein Joumaa, Ali Hariri, Ana Petrovska, Oleksii Osliak, Theodosis Dimitrakos, Bruno Crispo
SACMAT3
2024 Generation of Tailored and Confined Datasets for IDS Evaluation in Cyber-Physical Systems
abstract
The state-of-the-art evaluation of an Intrusion Detection System (IDS) relies on benchmark datasets composed of the regular system's and potential attackers' behavior. The datasets are collected once and independently of the IDS under analysis. This paper questions this practice by introducing a methodology to elicit particularly challenging samples to benchmark a given IDS. In detail, we propose (1) six fitness functions quantifying the suitability of individual samples, particularly tailored for safety-critical cyber-physical systems, (2) a scenario-based methodology for attacks on networks to systematically deduce optimal samples in addition to previous datasets, and (3) a respective extension of the standard IDS evaluation methodology. We applied our methodology to two network-based IDSs defending an advanced driver assistance system. Our results indicate that different IDSs show strongly differing characteristics in their edge case classifications and that the original datasets used for evaluation do not include such challenging behavior. In the worst case, this causes a critical undetected attack, as we document for one IDS. Our findings highlight the need to tailor benchmark datasets to the individual IDS in a final evaluation step. Especially the manual investigation of selected samples from edge case classifications by domain experts is vital for assessing the IDSs.
Thomas Hutzelmann, Dominik Mauksch, Ana Petrovska, Alexander Pretschner
IEEE Trans. Dependable Secur. Comput.3
2022 Defining adaptivity and logical architecture for engineering (smart) self-adaptive cyber-physical systems
Ana Petrovska, Stefan Kugele, Thomas Hutzelmann, Theo Beffart, Sebastian Bergemann, Alexander Pretschner
Inf. Softw. Technol.1
2021 Towards a Taxonomy of Autonomous Systems
Stefan Kugele, Ana Petrovska, Ilias Gerostathopoulos
ECSA2
2021 Runtime verification for dynamic architectures
Diego Marmsoler, Ana Petrovska
J. Log. Algebraic Methods Program.2