VLDB 2026 Research / reviewers in the wild / expert
Maximilian Walter
dblp:226/7640
· DBLP profile ↗
9ranked-venue papers
2as first author
7since 2021 · last 2023
0000-0003-0358-6644ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 9 · 2 first-author · 7 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 2 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2023 | Architecture-Based Attack Path Analysis for Identifying Potential Security Incidents
Maximilian Walter, Robert Heinrich, Ralf Reussner |
ECSA | 1 |
| 2023 | Generating adaptation rule-specific neural networks
Tomás Bures, Petr Hnetynka, Martin Krulis, Frantisek Plásil, Danylo Khalyeyev, Sebastian Hahner, Stephan Seifermann, Maximilian Walter, Robert Heinrich |
Int. J. Softw. Tools Technol. Transf. | 8 |
| 2022 | Handling Environmental Uncertainty in Design Time Access Control AnalysisabstractThe high complexity, connectivity, and data exchange of modern software systems make it crucial to consider confidentiality early. An often used mechanism to ensure confidentiality is access control. When the system is modeled during design time, access control can already be analyzed. This enables early identification of confidentiality violations and the ability to analyze the impact of what-if scenarios. However, due to the abstract view of the design time model and the ambiguity in the early stages of development, uncertainties exist in the system environment. These uncertainties can have a direct effect on the validity of access control attributes in use, which might result in compromised confidentiality.To handle such known uncertainty, we present a notion of confidence in the context of design time access control. We define confidence as a composition of known uncertainties in the environment of the system, which influence the validity of access control attributes. We extend an existing modeling and analysis approach for design time access control with our notion of confidence. For evaluation, we apply the notion of confidence to multiple real-world case studies and discuss the resulting benefits for different stages of system development. We also analyze the expressiveness of the extended approach in defining confidentiality constraints and measure the accuracy in identifying confidentiality violations. Our results show that using the notion of confidence increases expressiveness while being able to accurately identify access control violations. Nicolas Boltz, Sebastian Hahner, Maximilian Walter, Stephan Seifermann, Robert Heinrich, Tomás Bures, Petr Hnetynka |
SEAA | 3 |
| 2022 | Architectural Attack Propagation Analysis for Identifying Confidentiality IssuesabstractExchanging data between different systems enables us to build new smart services and digitise various areas of our daily life. This digitalisation leads to more efficient usage of resources, and an increased monetary value. However, the connection of different systems also increases the number of potential vulnerabilities. The vulnerabilities on their own might be harmless, but attackers could build attack paths based on the combination of different vulnerabilities. Additionally, attackers might exploit existing access control policies to further propagate through the system. For analysing this dependency between vulnerabilities and access control policies, we extended an architecture description language (ADL) to model access control policies and specify vulnerabilities. We developed an attack propagation analysis operating on the extended ADL, which can help to determine confidentiality violations in a system. We evaluated our approach by analysing the accuracy and the effort compared to a manual analysis using different scenarios in three case studies. The results indicate that our analysis is capable of identifying attack paths and reducing the effort compared to manual detection. Maximilian Walter, Robert Heinrich, Ralf Reussner |
ICSA | 1 |
| 2022 | Attuning Adaptation Rules via a Rule-Specific Neural Network
Tomás Bures, Petr Hnetynka, Martin Krulis, Frantisek Plásil, Danylo Khalyeyev, Sebastian Hahner, Stephan Seifermann, Maximilian Walter, Robert Heinrich |
ISoLA (3) | 8 |
| 2021 | A Classification for Managing Software Engineering KnowledgeabstractThis taxonomy paper presents a novel way of knowledge engineering in the software engineering research community. Till now, research papers are organized digitally as documents, mostly in PDF files. Not much effort is spent on effective knowledge classification, retrieval, storage, and representation. In contrast to the current paper-based approach for knowledge documentation, we present a statement-based approach, where each statement is linked to arguments and data of its evidence as well as to related statements. We argue that in this way, knowledge will be easier to retrieve, compare, and evaluate in contrast to current paper-based knowledge engineering in scientific search engines and digital libraries. Therefore, we present as a first step a novel multi-dimensional classification for statements in software engineering research. Statements are classified according to their research object, their kind (e.g., relevance), and their underlying evidence. This classification is validated and extended with a first systematic literature review. Additionally, we provide an example for illustration purpose. Angelika Kaplan, Maximilian Walter, Robert Heinrich |
EASE | 2 |
| 2021 | Aspect-Oriented Adaptation of Access Control RulesabstractCyber-physical systems (CPS) and IoT systems are nowadays commonly designed as self-adaptive, endowing them with the ability to dynamically reconFigure to reflect their changing environment. This adaptation concerns also the security, as one of the most important properties of these systems. Though the state of the art on adaptivity in terms of security related to these systems can often deal well with fully anticipated situations in the environment, it becomes a challenge to deal with situations that are not or only partially anticipated. This uncertainty is however omnipresent in these systems due to humans in the loop, open-endedness and only partial understanding of the processes happening in the environment. In this paper, we partially address this challenge by featuring an approach for tackling access control in face of partially unanticipated situations. We base our solution on special kind of aspects that build on existing access control system and create a second level of adaptation that addresses the partially unanticipated situations by modifying access control rules. The approach is based on our previous work where we have analyzed and classified uncertainty in security and trust in such systems and have outlined the idea of access-control related situational patterns. The aspects that we present in this paper serve as means for application-specific specialization of the situational patterns. We showcase our approach on a simplified but real-life example in the domain of Industry 4.0 that comes from one of our industrial projects. Tomás Bures, Ilias Gerostathopoulos, Petr Hnetynka, Stephan Seifermann, Maximilian Walter, Robert Heinrich |
SEAA | 5 |
| 2020 | Context-Based Confidentiality Analysis for Industrial IoTabstractIn this research paper, we present an approach for an analysis process, which can find confidentiality issues in data-exchange, on the architectural level of Industrial Internet of Things software systems. Existing approaches provide an insufficient definition of dataflow or lack support of finely granulated information for providing confidentiality. Based on an existing modeling and analysis process for Data-Driven Software Architecture, we extend the role-based approach for access control, with a model to model transformation utilizing a context-based approach. Using a case study based evaluation we show that our approach works accurately and scales in a way that is feasible for big organizations. Nicolas Boltz, Maximilian Walter, Robert Heinrich |
SEAA | 2 |
| 2020 | Capturing Dynamicity and Uncertainty in Security and Trust via Situational Patterns
Tomás Bures, Petr Hnetynka, Robert Heinrich, Stephan Seifermann, Maximilian Walter |
ISoLA (2) | 5 |